Anonim / 2 lata, 10 miesięcy temu | Download | Plaintext | Odpowiedz |

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-05-2015 01
Ran by tomek i monika (administrator) on TOMEK-KOMPUTER on 29-05-2015 12:22:58
Running from C:\Users\tomek i monika\Downloads
Loaded Profiles: tomek i monika (Available Profiles: Tomek & tomek i monika & Ola)
Platform: Microsoft Windows 7 Home Premium  (X86) OS Language: Polski (Polska)
Internet Explorer Version 8 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.362.0\BBSvc.EXE
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Dolby Laboratories Inc.) C:\Program Files\Dolby Advanced Audio v2\pcee4.exe
(Vimicro) C:\Program Files\USB Camera\VM331STI.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
() C:\Program Files\Opera\29.0.1795.60_0\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.60_0\opera.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [1704028 2013-04-25] (IDT, Inc.)
HKLM\...\Run: [DolbyTrayApp] => C:\Program Files\Dolby Advanced Audio v2\pcee4.exe [508144 2012-08-31] (Dolby Laboratories Inc.)
HKLM\...\Run: [Dolby Advanced Audio v2] => C:\Program Files\Dolby Advanced Audio v2\pcee4.exe [508144 2012-08-31] (Dolby Laboratories Inc.)
HKLM\...\Run: [331BigDog] => C:\Program Files\USB Camera\VM331STI.EXE [548864 2013-03-12] (Vimicro)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2440944 2013-04-04] (Synaptics Incorporated)
HKLM\...\Run: [Energy Management] => C:\Program Files\Lenovo\Energy Management\Energy Management.exe [8000560 2012-03-10] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files\Lenovo\Energy Management\Utility.exe [5936984 2012-03-08] (Lenovo(beijing) Limited)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-21-2915525027-370040383-3215915631-1001\...\MountPoints2: {41f47948-6ca2-11e4-ad69-342387f7366c} - G:\Startme.exe
HKU\S-1-5-21-2915525027-370040383-3215915631-1001\...\MountPoints2: {659ab957-feea-11e3-b801-806e6f6e6963} - F:\autorun.exe
HKU\S-1-5-21-2915525027-370040383-3215915631-1001\...\MountPoints2: {f3a5e9a0-6fc3-11e4-ad79-342387f7366c} - G:\LaunchU3.exe -a
HKU\S-1-5-21-2915525027-370040383-3215915631-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> 
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
URLSearchHook: HKLM - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-10-20] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-10-20] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Winsock: Catalog5 000000000008 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corp.)
Winsock: Catalog5 000000000009 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 194.204.152.34 194.204.159.1

FireFox:
========
FF ProfilePath: C:\Users\tomek i monika\AppData\Roaming\Mozilla\Firefox\Profiles\dqb1irz0.default
FF SelectedSearchEngineuser_pref("browser.search.selectedEngine","Yahoo! Search");: user_pref("browser.search.selectedEngine","Yahoo! Search");
FF DefaultSearchEngineuser_pref("browser.search.defaultenginename","Yahoo! Search");: user_pref("browser.search.defaultenginename","Yahoo! Search");
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-10-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-10-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Extension: Sale Charger - C:\Users\tomek i monika\AppData\Roaming\Mozilla\Firefox\Profiles\dqb1irz0.default\Extensions\{999dfb75-830f-4be2-adf1-8e98cb386aa5}.xpi [2015-05-19]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: No Name - C:\Users\tomek i monika\AppData\Roaming\Mozilla\Firefox\Profiles\dqb1irz0.default\extensions\3733101e-a53a-4b86-997a-bfa5beb3325b@0c7de234-778a-4255-b4ca-cab0545a9f50.com [not found]
FF Extension: No Name - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\owt0nt0g.default\extensions\faststartff@gmail.com [not found]
FF Extension: No Name - C:\Users\tomek i monika\AppData\Roaming\Mozilla\Firefox\Profiles\dqb1irz0.default\extensions\0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com [not found]
FF Extension: No Name - C:\Users\tomek i monika\AppData\Roaming\Mozilla\Firefox\Profiles\dqb1irz0.default\extensions\3446275a-5477-4d33-bd0d-44b466c519cd@4bf28e24-5833-4fb8-88c3-cd8403bb6141.com [not found]

Chrome: 
=======
CHR Profile: C:\Users\tomek i monika\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\tomek i monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-15]
CHR Extension: (YouTube) - C:\Users\tomek i monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-15]
CHR Extension: (Google Search) - C:\Users\tomek i monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-15]
CHR Extension: (Gmail) - C:\Users\tomek i monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-15]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

Opera: 
=======
OPR Extension: (Sale Charger) - C:\Users\tomek i monika\AppData\Roaming\Opera Software\Opera Stable\Extensions\npgfkibkmennbfadphcpjejdpfaeaenh [2015-05-28]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [277488 2013-01-26] (Intel Corporation)
R3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [169752 2012-04-24] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [462088 2012-06-19] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-09-18] (Intel Corporation)
R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-09-18] (Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1931632 2015-04-12] (Electronic Arts)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [311378 2013-04-25] (IDT, Inc.) [File not signed]
S3 TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [792016 2015-02-09] (Tunngle.net GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
S2 tbsvc_1.10.0.15; "C:\Program Files\TermBlazer_1.10.0.15\Service\tbsvc.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [24672 2011-12-15] (Lenovo Corporation)
R3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [57856 2012-10-03] (Alcor Micro, Corp.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [174552 2013-03-27] (Broadcom Corporation.)
R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [16880 2013-02-22] (Intel Corporation)
R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [352752 2013-02-22] (Intel Corporation)
R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [796656 2013-02-22] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [108624 2013-03-04] (Qualcomm Atheros Co., Ltd.)
R0 LHDmgr; C:\Windows\System32\DRIVERS\LhdX86.sys [32352 2010-01-15] (Lenovo.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-03] (Intel Corporation)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [28656 2013-04-04] (Synaptics Incorporated)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [27136 2009-09-16] (Tunngle.net)
R1 tbfd_1_10_0_15; C:\Windows\System32\drivers\tbfd_1_10_0_15.sys [52720 2015-05-04] (TermBlazer)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [1002240 2013-03-15] (Vimicro Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-29 12:22 - 2015-05-29 12:23 - 00016210 _____ () C:\Users\tomek i monika\Downloads\FRST.txt
2015-05-29 12:22 - 2015-05-29 12:23 - 00000000 ____D () C:\FRST
2015-05-29 12:21 - 2015-05-29 12:21 - 01147392 _____ (Farbar) C:\Users\tomek i monika\Downloads\FRST.exe
2015-05-29 11:53 - 2015-05-29 11:53 - 00000000 ____D () C:\NPE
2015-05-29 11:51 - 2015-05-29 12:01 - 00000000 ____D () C:\Users\tomek i monika\AppData\Local\NPE
2015-05-29 10:41 - 2015-05-29 12:19 - 00000000 ____D () C:\ProgramData\Norton
2015-05-29 10:39 - 2015-05-29 10:40 - 115397264 ____N (Symantec Corporation) C:\Users\tomek i monika\Downloads\NS-TW-22.0.0-PL.exe
2015-05-28 13:10 - 2015-05-29 12:19 - 00500166 _____ () C:\Windows\PFRO.log
2015-05-28 13:10 - 2015-05-29 12:19 - 00000336 _____ () C:\Windows\setupact.log
2015-05-28 13:10 - 2015-05-28 13:10 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-28 13:07 - 2015-05-28 13:07 - 02222592 _____ () C:\Users\tomek i monika\Downloads\AdwCleaner.exe
2015-05-28 13:02 - 2015-05-28 13:02 - 00025582 _____ () C:\Users\tomek i monika\Documents\cc_20150528_130236.reg
2015-05-28 12:39 - 2015-05-28 12:39 - 00001093 _____ () C:\Users\Public\Desktop\Opera.lnk
2015-05-28 12:39 - 2015-05-28 12:39 - 00001093 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-05-26 16:54 - 2015-05-26 16:54 - 00550344 _____ () C:\Users\tomek i monika\Downloads\Setup (2).exe
2015-05-25 07:53 - 2015-05-25 07:54 - 00550328 _____ () C:\Users\tomek i monika\Downloads\Setup (1).exe
2015-05-24 17:51 - 2015-05-24 17:52 - 00550328 _____ () C:\Users\tomek i monika\Downloads\Setup.exe
2015-05-24 14:34 - 2015-05-24 14:38 - 369129490 _____ () C:\Users\Tomek\Desktop\dontstarve_steam 2015-05-24 14-34-48-160.avi
2015-05-24 11:50 - 2015-05-24 11:50 - 00550328 _____ () C:\Users\Tomek\Downloads\Setup.exe
2015-05-23 21:52 - 2015-05-23 21:52 - 00000663 _____ () C:\Users\Tomek\Documents\Losowe gry.lnk
2015-05-20 19:20 - 2015-05-20 19:20 - 00000651 _____ () C:\Users\Tomek\Desktop\pizap.com14321423596031.lnk
2015-05-20 08:10 - 2015-05-28 12:54 - 00000001 _____ () C:\Windows\system32\SetupComponents.exe
2015-05-19 18:03 - 2015-05-19 18:03 - 00004431 _____ () C:\Users\Tomek\Documents\hewhjavn.wlmp
2015-05-19 14:04 - 2015-05-19 14:05 - 00022016 _____ () C:\Users\Tomek\Desktop\Intro.VSP
2015-05-19 13:34 - 2015-05-19 13:34 - 00584210 _____ () C:\Users\Tomek\Downloads\Kid_Laugh-Mike_Koenig-1673908713.wav
2015-05-19 13:33 - 2015-05-19 13:33 - 00000067 _____ () C:\Users\Tomek\Desktop\Kid Laugh.url
2015-05-19 13:27 - 2015-05-19 13:27 - 00000000 ____D () C:\Users\Tomek\AppData\Local\CrashDumps
2015-05-19 13:27 - 2015-05-19 13:27 - 00000000 ____D () C:\Users\tomek i monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Lunch Design
2015-05-19 13:23 - 2015-05-19 13:23 - 00000000 ____D () C:\Users\Tomek\Documents\Corel VideoStudio MW
2015-05-19 13:22 - 2015-05-19 20:46 - 00000000 ___RD () C:\Users\Tomek\Desktop\takie
2015-05-19 13:22 - 2015-05-19 20:39 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\Ulead Systems
2015-05-19 13:22 - 2015-05-19 13:36 - 00000000 ____D () C:\Users\Tomek\Documents\Corel VideoStudio Pro
2015-05-19 13:20 - 2015-05-19 13:22 - 00000000 ____D () C:\ProgramData\Protexis
2015-05-19 13:19 - 2015-05-19 13:19 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
2015-05-19 13:19 - 2015-05-19 13:19 - 00000000 ____D () C:\Program Files\Haali
2015-05-19 13:12 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2015-05-19 13:12 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2015-05-19 13:08 - 2015-05-19 20:44 - 00000000 ____D () C:\Program Files\Corel
2015-05-19 13:07 - 2015-05-19 13:07 - 1344094600 _____ (Acresso Software Inc.) C:\Users\Tomek\Downloads\VideoStudioX8_LimitedTrial_32bit.exe
2015-05-19 12:47 - 2015-05-19 12:47 - 00711936 _____ (Internet Program Web ) C:\Users\Tomek\Downloads\Corel-VideoStudio-Pro(16277)-dp.exe
2015-05-18 09:16 - 2015-05-18 09:20 - 00000000 ____D () C:\Users\Tomek\Desktop\Youtube gra
2015-05-18 09:16 - 2015-05-18 09:16 - 05042538 _____ () C:\Users\Tomek\Downloads\TubeTycoon-InDev-0.4.zip
2015-05-17 17:49 - 2015-05-24 19:41 - 00000000 ____D () C:\Users\Tomek\Documents\Electronic Arts
2015-05-17 17:48 - 2015-05-17 17:48 - 03391420 _____ () C:\Users\Tomek\Downloads\k8fhaiclara (1) (1).zip
2015-05-17 17:47 - 2015-05-17 17:47 - 03391420 _____ () C:\Users\Tomek\Downloads\k8fhaiclara (1).zip
2015-05-17 17:47 - 2015-05-17 17:47 - 00207845 _____ () C:\Users\Tomek\Downloads\k8-parsimonious-artisanssimple-sculptingstation-160910.zip
2015-05-17 17:47 - 2015-05-17 17:47 - 00093640 _____ () C:\Users\Tomek\Downloads\k8-parsimonious-contemporary-toybox-140212.zip
2015-05-17 17:46 - 2015-05-17 17:46 - 00402258 _____ () C:\Users\Tomek\Downloads\k8-parsimonious-alchemy-chemistrytable-010212.zip
2015-05-17 17:43 - 2015-05-17 17:43 - 00641466 _____ () C:\Users\Tomek\Downloads\k8-terrain-barn-daisyindaisies-071712.zip
2015-05-17 17:43 - 2015-05-17 17:43 - 00429799 _____ () C:\Users\Tomek\Downloads\k8-terrain-supernatural-thecastlepath2-080912.zip
2015-05-17 17:43 - 2015-05-17 17:43 - 00341496 _____ () C:\Users\Tomek\Downloads\k8-terrain-supernatural-thelostpath-light-080912.zip
2015-05-17 17:43 - 2015-05-17 17:43 - 00304679 _____ () C:\Users\Tomek\Downloads\k8-terrain-supernatural-thelostpath-dark-080912.zip
2015-05-17 17:43 - 2015-05-17 17:43 - 00099114 _____ () C:\Users\Tomek\Downloads\k8-wallpaper-latheatre-wall4-061611.zip
2015-05-17 17:43 - 2015-05-17 17:43 - 00088322 _____ () C:\Users\Tomek\Downloads\k8-wallpaper-latheatre-wall2-061611.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 01388233 _____ () C:\Users\Tomek\Downloads\k8foutwinterpjselder.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 01382748 _____ () C:\Users\Tomek\Downloads\k8foutwinterpjs.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00870872 _____ () C:\Users\Tomek\Downloads\k8foutloungedresssslacks.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00661298 _____ () C:\Users\Tomek\Downloads\k8foutathenateen.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00660003 _____ () C:\Users\Tomek\Downloads\k8foutathenaadult.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00646483 _____ () C:\Users\Tomek\Downloads\k8foutsupersleeksuit.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00572035 _____ () C:\Users\Tomek\Downloads\k8foutshortiesundress.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00510970 _____ () C:\Users\Tomek\Downloads\k8foutdriftdance.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00269866 _____ () C:\Users\Tomek\Downloads\k8foutsummertime.zip
2015-05-17 17:42 - 2015-05-17 17:42 - 00198090 _____ () C:\Users\Tomek\Downloads\k8foutmidnightrain.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00359946 _____ () C:\Users\Tomek\Downloads\k8fshotukmaryjanes.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00327586 _____ () C:\Users\Tomek\Downloads\k8shogogoboots.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00262743 _____ () C:\Users\Tomek\Downloads\k8fcorvintagevictoriacorset.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00181919 _____ () C:\Users\Tomek\Downloads\k8fsholatexkneeboots.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00164804 _____ () C:\Users\Tomek\Downloads\k8fshoconversefa.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00163501 _____ () C:\Users\Tomek\Downloads\k8ushoconverseunisexchild.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00138907 _____ () C:\Users\Tomek\Downloads\k8fshopilgrimboot.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00121977 _____ () C:\Users\Tomek\Downloads\k8fshopixieboot.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00090950 _____ () C:\Users\Tomek\Downloads\k8fshochichijanes.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00090950 _____ () C:\Users\Tomek\Downloads\k8fshochichijanes (1).zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00090402 _____ () C:\Users\Tomek\Downloads\k8fshoofficepeepwedgeboot.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00079373 _____ () C:\Users\Tomek\Downloads\k8fshogardenerswellies.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00074522 _____ () C:\Users\Tomek\Downloads\k8fshostripperheels.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00059607 _____ () C:\Users\Tomek\Downloads\k8fshopartygurlheels.zip
2015-05-17 17:41 - 2015-05-17 17:41 - 00033859 _____ () C:\Users\Tomek\Downloads\k8fshoplatformmaryjanes.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 03391420 _____ () C:\Users\Tomek\Downloads\k8fhaiclara.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 01204642 _____ () C:\Users\Tomek\Downloads\k8fhainichole.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 00486514 _____ () C:\Users\Tomek\Downloads\k8shoslipperbootsteen.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 00486032 _____ () C:\Users\Tomek\Downloads\k8shoslipperbootsadult.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 00443489 _____ () C:\Users\Tomek\Downloads\k8shoslipperbootsbaby.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 00156333 _____ () C:\Users\Tomek\Downloads\k8fhaipeggysue.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 00127546 _____ () C:\Users\Tomek\Downloads\k8fhaitaratiara.zip
2015-05-17 17:40 - 2015-05-17 17:40 - 00118985 _____ () C:\Users\Tomek\Downloads\k8fhaiharrietta.zip
2015-05-17 17:34 - 2015-05-17 17:34 - 05355192 _____ () C:\Users\Tomek\Downloads\Skysims-hair-194.package
2015-05-15 16:38 - 2015-05-15 16:39 - 00039175 _____ () C:\Users\Tomek\Downloads\download_repair (3).htm
2015-05-15 16:37 - 2015-05-15 16:38 - 00039175 _____ () C:\Users\Tomek\Downloads\download_repair (2).htm
2015-05-11 16:06 - 2015-05-11 16:14 - 121440076 _____ () C:\Users\Tomek\Desktop\bandicam 2015-05-11 16-06-08-284.avi
2015-05-11 08:13 - 2015-05-11 08:16 - 88124086 _____ () C:\Users\Tomek\Desktop\TS4 2015-05-11 08-13-26-587.avi
2015-05-11 08:01 - 2015-05-11 08:08 - 191886134 _____ () C:\Users\Tomek\Desktop\TS4 2015-05-11 08-01-50-533.avi
2015-05-10 17:50 - 2015-05-24 14:43 - 00000000 ____D () C:\Users\Tomek\Desktop\Filmy youtube
2015-05-10 16:16 - 2015-05-10 16:16 - 00000132 _____ () C:\Users\Tomek\Desktop\sims-4-worldwide-release-panned-critics-players-missing-features-1678988.url
2015-05-10 16:01 - 2015-05-10 16:01 - 00009097 _____ () C:\Users\Tomek\Desktop\Mój film 1.wlmp
2015-05-10 13:59 - 2015-05-10 13:59 - 00001251 _____ () C:\Users\Tomek\Desktop\Movie Maker.lnk
2015-05-09 14:30 - 2015-05-09 14:30 - 00002667 _____ () C:\Users\Tomek\Documents\Ble.wlmp
2015-05-08 13:05 - 2015-05-08 13:05 - 00007566 _____ () C:\Users\Tomek\Documents\Przegląd-Arka #1.wlmp
2015-05-08 12:16 - 2015-05-10 09:34 - 00000000 ____D () C:\Users\Tomek\AppData\Local\Razer
2015-05-08 12:16 - 2015-05-10 09:34 - 00000000 ____D () C:\ProgramData\Razer
2015-05-08 11:59 - 2015-05-08 11:59 - 00741672 _____ (Web software ) C:\Users\Tomek\Downloads\HyperCam(12897)-dp.exe
2015-05-07 21:01 - 2015-05-07 21:01 - 00004984 _____ () C:\Users\Tomek\Documents\Mój film.wlmp
2015-05-07 20:06 - 2015-05-07 10:21 - 47920857 ____N () C:\Users\Tomek\Desktop\CAM01035.mp4
2015-05-07 19:55 - 2015-05-07 19:55 - 00001251 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-05-07 19:55 - 2015-05-07 19:55 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-05-07 19:55 - 2015-05-07 19:55 - 00000000 ____D () C:\Windows\pl
2015-05-07 19:55 - 2014-03-31 21:36 - 00049856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fssfltr.sys
2015-05-07 19:54 - 2015-05-24 14:47 - 00000000 ____D () C:\Users\Tomek\Documents\Bandicam
2015-05-07 19:54 - 2015-05-07 19:54 - 00001320 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-05-07 19:54 - 2015-05-07 19:54 - 00000946 _____ () C:\Users\Tomek\Desktop\Bandicam.lnk
2015-05-07 19:54 - 2015-05-07 19:54 - 00000946 _____ () C:\Users\Ola\Desktop\Bandicam.lnk
2015-05-07 19:54 - 2015-05-07 19:54 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\BANDISOFT
2015-05-07 19:54 - 2015-05-07 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2015-05-07 19:54 - 2015-05-07 19:54 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2015-05-07 19:53 - 2015-05-07 19:54 - 00000000 ____D () C:\Program Files\Bandicam
2015-05-07 19:53 - 2015-05-07 19:53 - 00002432 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-05-07 19:53 - 2015-05-07 19:53 - 00001404 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-05-07 19:53 - 2015-05-07 19:53 - 00000000 ____D () C:\Program Files\BandiMPEG1
2015-05-07 19:52 - 2015-05-07 19:55 - 00000000 ____D () C:\Program Files\Windows Live
2015-05-07 19:52 - 2015-05-07 19:52 - 09864192 _____ (Bandisoft) C:\Users\Tomek\Downloads\bdcamsetup.exe
2015-05-07 19:52 - 2015-05-07 19:52 - 00741672 _____ (Web software ) C:\Users\Tomek\Downloads\Bandicam(30315)-dp.exe
2015-05-07 19:52 - 2015-05-07 19:52 - 00000000 ____D () C:\Windows\PCHEALTH
2015-05-07 19:50 - 2015-05-07 19:50 - 00000000 ___RD () C:\Users\Tomek\OneDrive
2015-05-07 19:50 - 2015-05-07 19:50 - 00000000 ____D () C:\Program Files\Microsoft OneDrive
2015-05-07 19:49 - 2015-05-07 19:49 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2015-05-07 19:49 - 2010-08-11 06:44 - 02983424 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2015-05-07 19:49 - 2010-08-11 06:35 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2015-05-07 19:47 - 2010-05-23 12:15 - 01619456 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2015-05-07 19:47 - 2010-05-23 12:11 - 03181568 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-05-07 19:47 - 2010-05-23 12:11 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2015-05-07 19:45 - 2015-05-19 14:17 - 00000000 ____D () C:\Users\Tomek\AppData\Local\Windows Live
2015-05-07 19:42 - 2015-05-07 19:42 - 01245896 _____ (Microsoft Corporation) C:\Users\Tomek\Downloads\Windows Movie Maker 16.4.3528.0331 [1].exe
2015-05-07 19:41 - 2015-05-07 19:41 - 00686504 _____ (Application Program web ) C:\Users\Tomek\Downloads\Windows Movie Maker 16.4.3528.0331.exe
2015-05-06 18:48 - 2015-05-10 09:34 - 00000000 ___RD () C:\Users\Tomek\Documents\MAGIX
2015-05-06 18:48 - 2015-05-10 09:34 - 00000000 ____D () C:\ProgramData\MAGIX
2015-05-06 18:48 - 2015-05-10 09:34 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2015-05-06 18:48 - 2015-05-06 18:48 - 00000000 ____D () C:\Program Files\MSXML 4.0
2015-05-06 18:48 - 2013-08-23 12:19 - 00120200 _____ () C:\Windows\system32\DLLDEV32i.dll
2015-05-06 18:38 - 2015-05-06 18:51 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\MAGIX
2015-05-06 18:38 - 2015-05-06 18:38 - 02860656 _____ (MAGIX AG) C:\Users\Tomek\Downloads\trial_videoeasy5_dlm.exe
2015-05-06 18:37 - 2015-05-06 18:37 - 00741672 _____ (Web software ) C:\Users\Tomek\Downloads\Corel-MotionStudio-3D(27917)-dp.exe
2015-05-06 17:48 - 2015-05-06 18:20 - 00000000 ____D () C:\Users\Tomek\Desktop\CAM01030
2015-05-06 17:42 - 2015-05-06 17:42 - 00001242 _____ () C:\Users\Tomek\Desktop\Paint.lnk
2015-05-06 17:41 - 2015-05-06 17:41 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
2015-05-06 17:40 - 2015-05-06 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
2015-05-06 17:40 - 2015-05-06 17:41 - 00000000 ____D () C:\Program Files\Common Files\AVSMedia
2015-05-06 17:39 - 2015-05-06 17:41 - 00000000 ____D () C:\Program Files\AVS4YOU
2015-05-06 17:39 - 2010-05-11 13:17 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msxml3a.dll
2015-05-06 17:36 - 2015-05-06 17:38 - 153899920 _____ (Online Media Technologies Ltd. ) C:\Users\Tomek\Downloads\AVSVideoEditor.exe
2015-05-06 17:14 - 2015-05-06 18:35 - 00005120 _____ () C:\Users\Tomek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-06 17:07 - 2015-05-06 17:07 - 17385800 _____ (Google Inc.) C:\Users\Tomek\Downloads\picasa39-setup.exe
2015-05-06 17:06 - 2015-05-06 17:06 - 01242304 _____ (Microsoft Corporation) C:\Users\Tomek\Downloads\wlsetup-we_ES.exe
2015-05-06 17:06 - 2015-05-06 17:06 - 00000000 ____D () C:\Program Files\Common Files\Windows Live
2015-05-06 17:01 - 2015-05-06 17:01 - 00000000 ____D () C:\ProgramData\Ashampoo
2015-05-06 16:55 - 2015-05-06 16:55 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-05-06 16:54 - 2009-11-25 21:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2015-05-06 16:54 - 2009-11-25 21:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2015-05-06 16:54 - 2009-11-25 21:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2015-05-06 16:54 - 2009-11-25 21:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2015-05-06 16:54 - 2009-11-25 21:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2015-05-06 16:51 - 2015-05-06 16:51 - 232417608 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Tomek\Downloads\ashampoo_movie_studio_pro_e1.0.7_sm.exe
2015-05-06 16:42 - 2015-05-06 16:42 - 00741672 _____ (Web software ) C:\Users\Tomek\Downloads\Ashampoo-Movie-Studio-Pro(49099)-dp.exe
2015-05-04 21:00 - 2015-05-04 21:00 - 00052720 _____ (TermBlazer) C:\Windows\system32\Drivers\tbfd_1_10_0_15.sys
2015-04-30 21:52 - 2015-04-30 21:53 - 00437676 _____ () C:\Users\Tomek\Downloads\Wimmie_YF_metallicpatchworkdress.package
2015-04-30 21:11 - 2015-04-30 21:11 - 28082925 _____ () C:\Users\Tomek\Downloads\opowiesci_z_narnii_pl_patch_1.zip
2015-04-30 20:52 - 2015-04-30 20:52 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-04-30 20:52 - 2015-04-30 20:52 - 00000000 ____D () C:\ProgramData\Buena Vista Games
2015-04-30 20:40 - 2015-04-30 20:41 - 02217984 _____ (AGORA S.A.) C:\Users\Tomek\Downloads\Opowie-ci_z_Narnii_Sciagnij.pl.exe
2015-04-29 19:36 - 2015-04-29 19:36 - 00036734 _____ () C:\Windows\system32\OggDSuninst.exe
2015-04-29 19:36 - 2015-04-29 19:36 - 00000000 ____D () C:\Users\Tomek\Documents\Waterpark Tycoon
2015-04-29 19:36 - 2015-04-29 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterpark-Tycoon
2015-04-29 19:34 - 2015-04-29 19:34 - 00000000 ____D () C:\Program Files\astragon
2015-04-29 15:23 - 2015-04-29 15:27 - 103461775 _____ (astragon ) C:\Users\Tomek\Downloads\Symulator - Parku Wodnego.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-29 12:22 - 2014-09-24 07:00 - 01742292 _____ () C:\Windows\WindowsUpdate.log
2015-05-29 12:19 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-29 12:15 - 2009-07-14 06:34 - 00014336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-29 12:15 - 2009-07-14 06:34 - 00014336 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-29 11:55 - 2014-07-12 10:50 - 00000000 ___RD () C:\Program Files\Skype
2015-05-29 11:52 - 2014-07-01 16:49 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-29 11:37 - 2014-06-29 19:27 - 00000000 ____D () C:\Program Files\Dolby Advanced Audio v2
2015-05-28 13:14 - 2014-10-20 12:20 - 00000000 ____D () C:\AdwCleaner
2015-05-28 13:09 - 2014-08-14 15:23 - 00001019 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-28 13:02 - 2014-09-08 06:52 - 00000000 ____D () C:\Windows\Minidump
2015-05-28 12:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system
2015-05-28 12:53 - 2015-01-17 20:22 - 00000000 ____D () C:\Users\Tomek\AppData\Local\ICSharpCode.net
2015-05-28 12:42 - 2014-10-20 11:03 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-28 12:41 - 2014-10-20 11:03 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-28 12:41 - 2014-10-20 11:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-28 12:41 - 2014-10-20 11:03 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-05-28 12:40 - 2014-07-23 14:34 - 00000000 ____D () C:\Users\tomek i monika\AppData\Roaming\Opera Software
2015-05-28 12:40 - 2014-07-23 14:34 - 00000000 ____D () C:\Users\tomek i monika\AppData\Local\Opera Software
2015-05-28 12:40 - 2014-07-19 09:02 - 00000000 ____D () C:\Program Files\Opera
2015-05-28 12:35 - 2014-07-02 15:35 - 00001421 _____ () C:\Users\tomek i monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-28 12:22 - 2014-09-13 12:36 - 00000000 ____D () C:\ProgramData\Origin
2015-05-28 12:11 - 2014-07-12 10:50 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\Skype
2015-05-27 03:17 - 2015-01-17 20:36 - 00000091 _____ () C:\Users\Tomek\AppData\Roaming\WB.CFG
2015-05-26 14:29 - 2014-07-18 09:16 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\.minecraft
2015-05-26 09:32 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-24 21:33 - 2015-03-14 16:35 - 00000000 ____D () C:\ProgramData\Tunngle
2015-05-24 21:33 - 2015-03-01 13:09 - 00000000 ____D () C:\Users\Tomek\AppData\Roaming\Tunngle
2015-05-24 21:07 - 2014-07-12 13:03 - 00000000 ____D () C:\Users\tomek i monika\AppData\Roaming\Skype
2015-05-24 16:43 - 2014-06-28 19:46 - 01664708 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-24 16:43 - 2009-07-14 10:07 - 00738706 _____ () C:\Windows\system32\perfh015.dat
2015-05-24 16:43 - 2009-07-14 10:07 - 00154784 _____ () C:\Windows\system32\perfc015.dat
2015-05-24 16:28 - 2014-07-02 17:55 - 00109672 _____ () C:\Users\tomek i monika\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-20 19:21 - 2014-06-29 19:48 - 00109672 _____ () C:\Users\Tomek\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-20 08:09 - 2009-07-14 06:33 - 00386344 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-19 13:11 - 2014-09-13 13:45 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-17 17:48 - 2014-10-12 11:02 - 00000000 ____D () C:\Users\Tomek\Desktop\gry moje
2015-05-10 09:41 - 2014-07-13 17:05 - 00000000 ____D () C:\Users\Tomek\AppData\Local\Google
2015-05-08 16:28 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-07 19:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-05-07 19:50 - 2014-06-28 19:42 - 00000000 ____D () C:\Users\Tomek
2015-05-07 19:39 - 2014-07-13 17:05 - 00000000 ____D () C:\Program Files\Google
2015-05-07 19:08 - 2015-03-01 13:18 - 00000000 ____D () C:\Users\tomek i monika\Documents\tita
2015-05-06 16:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\pl-PL

==================== Files in the root of some directories =======

2014-06-29 19:28 - 2014-06-29 19:28 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Ola\AppData\Local\Temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-26 17:54

==================== End of log ============================