Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 16-09-2017 Uruchomiony przez pawel (administrator) PAWEL-KOMPUTER (16-09-2017 13:05:08) Uruchomiony z D:\Programy\FRST64 Załadowane profile: pawel (Dostępne profile: pawel) Platform: Windows 7 Home Basic Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 8 (Domyślna przeglądarka: "D:\Programy\Mozilla\firefox.exe" -osint -url "%1") Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe (Hi-Rez Studios) D:\Gry\Hi-Rez\HiPatchService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe () D:\Gry\RivaTuner Statistics Server\RTSS.exe () D:\Programy\MSI Afterburner\MSIAfterburner.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe () C:\Program Files (x86)\Google\Drive\googledrivesync.exe (DT Soft Ltd) D:\Programy\DAEMON Tools Pro\DTShellHlp.exe () C:\Program Files (x86)\Google\Drive\googledrivesync.exe () D:\Gry\RivaTuner Statistics Server\EncoderServer.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avpui.exe () C:\Windows\System32\PnkBstrA.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe () D:\Gry\RivaTuner Statistics Server\RTSSHooksLoader64.exe () D:\Programy\qBittorrent\qbittorrent.exe (Valve Corporation) D:\Gry\STEAM\Steam.exe (Valve Corporation) D:\Gry\STEAM\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) D:\Gry\STEAM\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) D:\Gry\STEAM\bin\cef\cef.win7\steamwebhelper.exe (Mozilla Corporation) D:\Programy\Mozilla\firefox.exe (MPC-HC Team) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Rejestr (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKU\S-1-5-21-1914535750-134526615-2474134899-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [40257336 2017-08-31] () HKU\S-1-5-21-1914535750-134526615-2474134899-1000\...\MountPoints2: {7d5ca268-9777-11e6-9d17-bcaec52a899b} - G:\LaunchU3.exe -a BootExecute: autocheck autochk * ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 195.88.28.30 Tcpip\..\Interfaces\{FE420FAD-1EA1-490F-9A0E-214FF6F099D9}: [DhcpNameServer] 195.88.28.30 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-1914535750-134526615-2474134899-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-1914535750-134526615-2474134899-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab) BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab) Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab) Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: 01nfsorl.default-1481237936833-1503743269485 FF ProfilePath: C:\Users\pawel\AppData\Roaming\Mozilla\Firefox\Profiles\01nfsorl.default-1481237936833-1503743269485 [2017-09-16] FF Homepage: Mozilla\Firefox\Profiles\01nfsorl.default-1481237936833-1503743269485 -> gogle.pl FF Extension: (Double-click Image Downloader) - C:\Users\pawel\AppData\Roaming\Mozilla\Firefox\Profiles\01nfsorl.default-1481237936833-1503743269485\Extensions\jid1-xgtdawe3yyUeBQ@jetpack.xpi [2017-09-03] FF Extension: (Bulk Image Downloader) - C:\Users\pawel\AppData\Roaming\Mozilla\Firefox\Profiles\01nfsorl.default-1481237936833-1503743269485\Extensions\{524B8EF8-C312-11DB-8039-536F56D89593}.xpi [2017-09-03] FF Extension: (Adblock Plus) - C:\Users\pawel\AppData\Roaming\Mozilla\Firefox\Profiles\01nfsorl.default-1481237936833-1503743269485\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-08-26] FF Extension: (DownThemAll!) - C:\Users\pawel\AppData\Roaming\Mozilla\Firefox\Profiles\01nfsorl.default-1481237936833-1503743269485\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2017-09-02] FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-08-11] FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2017-01-01] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2017-01-01] () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-27] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-27] (Google Inc.) StartMenuInternet: FIREFOX.EXE - D:\Programy\Mozilla\firefox.exe Chrome: ======= CHR Profile: C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default [2017-09-11] CHR Extension: (Prezentacje Google) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-08-27] CHR Extension: (Dokumenty Google) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-08-27] CHR Extension: (Dysk Google) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-27] CHR Extension: (YouTube) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-27] CHR Extension: (Arkusze Google) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-08-27] CHR Extension: (Kaspersky Protection) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-08-27] CHR Extension: (Dokumenty Google offline) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-09-06] CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2017-09-06] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-27] CHR Extension: (Gmail) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-27] CHR Extension: (Chrome Media Router) - C:\Users\pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-27] CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib CHR HKU\S-1-5-21-1914535750-134526615-2474134899-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\pawel\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-10-27] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1530888 2017-07-29] () S4 Bonjour Service; C:\Program Files (x86)\Blizzard\Bonjour Service\mDNSResponder.exe [390504 2017-04-19] (Apple Inc.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [383016 2017-07-21] (EasyAntiCheat Ltd) S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [487488 2017-07-28] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [8163392 2017-07-13] (GOG.com) U2 HiPatchService; D:\Gry\Hi-Rez\HiPatchService.exe [9728 2017-07-12] (Hi-Rez Studios) [Brak podpisu cyfrowego] S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [7987104 2017-04-10] (INCA Internet Co., Ltd.) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-08-10] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-08-10] (NVIDIA Corporation) S3 Origin Client Service; D:\Gry\Origin\OriginClientService.exe [2098528 2017-08-23] (Electronic Arts) S2 Origin Web Helper Service; D:\Gry\Origin\OriginWebHelperService.exe [2977640 2017-08-23] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2017-07-23] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-07-22] () S2 SkypeUpdate; D:\Programy\Skype\Updater\Updater.exe [317400 2017-04-05] (Skype Technologies) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270704 2013-07-10] (Western Digital Technologies, Inc.) S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2016-11-24] (DT Soft Ltd) R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2017-05-13] (Glarysoft Ltd) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [195264 2017-08-11] (AO Kaspersky Lab) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [314840 2017-08-11] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1038528 2017-08-11] (AO Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [57936 2017-03-29] (AO Kaspersky Lab) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [52144 2016-05-19] (AO Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AO Kaspersky Lab) R3 kltap; C:\Windows\System32\DRIVERS\kltap.sys [52152 2016-06-07] (The OpenVPN Project) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [75696 2016-05-17] (AO Kaspersky Lab) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [135904 2017-03-29] (AO Kaspersky Lab) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [199640 2017-08-11] (AO Kaspersky Lab) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56376 2016-10-01] (NVIDIA Corporation) S1 prodrv06; C:\Windows\SysWOW64\drivers\prodrv06.sys [52224 2004-01-26] (Protection Technology) [Brak podpisu cyfrowego] S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [95552 2004-01-26] (Protection Technology) [Brak podpisu cyfrowego] R3 RTCore64; D:\Programy\MSI Afterburner\RTCore64.sys [13512 2016-09-02] () S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology) [Brak podpisu cyfrowego] R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [132120 2016-10-18] (Oracle Corporation) R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [206416 2016-10-18] (Oracle Corporation) S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [138896 2016-10-18] (Oracle Corporation) S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S3 MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-09-16 10:52 - 2017-09-16 10:52 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\David Wehle 2017-09-16 10:49 - 2017-09-16 10:52 - 000000000 ____D C:\Users\pawel\AppData\Roaming\ToothAndTail 2017-09-16 09:34 - 2017-09-16 09:34 - 000000000 ____D C:\Program Files (x86)\Ubisoft 2017-09-16 09:08 - 2017-09-16 09:08 - 000000000 ____D C:\Users\pawel\AppData\Local\PyramazeTheGame 2017-09-16 09:07 - 2017-09-16 09:07 - 000000000 ____D C:\Users\pawel\AppData\Local\Crashpad 2017-09-16 08:59 - 2017-09-16 08:59 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Roger Barton 2017-09-16 08:54 - 2017-09-16 08:54 - 000000000 ____D C:\Users\pawel\AppData\Roaming\com.ediogames.ub.steam 2017-09-16 08:37 - 2017-09-16 08:37 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Iceberg Interactive 2017-09-16 07:51 - 2017-09-16 07:51 - 000000206 _____ C:\Users\pawel\Desktop\MONITOR The Game.url 2017-09-16 06:59 - 2017-09-16 06:59 - 000045059 _____ C:\Users\pawel\Desktop\przelew.pdf 2017-09-16 06:52 - 2017-09-16 06:52 - 032200506 _____ C:\Users\pawel\Desktop\politechnika_czestochowska_informator_o_studiach_2017.pdf 2017-09-15 16:31 - 2017-09-15 16:31 - 000000000 ____D C:\Users\pawel\AppData\Local\Tactics 2017-09-15 15:44 - 2017-09-15 15:44 - 000000204 _____ C:\Users\pawel\Desktop\Psychonauts.url 2017-09-14 20:35 - 2017-09-14 20:35 - 000000000 ____D C:\Users\pawel\Documents\Brawl of Ages 2017-09-14 20:24 - 2017-09-14 20:24 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Pixel Constructor, LLC 2017-09-14 19:21 - 2017-09-15 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Port Royale 2017-09-14 19:21 - 2017-09-14 19:21 - 000000000 ____D C:\Users\pawel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Port Royale 2017-09-13 04:44 - 2017-09-13 04:44 - 000000206 _____ C:\Users\pawel\Desktop\Hand of the Gods.url 2017-09-12 18:12 - 2017-09-12 18:12 - 000000206 _____ C:\Users\pawel\Desktop\Transport Defender.url 2017-09-12 15:27 - 2017-09-12 15:27 - 000000000 ____D C:\Users\Default\AppData\Local\Google 2017-09-12 15:27 - 2017-09-12 15:27 - 000000000 ____D C:\Users\Default User\AppData\Local\Google 2017-09-11 18:54 - 2017-09-11 18:54 - 000000000 ____D C:\Users\pawel\Documents\Square Enix 2017-09-11 17:50 - 2017-09-11 17:50 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Bad Seed SRL 2017-09-11 15:14 - 2017-09-11 15:14 - 000295424 _____ C:\Windows\system32\FNTCACHE.DAT 2017-09-11 15:12 - 2017-09-11 15:12 - 000064800 _____ C:\Users\pawel\AppData\Local\GDIPFONTCACHEV1.DAT 2017-09-10 23:51 - 2017-09-10 23:51 - 000003544 ____N C:\bootsqm.dat 2017-09-10 20:40 - 2017-09-10 20:40 - 000000000 ____D C:\Users\pawel\AppData\Local\World in Conflict 2017-09-10 10:14 - 2017-09-10 10:14 - 000000000 ____D C:\Users\pawel\Documents\Telltale Games 2017-09-10 08:49 - 2017-09-10 08:49 - 000000000 ____D C:\Users\pawel\AppData\Local\TBL 2017-09-09 21:12 - 2017-09-09 21:12 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Codename Entertainment 2017-09-09 19:54 - 2017-09-09 19:54 - 000001065 _____ C:\Users\pawel\Desktop\GetEven.lnk 2017-09-09 14:40 - 2017-09-09 14:52 - 000000000 ____D C:\Users\pawel\Documents\Stronghold 2017-09-09 13:15 - 2017-09-09 13:18 - 000000000 ____D C:\Users\pawel\AppData\Roaming\Nex Machina 2017-09-09 12:50 - 2017-09-09 12:50 - 000000000 ____D C:\Users\pawel\AppData\Local\ROA2 2017-09-09 11:54 - 2017-09-09 13:43 - 000000000 ____D C:\Users\pawel\Documents\Ubisoft 2017-09-09 11:53 - 2017-09-09 13:43 - 000000000 ____D C:\ProgramData\Orbit 2017-09-09 09:41 - 2017-09-09 09:42 - 000000000 ____D C:\Users\pawel\AppData\Roaming\StarwayFleet 2017-09-09 09:41 - 2017-09-09 09:41 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\StormCubeGames 2017-09-09 08:31 - 2017-09-09 08:31 - 000000000 ____D C:\Users\pawel\AppData\Local\NanoPlus 2017-09-07 19:34 - 2017-09-15 19:18 - 000003012 _____ C:\Windows\System32\Tasks\MSIAfterburner 2017-09-03 20:54 - 2017-09-03 20:54 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Might and Delight 2017-09-03 20:45 - 2017-09-03 20:45 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Ovosonico 2017-09-03 19:44 - 2017-09-03 19:44 - 000000000 ____D C:\Users\pawel\AppData\Roaming\electron-quick-start 2017-09-03 19:44 - 2017-09-03 19:44 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Sauropod Studio 2017-09-03 18:40 - 2017-09-03 18:40 - 000000000 ____D C:\Users\pawel\AppData\Local\RAID WW2 Beta 2017-09-03 10:01 - 2017-09-03 10:27 - 000000000 ____D C:\Users\pawel\Downloads\NeoDownloader 2017-09-03 10:00 - 2017-09-03 10:01 - 000000000 ____D C:\Users\pawel\AppData\Roaming\NeoDownloader 2017-09-03 10:00 - 2017-09-03 10:00 - 000000776 _____ C:\Users\Public\Desktop\NeoDownloader 3.0.3.lnk 2017-09-03 10:00 - 2017-09-03 10:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoDownloader 2017-09-02 17:37 - 2017-09-02 17:37 - 000000000 ____D C:\Users\pawel\Documents\GTA Vice City User Files 2017-09-02 17:36 - 2017-09-02 17:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kolekcja Klasyki 2017-09-02 17:16 - 2017-09-02 17:16 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Playsport Games 2017-09-02 16:15 - 2017-09-02 16:15 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Tzar Leonardi 2017-09-02 16:01 - 2017-09-02 16:01 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Llama Software 2017-09-02 15:54 - 2017-09-02 15:54 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\GreyGods 2017-09-02 15:52 - 2017-09-02 15:52 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Cuirass Entertainment Ltd_ 2017-09-02 12:24 - 2017-09-02 14:57 - 000000000 ____D C:\Users\pawel\Documents\GTA3 User Files 2017-09-02 12:21 - 2017-09-02 17:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games 2017-09-02 11:10 - 2017-09-02 11:10 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\GuglhupfGames 2017-09-02 11:05 - 2017-09-02 11:05 - 000000000 ____D C:\Users\pawel\AppData\Local\P_Knockback 2017-09-01 20:19 - 2017-09-01 20:19 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Fishing Planet LLC 2017-08-29 21:48 - 2017-08-29 22:13 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Daybreak Game Company 2017-08-29 21:48 - 2017-08-29 21:48 - 000000000 ____D C:\Users\pawel\AppData\Local\SCE 2017-08-29 21:48 - 2017-08-29 21:48 - 000000000 ____D C:\Users\pawel\AppData\Local\Daybreak Game Company 2017-08-28 22:38 - 2017-09-12 15:28 - 000002048 _____ C:\Users\Public\Desktop\Google Slides.lnk 2017-08-28 22:38 - 2017-09-12 15:28 - 000002046 _____ C:\Users\Public\Desktop\Google Sheets.lnk 2017-08-28 22:38 - 2017-09-12 15:28 - 000002036 _____ C:\Users\Public\Desktop\Google Docs.lnk 2017-08-28 22:38 - 2017-09-12 15:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google 2017-08-27 20:42 - 2017-08-27 20:42 - 000002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-08-27 20:42 - 2017-08-27 20:42 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-08-27 20:39 - 2017-08-28 22:38 - 000000000 ____D C:\Users\pawel\AppData\Local\Google 2017-08-27 20:39 - 2017-08-28 22:38 - 000000000 ____D C:\Program Files (x86)\Google 2017-08-27 20:39 - 2017-08-27 20:39 - 000003480 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-08-27 20:39 - 2017-08-27 20:39 - 000003352 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-08-27 11:31 - 2017-08-27 11:31 - 000000000 ____D C:\Users\pawel\AppData\Local\My Games 2017-08-26 19:16 - 2017-08-26 19:16 - 000000000 ____D C:\Users\pawel\Screenshot 2017-08-26 18:43 - 2017-08-26 18:43 - 000000000 ____D C:\Users\pawel\Documents\KoeiTecmo 2017-08-26 12:12 - 2017-08-26 12:12 - 000000000 ____D C:\Users\pawel\AppData\Local\HellbladeGame 2017-08-26 10:13 - 2017-08-26 10:13 - 000000000 ____D C:\Users\pawel\ansel 2017-08-23 16:17 - 2017-08-23 16:17 - 000000000 ____D C:\Program Files (x86)\AGEIA Technologies 2017-08-22 17:53 - 2017-08-22 17:53 - 000000000 ____D C:\Users\pawel\Documents\Paradox Interactive 2017-08-22 00:04 - 2017-08-22 00:04 - 000000000 ____D C:\Users\pawel\AppData\Local\Kukui_PC 2017-08-21 23:48 - 2017-08-21 23:48 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Acid Wizard Studio 2017-08-21 23:06 - 2017-08-21 23:06 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Borealys Games Inc_ 2017-08-21 22:27 - 2017-08-21 22:27 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Lofty Sky Entertainment 2017-08-21 22:04 - 2017-08-21 22:14 - 000000000 ____D C:\Users\pawel\Documents\StarTrail 2017-08-21 20:25 - 2017-08-21 20:27 - 000000509 _____ C:\Users\pawel\AppData\Roaming\SineMoraEX.dat 2017-08-21 18:23 - 2017-08-21 18:23 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\CQXY 2017-08-21 16:42 - 2017-08-21 16:42 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Inner Void Interactive 2017-08-21 01:17 - 2017-08-21 01:25 - 000000000 ____D C:\Users\pawel\AppData\Roaming\Anvsoft 2017-08-21 01:17 - 2017-08-21 01:17 - 000000547 _____ C:\Users\pawel\Desktop\Any Video Converter.lnk 2017-08-21 01:17 - 2017-08-21 01:17 - 000000000 ____D C:\Users\pawel\Documents\Any Video Converter 2017-08-21 00:01 - 2017-08-21 01:27 - 000000000 ____D C:\Users\pawel\AppData\Roaming\NVIDIA 2017-08-20 23:56 - 2017-09-16 06:41 - 000000000 ____D C:\ProgramData\NVIDIA 2017-08-20 23:56 - 2017-08-20 23:56 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2017-08-20 23:56 - 2017-08-20 23:56 - 000000000 ____D C:\Program Files (x86)\VulkanRT 2017-08-20 23:56 - 2017-08-10 02:22 - 000512960 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2017-08-20 23:56 - 2017-08-10 02:22 - 000418752 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2017-08-20 23:56 - 2017-08-10 02:22 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat 2017-08-20 23:56 - 2017-08-10 00:53 - 006463608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2017-08-20 23:56 - 2017-08-10 00:53 - 002479224 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2017-08-20 23:56 - 2017-08-10 00:53 - 001762936 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2017-08-20 23:56 - 2017-08-10 00:53 - 000549496 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2017-08-20 23:56 - 2017-08-10 00:53 - 000392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2017-08-20 23:56 - 2017-08-10 00:53 - 000081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2017-08-20 23:56 - 2017-08-10 00:53 - 000069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2017-08-20 23:56 - 2017-08-10 00:47 - 000001951 _____ C:\Windows\NvContainerRecovery.bat 2017-08-20 23:56 - 2017-08-08 11:39 - 008112721 _____ C:\Windows\system32\nvcoproc.bin 2017-08-20 23:56 - 2017-03-10 23:17 - 000536864 _____ C:\Windows\system32\vulkan-1.dll 2017-08-20 23:56 - 2017-03-10 23:17 - 000525600 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-08-20 23:56 - 2017-03-10 23:17 - 000254240 _____ C:\Windows\system32\vulkaninfo.exe 2017-08-20 23:56 - 2017-03-10 23:17 - 000233760 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-08-20 23:54 - 2017-08-10 02:22 - 040239552 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 035805632 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 035314296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 028930496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 023075016 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 021403392 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 018804976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 018705072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 017807936 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 015425984 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-08-20 23:54 - 2017-08-10 02:22 - 014689632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 013649992 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 012133296 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 011585736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 009982968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 004187336 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 003803768 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 003691704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 003359680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 001988216 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438528.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 001598072 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438528.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 001067640 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 001005176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000972920 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000924096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000689808 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000609912 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000578056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000512856 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000499136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000491536 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000429920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000171200 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000154392 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000149224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000132072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-08-20 23:54 - 2017-08-10 02:22 - 000044200 _____ C:\Windows\system32\nvinfo.pb 2017-08-20 23:54 - 2017-08-10 02:22 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json 2017-08-20 23:54 - 2017-08-10 02:22 - 000000669 _____ C:\Windows\system32\nv-vk64.json 2017-08-20 22:50 - 2017-08-20 22:50 - 000001047 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk 2017-08-20 22:41 - 2017-08-20 22:50 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy 2017-08-20 22:36 - 2017-08-20 22:36 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Revolt and Rebel 2017-08-20 21:25 - 2017-08-22 16:30 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Fullbright 2017-08-20 21:02 - 2017-08-27 11:03 - 000000000 ____D C:\Users\pawel\AppData\Local\Hinterland 2017-08-20 21:02 - 2017-08-20 21:02 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Hinterland 2017-08-20 20:59 - 2017-09-10 22:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com 2017-08-20 20:13 - 2017-08-20 20:13 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\SKS 2017-08-20 17:17 - 2017-08-20 17:17 - 000000000 ____D C:\Users\pawel\AppData\Roaming\com.kongregate.mobile.realmgrinder.air 2017-08-20 17:01 - 2017-08-20 17:01 - 000000000 ____D C:\Users\pawel\AppData\Roaming\HeroesTactics 2017-08-20 15:53 - 2017-08-20 15:53 - 000000609 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk 2017-08-20 15:53 - 2017-08-20 15:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm 2017-08-20 13:49 - 2017-08-20 13:59 - 000000000 ____D C:\Users\pawel\AppData\Roaming\PDO2 2017-08-20 13:49 - 2017-08-20 13:49 - 000000000 ____D C:\Users\pawel\AppData\Roaming\PDO2Launcher_Steam 2017-08-20 13:34 - 2017-08-20 17:57 - 000000000 ____D C:\Users\pawel\Documents\Heroes of the Storm 2017-08-20 13:28 - 2017-08-20 13:28 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\gentlymad 2017-08-20 13:23 - 2017-08-20 13:23 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\WnMStudio 2017-08-20 12:34 - 2017-08-20 12:34 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\8floor 2017-08-20 11:25 - 2017-08-20 11:26 - 000000000 ____D C:\Users\pawel\AppData\Roaming\com.berzerkstudio.zombidle.steam ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-09-16 13:05 - 2017-08-11 15:35 - 000000000 ____D C:\FRST 2017-09-16 12:56 - 2017-08-12 11:53 - 000000000 ____D C:\Users\pawel\AppData\Roaming\qBittorrent 2017-09-16 11:26 - 2016-12-11 17:06 - 000000000 ____D C:\Users\pawel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2017-09-16 10:29 - 2017-05-26 19:06 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-09-16 10:28 - 2009-07-14 07:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-09-16 09:37 - 2017-02-03 12:22 - 000000000 ____D C:\Users\pawel\AppData\Local\Ubisoft Game Launcher 2017-09-16 08:37 - 2016-11-02 16:45 - 000000000 ____D C:\Users\pawel\Documents\My Games 2017-09-16 06:57 - 2017-05-18 23:51 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2017-09-16 06:49 - 2009-07-14 06:45 - 000014336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-09-16 06:49 - 2009-07-14 06:45 - 000014336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-09-16 06:41 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-09-15 18:11 - 2017-03-17 16:00 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\DefaultCompany 2017-09-15 17:27 - 2017-03-18 22:15 - 000000000 ____D C:\Users\pawel\AppData\Local\Battle.net 2017-09-15 15:59 - 2016-10-20 01:01 - 000000000 ____D C:\Users\pawel\AppData\Local\VirtualStore 2017-09-15 15:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf 2017-09-14 20:47 - 2016-10-20 01:48 - 000000000 ____D C:\ProgramData\Package Cache 2017-09-14 20:44 - 2016-12-13 02:03 - 000000000 ____D C:\Users\pawel\AppData\Local\HirezLauncherUI 2017-09-14 16:04 - 2009-07-14 19:55 - 000717972 _____ C:\Windows\system32\perfh015.dat 2017-09-14 16:04 - 2009-07-14 19:55 - 000146822 _____ C:\Windows\system32\perfc015.dat 2017-09-14 16:04 - 2009-07-14 07:13 - 001608644 _____ C:\Windows\system32\PerfStringBackup.INI 2017-09-12 18:33 - 2016-10-20 12:10 - 000000000 ____D C:\Users\pawel\.VirtualBox 2017-09-12 17:27 - 2017-06-25 21:07 - 000000000 ____D C:\Users\pawel\AppData\Local\CrashDumps 2017-09-11 18:25 - 2016-11-24 21:55 - 000000000 ____D C:\Users\pawel\AppData\Roaming\DAEMON Tools Pro 2017-09-10 22:33 - 2016-11-13 01:55 - 000000000 ____D C:\Users\pawel\AppData\Roaming\Skype 2017-09-10 18:46 - 2017-02-15 21:04 - 000000000 ____D C:\ProgramData\Origin 2017-09-10 18:35 - 2017-02-15 21:19 - 000000000 ____D C:\Users\pawel\AppData\Roaming\Origin 2017-09-09 20:16 - 2016-11-16 09:58 - 000000000 ____D C:\Users\pawel\AppData\LocalLow\Mozilla 2017-09-06 19:52 - 2016-11-14 20:46 - 000000000 ____D C:\Users\pawel\AppData\Roaming\TS3Client 2017-09-03 21:06 - 2016-10-20 01:16 - 000000000 ___RD C:\Users\pawel\Desktop\Nauka 2017-08-30 17:58 - 2017-06-15 09:56 - 000000000 ____D C:\Users\pawel\Documents\Endless Space 2 2017-08-28 22:02 - 2009-07-14 07:08 - 000032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-08-28 00:02 - 2017-03-18 22:02 - 000000000 ____D C:\Users\pawel\AppData\Roaming\Battle.net 2017-08-26 19:16 - 2016-10-20 01:01 - 000000000 ____D C:\Users\pawel 2017-08-21 00:39 - 2017-02-26 18:31 - 000000000 ____D C:\Users\pawel\AppData\Roaming\HelloGames 2017-08-20 23:56 - 2016-10-20 01:49 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-08-20 23:56 - 2016-10-20 01:42 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2017-08-20 23:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\Help 2017-08-20 22:41 - 2017-03-06 12:25 - 000000000 ____D C:\ProgramData\GOG.com 2017-08-20 20:41 - 2017-05-09 01:40 - 000000000 ____D C:\Users\pawel\AppData\Roaming\SmartSteamEmu 2017-08-20 17:56 - 2017-03-19 00:37 - 000000000 ____D C:\ProgramData\Blizzard Entertainment 2017-08-20 15:05 - 2017-08-05 10:39 - 000001735 _____ C:\Users\pawel\Desktop\Informatyka - przydatne linki.txt ==================== Pliki w katalogu głównym wybranych folderów ======= 2017-05-05 18:48 - 2017-05-05 18:48 - 000000024 ___SH () C:\Users\pawel\AppData\Roaming\1D959CA221C7573.sys 2017-08-05 15:42 - 2017-08-05 15:42 - 000000000 _____ () C:\Users\pawel\AppData\Roaming\gdfw.log 2017-08-05 15:41 - 2017-08-05 15:42 - 000000779 _____ () C:\Users\pawel\AppData\Roaming\gdscan.log 2017-01-18 22:57 - 2017-01-20 21:44 - 000000098 _____ () C:\Users\pawel\AppData\Roaming\LauncherSettings_live.cfg 2017-08-21 20:25 - 2017-08-21 20:27 - 000000509 _____ () C:\Users\pawel\AppData\Roaming\SineMoraEX.dat 2017-04-08 12:08 - 2017-04-10 00:44 - 000002608 _____ () C:\Users\pawel\AppData\Roaming\SpeedRunnersLog.txt 2017-05-05 18:48 - 2017-05-05 18:48 - 000000024 ___SH () C:\Users\pawel\AppData\Roaming\System5908ConfigCollection.dat 2017-04-08 12:08 - 2017-04-08 12:08 - 000002574 _____ () C:\Users\pawel\AppData\Roaming\TargetInvocationLog.txt 2017-01-18 22:56 - 2017-01-19 03:46 - 000000043 _____ () C:\Users\pawel\AppData\Roaming\TheHunterSettings_steam_live.cfg 2016-11-27 13:16 - 2017-05-20 14:23 - 001307648 _____ () C:\Users\pawel\AppData\Local\file__0.localstorage 2016-11-13 02:01 - 2017-06-28 22:31 - 000007631 _____ () C:\Users\pawel\AppData\Local\Resmon.ResmonCfg 2017-06-28 21:19 - 2017-06-28 21:19 - 000047070 _____ () C:\ProgramData\agent.1498677576.bdinstall.bin 2017-06-28 22:26 - 2017-06-28 22:26 - 000028462 _____ () C:\ProgramData\agent.1498681567.bdinstall.bin 2017-06-28 22:43 - 2017-06-28 22:44 - 000028461 _____ () C:\ProgramData\agent.1498682627.bdinstall.bin 2017-06-28 23:14 - 2017-06-28 23:14 - 000028463 _____ () C:\ProgramData\agent.1498684434.bdinstall.bin 2017-06-28 21:32 - 2017-06-28 21:32 - 000425039 _____ () C:\ProgramData\cl.1498678177.bdinstall.bin 2017-06-28 21:57 - 2017-06-28 21:57 - 000433553 _____ () C:\ProgramData\cl.repair.1498679754.bdinstall.bin 2017-06-28 22:02 - 2017-06-28 22:02 - 000210443 _____ () C:\ProgramData\cl.uninstall.1498680071.bdinstall.bin 2016-12-13 10:13 - 2016-12-13 10:13 - 000000016 _____ () C:\ProgramData\mntemp Niektóre pliki w TEMP: ==================== 2017-09-14 20:47 - 2017-05-23 11:59 - 000037376 _____ (Microsoft) C:\Users\pawel\AppData\Local\Temp\HiPatchSelfUpdateWindow.exe 2017-09-14 20:47 - 2017-05-23 11:59 - 000020480 _____ (Microsoft) C:\Users\pawel\AppData\Local\Temp\HiRezLauncherControls.dll 2017-09-16 09:38 - 2017-09-16 09:38 - 000365669 _____ () C:\Users\pawel\AppData\Local\Temp\ubiFF39.tmp.exe ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2017-09-13 16:30 ==================== Koniec FRST.txt ============================