Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 06-10-2017 Uruchomiony przez wiczi (administrator) WICZI-KOMPUTER (07-10-2017 13:25:22) Uruchomiony z C:\Users\wiczi\Downloads Załadowane profile: wiczi (Dostępne profile: wiczi) Platform: Windows 7 Home Premium Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: IE) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe () C:\ProgramData\Logic Cramble\set.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe () C:\Program Files (x86)\RIVpemjyECl8 Updater\RIVpemjyECl8 Updater.exe () C:\Program Files (x86)\suUqZBp2wcSI Updater\suUqZBp2wcSI Updater.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe (Spotify Ltd) C:\Users\wiczi\AppData\Roaming\Spotify\SpotifyWebHelper.exe (59) C:\Program Files\039D13FSE0\039D13FSE.exe (TODO: ) C:\Disk\WebService.exe (59) C:\Program Files\J33CWQTO0X\J33CWQTO0.exe (59) C:\Program Files\AYMZ4WRTNO\AYMZ4WRTN.exe (59) C:\Program Files\K7KJNWYTE4\K7KJNWYTE.exe (59) C:\Program Files\ZEVYAVKYSI\ZEVYAVKYS.exe (59) C:\Program Files\PYKWL8MGUZ\PYKWL8MGU.exe (59) C:\Program Files\17B7WZZR38\17B7WZZR3.exe (59) C:\Program Files\MDNQT2KV8R\MDNQT2KV8.exe (SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Elaborate Bytes AG) D:\vcd\VirtualCloneDrive\VCDDaemon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (TODO: ) C:\Disk\WebService.exe (Valve Corporation) D:\steam\Steam.exe (Valve Corporation) D:\steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) D:\steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (PC Tools) C:\Disk\securedisk.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040792 2015-07-07] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation) HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [SERVICE] => [X] HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-21] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation) HKLM-x32\...\Run: [VirtualCloneDrive] => D:\vcd\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [Steam] => D:\steam\steam.exe [3074336 2017-10-05] (Valve Corporation) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [Spotify] => C:\Users\wiczi\AppData\Roaming\Spotify\Spotify.exe [20803184 2017-09-30] (Spotify Ltd) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [WifiAudio] => C:\Users\wiczi\AppData\Local\Temp\Rar$EXa0.900\wifiaudio_windows.exe <==== UWAGA HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [ALLUpdate] => C:\Program Files (x86)\OpenSubtitlesPlayer\ALLUpdate.exe [3520968 2015-11-01] (Opensubtitles.org) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [OSDownloaderUpdate] => "C:\Program Files (x86)\OSDownloader\OSDownloaderUpdate.exe" "sleep" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [8473600 2014-06-18] (Visicom Media Inc.) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [GG] => C:\Users\wiczi\AppData\Local\GG\Application\gghub.exe [4078144 2016-07-04] (GG Network S.A.) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [Spotify Web Helper] => C:\Users\wiczi\AppData\Roaming\Spotify\SpotifyWebHelper.exe [777840 2017-09-30] (Spotify Ltd) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [msiql] => C:\Users\wiczi\AppData\Local\Temp\00007476\msiql.exe /RUNNING <==== UWAGA HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [jorrj0dirj4] => "C:\Users\wiczi\AppData\Roaming\mgdc00zcfgp\2mslswu0add.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [AC4B63GB8D7ZXQY] => C:\Program Files\039D13FSE0\039D13FSE.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [ans55we5zxf] => "C:\Users\wiczi\AppData\Roaming\ctsli5py401\lrkyvvmkhj1.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [k2hbjtkux4n] => "C:\Users\wiczi\AppData\Roaming\3lx1isnuf5g\0vjx5xcdz01.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [35s1qqalrvf] => "C:\Users\wiczi\AppData\Roaming\sd4uyjj3qwd\bfmlqaqsivp.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [3LDCG2UWTIBBNNW] => C:\Program Files\J33CWQTO0X\J33CWQTO0.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [B9XA3KPASSP0IEP] => C:\Program Files\AYMZ4WRTNO\AYMZ4WRTN.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [j3rpfkwdop4] => "C:\Users\wiczi\AppData\Roaming\aa3xp1m3evr\qxgmkgztgij.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [R4TBOLE2FWLHC2W] => C:\Program Files\K7KJNWYTE4\K7KJNWYTE.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [ty3nb2wyauq] => "C:\Users\wiczi\AppData\Roaming\biy1bidt4l0\tsxuupndsze.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [t14dhmjgejq] => "C:\Users\wiczi\AppData\Roaming\2abg233kem3\um1ag4wwd4y.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [ouwa0r4lz30] => "C:\Users\wiczi\AppData\Roaming\iagqaaqvol0\n4ekvd3z3qr.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [PEHBPKUX8X99RZ3] => C:\Program Files\ZEVYAVKYSI\ZEVYAVKYS.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [46NFVDANM7YK9DW] => C:\Program Files\PYKWL8MGUZ\PYKWL8MGU.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [rfra4ehjfvj] => "C:\Users\wiczi\AppData\Roaming\jxdezycqule\mh00zvmvibr.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [brdvwcdk4ao] => "C:\Users\wiczi\AppData\Roaming\0jqi0zgv0ji\s2jft1xc53b.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [nj44jggelhu] => "C:\Users\wiczi\AppData\Roaming\gbs2qwnbw14\glgusc5w4kb.exe" HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [RGIM0EA3JE1WX9Q] => C:\Program Files\17B7WZZR38\17B7WZZR3.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\Run: [JQIRXKQRID2CHP5] => C:\Program Files\MDNQT2KV8R\MDNQT2KV8.exe [668672 2017-10-07] (59) HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\MountPoints2: {18a89b8f-6962-11e7-969e-806e6f6e6963} - E:\Run.exe HKU\S-1-5-21-319334698-2115631649-3299897735-1000\...\MountPoints2: {39053065-9b7d-11e7-a78c-408d5c7e0e6e} - H:\autorun.exe HKU\S-1-5-21-319334698-2115631649-3299897735-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\ProgramData\DreamScreen\DreamScreen.scr [5313536 2017-10-07] (TODO: <公司名>) ShellExecuteHooks: Brak nazwy - {5F51FFFE-7463-4220-B711-E5B9ACB8EDFE} - C:\Users\wiczi\AppData\Roaming\tmp546.dat -> Brak pliku Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2017-10-04] ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS) Startup: C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2017-10-03] ShortcutTarget: Twitch.lnk -> C:\Users\wiczi\AppData\Roaming\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc.) GroupPolicy: Ograniczenia - Chrome <==== UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 217.113.224.134 217.113.224.135 Tcpip\Parameters: [NameServer] 82.163.143.136 82.163.142.138 Tcpip\..\Interfaces\{669E9543-2778-4A2E-BE7D-4CC3C7525398}: [NameServer] 82.163.142.8,95.211.158.136 Tcpip\..\Interfaces\{669E9543-2778-4A2E-BE7D-4CC3C7525398}: [DhcpNameServer] 217.113.224.134 217.113.224.135 Internet Explorer: ================== HKU\S-1-5-21-319334698-2115631649-3299897735-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvHPkpvb-No78HikOEZEV2_LfH80ml8jqaUs3k_rxzv8Fc2MqsPUWbWU0f55y6UhUhXjFR4Ifimk_SXDDbLQTfSW8fFDa20g6OXN_f9UZwckQTBRyJxl-_hnOjxCywjkR0FJafhNXysuyoQalkYEbYjAub8Q,,&q={searchTerms} HKU\S-1-5-21-319334698-2115631649-3299897735-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvHPkpvb-No78HikOEZEV2_LfH80ml8jqaUs3k_rxzv8Fc2MqsPUWbWU0f55y6UhUt99UoLAxdD8NuPXs55NQpueu9KN1m6ZTGiXWq1p6eLKO43l_L4ei16X-VY4IA2E9pyieNyNJCI9H0ZhBxMb9gbEMANw,, SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvHPkpvb-No78HikOEZEV2_LfH80ml8jqaUs3k_rxzv8Fc2MqsPUWbWU0f55y6UhUhXjFR4Ifimk_SXDDbLQTfSW8fFDa20g6OXN_f9UZwckQTBRyJxl-_hnOjxCywjkR0FJafhNXysuyoQalkYEbYjAub8Q,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-319334698-2115631649-3299897735-1000 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvHPkpvb-No78HikOEZEV2_LfH80ml8jqaUs3k_rxzv8Fc2MqsPUWbWU0f55y6UhUhXjFR4Ifimk_SXDDbLQTfSW8fFDa20g6OXN_f9UZwckQTBRyJxl-_hnOjxCywjkR0FJafhNXysuyoQalkYEbYjAub8Q,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-319334698-2115631649-3299897735-1000 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = hxxp://www.daemon-search.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-319334698-2115631649-3299897735-1000 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvHPkpvb-No78HikOEZEV2_LfH80ml8jqaUs3k_rxzv8Fc2MqsPUWbWU0f55y6UhUhXjFR4Ifimk_SXDDbLQTfSW8fFDa20g6OXN_f9UZwckQTBRyJxl-_hnOjxCywjkR0FJafhNXysuyoQalkYEbYjAub8Q,,&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-29] (Oracle Corporation) BHO: YoutubeAdBlock -> {C0D38E5A-7CF8-4105-8FE8-31B81443A114} -> C:\Program Files (x86)\CKCpTyVyQIE\tGuXvQ1b.dll [2017-09-20] () BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-29] (Oracle Corporation) BHO-x32: YoutubeAdBlock -> {C0D38E5A-7CF8-4105-8FE8-31B81443A114} -> C:\Program Files (x86)\CKCpTyVyQIE\k77Om3ScG.dll => Brak pliku Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2009-10-30] () Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2009-10-30] () FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-29] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-29] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-06-27] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-06-27] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-15] (Google Inc.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYvHPkpvb-No78HikOEZEV2_LfH80ml8jqaUs3k_rxzv8Fc2MqsPUWbWU0f55y6UhUhRUsNvWw5M9AO9drg1XVRzKClyLFY6lwEOj-mdUGkERacYWGX4zOQdYLpyP8DPgDukEj4ZRGV2PEryUmtzeVsk1YYXw,, CHR DefaultSearchURL: Default -> hxxps://feed.wizesearch.com/?fext=true&publisherid=51554&publisher=defaultwize&st=ed&q={searchTerms} CHR DefaultSearchKeyword: Default -> Wize search CHR Profile: C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default [2017-10-07] CHR Extension: (Prezentacje Google) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-09-20] CHR Extension: (Dokumenty Google) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-09-20] CHR Extension: (Dysk Google) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-09-20] CHR Extension: (YouTube) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-09-20] CHR Extension: (Wize) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\feeilhmlfcpfchpbgoknoeefdkbgionj [2017-09-20] CHR Extension: (Arkusze Google) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-09-20] CHR Extension: (Adblocker for Youtube™) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdlphncgdlaajddhdginocbkndmceaml [2017-09-20] CHR Extension: (Dokumenty Google offline) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-09-20] CHR Extension: (AdBlock) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-09-19] CHR Extension: (Clean My Chrome) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieinnneanoadfjcfhpjjncohgejljopj [2017-09-19] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (TunnelBear VPN) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdakjcmkglenbhjadbccaookpfjihpa [2017-07-30] CHR Extension: (Gmail) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-09-20] CHR Extension: (Chrome Media Router) - C:\Users\wiczi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-19] CHR HKLM-x32\...\Chrome\Extension: [clgckgfbhciacomhlchmgdnplmdiadbj] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (AdBlock) - C:\Users\wiczi\AppData\Roaming\Opera Software\Opera Stable\Extensions\aobdicepooefnbaeokijohmhjlleamfj [2017-09-30] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AdsService; C:\Users\wiczi\AppData\Local\AdService\AdService.dll [730624 2017-09-18] () [Brak podpisu cyfrowego] R2 backlh; C:\ProgramData\Logic Cramble\set.exe [3780096 2017-08-17] () [Brak podpisu cyfrowego] <==== UWAGA S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [369720 2017-09-25] (BlueStack Systems, Inc.) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-07-13] (Digital Wave Ltd.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Brak podpisu cyfrowego] S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-06-27] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-06-21] (NVIDIA Corporation) R2 RIVpemjyECl8 Updater; C:\Program Files (x86)\RIVpemjyECl8 Updater\RIVpemjyECl8 Updater.exe [313344 2017-09-18] () [Brak podpisu cyfrowego] R2 suUqZBp2wcSI Updater; C:\Program Files (x86)\suUqZBp2wcSI Updater\suUqZBp2wcSI Updater.exe [313344 2017-10-05] () [Brak podpisu cyfrowego] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-06-21] (Bluestack System Inc. ) S3 CEDRIVER60; C:\Program Files (x86)\Cheat Engine 6.7\dbk64.sys [123104 2017-05-30] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-06-23] (Intel Corporation) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [49264 2014-07-28] (Visicom Media Inc.) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35440 2014-05-13] (Visicom Media Inc.) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-07] (Intel Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-06-21] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [48248 2017-06-21] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57976 2017-06-21] (NVIDIA Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2017-08-10] () [Brak podpisu cyfrowego] R3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [46408 2017-06-02] (SteelSeries ApS) R3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [45936 2017-08-16] (SteelSeries ApS) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2013-09-25] (VIA Technologies, Inc.) R1 wfcre; C:\Windows\System32\drivers\wfcre.sys [124288 2017-07-04] () R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [296960 2013-09-25] (VIA Technologies, Inc.) U3 agfgtz6v; C:\Windows\System32\Drivers\agfgtz6v.sys [0 ] (Microsoft Corporation) <==== UWAGA (zerobajtowy plik/folder) S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-10-07 13:25 - 2017-10-07 13:26 - 000023011 _____ C:\Users\wiczi\Downloads\FRST.txt 2017-10-07 13:24 - 2017-10-07 13:25 - 000000000 ____D C:\FRST 2017-10-07 13:24 - 2017-10-07 13:24 - 002400768 _____ (Farbar) C:\Users\wiczi\Downloads\FRST64.exe 2017-10-07 10:52 - 2017-10-07 10:52 - 000000867 _____ C:\Users\wiczi\Desktop\securedisk — skrót.lnk 2017-10-07 10:51 - 2017-10-07 10:51 - 000000000 ____D C:\Rbackup 2017-10-07 10:50 - 2017-10-07 13:10 - 000000823 _____ C:\Users\wiczi\Desktop\Perfect Uninstaller.lnk 2017-10-07 10:50 - 2017-10-07 10:51 - 000000000 ____D C:\Program Files\Perfect Uninstaller 2017-10-07 10:50 - 2017-10-07 10:50 - 002670160 _____ (www.PerfectUninstaller.com ) C:\Users\wiczi\Desktop\PerfectUninstaller_Setup.exe 2017-10-07 10:50 - 2017-10-07 10:50 - 000000042 _____ C:\Windows\SysWOW64\AK083E209605E394C.lie 2017-10-07 10:50 - 2017-10-07 10:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect Uninstaller 2017-10-07 10:20 - 2017-10-07 10:20 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-10-07 10:20 - 2017-10-07 10:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-10-07 10:20 - 2017-10-07 10:20 - 000000000 ____D C:\ProgramData\Malwarebytes 2017-10-07 10:20 - 2017-10-07 10:20 - 000000000 ____D C:\Program Files\Malwarebytes 2017-10-07 10:20 - 2017-10-04 13:15 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-10-07 10:19 - 2017-10-07 10:19 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\jxdezycqule 2017-10-07 10:19 - 2017-10-07 10:19 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\gbs2qwnbw14 2017-10-07 10:19 - 2017-10-07 10:19 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\0jqi0zgv0ji 2017-10-07 10:19 - 2017-10-07 10:19 - 000000000 ____D C:\Program Files\MDNQT2KV8R 2017-10-07 10:19 - 2017-10-07 10:19 - 000000000 ____D C:\Program Files\17B7WZZR38 2017-10-07 10:18 - 2017-10-07 10:19 - 071535032 _____ (Malwarebytes ) C:\Users\wiczi\Downloads\mb3-setup-consumer-3.2.2.2029-1.0.212-1.0.2951.exe 2017-10-07 10:16 - 2017-10-07 10:19 - 000001220 _____ C:\Users\Public\Desktop\Download icq.lnk 2017-10-07 10:16 - 2017-10-07 10:16 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\iagqaaqvol0 2017-10-07 10:16 - 2017-10-07 10:16 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\biy1bidt4l0 2017-10-07 10:16 - 2017-10-07 10:16 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\2abg233kem3 2017-10-07 10:16 - 2017-10-07 10:16 - 000000000 ____D C:\Program Files\ZEVYAVKYSI 2017-10-07 10:16 - 2017-10-07 10:16 - 000000000 ____D C:\Program Files\PYKWL8MGUZ 2017-10-07 10:15 - 2017-10-07 10:15 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\aa3xp1m3evr 2017-10-07 10:15 - 2017-10-07 10:15 - 000000000 ____D C:\Program Files\K7KJNWYTE4 2017-10-07 10:13 - 2017-10-07 10:13 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\DreamScreen 2017-10-07 10:13 - 2017-10-07 10:13 - 000000000 ____D C:\ProgramData\DreamScreen 2017-10-07 10:13 - 2017-10-07 10:13 - 000000000 ____D C:\ProgramData\DreamCompress 2017-10-07 10:13 - 2017-10-07 10:13 - 000000000 ____D C:\ProgramData\CupCheck 2017-10-07 10:12 - 2017-10-07 11:00 - 000000000 ____D C:\Disk 2017-10-07 10:12 - 2017-10-07 10:40 - 000016686 _____ C:\Windows\System32\Tasks\Beeper 2017-10-07 10:12 - 2017-10-07 10:19 - 000000000 ____D C:\Program Files (x86)\ShutdownTime 2017-10-07 10:12 - 2017-10-07 10:12 - 000003246 _____ C:\Windows\System32\Tasks\LaCieS 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Windat 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\sd4uyjj3qwd 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\mgdc00zcfgp 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\ctsli5py401 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\3lx1isnuf5g 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Program Files\J33CWQTO0X 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Program Files\AYMZ4WRTNO 2017-10-07 10:12 - 2017-10-07 10:12 - 000000000 ____D C:\Program Files\039D13FSE0 2017-10-05 19:02 - 2017-10-05 19:02 - 000838054 _____ C:\Users\wiczi\Downloads\ZooTycon2.rar 2017-10-05 19:00 - 2017-10-05 19:00 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Microsoft Games 2017-10-05 18:59 - 2017-10-05 18:59 - 000000000 ____D C:\ProgramData\Microsoft Games 2017-10-05 18:58 - 2017-10-05 18:59 - 000002087 _____ C:\Users\Public\Desktop\Zoo Tycoon 2.lnk 2017-10-05 18:58 - 2017-10-05 18:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games 2017-10-05 18:58 - 2017-10-05 18:58 - 000000000 ____D C:\Program Files (x86)\Microsoft Games 2017-10-05 18:53 - 2017-10-05 18:56 - 1038090240 _____ C:\Users\wiczi\Downloads\Zoo.Tycoon.2.Ultimate.Collection.part1.rar 2017-10-05 18:52 - 2017-10-05 18:52 - 000000000 ____D C:\Program Files (x86)\suUqZBp2wcSI Updater 2017-10-05 18:51 - 2017-10-07 10:12 - 000000000 ____D C:\Program Files (x86)\YeaDesktop 2017-10-05 18:50 - 2017-10-05 18:50 - 000564224 _____ C:\Users\wiczi\Desktop\Zoo Tycoon 2 Ultimate Collection (2008) P2P Polska wersja jzykowa Repack.exe 2017-10-05 15:59 - 2017-10-05 15:59 - 000000046 _____ C:\Users\wiczi\Desktop\Nowy dokument tekstowy.txt 2017-10-05 15:24 - 2017-10-05 15:24 - 000000000 ____D C:\Users\wiczi\AppData\LocalLow\uTorrent 2017-10-04 20:06 - 2017-10-05 19:00 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2017-10-04 20:05 - 2017-10-04 20:05 - 000000996 _____ C:\Users\wiczi\Desktop\GameSpy Arcade.lnk 2017-10-04 20:04 - 2017-10-04 20:06 - 000000000 ____D C:\Program Files (x86)\GameSpy Arcade 2017-10-04 20:04 - 2017-10-04 20:04 - 000001523 _____ C:\Users\Public\Desktop\Tony Hawks Pro Skater 4.lnk 2017-10-04 20:04 - 2017-10-04 20:04 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2017-10-04 20:04 - 2017-10-04 20:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2017-10-04 20:04 - 2017-10-04 20:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aspyr 2017-10-04 15:06 - 2017-10-04 15:08 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\steelseries-engine-3-client 2017-10-04 15:06 - 2017-10-04 15:06 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_sshid_01011.Wdf 2017-10-04 15:06 - 2017-10-04 15:06 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssdevfactory_01011.Wdf 2017-10-04 15:06 - 2017-10-04 15:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries 2017-10-04 15:06 - 2017-10-04 15:06 - 000000000 ____D C:\Program Files\DIFX 2017-10-04 15:05 - 2017-10-04 15:05 - 000000000 ____D C:\ProgramData\SteelSeries 2017-10-04 15:05 - 2017-10-04 15:05 - 000000000 ____D C:\Program Files\SteelSeries 2017-10-04 15:04 - 2017-10-04 15:04 - 109883336 _____ C:\Users\wiczi\Desktop\SteelSeriesEngine3.11.4Setup.exe 2017-10-04 14:45 - 2017-10-04 14:46 - 000003728 _____ C:\Windows\System32\Tasks\{63AD27C3-C35E-E0B0-63EC-813B01F4AC0F} 2017-10-04 14:45 - 2017-10-04 14:45 - 000023400 _____ C:\Windows\System32\Tasks\{7D0F0A47-0E78-7F0B-0F11-7F0F09791179} 2017-10-04 14:45 - 2017-10-04 14:45 - 000004028 _____ C:\Windows\System32\Tasks\{E9AB34FF-5E00-8354-C440-05D4A8CF09DE} 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\ab4f31a8 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\3b81ec62-52e7-1 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\3b81ec62-37a7-0 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\3b81ec62-3283-0 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\3b81ec62-1b63-1 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\{D4CDA45A-6366-13F1-FDF6-2F6E87F2843B} 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\{710b224b-412c-0} 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\{6d261e0a-012c-1} 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\{392f7f5f-012c-0} 2017-10-04 14:45 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\{071E9CDE-B0B5-2B75-8F6A-A7A75FE71BC0} 2017-10-03 14:21 - 2017-10-07 11:02 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Twitch 2017-10-03 14:21 - 2017-10-03 14:21 - 000000929 _____ C:\Users\wiczi\Desktop\Twitch.lnk 2017-10-03 14:21 - 2017-10-03 14:21 - 000000915 _____ C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk 2017-10-03 14:20 - 2017-10-03 14:20 - 124846712 _____ C:\Users\wiczi\Desktop\TwitchSetup.exe 2017-10-02 22:37 - 2017-10-02 22:37 - 002770904 _____ C:\Users\wiczi\Downloads\ZickZackv5.zip 2017-10-02 20:51 - 2017-10-02 20:51 - 000000000 ____D C:\ProgramData\Origin 2017-10-02 20:49 - 2017-10-02 20:49 - 000000000 ____D C:\Users\wiczi\Documents\SimCity 2017-10-02 20:46 - 2017-10-02 20:46 - 000000638 _____ C:\Users\wiczi\Desktop\SimCity.lnk 2017-10-02 20:46 - 2017-10-02 20:46 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\SimCity 2017-10-02 20:46 - 2017-10-02 20:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2017-10-01 15:14 - 2017-10-01 15:14 - 001853332 _____ C:\Users\wiczi\Desktop\Miya Folick - Talking with Strangers (HQ) - Part_1.wav 2017-09-30 20:27 - 2017-09-30 20:27 - 000002361 _____ C:\Users\wiczi\Desktop\Tower Defense King.lnk 2017-09-30 17:10 - 2017-10-04 14:47 - 000004136 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1506784223 2017-09-30 17:10 - 2017-09-30 17:10 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Opera Software 2017-09-30 17:10 - 2017-09-30 17:10 - 000000000 ____D C:\Users\wiczi\AppData\Local\Opera Software 2017-09-30 17:09 - 2017-09-30 17:09 - 000001085 _____ C:\Users\wiczi\Desktop\Cheat Engine.lnk 2017-09-30 17:09 - 2017-09-30 17:09 - 000000000 ____D C:\Users\wiczi\Documents\My Cheat Tables 2017-09-30 17:09 - 2017-09-30 17:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.7 2017-09-30 17:09 - 2017-09-30 17:09 - 000000000 ____D C:\Program Files (x86)\Cheat Engine 6.7 2017-09-30 17:07 - 2017-09-30 17:08 - 012117240 _____ (Cheat Engine ) C:\Users\wiczi\Downloads\CheatEngine67.exe 2017-09-30 11:48 - 2017-09-30 11:48 - 000000000 ____D C:\Users\wiczi\AppData\LocalLow\Sauropod Studio 2017-09-30 11:46 - 2017-09-30 11:48 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\electron-quick-start 2017-09-30 11:45 - 2017-09-30 11:45 - 000000600 _____ C:\Users\wiczi\Desktop\Castle Story.lnk 2017-09-30 11:45 - 2017-09-30 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Castle Story 2017-09-30 11:36 - 2017-09-30 11:40 - 1874916250 _____ C:\Users\wiczi\Downloads\Castle.Story-CODEX.rar 2017-09-30 11:28 - 2017-09-30 11:29 - 030219512 _____ C:\Users\wiczi\Downloads\Castle.Story.Update.v1.0.3-CODEX.rar 2017-09-30 11:22 - 2017-09-30 11:22 - 000002241 _____ C:\Users\wiczi\Desktop\Kik.lnk 2017-09-30 11:10 - 2017-09-30 11:10 - 000002335 _____ C:\Users\wiczi\Desktop\M O B B Y N.lnk 2017-09-30 11:00 - 2017-09-30 11:00 - 000002441 _____ C:\Users\wiczi\Desktop\ES Eksplorator plików.lnk 2017-09-30 10:49 - 2017-09-30 10:49 - 000002249 _____ C:\Users\wiczi\Desktop\Tinder.lnk 2017-09-30 10:45 - 2017-09-30 10:45 - 000002263 _____ C:\Users\wiczi\Desktop\Fake GPS.lnk 2017-09-30 10:42 - 2017-09-30 10:42 - 000001545 _____ C:\Users\Public\Desktop\BlueStacks.lnk 2017-09-30 10:42 - 2017-09-30 10:42 - 000001545 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk 2017-09-30 10:41 - 2017-10-01 12:22 - 000000000 ____D C:\ProgramData\BlueStacksSetup 2017-09-30 10:41 - 2017-09-30 10:42 - 000000000 ____D C:\Program Files (x86)\BlueStacks 2017-09-30 10:41 - 2017-09-30 10:41 - 000000000 ____D C:\ProgramData\BlueStacks 2017-09-30 10:40 - 2017-09-30 10:42 - 000000000 ____D C:\Users\wiczi\AppData\Local\Bluestacks 2017-09-30 10:39 - 2017-09-30 10:40 - 255452712 _____ (BlueStack Systems Inc.) C:\Users\wiczi\Downloads\BlueStacks-Installer_BS3_native_5a4d9b6a57341c0af7cb1e2d6a68b794.exe 2017-09-22 19:49 - 2017-09-22 19:49 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\.blazingpack 2017-09-22 19:45 - 2017-09-22 19:46 - 000000000 ____D C:\Program Files (x86)\Minecraft 2017-09-22 13:51 - 2017-09-22 13:51 - 000000524 _____ C:\Users\Public\Desktop\LUXONIX Purity.lnk 2017-09-22 13:51 - 2017-09-22 13:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LUXONIX 2017-09-22 13:51 - 2017-09-22 13:51 - 000000000 ____D C:\Program Files (x86)\Steinberg 2017-09-21 13:42 - 2017-09-21 13:42 - 000000000 ____D C:\Users\wiczi\Documents\Paradox Interactive 2017-09-21 13:38 - 2017-09-21 13:38 - 000000202 _____ C:\Users\wiczi\Desktop\Europa Universalis IV.url 2017-09-21 11:26 - 2017-09-21 10:58 - 004734880 _____ () C:\Users\wiczi\Desktop\TechnicLauncher.exe 2017-09-20 18:56 - 2017-10-07 13:10 - 006220854 _____ C:\Users\wiczi\Desktop\Nowy obraz mapy bitowej (3).bmp 2017-09-20 12:39 - 2017-09-20 12:39 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\The Creative Assembly 2017-09-20 12:35 - 2017-09-20 12:35 - 000000000 ____D C:\Users\wiczi\Documents\Xfer 2017-09-20 12:35 - 2017-09-20 12:35 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Xfer 2017-09-20 12:29 - 2017-09-20 12:29 - 000000656 _____ C:\Users\Public\Desktop\Total War ROME II Emperor Edition.lnk 2017-09-20 12:29 - 2017-09-20 12:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total War ROME II Emperor Edition 2017-09-20 09:48 - 2017-10-07 13:16 - 000000000 ____D C:\Program Files (x86)\ICBaloCIDxXU2 2017-09-20 09:48 - 2017-10-07 12:00 - 000000000 ____D C:\Program Files (x86)\CKCpTyVyQIE 2017-09-20 09:48 - 2017-10-07 10:37 - 000000000 ____D C:\Program Files (x86)\TQoarIXzU 2017-09-20 09:48 - 2017-09-20 09:48 - 000000000 ____D C:\Program Files (x86)\AvMVIUoBwtUn 2017-09-19 12:14 - 2017-09-19 12:14 - 000000266 __RSH C:\Users\wiczi\ntuser.pol 2017-09-18 17:35 - 2017-09-18 17:35 - 000000000 ____D C:\Users\wiczi\AppData\Local\GOG.com 2017-09-18 13:28 - 2017-09-18 13:28 - 000000000 _____ C:\autoexec.bat 2017-09-18 09:32 - 2017-09-18 09:32 - 000000000 ____D C:\ProgramData\Microleaves 2017-09-18 09:30 - 2017-10-07 10:40 - 000000290 _____ C:\Windows\Tasks\jJKowXmxzIFxIuj.job 2017-09-18 09:30 - 2017-10-07 10:13 - 000000000 ____D C:\Users\wiczi\AppData\LocalLow\zwMRXEuCYLuhR 2017-09-18 09:30 - 2017-10-04 14:46 - 000000000 ____D C:\ProgramData\bc3f3d8e-2d13-0 2017-09-18 09:30 - 2017-10-04 14:46 - 000000000 ____D C:\ProgramData\0226e74a-0ac3-0 2017-09-18 09:30 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\bc3f3d8e-27a1-1 2017-09-18 09:30 - 2017-10-04 14:45 - 000000000 ____D C:\ProgramData\0226e74a-75c1-1 2017-09-18 09:30 - 2017-09-20 09:48 - 000003060 _____ C:\Windows\System32\Tasks\LSjUFtTofwjkxN 2017-09-18 09:30 - 2017-09-20 09:48 - 000002706 _____ C:\Windows\System32\Tasks\jJKowXmxzIFxIuj2 2017-09-18 09:30 - 2017-09-20 09:48 - 000002564 _____ C:\Windows\System32\Tasks\jJKowXmxzIFxIuj 2017-09-18 09:30 - 2017-09-18 09:36 - 000000000 ____D C:\Program Files\RunBooster 2017-09-18 09:30 - 2017-09-18 09:30 - 000003568 _____ C:\Windows\System32\Tasks\FastDataX Task 2017-09-18 09:30 - 2017-09-18 09:30 - 000000000 ____D C:\Program Files (x86)\FastDataX 2017-09-18 09:29 - 2017-10-07 13:22 - 000000342 _____ C:\Windows\Tasks\Online Application V2G3.job 2017-09-18 09:29 - 2017-10-07 13:22 - 000000342 _____ C:\Windows\Tasks\Online Application V2G2.job 2017-09-18 09:29 - 2017-10-07 13:22 - 000000342 _____ C:\Windows\Tasks\Online Application V2G1.job 2017-09-18 09:29 - 2017-10-07 10:34 - 000000000 ____D C:\Applications 2017-09-18 09:29 - 2017-10-06 21:32 - 000000374 _____ C:\Windows\Tasks\Updater_Online_Application.job 2017-09-18 09:29 - 2017-09-18 09:29 - 000015606 _____ C:\Windows\SysWOW64\findit.xml 2017-09-18 09:29 - 2017-09-18 09:29 - 000003256 _____ C:\Windows\System32\Tasks\ShadowsocksS 2017-09-18 09:29 - 2017-09-18 09:29 - 000003206 _____ C:\Windows\System32\Tasks\Updater_Online_Application 2017-09-18 09:29 - 2017-09-18 09:29 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G3 2017-09-18 09:29 - 2017-09-18 09:29 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G2 2017-09-18 09:29 - 2017-09-18 09:29 - 000003170 _____ C:\Windows\System32\Tasks\Online Application V2G1 2017-09-18 09:29 - 2017-09-18 09:29 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Microleaves 2017-09-18 09:29 - 2017-09-18 09:29 - 000000000 ____D C:\Users\wiczi\AppData\Local\AdvinstAnalytics 2017-09-18 09:29 - 2017-09-18 09:29 - 000000000 ____D C:\Users\Public\Documents\XMUpdate 2017-09-18 09:29 - 2017-09-18 09:29 - 000000000 ____D C:\ProgramData\Quoteexs 2017-09-18 09:29 - 2017-09-18 09:29 - 000000000 ____D C:\Program Files (x86)\RIVpemjyECl8 Updater 2017-09-18 09:29 - 2017-09-18 09:29 - 000000000 ____D C:\Program Files (x86)\Microleaves 2017-09-18 09:28 - 2017-09-18 09:28 - 007327744 _____ C:\Users\wiczi\AppData\Local\agent.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 002554368 _____ (TODO: ) C:\Users\wiczi\AppData\Local\TinRanfix.exe 2017-09-18 09:28 - 2017-09-18 09:28 - 002554368 _____ (TODO: ) C:\Users\wiczi\AppData\Local\GreenWarm.exe 2017-09-18 09:28 - 2017-09-18 09:28 - 001899389 _____ C:\Users\wiczi\AppData\Local\GreenWarm.tst 2017-09-18 09:28 - 2017-09-18 09:28 - 001895382 _____ C:\Users\wiczi\AppData\Local\Faxjob.bin 2017-09-18 09:28 - 2017-09-18 09:28 - 000278508 _____ C:\Users\wiczi\AppData\Local\TinRanfix.tst 2017-09-18 09:28 - 2017-09-18 09:28 - 000140800 _____ C:\Users\wiczi\AppData\Local\installer.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 000126464 _____ C:\Users\wiczi\AppData\Local\noah.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 000070800 _____ C:\Users\wiczi\AppData\Local\Config.xml 2017-09-18 09:28 - 2017-09-18 09:28 - 000018432 _____ C:\Users\wiczi\AppData\Local\Main.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 000016464 _____ C:\Users\wiczi\AppData\Local\InstallationConfiguration.xml 2017-09-18 09:28 - 2017-09-18 09:28 - 000005568 _____ C:\Users\wiczi\AppData\Local\md.xml 2017-09-18 09:28 - 2017-09-18 09:28 - 000000000 ____D C:\Users\wiczi\AppData\Local\AdService 2017-09-18 09:28 - 2017-09-18 09:28 - 000000000 ____D C:\ProgramData\Logic Cramble 2017-09-17 23:06 - 2017-09-17 23:06 - 000000000 ____D C:\Users\wiczi\ansel 2017-09-17 23:05 - 2017-09-17 23:05 - 000000000 ____D C:\ProgramData\Dishonored 2 2017-09-17 23:03 - 2017-09-17 23:03 - 000000559 _____ C:\Users\Public\Desktop\Dishonored 2.lnk 2017-09-17 23:03 - 2017-09-17 23:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dishonored 2 2017-09-17 22:14 - 2017-09-17 22:14 - 000000671 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk 2017-09-17 22:14 - 2017-09-17 22:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes 2017-09-17 18:09 - 2017-09-18 09:30 - 000000266 __RSH C:\ProgramData\ntuser.pol 2017-09-17 11:18 - 2017-09-17 11:18 - 000000000 ____D C:\Users\wiczi\Documents\Electronic Arts 2017-09-17 11:17 - 2017-09-17 11:17 - 000000704 _____ C:\Users\Public\Desktop\The Sims 4.lnk 2017-09-17 11:17 - 2017-09-17 11:17 - 000000704 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4.lnk 2017-09-17 11:17 - 2014-10-19 15:54 - 000447752 _____ (On2.com) C:\Windows\SysWOW64\vp6vfw.dll 2017-09-13 21:22 - 2017-09-13 21:22 - 000000000 ____D C:\Users\wiczi\aTubeCatcher 2017-09-13 21:21 - 2017-09-13 21:21 - 000001330 _____ C:\Users\Public\Desktop\Music Search MP3.lnk 2017-09-13 21:21 - 2017-09-13 21:21 - 000001186 _____ C:\Users\Public\Desktop\aTube Catcher.lnk 2017-09-13 21:21 - 2017-09-13 21:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher 2017-09-13 21:21 - 2017-09-13 21:21 - 000000000 ____D C:\Program Files (x86)\DsNET Corp 2017-09-13 21:21 - 2013-05-23 09:52 - 000386560 _____ (Dart Communications) C:\Windows\SysWOW64\DartSecure2.dll 2017-09-13 21:21 - 2013-05-23 09:52 - 000234496 _____ (Dart Communications) C:\Windows\SysWOW64\DartCertificate.dll 2017-09-13 21:21 - 2013-05-06 13:17 - 000425472 _____ (Dart Communications) C:\Windows\SysWOW64\DartSock.dll 2017-09-13 21:21 - 2008-08-18 19:18 - 000077824 _____ (Fox Magic Software) C:\Windows\SysWOW64\fmcodec.DLL 2017-09-13 21:20 - 2017-09-13 21:20 - 021020640 _____ (DsNET Corp ) C:\Users\wiczi\Downloads\aTube_Catcher.exe 2017-09-13 21:10 - 2017-08-19 17:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2017-09-13 21:10 - 2017-08-19 17:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2017-09-13 21:10 - 2017-08-16 17:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-09-13 21:10 - 2017-08-16 17:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-09-13 21:10 - 2017-08-16 16:57 - 003224576 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-09-13 21:10 - 2017-08-15 17:29 - 014182400 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-09-13 21:10 - 2017-08-15 17:29 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-09-13 21:10 - 2017-08-15 17:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-09-13 21:10 - 2017-08-15 17:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-09-13 21:10 - 2017-08-14 19:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll 2017-09-13 21:10 - 2017-08-14 19:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll 2017-09-13 21:10 - 2017-08-14 19:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll 2017-09-13 21:10 - 2017-08-14 19:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll 2017-09-13 21:10 - 2017-08-14 19:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll 2017-09-13 21:10 - 2017-08-14 19:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll 2017-09-13 21:10 - 2017-08-14 19:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll 2017-09-13 21:10 - 2017-08-14 19:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll 2017-09-13 21:10 - 2017-08-13 23:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2017-09-13 21:10 - 2017-08-13 23:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe 2017-09-13 21:10 - 2017-08-11 08:42 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-09-13 21:10 - 2017-08-11 08:38 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-09-13 21:10 - 2017-08-11 08:38 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-09-13 21:10 - 2017-08-11 08:38 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-09-13 21:10 - 2017-08-11 08:38 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-09-13 21:10 - 2017-08-11 08:36 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-09-13 21:10 - 2017-08-11 08:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:24 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-09-13 21:10 - 2017-08-11 08:24 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-09-13 21:10 - 2017-08-11 08:21 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-09-13 21:10 - 2017-08-11 08:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe 2017-09-13 21:10 - 2017-08-11 08:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe 2017-09-13 21:10 - 2017-08-11 08:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 08:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe 2017-09-13 21:10 - 2017-08-11 08:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe 2017-09-13 21:10 - 2017-08-11 08:07 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-09-13 21:10 - 2017-08-11 08:07 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-09-13 21:10 - 2017-08-11 08:07 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-09-13 21:10 - 2017-08-11 08:06 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-09-13 21:10 - 2017-08-11 08:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-09-13 21:10 - 2017-08-11 08:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe 2017-09-13 21:10 - 2017-08-11 08:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-09-13 21:10 - 2017-08-11 08:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll 2017-09-13 21:10 - 2017-08-11 08:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2017-09-13 21:10 - 2017-08-11 08:00 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-09-13 21:10 - 2017-08-11 08:00 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-09-13 21:10 - 2017-08-11 07:59 - 000460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-09-13 21:10 - 2017-08-11 07:59 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-09-13 21:10 - 2017-08-11 07:59 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-09-13 21:10 - 2017-08-11 07:59 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-09-13 21:10 - 2017-08-11 07:59 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-09-13 21:10 - 2017-08-11 07:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-09-13 21:10 - 2017-08-11 07:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-09-13 21:10 - 2017-08-11 07:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys 2017-09-13 21:10 - 2017-08-11 07:56 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-09-13 21:10 - 2017-08-11 07:56 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-09-13 21:10 - 2017-08-11 07:56 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-09-13 21:10 - 2017-08-11 07:56 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-09-13 21:10 - 2017-08-11 07:55 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-09-13 21:10 - 2017-08-11 07:55 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 07:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 07:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-09-13 21:10 - 2017-08-11 07:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-09-13 21:10 - 2017-07-07 17:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll 2017-09-13 21:10 - 2017-07-07 17:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll 2017-09-10 19:08 - 2009-02-16 22:48 - 001474048 _____ C:\Users\wiczi\Downloads\autorun.exe 2017-09-10 19:08 - 2009-02-16 22:48 - 000987009 _____ C:\Users\wiczi\Downloads\autorun.apm 2017-09-10 19:08 - 2009-02-16 21:46 - 000552214 _____ C:\Users\wiczi\Downloads\ISSetup.dll 2017-09-10 19:08 - 2009-02-16 21:46 - 000404175 _____ C:\Users\wiczi\Downloads\data1.cab 2017-09-10 19:08 - 2009-02-16 21:46 - 000015134 _____ C:\Users\wiczi\Downloads\data1.hdr 2017-09-10 19:08 - 2009-01-21 07:48 - 002359350 _____ C:\Users\wiczi\Downloads\a2009_0121_0748_00_687.bmp 2017-09-10 19:08 - 2006-05-17 10:21 - 000152496 _____ (Macrovision Corporation) C:\Users\wiczi\Downloads\_setup.dll 2017-09-10 19:00 - 2017-09-24 11:04 - 000000078 _____ C:\Users\wiczi\Desktop\Password Cracker.txt 2017-09-10 19:00 - 2017-09-10 19:00 - 000001018 _____ C:\Users\wiczi\Desktop\Password Cracker.bat 2017-09-10 19:00 - 2017-09-10 19:00 - 000000000 ____D C:\Users\wiczi\Desktop\Temp 2017-09-10 10:24 - 2017-09-10 10:24 - 000000202 _____ C:\Users\wiczi\Desktop\H1Z1 King of the Kill.url 2017-09-08 22:23 - 2017-09-08 22:24 - 000000482 _____ C:\Users\wiczi\Desktop\url.htm 2017-09-08 20:33 - 2017-09-08 20:33 - 000079110 _____ C:\Users\wiczi\Desktop\Nowy obraz mapy bitowej (2).bmp 2017-09-08 20:32 - 2017-09-08 20:32 - 000000000 _____ C:\Users\wiczi\Desktop\Nowy obraz mapy bitowej.bmp 2017-09-08 17:54 - 2017-09-18 09:29 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Mozilla 2017-09-08 17:54 - 2017-09-08 17:54 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Macromedia 2017-09-08 17:53 - 2017-10-07 10:43 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\GG 2017-09-08 17:53 - 2017-09-08 17:54 - 000000000 ____D C:\Users\wiczi\AppData\Local\GG 2017-09-08 17:53 - 2017-09-08 17:53 - 000001151 _____ C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk 2017-09-08 17:53 - 2017-09-08 17:53 - 000001143 _____ C:\Users\wiczi\Desktop\GG.lnk ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-10-07 12:25 - 2017-07-15 16:19 - 000000000 ____D C:\ProgramData\NVIDIA 2017-10-07 11:00 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Beeper 2017-10-07 10:49 - 2009-07-14 06:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-10-07 10:49 - 2009-07-14 06:45 - 000021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-10-07 10:43 - 2017-07-19 20:31 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Spotify 2017-10-07 10:42 - 2017-08-07 18:24 - 000000000 ____D C:\Users\wiczi\AppData\Local\CrashDumps 2017-10-07 10:42 - 2017-07-17 14:39 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Skype 2017-10-07 10:41 - 2017-08-21 09:55 - 000000000 ____D C:\Users\wiczi\AppData\Local\ManyCam 2017-10-07 10:40 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-10-07 10:17 - 2017-07-19 22:42 - 000000000 ____D C:\Users\wiczi\AppData\Local\Spotify 2017-10-07 10:12 - 2017-07-15 15:42 - 000002255 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-10-07 10:12 - 2017-07-15 15:42 - 000002243 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-10-06 17:22 - 2009-07-14 07:08 - 000032520 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-10-05 22:50 - 2017-07-15 17:36 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\uTorrent 2017-10-05 19:00 - 2017-07-15 15:45 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-10-05 17:43 - 2017-08-27 20:53 - 000000000 ____D C:\Users\wiczi\AppData\Local\ElevatedDiagnostics 2017-10-04 15:07 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf 2017-09-23 21:23 - 2017-07-20 23:07 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\DVDVideoSoft 2017-09-23 19:19 - 2017-07-29 20:03 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\.minecraft 2017-09-22 19:45 - 2017-07-29 20:02 - 000000961 _____ C:\Users\Public\Desktop\Minecraft.lnk 2017-09-22 19:45 - 2017-07-29 20:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2017-09-22 18:55 - 2017-07-16 14:53 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\TS3Client 2017-09-21 13:41 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-09-21 13:38 - 2017-07-18 16:24 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-09-21 11:21 - 2017-07-15 15:43 - 000000000 ____D C:\Program Files\Google 2017-09-21 11:21 - 2017-07-15 15:42 - 000000000 ____D C:\Program Files (x86)\Google 2017-09-21 11:17 - 2017-08-02 01:59 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com Games 2017-09-21 11:17 - 2017-07-15 15:42 - 000000000 ____D C:\Users\wiczi\AppData\Local\Google 2017-09-19 21:36 - 2017-07-20 23:05 - 000000000 ____D C:\Users\wiczi\Desktop\Nowy folder 2017-09-19 12:19 - 2017-07-15 15:40 - 000001421 _____ C:\Users\wiczi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2017-09-19 12:14 - 2017-07-15 15:39 - 000000000 ____D C:\Users\wiczi 2017-09-18 09:30 - 2009-07-14 05:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy 2017-09-17 23:05 - 2017-07-15 16:19 - 000000000 ____D C:\ProgramData\Package Cache 2017-09-17 22:10 - 2017-08-10 10:01 - 000000000 ____D C:\Users\wiczi\AppData\Roaming\DAEMON Tools Lite 2017-09-17 21:30 - 2017-07-30 11:30 - 000001278 _____ C:\Users\wiczi\Desktop\nativelog.txt 2017-09-17 16:24 - 2011-04-12 15:21 - 000741024 _____ C:\Windows\system32\perfh015.dat 2017-09-17 16:24 - 2011-04-12 15:21 - 000156096 _____ C:\Windows\system32\perfc015.dat 2017-09-17 16:24 - 2009-07-14 07:13 - 001672152 _____ C:\Windows\system32\PerfStringBackup.INI 2017-09-17 11:17 - 2009-07-14 07:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-09-16 18:35 - 2017-07-17 14:39 - 000000000 ___RD C:\Program Files (x86)\Skype 2017-09-16 18:35 - 2017-07-17 14:39 - 000000000 ____D C:\ProgramData\Skype 2017-09-16 10:31 - 2009-07-14 06:45 - 000266656 _____ C:\Windows\system32\FNTCACHE.DAT 2017-09-13 22:38 - 2017-07-15 15:44 - 001643550 _____ C:\Windows\SysWOW64\PerfStringBackup.INI ==================== Pliki w katalogu głównym wybranych folderów ======= 2017-09-18 09:28 - 2017-09-18 09:28 - 007327744 _____ () C:\Users\wiczi\AppData\Local\agent.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 000070800 _____ () C:\Users\wiczi\AppData\Local\Config.xml 2017-09-18 09:28 - 2017-09-18 09:28 - 001895382 _____ () C:\Users\wiczi\AppData\Local\Faxjob.bin 2017-09-18 09:28 - 2017-09-18 09:28 - 002554368 _____ (TODO: ) C:\Users\wiczi\AppData\Local\GreenWarm.exe 2017-09-18 09:28 - 2017-09-18 09:28 - 001899389 _____ () C:\Users\wiczi\AppData\Local\GreenWarm.tst 2017-09-18 09:28 - 2017-09-18 09:28 - 000016464 _____ () C:\Users\wiczi\AppData\Local\InstallationConfiguration.xml 2017-09-18 09:28 - 2017-09-18 09:28 - 000140800 _____ () C:\Users\wiczi\AppData\Local\installer.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 000018432 _____ () C:\Users\wiczi\AppData\Local\Main.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 000005568 _____ () C:\Users\wiczi\AppData\Local\md.xml 2017-09-18 09:28 - 2017-09-18 09:28 - 000126464 _____ () C:\Users\wiczi\AppData\Local\noah.dat 2017-09-18 09:28 - 2017-09-18 09:28 - 002554368 _____ (TODO: ) C:\Users\wiczi\AppData\Local\TinRanfix.exe 2017-09-18 09:28 - 2017-09-18 09:28 - 000278508 _____ () C:\Users\wiczi\AppData\Local\TinRanfix.tst 2017-09-18 09:28 - 2017-09-18 09:28 - 000032038 _____ () C:\Users\wiczi\AppData\Local\uninstall_temp.ico Niektóre pliki w TEMP: ==================== 2017-10-04 20:04 - 2003-03-04 13:29 - 000040960 _____ () C:\Users\wiczi\AppData\Local\Temp\comver.dll 2017-09-03 10:24 - 2017-09-03 10:24 - 000019968 ____N (Red Hat®, Inc.) C:\Users\wiczi\AppData\Local\Temp\jansi-64-5000759554432912579.dll 2017-09-03 10:26 - 2017-09-03 10:26 - 000019968 ____N (Red Hat®, Inc.) C:\Users\wiczi\AppData\Local\Temp\jansi-64-8462989600251554272.dll 2017-10-07 10:12 - 2017-10-07 10:12 - 000374181 _____ (WeMonetize ) C:\Users\wiczi\AppData\Local\Temp\MQ0FGEP.exe 2017-10-07 10:19 - 2017-10-07 10:19 - 000053248 _____ (59) C:\Users\wiczi\AppData\Local\Temp\MWUMJPSLIQ2K.exe 2017-08-15 10:57 - 2017-08-15 10:57 - 004511963 _____ (OpenSubtitles.org ) C:\Users\wiczi\AppData\Local\Temp\OSDownloader.exe 2017-08-16 15:20 - 2017-08-16 15:20 - 058782680 _____ (Skype Technologies S.A.) C:\Users\wiczi\AppData\Local\Temp\SkypeSetup.exe 2017-08-15 20:48 - 2017-09-11 20:27 - 000020596 _____ () C:\Users\wiczi\AppData\Local\Temp\t.dll ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo C:\Windows\system32\drivers\sptd.sys -> MD5 = D41D8CD98F00B204E9800998ECF8427E (0-byte MD5) <======= UWAGA LastRegBack: 2017-10-01 16:57 ==================== Koniec FRST.txt ============================