Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2014 Ran by radoslawt (administrator) on RADOSLAWT on 19-12-2014 13:24:09 Running from C:\Users\RadoslawT.ELKAR\Desktop\Pobrane Loaded Profile: radoslawt (Available profiles: tomaszw & radoslawt & krzysztofs & Administrator) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Polski (Polska) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Windows\System32\nvwmi64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Windows\System32\nvwmi64.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe (Dassault Systèmes) C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe (Logitech Inc.) C:\Program Files\Logitech\SetPoint II\SetPointII.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2636827988-668989614-3064574600-1115\...\RunOnce: [Adobe Speed Launcher] => 1418991684 HKU\S-1-5-21-2636827988-668989614-3064574600-1115\...\MountPoints2: {4571889e-6715-11e4-8914-74d435070950} - G:\Lenovo_Suite.exe HKU\S-1-5-21-2636827988-668989614-3064574600-1115\...\MountPoints2: {457188b1-6715-11e4-8914-74d435070950} - I:\setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SetPointII.lnk ShortcutTarget: SetPointII.lnk -> C:\Program Files\Logitech\SetPoint II\SetPointII.exe (Logitech Inc.) ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll No File BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL No File Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.0.20 FireFox: ======== FF Plugin: @3ds.com/3dxml -> C:\Program Files\Dassault Systemes\3D XML Player\win_b64\code\bin\NP3DXMLPlugin.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @3ds.com/3dxml -> C:\Program Files\Dassault Systemes\3D XML Player\win_b64\code\bin32\NP3DXMLPlugin.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn [2014-12-19] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF [2014-04-12] Chrome: ======= CHR Profile: C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Dokumenty Google) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-18] CHR Extension: (Dysk Google) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-18] CHR Extension: (YouTube) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-18] CHR Extension: (Adblock Plus) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-18] CHR Extension: (Szukaj w Google) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-18] CHR Extension: (AdBlock) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-12-19] CHR Extension: (Norton Identity Safe) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-12-18] CHR Extension: (Google Wallet) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-18] CHR Extension: (Gmail) - C:\Users\RadoslawT.ELKAR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-18] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-06] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-06] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 BotkindSyncService; C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe [182784 2013-12-12] () [File not signed] R2 DraftSight API Service; C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [123392 2014-03-14] (Dassault Systèmes) [File not signed] R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-04-11] (Intel Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation) R2 NVWMI; C:\Windows\system32\nvwmi64.exe [2683736 2014-08-19] () S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2014-03-26] (SolidWorks) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21584 2013-02-19] () R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\BASHDefs\20141209.001\BHDrvx64.sys [1587416 2014-10-03] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-12] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-12] (Symantec Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-04-30] (Intel Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\IPSDefs\20141218.001\IDSvia64.sys [637656 2014-11-18] (Symantec Corporation) S3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\VirusDefs\20141218.020\ENG64.SYS [129752 2014-11-25] (Symantec Corporation) S3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\VirusDefs\20141218.020\EX64.SYS [2137304 2014-11-25] (Symantec Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2014-11-08] () [File not signed] S3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2013-10-30] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-10] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [21584 2013-05-06] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-19 12:34 - 2014-12-19 12:34 - 00028581 _____ () C:\Users\RadoslawT.ELKAR\Downloads\FRST (1).txt 2014-12-19 12:03 - 2014-12-19 13:24 - 00000000 ____D () C:\FRST 2014-12-19 12:03 - 2014-12-19 12:25 - 00028443 _____ () C:\Users\RadoslawT.ELKAR\Downloads\FRST.txt 2014-12-19 12:03 - 2014-12-19 12:09 - 00030804 _____ () C:\Users\RadoslawT.ELKAR\Downloads\Addition.txt 2014-12-19 12:02 - 2014-12-19 12:03 - 02121216 _____ (Farbar) C:\Users\RadoslawT.ELKAR\Downloads\FRST64.exe 2014-12-19 11:29 - 2014-12-19 11:29 - 00085890 _____ () C:\Users\RadoslawT.ELKAR\Downloads\OTL (1).Txt 2014-12-19 11:23 - 2014-12-19 11:23 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\Desktop\DTR 2014-12-19 11:19 - 2014-12-19 11:19 - 00085890 _____ () C:\Users\RadoslawT.ELKAR\Downloads\OTL.Txt 2014-12-19 11:17 - 2014-12-19 11:17 - 00000085 _____ () C:\Windows\wininit.ini 2014-12-19 11:15 - 2014-12-19 11:15 - 00602112 _____ (OldTimer Tools) C:\Users\RadoslawT.ELKAR\Downloads\OTL.exe 2014-12-19 11:15 - 2014-12-19 11:15 - 00602112 _____ (OldTimer Tools) C:\Users\RadoslawT.ELKAR\Downloads\OTL (1).exe 2014-12-19 10:33 - 2014-12-19 10:36 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\RadoslawT.ELKAR\Downloads\spybot-2.4.exe 2014-12-18 12:07 - 2014-12-18 09:59 - 00015761 _____ () C:\Users\RadoslawT.ELKAR\Desktop\HARMONOGRAM.xlsx 2014-12-18 12:06 - 2014-12-18 12:57 - 00589312 _____ () C:\Users\RadoslawT.ELKAR\Desktop\Harmonogram Planowania Prac.xls 2014-12-18 10:28 - 2014-12-18 10:28 - 00002267 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-12-18 10:28 - 2014-12-18 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-18 10:26 - 2014-12-19 13:21 - 00001050 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-12-18 10:26 - 2014-12-19 12:32 - 00001054 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-18 10:26 - 2014-12-18 10:26 - 00004050 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-12-18 10:26 - 2014-12-18 10:26 - 00003798 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-12-18 08:53 - 2014-12-18 08:52 - 00016296 _____ () C:\Users\RadoslawT.ELKAR\Desktop\Zeszyt12.xlsx 2014-12-17 16:40 - 2014-12-17 16:40 - 00009279 _____ () C:\Users\RadoslawT.ELKAR\Desktop\bookmarks_17.12.2014.html 2014-12-17 14:43 - 2014-12-19 13:20 - 00014402 _____ () C:\Windows\PFRO.log 2014-12-17 14:43 - 2014-12-19 13:20 - 00000392 _____ () C:\Windows\setupact.log 2014-12-17 14:43 - 2014-12-17 14:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-12-17 13:13 - 2014-12-17 13:13 - 00000000 _____ () C:\autoexec.bat 2014-12-12 12:50 - 2014-12-12 12:50 - 00001269 _____ () C:\Users\RadoslawT.ELKAR\Desktop\DELEGACJE1.xlsx — skrót.lnk 2014-12-10 15:22 - 2014-12-10 15:22 - 00001508 _____ () C:\Users\RadoslawT.ELKAR\Desktop\TABELA OBRÓBKA ELKAR.xls — skrót.lnk 2014-12-05 15:25 - 2014-12-05 15:25 - 00001727 _____ () C:\Users\RadoslawT.ELKAR\Desktop\Nazwy projektów.xls — skrót.lnk 2014-12-05 15:25 - 2014-12-05 15:25 - 00001259 _____ () C:\Users\RadoslawT.ELKAR\Desktop\Podajnik szczebelkowy SHINBAN EL14710 05.12.2014 — skrót.lnk 2014-12-05 13:49 - 2014-12-05 13:49 - 00001178 _____ () C:\Users\RadoslawT.ELKAR\Desktop\FAKTURY PRZEDSIĘBIORSTWO WIELOBRANŻOWE JAX 77 73 91 — skrót.lnk 2014-12-05 08:09 - 2014-12-05 08:09 - 00000808 _____ () C:\Users\RadoslawT.ELKAR\Desktop\FOTO PO 2008 — skrót.lnk 2014-12-05 08:08 - 2014-12-05 08:08 - 00001523 _____ () C:\Users\RadoslawT.ELKAR\Desktop\Ewidencja czasu pracy 12_2014.xls — skrót.lnk 2014-12-05 08:08 - 2014-12-05 08:08 - 00000699 _____ () C:\Users\RadoslawT.ELKAR\Desktop\ZAMÓWIENIA — skrót.lnk 2014-12-05 07:59 - 2014-12-05 07:59 - 00000000 ____D () C:\ProgramData\GroupPolicy 2014-12-03 13:06 - 2014-12-03 13:16 - 00000000 ____D () C:\Users\Konstruktor 2014-12-03 10:12 - 2014-08-25 11:49 - 00795120 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3xhc.sys 2014-12-03 10:12 - 2014-08-25 11:49 - 00383984 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hub.sys 2014-12-03 10:12 - 2014-08-25 11:49 - 00020464 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hcs.sys 2014-12-03 10:08 - 2014-12-03 10:08 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Roaming\driveridentifier 2014-12-03 10:05 - 2014-12-03 10:05 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Local\DriverToolkit 2014-12-03 09:23 - 2014-07-02 11:14 - 03826628 _____ () C:\Windows\system32\nvcoproc.bin 2014-11-24 13:57 - 2014-11-24 13:57 - 02478447 _____ () C:\Users\RadoslawT.ELKAR\Documents\EL14590.100.000.smpd 2014-11-24 08:41 - 2014-11-24 08:41 - 00000000 _____ () C:\Windows\SysWOW64\debug.log ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-19 13:24 - 2014-11-08 13:25 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\Desktop\Pobrane 2014-12-19 13:24 - 2014-03-25 13:25 - 01516042 _____ () C:\Windows\WindowsUpdate.log 2014-12-19 13:21 - 2014-03-25 14:13 - 00003082 __RSH () C:\ProgramData\ntuser.pol 2014-12-19 13:21 - 2014-03-25 14:11 - 00000120 _____ () C:\Windows\system32\config\netlogon.ftl 2014-12-19 13:21 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-19 13:19 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-12-19 10:54 - 2014-03-31 12:28 - 00000000 ____D () C:\temp 2014-12-19 07:19 - 2009-07-14 05:45 - 00015360 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-19 07:19 - 2009-07-14 05:45 - 00015360 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-19 07:15 - 2014-03-26 09:01 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Roaming\GG 2014-12-18 10:28 - 2014-03-25 14:38 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Local\Google 2014-12-18 10:28 - 2014-03-25 14:38 - 00000000 ____D () C:\Program Files (x86)\Google 2014-12-18 10:26 - 2014-03-25 14:37 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Local\Deployment 2014-12-18 10:15 - 2014-06-23 07:28 - 00000663 _____ () C:\Users\RadoslawT.ELKAR\Desktop\Projekty — skrót.lnk 2014-12-18 07:08 - 2009-07-14 05:45 - 00446496 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-17 16:43 - 2014-03-25 14:17 - 00122600 _____ () C:\Users\RadoslawT.ELKAR\AppData\Local\GDIPFONTCACHEV1.DAT 2014-12-17 14:51 - 2014-10-23 15:10 - 00000911 _____ () C:\Users\RadoslawT.ELKAR\Desktop\SMC Best In Automation.exe —.lnk 2014-12-17 14:33 - 2014-11-18 16:01 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Roaming\TeamViewer 2014-12-17 14:33 - 2014-03-29 10:18 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Local\CrashDumps 2014-12-17 14:32 - 2014-06-17 12:53 - 00002780 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-12-17 13:53 - 2014-04-24 13:34 - 00000000 ____D () C:\Windows\Minidump 2014-12-17 13:46 - 2014-06-03 10:21 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Local\NPE 2014-12-17 13:45 - 2014-03-26 09:19 - 00000000 ____D () C:\ProgramData\Norton 2014-12-17 13:13 - 2014-03-25 14:16 - 00000000 ____D () C:\Users\RadoslawT.ELKAR 2014-12-12 09:06 - 2009-07-14 18:55 - 00744846 _____ () C:\Windows\system32\perfh015.dat 2014-12-12 09:06 - 2009-07-14 18:55 - 00157826 _____ () C:\Windows\system32\perfc015.dat 2014-12-12 09:06 - 2009-07-14 06:13 - 01682848 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-11 11:05 - 2014-03-26 09:26 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-12-10 15:50 - 2014-03-25 14:26 - 00009092 _____ () C:\Users\RadoslawT.ELKAR\Desktop\przeliczanie prędości liniowej na obroty.xlsx 2014-12-08 07:20 - 2014-03-26 09:01 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Local\GG 2014-12-08 07:00 - 2009-07-14 06:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-12-03 09:45 - 2014-03-25 14:00 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-12-03 09:37 - 2014-03-25 14:01 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-12-03 09:22 - 2014-03-25 14:00 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-11-28 09:39 - 2014-03-25 14:26 - 00190557 _____ () C:\Users\RadoslawT.ELKAR\Desktop\Zamówienia 2014.xlsx 2014-11-25 11:07 - 2014-08-13 07:39 - 00000000 ____D () C:\Users\a\AppData\Local\TempSW Katalog dla kopii zapasowych 2014-11-25 09:40 - 2014-04-23 06:28 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Roaming\SMC 2014-11-24 09:34 - 2014-03-25 14:26 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\Desktop\Ubrania 2014-11-24 08:41 - 2014-03-26 09:02 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Roaming\Adobe 2014-11-20 15:20 - 2014-07-28 06:46 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Roaming\FileZilla 2014-11-20 10:57 - 2014-03-26 08:50 - 00000000 ____D () C:\Users\RadoslawT.ELKAR\AppData\Local\DassaultSystemes ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-05-09 07:38 ==================== End Of Log ============================