JustPaste.it

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.11.2018
Ran by Andrzej (administrator) on ANDRZEJ-PC (18-11-2018 10:23:57)
Running from J:\Pobrane
Loaded Profiles: Andrzej (Available Profiles: Andrzej)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angielski (Stany Zjednoczone)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
() C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
() C:\Program Files (x86)\Gigabyte\AppCenter\ApCent.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDWebCam.exe
(FinalWire Ltd.) C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPictureViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDYT.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMovieViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Cucusoft, Inc.) C:\Program Files\Cucusoft\NetGuard\SysMsgProxySrvc.sys
() C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(www.shadowexplorer.com) C:\Program Files (x86)\ShadowExplorer\sesvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [CucusoftNetGuard] => [X]
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15642744 2016-03-30] (Logitech Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [Cmaudio8788GX] => C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] ()
HKLM\...\Run: [Cmaudio8788GX64] => C:\Windows\system\HsMgr64.exe [282112 2008-07-11] ()
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [134480 2016-03-24] (Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2018-10-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\RunOnce: [EasyTune] => C:\Program Files (x86)\Gigabyte\EasyTune\etro.exe [5632 2014-08-18] (GIGA-BYTE TECHNOLOGY CO., LTD.)
HKLM-x32\...\RunOnce: [PreRun] => C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe [8192 2013-04-29] ()
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\Run: [] => [X]
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3986544 2018-10-18] (Tonec Inc.)
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: G - G:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: H - H:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: I - I:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: J - J:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: K - K:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: L - L:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: M - M:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: N - N:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\MountPoints2: {4015a3b3-b3d6-11e6-8285-806e6f6e6963} - D:\setup.exe
HKU\S-1-5-21-781891965-1419206771-198316140-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [242688 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [ZoneAlarm Windows 10 Upgrader] => "C:\ProgramData\CheckPoint\ZoneAlarm\Data\Updates\unpacked==win10=update_win10.zip\upgrade.exe" /delay
HKU\S-1-5-18\...\Run: [script_fcbd] => "F:\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\fcbd.bat"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2015-05-23]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
GroupPolicy: Restriction ? <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1AE999F6-38FE-42C6-8257-FEEC76A2E62E}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4B373FD2-4C0C-41F9-8972-D29B6E641E00}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{62E8C5B4-EE92-47A8-A13D-98748000E3CE}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-781891965-1419206771-198316140-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pl-pl/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-781891965-1419206771-198316140-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2018-06-19] (Internet Download Manager, Tonec Inc.)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2018-06-19] (Internet Download Manager, Tonec Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-04-20] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Arc\Plugins\ArcPluginIE.dll [2017-04-28] (Perfect World Entertainment Inc)
BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\SysWOW64\mscoree.dll [2010-11-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-20] (Oracle Corporation)
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\Windows\SysWOW64\mscoree.dll [2010-11-21] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile:
FF HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2018-10-18]
FF HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Andrzej\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Andrzej\AppData\Roaming\IDM\idmmzcc5 [2018-11-17] [Legacy] [not signed]
FF HKU\S-1-5-21-781891965-1419206771-198316140-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_148.dll [2018-11-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_148.dll [2018-11-13] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-20] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-11-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-11-13] (NVIDIA Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Arc\Plugins\npArcPluginFF.dll [2017-04-28] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=pl-pl
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR Profile: C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default [2018-11-18]
CHR Extension: (HTML Viewer) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajeckfnejjkkhcbdhidfgahjpelakpcd [2016-11-25]
CHR Extension: (Dokumenty) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-31]
CHR Extension: (Dysk Google) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-18]
CHR Extension: (Dark Skin for Youtube™) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfeknfgchonpnofdjokchhdhdnddhglm [2017-09-05]
CHR Extension: (Bloker reklam AdGuard) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2018-10-25]
CHR Extension: (YouTube) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-25]
CHR Extension: (Adblock Plus) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-11-14]
CHR Extension: (Stylus) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\clngdbkpkpeebahjckkjfobafhncgmne [2018-11-06]
CHR Extension: (Google Search) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-11-25]
CHR Extension: (HTML Editor) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dacmeeeegjoaddfondbeaaafohldgfof [2016-11-25]
CHR Extension: (Tampermonkey) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-09-01]
CHR Extension: (Adobe Acrobat) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (AdBlock) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-10-25]
CHR Extension: (Black red shards) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpjlkkaalgfbbegfnjoclhfidancjpch [2017-06-14]
CHR Extension: (Skype) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-04]
CHR Extension: (IDM Integration Module) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-10-26]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Gmail) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-25]
CHR Extension: (Chrome Media Router) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-18]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-10-18]
CHR HKU\S-1-5-21-781891965-1419206771-198316140-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-10-18]
CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [891472 2018-11-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [248312 2018-11-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [248312 2018-11-13] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1162120 2018-11-13] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [87064 2017-04-28] (Perfect World Entertainment Inc)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [431688 2018-10-09] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6076936 2018-10-24] ()
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2012-10-26] (Brother Industries, Ltd.) [File not signed]
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [369720 2017-08-16] (BlueStack Systems, Inc.)
R2 CS_SysMsgProxy; C:\Program Files\Cucusoft\NetGuard\SysMsgProxySrvc.sys [255136 2013-06-21] (Cucusoft, Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2018-10-20] (EasyAntiCheat Ltd)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342456 2018-09-27] (Futuremark)
R2 gadjservice; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [16896 2015-04-14] () [File not signed]
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [706120 2018-10-23] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7112264 2018-10-05] (GOG.com)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-10-10] (Hi-Rez Studios) [File not signed]
S3 HwmRecordService; C:\Program Files (x86)\GIGABYTE\SIV\HwmRecordService.exe [62784 2015-07-01] (GIGA-BYTE TECHNOLOGY CO., LTD.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [355232 2015-08-09] (Intel Corporation)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-03-30] (Logitech Inc.)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4307704 2016-02-25] (INCA Internet Co., Ltd.)
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros) [File not signed]
R2 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2013-01-02] (www.shadowexplorer.com) [File not signed]
S3 Survarium Update Service; C:\Program Files (x86)\Survarium\game\binaries\x86\survarium_service.exe [121992 2018-11-17] ()
S3 Survarium-Steam Update Service; H:\SteamLibrary\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-12-20] ()
S2 SwOffScheduler; C:\Program Files\Airytec\Switch Off\swoff.exe [173056 2014-09-23] (Airytec) [File not signed]
S2 SwOffWeb; C:\Program Files\Airytec\Switch Off\swoff.exe [173056 2014-09-23] (Airytec) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH)
S2 upsMonitor; C:\PowerWalker_ViewPower\upsMonitor.exe [552960 2018-10-17] (Flexera Software) [File not signed]
S3 upsTomcat; C:\PowerWalker_ViewPower\tomcat\bin\tomcat7.exe [80896 2013-12-19] (Apache Software Foundation) [File not signed]
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3746584 2016-03-24] (Check Point Software Technologies Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [18232 2016-08-25] (Intel(R) Corporation)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [96272 2015-10-19] (Check Point Software Technologies, Ltd.)
S3 DAUpdaterSvc; D:\Gry\Dragon Age Orgins\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AcpiCtlDrv; C:\Windows\System32\DRIVERS\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation)
R3 AIDA64Driver; C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [45728 2016-06-27] ()
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] ()
R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [73240 2018-08-12] (Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [199920 2018-07-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [153040 2018-07-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-03-03] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-03-03] (Avira Operations GmbH & Co. KG)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-06-21] (Bluestack System Inc. )
R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2735616 2015-06-02] (C-Media Inc)
R3 etocdrv; C:\Windows\etocdrv.sys [15584 2013-10-31] (Giga-Byte Technology CO., LTD.)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2014-05-28] (Intel Corporation)
S3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
R2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [37064 2016-08-24] (Intel Corporation)
S3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.)
R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [180264 2015-12-25] (Intel Corporation)
S3 NVFLASH; C:\Windows\system32\drivers\nvflash.sys [14664 2016-03-05] ()
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [69544 2018-09-06] (NVIDIA Corporation)
S3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [65792 2018-09-06] (NVIDIA Corporation)
S3 rspLLL; C:\Windows\System32\DRIVERS\rspLLL64.sys [26368 2015-07-13] (Resplendence Software Projects Sp.)
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] ()
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3731672 2015-09-23] (Realtek Semiconductor Corporation )
S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] ()
S3 usbohci; C:\Windows\system32\drivers\usbohci.sys [25600 2012-10-11] (Microsoft Corporation) [File not signed]
S3 usbuhci; C:\Windows\system32\drivers\usbuhci.sys [30720 2012-10-11] (Microsoft Corporation) [File not signed]
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [462304 2016-03-24] (Check Point Software Technologies Ltd.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

========================== Drivers MD5 =======================

C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AcpiCtlDrv.sys 2EA3EB3E69B6480AB112E876F3096312
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys 0DC2A9882540DEA4A55B08785E09D8FC
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 A05B9C895419A55007809767F46B9C2D
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys 00D77B30CA9CB1D7793AC952549331A0
C:\Windows\System32\DRIVERS\AppleCharger.sys E4D0F0D5EB374D8BACF40E30E9771D60
C:\Windows\system32\drivers\arc.sys ==> MD5 is legit
C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\avdevprot.sys 0174666BA4361AE37DD8212D229FA6C8
C:\Windows\System32\DRIVERS\avgntflt.sys F6456F69FE9E63DF2D365A3F5F643135
C:\Windows\System32\DRIVERS\avipbb.sys 9FB497B1EA6638FF6751236BD15CCF7B
C:\Windows\System32\DRIVERS\avkmgr.sys 3E0AB8C453FA433B15A30BAA8BD4B275
C:\Windows\System32\DRIVERS\avnetflt.sys 19B6F9073BD606B7ABEC03A0328FDC1B
C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bflwfx64.sys 35BAC943C9C9C501B2DB888858D41F99
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ABA3984C822E4D3F889699912D85D6C5
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Program Files (x86)\BlueStacks\BstkDrv.sys 7DB8EE09821A6D81A19A6591C9B8AA3A
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys 3D67C27DD17B254D7915FA16A5AE3573
C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\drivers\cmudaxp.sys 12145BABD827F3B68B27A4F73B7284CD
C:\Windows\System32\Drivers\cng.sys A98CED39AD91B445E2E442A9BD67E8B4
C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\csc.sys ==> MD5 is legit
C:\Windows\System32\Drivers\dfsc.sys 9B38580063D281A99E68EF5813022A5F
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\drivers\disk.sys 616387BBD83372220B09DE95F4E67BBC
C:\Windows\system32\drivers\dmvsc.sys 5DB085A8A6600BE6401F2B24EECB5415
C:\Windows\system32\drivers\drmkaud.sys 26FE888505E5A945B0536AF9A2A27A6F
C:\Windows\System32\drivers\dxgkrnl.sys 30545EF2A1E3EF79450AED5DF80F5884
C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit
C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\etocdrv.sys ED2037F8C941E66E3C7F6545BEEA1681
C:\Windows\System32\Drivers\exfat.sys 7E45F8B117419ABA3BB26579F6E70324
C:\Windows\System32\Drivers\fastfat.sys 6EDFA237D25433C03F42FBFDB16BDD24
C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit
C:\Windows\gdrv.sys 9AB9F3B75A2EB87FAFB1B7361BE9DFB3
C:\Windows\System32\DRIVERS\hamachi.sys 870C497E7E6990A2EA0C56B1F0D2FFEE
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys F61634BEC53F73702A10DE69F6DCAF57
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\iaStorA.sys 9EBE1AE8B3DA91D06BE1971EB37F7DA0
C:\Windows\System32\DRIVERS\iaStorF.sys C018747131B4E90E9267BA5B31EB43A7
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\System32\DRIVERS\ICCWDT.sys 231ADCE77616144B8E3D29707B282C82
C:\Windows\System32\DRIVERS\idmwfp.sys 6248F7270A37B8890C7A058AAD4D6620
C:\Windows\System32\DRIVERS\igdkmd64.sys 5863E2DD2E5C2D1B1F70C3826C162A7B
C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys CAA8BC6737DFA3BF1A50175CFB226788
C:\Windows\System32\drivers\RTKVHD64.sys 1747CAA9AB414DEC0FF38CDEBD3A7418
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys 1619EE2C1FC5684C526D6F0D7DD40F50
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6
C:\Windows\System32\DRIVERS\iusb3hcs.sys 71BA329D2919AE51429ED2AF035B1433
C:\Windows\System32\DRIVERS\iusb3hub.sys A9C28AFEDE53CF4B55FE98E66C3C7207
C:\Windows\System32\DRIVERS\iusb3xhc.sys F144C98AC92F30C6897088855B19422F
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\e22w7x64.sys 819433A6CFC8771F0A2B0BB8EF6125B1
C:\Windows\System32\Drivers\ksecdd.sys 15682ED7B70B186C9C2BE6CA423D8E74
C:\Windows\System32\Drivers\ksecpkg.sys 945F4DA63A76EB2725C070BF3A86B5A5
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
C:\Windows\System32\drivers\LGBusEnum.sys 17325C9B9ADB2BB99049936D0C9812C8
C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys 2D7F1C02B94D6F0F3E10107E5EA8E141
C:\Windows\System32\drivers\LGJoyXlCore.sys C7AF05942E041D4B1F345ACF79993BB3
C:\Windows\System32\Drivers\LGPBTDD.sys F705A641C18DF31B48B5DBDA94B425E4
C:\Windows\System32\drivers\LGVirHid.sys 1DDB8DE3D6EEF31EDCF4977B2D2FAACC
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MBfilt64.sys 8FF2D95CBA49B405C5DE27039FF0BF35
C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\TeeDriverx64.sys 453DE62ACB654D39AF0162F97E3B5FA3
C:\Windows\System32\drivers\modem.sys BFFB0C93D9FB43CA42EF11C9240BFF7F
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys 8ADB5445B29941CB41AF2846FD5C93C7
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys 98DB1790F0A584E0A2528B92B052417F
C:\Windows\System32\DRIVERS\mrxsmb.sys 054F780A442DB96F9FE10501B35E75CA
C:\Windows\System32\DRIVERS\mrxsmb10.sys A1EAC982807B3179DD92235B6B709C0A
C:\Windows\System32\DRIVERS\mrxsmb20.sys E6B504F163094F2DB84F7D34A893FA00
C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys F7309F42555F8AAB7144A51A1F2585B0
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys E47D571FEC2C76E867935109AB2A770C
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys 47B2D0B31BDC3EBE6090228E2BA3764D
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\system32\drivers\nvflash.sys ABDB6F41085F6947174615B2F6AC7BAE
C:\Windows\System32\drivers\nvhda64v.sys 0A4C96A706AAD735FFE0F98C408242A8
C:\Windows\System32\DRIVERS\nvlddmkm.sys 66373626C3643158CEC6C86E9AC6C8E1
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\System32\drivers\nvvad64v.sys 31A62118FFA56D758D3CA4D00EAEA430
C:\Windows\System32\DRIVERS\nvvhci.sys 05524B29F19E0BB19FA0297880D788B0
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\system32\drivers\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys EA4D67448BE493D543F1730D6CD04694
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\drivers\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34
C:\Windows\System32\Drivers\RDPWD.sys FE571E088C2D83619D2D48D4E961BF41
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rspLLL64.sys AD53BCEE2C4EE1BCE383D75030B0EDF6
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Program Files (x86)\MSI Afterburner\RTCore64.sys 2D8E4F38B36C334D0A32A7324832501D
C:\Windows\System32\DRIVERS\rtwlane.sys CAF9B803F01F807783FF7611315C381B
C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\Drivers\SCDEmu.sys FA895C8D357C9FF0AC5FED6CD5F0D1CC
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit
C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\SysWOW64\speedfan.sys 0FFE35F0B0CD5A324BBE22F02569AE3B
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys 546C81F238F084A393EC54114741A0A8
C:\Windows\System32\DRIVERS\srv2.sys 431D2B06E8F93EAEC53E8FA37FCFF2F1
C:\Windows\System32\DRIVERS\srvnet.sys 42EDAB3E3E8E25C7093674936C2DB4BD
C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\serscan.sys DECACB6921DED1A38642642685D77DAC
C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit
C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
C:\Windows\System32\drivers\synth3dvsc.sys C3A39C4079305480972D29C44B868C78
C:\Windows\System32\drivers\tcpip.sys 351A21ED3971ADD558956FF3EB0F6FED
C:\Windows\System32\DRIVERS\tcpip.sys 351A21ED3971ADD558956FF3EB0F6FED
C:\Windows\System32\drivers\tcpipreg.sys 7FE5586314EE7D6AA8483264A089E5AF
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys EC75A942C32F7F405659D86156DCE4C5
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
C:\Windows\system32\drivers\terminpt.sys EF4469AB69EB15E5D3754E6AEAFBCD3D
C:\Windows\System32\DRIVERS\tssecsrv.sys 19BEDA57F3E0A06B8D5EB6D619BD5624
C:\Windows\System32\drivers\tsusbflt.sys E9981ECE8D894CEF7038FD1D040EB426
C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07
C:\Windows\System32\drivers\tsusbhub.sys E1748D04AE40118B62BC18AC86032192
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\umpass.sys ==> MD5 is legit
C:\Windows\System32\drivers\usbaudio.sys B0435098C81D04CAFFF80DDB746CD3A2
C:\Windows\System32\DRIVERS\usbccgp.sys 28B81917A195B67617AF7DCF4DFE5736
C:\Windows\System32\DRIVERS\UsbCharger.sys 84A8E67E6CB15B070A2A7A0B3A9F1609
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys B626F048318DAE65A3317F0592BE592C
C:\Windows\system32\drivers\usbhub.sys 390109E8E05BA00375DCB1ED64DC60AF
C:\Windows\system32\drivers\usbohci.sys 9840FC418B4CBD632D3D0A667A725C31
C:\Windows\system32\drivers\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\USBSTOR.SYS D029DD09E22EB24318A8FC3D8138BA43
C:\Windows\system32\drivers\usbuhci.sys 62069A34518BCF9C1FD9E74B3F6DB7CD
C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\system32\drivers\vmbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vsdatant.sys 6F3667F0F059A500471A902C5013B278
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwifimp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\drivers\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
C:\Windows\System32\drivers\WmBEnum.sys 680A7846370000D20D7E74917D5B7936
C:\Windows\System32\drivers\WmFilter.sys 14C35BA8189C6F65D839163AA285E954
C:\Windows\System32\drivers\WmHidLo.sys AC4331AF118A720F13C9C5CABBFE27BD
C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 is legit
C:\Windows\System32\drivers\WmVirHid.sys 8488DD91A3EE54A8E29F02AD7BB8201E
C:\Windows\System32\drivers\WmXlCore.sys 14802B3A30AA849C97CB968CCC813BF3
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659
C:\Windows\System32\DRIVERS\xnacc.sys 4A5CE13408945E525503B5F73D29B9C5
C:\Windows\System32\DRIVERS\xusb21.sys 2C6BC21B2D5B58D8B1D638C1704CB494

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-18 10:23 - 2018-11-18 10:23 - 000000000 ____D C:\FRST
2018-11-18 10:18 - 2018-11-18 10:18 - 000305856 _____ C:\Windows\system32\FNTCACHE.DAT
2018-11-17 08:00 - 2018-11-17 08:00 - 000410624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\systemcpl.dll
2018-11-17 08:00 - 2018-11-17 08:00 - 000193024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcomapi.dll
2018-11-17 08:00 - 2018-11-17 08:00 - 000113629 _____ C:\Windows\SysWOW64\slmgr.vbs.removewat
2018-11-17 07:53 - 2018-11-17 07:53 - 000000020 ___SH C:\Users\Andrzej\ntuser.ini
2018-11-17 05:43 - 2018-11-17 05:43 - 000000000 ____D C:\Program Files (x86)\iBoysoft
2018-11-17 05:14 - 2018-11-17 05:42 - 000000000 _RSHD C:\ProgramData\Key-Base
2018-11-17 05:14 - 2018-11-17 05:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar Data Recovery Professional
2018-11-17 05:14 - 2018-11-17 05:14 - 000000000 ____D C:\ProgramData\{6D4A6AEB-FCC1-8759-7DE3-CC39EB1332C4}
2018-11-17 05:14 - 2018-11-17 05:14 - 000000000 ____D C:\Program Files (x86)\Stellar Data Recovery Professional
2018-11-17 04:39 - 2018-11-17 04:39 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\www.shadowexplorer.com
2018-11-17 04:39 - 2018-11-17 04:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShadowExplorer
2018-11-17 04:39 - 2018-11-17 04:39 - 000000000 ____D C:\Program Files (x86)\ShadowExplorer
2018-11-17 03:15 - 2018-11-17 03:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-11-17 03:15 - 2018-11-17 03:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-11-17 03:15 - 2018-11-17 03:15 - 000000000 ____D C:\Program Files\Malwarebytes
2018-11-17 03:15 - 2018-10-18 08:44 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-11-17 02:35 - 2018-11-17 03:17 - 000000000 ____D C:\ProgramData\Srrs
2018-11-17 02:35 - 2018-11-17 02:35 - 000009354 _____ C:\Users\Andrzej\AppData\IZDTL-DECRYPT.txt
2018-11-17 02:35 - 2018-11-17 02:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Survarium
2018-11-17 02:35 - 2018-11-17 02:35 - 000000000 ____D C:\Program Files (x86)\Survarium
2018-11-17 02:34 - 2018-11-17 03:17 - 000000000 ____D C:\Program Files (x86)\Removewat 2.2.7
2018-11-17 02:34 - 2018-11-17 02:34 - 000000000 ____D C:\Windows\DIR
2018-11-17 02:34 - 2018-11-17 02:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Margin
2018-11-17 02:34 - 2018-11-17 02:34 - 000000000 ____D C:\Program Files (x86)\Margin Trade
2018-11-17 02:21 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Tenorshare
2018-11-17 02:21 - 2018-11-17 02:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\(Default)
2018-11-17 02:21 - 2018-11-17 02:21 - 000000000 ____D C:\Program Files (x86)\PassFab Product Key Recovery
2018-11-17 02:15 - 2018-11-17 10:41 - 000000000 ____D C:\Program Files\KMSpico
2018-11-17 01:04 - 2018-11-17 01:04 - 000000000 ____D C:\ProgramData\Microsoft Toolkit
2018-11-17 00:58 - 2018-11-17 16:52 - 000003030 _____ C:\Windows\System32\Tasks\MSIAfterburner
2018-11-17 00:58 - 2018-11-17 00:58 - 000468594 __RSH C:\VPIMU
2018-11-16 14:50 - 2018-11-17 17:12 - 000000000 ___HD C:\$WINDOWS.~BT
2018-11-16 05:06 - 2018-11-17 00:46 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\uTorrent
2018-11-15 20:24 - 2018-11-15 20:24 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\Bethesda
2018-11-15 19:21 - 2018-11-13 02:50 - 000133432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2018-11-15 19:21 - 2018-10-10 11:39 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2018-11-15 19:20 - 2018-11-13 20:07 - 000978128 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2018-11-15 19:20 - 2018-11-13 20:07 - 000978128 _____ C:\Windows\system32\vulkan-1.dll
2018-11-15 19:20 - 2018-11-13 20:07 - 000845008 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2018-11-15 19:20 - 2018-11-13 20:07 - 000845008 _____ C:\Windows\SysWOW64\vulkan-1.dll
2018-11-15 19:20 - 2018-11-13 20:07 - 000551520 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2018-11-15 19:20 - 2018-11-13 20:07 - 000456448 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2018-11-15 19:20 - 2018-11-13 20:07 - 000267984 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2018-11-15 19:20 - 2018-11-13 20:07 - 000267984 _____ C:\Windows\system32\vulkaninfo.exe
2018-11-15 19:20 - 2018-11-13 20:07 - 000243408 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2018-11-15 19:20 - 2018-11-13 20:07 - 000243408 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2018-11-15 19:20 - 2018-11-13 20:06 - 048639560 _____ (NVIDIA Corp.) C:\Windows\system32\nvoptix.dll
2018-11-15 19:20 - 2018-11-13 20:06 - 040094192 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2018-11-15 19:20 - 2018-11-13 20:06 - 029811504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2018-11-15 19:20 - 2018-11-13 20:06 - 020469584 _____ (NVIDIA Corporation) C:\Windows\system32\nvrtum64.dll
2018-11-15 19:20 - 2018-11-13 20:06 - 000383776 _____ C:\Windows\system32\nvofapi.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 040254448 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 035151800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 020083680 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2018-11-15 19:20 - 2018-11-13 20:05 - 004536800 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 004029408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 002017736 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6441694.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 001999144 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 001508936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 001468032 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6441694.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 001457552 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 001123624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 000631424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 000521856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2018-11-15 19:20 - 2018-11-13 20:05 - 000489408 _____ (NVIDIA Corporation) C:\Windows\system32\nvcbl64.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 035297416 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl64.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 029971856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl32.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 020845912 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 019704368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 016983336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 015908712 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 013203608 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 001167792 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000914792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000524456 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000450880 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000420680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000181552 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000163392 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000159176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2018-11-15 19:20 - 2018-11-13 20:04 - 000141776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2018-11-15 19:20 - 2018-11-13 04:18 - 000227896 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2018-11-15 19:20 - 2018-11-13 04:18 - 000047384 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2018-11-15 19:20 - 2018-11-13 04:18 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2018-11-15 19:20 - 2018-11-13 04:18 - 000000669 _____ C:\Windows\system32\nv-vk64.json
2018-11-15 19:17 - 2007-04-04 18:54 - 000107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2018-11-15 19:12 - 2018-11-15 19:28 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bethesda.net Launcher
2018-11-15 16:30 - 2018-11-17 08:07 - 000033534 _____ C:\Windows\SysWOW64\report.txt
2018-11-15 16:30 - 2018-11-15 16:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda.net Launcher
2018-11-15 16:29 - 2018-11-17 16:52 - 000000000 ____D C:\Program Files (x86)\Bethesda.net Launcher
2018-11-14 23:58 - 2018-11-14 23:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sting!
2018-11-14 05:11 - 2018-11-14 05:11 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\WalkiusGames
2018-11-12 20:13 - 2018-11-12 20:13 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\Noble Muffins
2018-11-12 20:12 - 2018-11-12 20:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thief Simulator
2018-11-10 02:57 - 2018-11-10 02:57 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\GLab
2018-11-10 02:25 - 2018-11-10 02:25 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\BeWilder
2018-11-06 17:58 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Bungie
2018-11-06 17:30 - 2018-11-17 10:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Empires II HD
2018-11-05 16:51 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Blizzard
2018-11-05 16:51 - 2018-11-05 16:51 - 000000000 ____D C:\Program Files (x86)\Blizzard
2018-11-03 12:23 - 2018-11-17 10:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Destiny 2
2018-11-03 07:28 - 2018-11-03 07:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft
2018-11-03 07:20 - 2018-11-03 07:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2018-11-03 06:46 - 2018-11-03 06:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
2018-11-03 06:43 - 2018-11-03 07:28 - 000000000 ____D C:\Program Files (x86)\StarCraft
2018-11-03 06:41 - 2018-11-14 02:00 - 000000000 ____D C:\Program Files (x86)\StarCraft II
2018-11-03 06:41 - 2018-11-07 00:26 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2018-11-03 06:39 - 2018-11-05 16:54 - 000000000 ____D C:\ProgramData\Blizzard Entertainment
2018-11-03 06:37 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Battle.net
2018-11-03 06:37 - 2018-11-03 06:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2018-11-03 06:36 - 2018-11-17 08:08 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-11-03 06:35 - 2018-11-03 06:35 - 000000000 ____D C:\ProgramData\Battle.net
2018-11-01 05:01 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Portalarium
2018-11-01 05:01 - 2018-11-01 05:01 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\Portalarium
2018-10-28 18:04 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Help
2018-10-28 17:58 - 2018-10-28 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HoMM3 HD
2018-10-26 19:49 - 2018-11-17 16:52 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\DMCache
2018-10-26 19:49 - 2018-11-17 10:34 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\IDM
2018-10-26 19:49 - 2018-10-26 19:49 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2018-10-26 19:49 - 2018-10-26 19:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2018-10-26 19:49 - 2018-10-26 19:49 - 000000000 ____D C:\ProgramData\IDM
2018-10-26 19:49 - 2018-10-26 19:49 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2018-10-22 11:30 - 2018-10-22 11:30 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\Faerin
2018-10-22 09:41 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\MMFApplications
2018-10-19 23:50 - 2018-10-19 23:50 - 000000000 ____D C:\Windows\System32\Tasks\MEGA
2018-10-19 23:50 - 2018-10-19 23:50 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
2018-10-19 22:42 - 2018-10-19 22:42 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\Sylent3d
2018-10-19 20:43 - 2018-10-19 20:43 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\The Architect
2018-10-19 13:31 - 2018-10-19 13:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2018-10-18 10:31 - 2018-03-01 12:36 - 000226032 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys
2018-10-17 08:55 - 2018-11-17 17:12 - 000000000 ____D C:\PowerWalker_ViewPower
2018-10-17 08:55 - 2018-11-17 10:30 - 000000000 ___HD C:\Users\Andrzej\InstallAnywhere
2018-09-30 15:13 - 2018-09-30 15:13 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\F4SE
2018-09-30 12:33 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\FutureXGame
2018-09-29 10:12 - 2018-11-17 10:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vampyr
2018-09-29 09:56 - 2018-11-17 10:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conan Exiles
2018-09-29 06:25 - 2018-09-29 06:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4
2018-09-28 18:13 - 2018-09-28 18:13 - 000000000 ____D C:\Program Files (x86)\Futuremark
2018-09-28 17:24 - 2018-09-28 17:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunder Master
2018-09-28 17:24 - 2018-09-28 17:24 - 000000000 ____D C:\Program Files (x86)\Thunder Master
2018-09-28 17:15 - 2018-11-13 20:05 - 031374088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2018-09-28 17:15 - 2018-09-26 11:44 - 002018048 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6441170.dll
2018-09-28 17:15 - 2018-09-26 11:44 - 001467808 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6441170.dll
2018-09-28 17:02 - 2018-09-28 17:02 - 000047195 _____ C:\Windows\Cmicnfgp.ini.cfl
2018-09-28 17:02 - 2018-09-28 17:02 - 000000854 _____ C:\Windows\system\Cmicnfgp.ini
2018-09-28 17:02 - 2018-09-28 17:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UNi Xonar Audio
2018-09-28 17:02 - 2015-08-11 08:04 - 008048640 ____N (C-Media Corporation) C:\Windows\SysWOW64\CmiCnfgp.dll
2018-09-28 17:02 - 2015-06-02 11:23 - 002735616 _____ (C-Media Inc) C:\Windows\system32\Drivers\cmudaxp.sys
2018-09-28 17:02 - 2015-06-02 11:23 - 000315392 _____ (C-Media Electronics Inc.) C:\Windows\SysWOW64\CmiFltr.dll
2018-09-28 17:02 - 2015-06-02 11:23 - 000315392 _____ (C-Media Electronics Inc.) C:\Windows\system\CmiFltr.dll
2018-09-28 17:02 - 2015-06-02 11:23 - 000032768 _____ (C-Media Electronics Inc.) C:\Windows\system32\cmudaxp.dll
2018-09-28 17:02 - 2013-10-16 10:55 - 000143360 ____N C:\Windows\SysWOW64\VmixP8.dll
2018-09-28 17:02 - 2012-10-05 09:37 - 000465408 ____N (C-Media Electronics Inc.) C:\Windows\system32\cmasiopx.dll
2018-09-28 17:02 - 2012-10-05 09:37 - 000303104 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\cmasiop.dll
2018-09-28 17:02 - 2012-09-16 22:23 - 000293376 ____N C:\Windows\system32\CmiCnfgP.cpl
2018-09-28 17:02 - 2012-01-06 09:30 - 000212992 ____N (C-Media Electronics Inc.) C:\Windows\SysWOW64\HsSrv2.dll
2018-09-28 17:02 - 2012-01-06 09:30 - 000122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv642.dll
2018-09-28 17:02 - 2012-01-06 09:30 - 000122880 ____N (C-Media Electronics Inc.) C:\Windows\system\HsSrv64.dll
2018-09-28 17:02 - 2010-07-15 16:12 - 000000062 ____N C:\Windows\system32\cmasiopx.ini
2018-09-28 17:02 - 2010-07-15 16:12 - 000000057 ____N C:\Windows\SysWOW64\cmasiop.ini
2018-09-28 17:02 - 2008-07-11 15:04 - 000200704 ____N C:\Windows\SysWOW64\HsMgr.exe
2018-09-28 17:02 - 2008-07-11 15:03 - 000282112 ____N C:\Windows\system\HsMgr64.exe
2018-09-28 17:02 - 2007-12-13 17:12 - 000122880 ____N (CMedia Electronics Inc.) C:\Windows\SysWOW64\Cm_Oal.dll
2018-09-28 17:02 - 2007-12-13 17:12 - 000122880 ____N (CMedia Electronics Inc.) C:\Windows\system32\Cm_Oal.dll
2018-09-28 17:02 - 2006-09-13 10:21 - 000200704 ____N (C-Media) C:\Windows\SysWOW64\Cmpaoxy.dll
2018-09-21 22:50 - 2018-09-21 22:50 - 000000000 ____D C:\ProgramData\Dishonored 2
2018-09-21 16:40 - 2018-09-21 16:40 - 000003514 _____ C:\Windows\System32\Tasks\BlueStacksHelper
2018-09-12 00:17 - 2018-11-13 04:18 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2018-09-12 00:16 - 2018-11-13 02:44 - 005945144 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2018-09-12 00:16 - 2018-11-13 02:44 - 002611592 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2018-09-12 00:16 - 2018-11-13 02:44 - 001767280 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2018-09-12 00:16 - 2018-11-13 02:44 - 000635248 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2018-09-12 00:16 - 2018-11-13 02:44 - 000451056 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2018-09-12 00:16 - 2018-11-13 02:44 - 000124112 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2018-09-12 00:16 - 2018-11-13 02:44 - 000083336 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2018-09-12 00:16 - 2018-11-12 15:30 - 008407912 _____ C:\Windows\system32\nvcoproc.bin
2018-09-12 00:16 - 2018-09-12 00:16 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2018-09-12 00:15 - 2018-11-13 20:05 - 036608024 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2018-09-12 00:15 - 2018-11-13 20:05 - 000505904 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2018-09-12 00:15 - 2018-11-13 20:04 - 017287864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2018-09-12 00:15 - 2018-11-13 20:04 - 004839592 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2018-09-12 00:15 - 2018-11-13 20:04 - 004280520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2018-09-12 00:15 - 2018-11-13 04:18 - 000045443 _____ C:\Windows\system32\nvinfo.pb
2018-09-12 00:15 - 2018-09-06 19:29 - 002014624 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6439924.dll
2018-09-12 00:15 - 2018-09-06 19:29 - 001467624 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6439924.dll
2018-09-12 00:15 - 2018-09-06 03:50 - 000069544 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2018-09-12 00:15 - 2018-09-06 03:50 - 000065792 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2018-09-11 15:47 - 2018-09-11 15:47 - 000000000 ____D C:\ProgramData\Futuremark
2018-09-11 15:38 - 2018-09-11 15:38 - 000000000 ____D C:\ProgramData\UL
2018-09-09 08:18 - 2018-09-09 08:18 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MetaGeek
2018-09-06 10:44 - 2018-11-17 02:36 - 000000000 __SHD C:\Users\Andrzej\AppData\Roaming\x86_microsoft-windows-m..-r-backcompat-tlb28_31bf3856ad364e35_10.0.17134.1_none_0b0c37972a37a6cf
2018-09-06 10:44 - 2018-09-06 10:44 - 000000000 ____D C:\Windows\System32\Tasks\S-1-5-21-1378260646-1176595518-1075370210-7693
2018-09-01 09:05 - 2018-09-01 09:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigabyte
2018-09-01 08:49 - 2013-10-31 02:21 - 000015584 _____ (Giga-Byte Technology CO., LTD.) C:\Windows\etocdrv.sys
2018-09-01 07:36 - 2018-09-01 07:36 - 000000000 ____D C:\Windows\System32\Tasks\Intel
2018-09-01 07:36 - 2018-09-01 07:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2018-09-01 07:22 - 2018-11-17 10:43 - 000000000 ____D C:\Program Files (x86)\SpeedFan
2018-09-01 07:22 - 2018-09-01 07:22 - 000000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2018-09-01 06:00 - 2018-11-17 10:30 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Google
2018-08-27 20:39 - 2018-08-27 20:40 - 000000000 ____D C:\Program Files (x86)\Twists of My Life
2018-08-27 20:37 - 2018-08-27 20:37 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\Eek
2018-08-27 20:36 - 2018-08-27 20:36 - 000000000 ____D C:\Windows\System32\Tasks\Windows

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-18 10:22 - 2016-12-13 23:04 - 000004000 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{CEEAD669-B3E9-4479-98D7-1FC0F22119EB}
2018-11-18 10:20 - 2015-05-24 21:32 - 000000000 ____D C:\Program Files (x86)\Steam
2018-11-18 10:18 - 2018-05-04 10:16 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-11-18 10:18 - 2016-09-16 21:43 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-11-18 10:18 - 2016-05-01 15:07 - 000003226 _____ C:\Windows\System32\Tasks\AIDA64 AutoStart
2018-11-18 10:18 - 2015-06-24 20:03 - 000000000 ____D C:\ProgramData\NVIDIA
2018-11-18 10:18 - 2015-05-23 09:59 - 000026192 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2018-11-18 10:18 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-11-17 17:51 - 2017-03-09 00:23 - 000000000 ____D C:\Users\Andrzej\.prefs
2018-11-17 17:51 - 2017-01-24 23:33 - 000000000 ____D C:\Users\Andrzej\.TeamSpeak 3
2018-11-17 17:51 - 2016-11-21 14:38 - 000000000 ____D C:\Users\Andrzej\.thumbnails
2018-11-17 17:51 - 2016-11-21 14:37 - 000000000 ____D C:\Users\Andrzej\.gimp-2.8
2018-11-17 17:51 - 2016-11-19 11:37 - 000000000 ____D C:\Users\Andrzej\.QtWebEngineProcess
2018-11-17 17:51 - 2016-11-19 11:37 - 000000000 ____D C:\Users\Andrzej\.EVE
2018-11-17 17:51 - 2016-08-31 22:29 - 000000000 ____D C:\Users\Andrzej\.junique
2018-11-17 17:51 - 2015-08-30 11:00 - 000000000 ____D C:\Users\Andrzej\.oracle_jre_usage
2018-11-17 17:12 - 2018-06-04 13:02 - 000000000 __SHD C:\82ace7d6-0197-474d-bf4b-a2043e72329b
2018-11-17 17:12 - 2018-02-19 17:04 - 000000000 ____D C:\PIT Format 2017
2018-11-17 17:12 - 2017-04-13 06:36 - 000000000 ____D C:\Dell
2018-11-17 17:12 - 2017-03-30 13:23 - 000000000 ___HD C:\_acestream_cache_
2018-11-17 17:12 - 2017-02-10 00:03 - 000000000 ____D C:\PIT Format 2016
2018-11-17 17:12 - 2016-04-21 18:28 - 000000000 ____D C:\driver_memscan
2018-11-17 17:12 - 2016-04-01 14:55 - 000000000 ____D C:\PIT Format 2015
2018-11-17 17:12 - 2016-01-22 04:00 - 000000000 ____D C:\EW-7822PIC_Windows_Driver_v1.0.0.3
2018-11-17 17:12 - 2015-12-20 20:56 - 000000000 ____D C:\Dynamix
2018-11-17 17:12 - 2015-12-11 17:14 - 000000000 ____D C:\temp
2018-11-17 17:12 - 2015-12-11 17:14 - 000000000 ____D C:\PowerWalker
2018-11-17 17:12 - 2015-09-11 22:12 - 000000000 ___HD C:\ArcTemp
2018-11-17 17:12 - 2015-08-16 19:44 - 000000000 ____D C:\Brother
2018-11-17 17:12 - 2015-07-30 23:30 - 000000000 ___HD C:\$Windows.~WS
2018-11-17 17:12 - 2015-06-25 11:54 - 000000000 ____D C:\Fraps
2018-11-17 17:12 - 2015-06-06 19:14 - 000000000 ____D C:\Saves
2018-11-17 17:12 - 2015-05-23 10:05 - 000000000 ____D C:\uninstall
2018-11-17 17:12 - 2015-05-23 10:05 - 000000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2018-11-17 17:12 - 2015-05-23 10:05 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2018-11-17 17:12 - 2015-05-22 22:48 - 000000000 ____D C:\Intel
2018-11-17 16:52 - 2017-09-17 21:56 - 000003292 _____ C:\Windows\System32\Tasks\Avira_Antivirus_Systray
2018-11-17 16:52 - 2009-07-14 05:45 - 000038016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-11-17 16:52 - 2009-07-14 05:45 - 000038016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-11-17 16:44 - 2015-05-22 21:59 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-11-17 16:09 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-11-17 10:46 - 2015-11-16 02:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Castles
2018-11-17 10:42 - 2018-02-07 18:34 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\OpenDNS Updater
2018-11-17 10:41 - 2016-11-28 23:07 - 000000000 ____D C:\Windows\System32\Tasks\Lenovo
2018-11-17 10:38 - 2015-05-22 21:56 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-11-17 10:37 - 2017-03-30 13:22 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\.ACEStream
2018-11-17 10:37 - 2017-03-30 13:20 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\ACEStream
2018-11-17 10:34 - 2017-06-15 18:11 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossout
2018-11-17 10:34 - 2016-12-19 18:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deus Ex Mankind Divided
2018-11-17 10:34 - 2016-12-19 15:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cossacks 3
2018-11-17 10:34 - 2016-12-19 15:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shadow Warrior 2
2018-11-17 10:34 - 2016-12-19 15:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sniper Elite 3
2018-11-17 10:34 - 2016-10-28 21:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mafia III
2018-11-17 10:34 - 2015-11-17 21:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout 4
2018-11-17 10:34 - 2015-06-12 19:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DayZLauncher
2018-11-17 10:34 - 2015-05-25 21:54 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\TS3Client
2018-11-17 10:34 - 2015-05-23 11:59 - 000000000 ____D C:\Windows\Minidump
2018-11-17 10:30 - 2018-06-05 12:10 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\EasyAntiCheat
2018-11-17 10:30 - 2018-06-04 11:17 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\RenPy
2018-11-17 10:30 - 2018-05-04 10:16 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\TeamViewer
2018-11-17 10:30 - 2018-02-19 19:48 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\discord
2018-11-17 10:30 - 2017-12-31 20:45 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Trine1
2018-11-17 10:30 - 2017-08-22 17:27 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\BluestacksCN
2018-11-17 10:30 - 2017-08-22 17:26 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\BlueStacksFriends
2018-11-17 10:30 - 2017-06-27 13:47 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\PC Remote
2018-11-17 10:30 - 2017-06-15 19:35 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Arc
2018-11-17 10:30 - 2017-06-04 11:46 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\SmartSteamEmu
2018-11-17 10:30 - 2017-04-23 18:24 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\TankiOnline
2018-11-17 10:30 - 2017-03-22 16:35 - 000000000 ____D C:\Users\Andrzej\hitman
2018-11-17 10:30 - 2017-03-10 07:23 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\MPC-HC
2018-11-17 10:30 - 2017-03-05 20:02 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\fillUp
2018-11-17 10:30 - 2017-03-05 20:02 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\com.efile.epity
2018-11-17 10:30 - 2017-01-12 00:13 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\com.playa-games.sfgame
2018-11-17 10:30 - 2016-12-31 21:53 - 000000000 ____D C:\Users\Andrzej\Cheathappens
2018-11-17 10:30 - 2016-12-28 23:42 - 000000000 ____D C:\Users\Andrzej\Screenshot
2018-11-17 10:30 - 2016-12-28 19:26 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Eidos Montreal
2018-11-17 10:30 - 2016-11-08 21:27 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Opera Software
2018-11-17 10:30 - 2016-10-16 18:58 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\GameRanger
2018-11-17 10:30 - 2016-10-16 17:01 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Mount&Blade Warband
2018-11-17 10:30 - 2016-10-15 17:46 - 000000000 ____D C:\Users\Andrzej\BrawlhallaReplays
2018-11-17 10:30 - 2016-10-15 17:41 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\BrawlhallaAir
2018-11-17 10:30 - 2016-10-15 00:23 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\ASUS
2018-11-17 10:30 - 2016-10-09 18:45 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Kalypso Media
2018-11-17 10:30 - 2016-10-09 02:43 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\TERA
2018-11-17 10:30 - 2016-09-26 19:51 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Carbon
2018-11-17 10:30 - 2016-09-16 21:37 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\HeroesAndGeneralsDesktop
2018-11-17 10:30 - 2016-09-07 17:49 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Earth 2140
2018-11-17 10:30 - 2016-07-05 18:39 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\SpaceEngineers
2018-11-17 10:30 - 2016-07-04 22:28 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\epm
2018-11-17 10:30 - 2016-07-03 23:01 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Spore
2018-11-17 10:30 - 2016-06-27 22:57 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\rockbox.org
2018-11-17 10:30 - 2016-06-27 22:01 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\KTW
2018-11-17 10:30 - 2016-06-07 21:37 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Testy.HUS
2018-11-17 10:30 - 2016-05-23 20:38 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\LolClient
2018-11-17 10:30 - 2016-04-23 13:26 - 000000000 ____D C:\Users\Andrzej\Tracing
2018-11-17 10:30 - 2016-04-23 13:00 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Skype
2018-11-17 10:30 - 2016-04-01 15:04 - 000000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2018-11-17 10:30 - 2016-04-01 15:04 - 000000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2018-11-17 10:30 - 2016-04-01 15:04 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1
2018-11-17 10:30 - 2016-04-01 15:04 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\e-Deklaracje
2018-11-17 10:30 - 2016-03-13 19:45 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\NapiProjekt
2018-11-17 10:30 - 2016-03-04 00:41 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\The Zombie Infection
2018-11-17 10:30 - 2016-02-18 18:14 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Riot Games
2018-11-17 10:30 - 2016-01-09 01:00 - 000000000 ____D C:\Users\Andrzej\Valley
2018-11-17 10:30 - 2016-01-01 16:59 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\vlc
2018-11-17 10:30 - 2015-12-03 00:08 - 000000000 ____D C:\WMSDK
2018-11-17 10:30 - 2015-09-19 16:10 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Steam
2018-11-17 10:30 - 2015-09-18 20:52 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\java
2018-11-17 10:30 - 2015-09-13 13:21 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\DarkSoulsII
2018-11-17 10:30 - 2015-09-13 13:15 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Ubisoft
2018-11-17 10:30 - 2015-08-30 11:01 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Sun
2018-11-17 10:30 - 2015-08-17 15:49 - 000000000 ___RD C:\Users\Andrzej\AppData\Roaming\Brother
2018-11-17 10:30 - 2015-08-16 20:03 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\ControlCenter4
2018-11-17 10:30 - 2015-08-16 19:39 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\InstallShield
2018-11-17 10:30 - 2015-08-03 19:24 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Audacity
2018-11-17 10:30 - 2015-07-15 22:15 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Assassin's Creed Unity
2018-11-17 10:30 - 2015-07-15 21:15 - 000000000 __RHD C:\Users\Andrzej\AppData\Roaming\SecuROM
2018-11-17 10:30 - 2015-07-12 21:47 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Trine3
2018-11-17 10:30 - 2015-07-01 00:27 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\OpenOffice
2018-11-17 10:30 - 2015-06-24 23:56 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Dead Rising 3 Apocalypse Edition
2018-11-17 10:30 - 2015-06-24 21:57 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\NVIDIA
2018-11-17 10:30 - 2015-06-12 20:07 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Locktime
2018-11-17 10:30 - 2015-06-12 20:06 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Locktime Software
2018-11-17 10:30 - 2015-06-06 21:45 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Trine2
2018-11-17 10:30 - 2015-06-06 19:27 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\uplay
2018-11-17 10:30 - 2015-06-06 16:12 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\PowerISO
2018-11-17 10:30 - 2015-06-02 12:55 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\NetGuard
2018-11-17 10:30 - 2015-05-28 15:04 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Logitech
2018-11-17 10:30 - 2015-05-28 15:04 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Logishrd
2018-11-17 10:30 - 2015-05-24 20:52 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\NoAPM
2018-11-17 10:30 - 2015-05-23 11:43 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Tunngle
2018-11-17 10:30 - 2015-05-23 11:33 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\HD Tune Pro
2018-11-17 10:30 - 2015-05-23 08:49 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Mozilla
2018-11-17 10:30 - 2015-05-23 08:49 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Avira
2018-11-17 10:30 - 2015-05-23 01:59 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Airytec
2018-11-17 10:30 - 2015-05-23 00:24 - 000000000 ____D C:\Users\Andrzej\Intel
2018-11-17 10:30 - 2015-05-23 00:24 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Intel Corporation
2018-11-17 10:30 - 2015-05-23 00:19 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\WinRAR
2018-11-17 10:30 - 2015-05-23 00:18 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Macromedia
2018-11-17 10:30 - 2015-05-23 00:17 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\uTorrent
2018-11-17 10:30 - 2015-05-22 23:04 - 000000000 __SHD C:\Users\Andrzej\IntelGraphicsProfiles
2018-11-17 10:30 - 2015-05-22 22:01 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Adobe
2018-11-17 10:30 - 2015-05-22 21:54 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Media Center Programs
2018-11-17 10:30 - 2015-05-22 21:54 - 000000000 ____D C:\Users\Andrzej
2018-11-17 10:30 - 2009-07-14 04:20 - 000000000 __RHD C:\Users\Public\Libraries
2018-11-17 08:11 - 2015-05-22 22:24 - 000733400 _____ C:\Windows\system32\perfh015.dat
2018-11-17 08:11 - 2015-05-22 22:24 - 000153650 _____ C:\Windows\system32\perfc015.dat
2018-11-17 08:11 - 2009-07-14 06:13 - 001653100 _____ C:\Windows\system32\PerfStringBackup.INI
2018-11-17 08:10 - 2015-11-26 01:13 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-11-17 08:05 - 2015-06-24 20:18 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2018-11-17 08:03 - 2016-12-14 01:22 - 001008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2018-11-17 08:03 - 2016-12-14 01:22 - 000833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2018-11-17 08:03 - 2010-11-21 04:24 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2018-11-17 08:03 - 2010-11-21 04:24 - 000014848 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2018-11-17 08:03 - 2010-11-21 04:23 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2018-11-17 08:00 - 2016-12-14 01:22 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winver.exe
2018-11-17 07:15 - 2015-06-06 16:32 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\.minecraft
2018-11-17 03:17 - 2016-01-02 00:03 - 000000000 ____D C:\Program Files (x86)\Cheat Engine 6.5
2018-11-17 02:36 - 2018-06-04 13:02 - 000000761 ___SH C:\Users\Public\Libraries.ini.izdtl
2018-11-17 02:36 - 2015-05-22 21:54 - 000000560 ___SH C:\Users\Andrzej\ntuser.ini.izdtl
2018-11-17 02:35 - 2018-06-14 12:00 - 000000000 ____D C:\Users\Andrzej\ansel
2018-11-17 02:35 - 2009-07-14 04:20 - 000000000 ____D C:\PerfLogs
2018-11-16 14:50 - 2015-12-19 16:55 - 000001908 _____ C:\Windows\diagwrn.xml
2018-11-16 14:50 - 2015-12-19 16:55 - 000001908 _____ C:\Windows\diagerr.xml
2018-11-16 14:50 - 2015-05-23 07:51 - 000000000 ____D C:\Windows\Panther
2018-11-16 00:26 - 2015-08-17 15:47 - 000002471 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-11-15 19:21 - 2015-06-24 20:02 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-11-15 19:21 - 2015-06-24 20:02 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-11-15 19:21 - 2015-06-24 20:00 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-11-15 00:54 - 2015-06-06 16:22 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2018-11-14 00:09 - 2016-12-08 00:07 - 000004558 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-11-14 00:09 - 2015-05-22 21:59 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-11-14 00:09 - 2015-05-22 21:59 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-11-14 00:09 - 2015-05-22 21:59 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-11-14 00:09 - 2015-05-22 21:59 - 000000000 ____D C:\Windows\system32\Macromed
2018-11-13 23:09 - 2018-03-14 13:09 - 000004570 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-11-13 04:18 - 2017-02-14 10:26 - 001682896 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2018-11-13 00:14 - 2015-05-22 22:00 - 000002230 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-11-10 05:46 - 2016-08-29 20:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2018-11-10 05:46 - 2016-08-29 20:47 - 000000000 ____D C:\Program Files\LatencyMon
2018-11-07 20:20 - 2016-01-22 02:31 - 000000000 ____D C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crucial Storage Executive
2018-11-05 17:24 - 2009-07-14 06:08 - 000032604 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-10-28 17:50 - 2015-06-13 21:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2018-10-26 18:43 - 2017-01-21 22:49 - 000003082 _____ C:\Windows\System32\Tasks\klcp_update
2018-10-26 18:43 - 2017-01-21 22:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2018-10-26 18:43 - 2017-01-21 22:48 - 000000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2018-10-26 18:43 - 2009-07-14 05:57 - 000001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-10-23 20:18 - 2016-12-03 07:27 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy
2018-10-20 16:02 - 2016-02-18 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2018-10-19 13:31 - 2015-05-23 00:22 - 000000000 ____D C:\ProgramData\Package Cache
2018-10-19 11:36 - 2015-08-17 15:47 - 000000000 ____D C:\Users\Andrzej\AppData\LocalLow\Adobe

==================== Files in the root of some directories =======

2015-05-23 00:29 - 2015-05-23 00:29 - 000000000 _____ () C:\Users\Andrzej\AppData\Local\Driver_LOM_8161Present.flag
2016-01-09 01:00 - 2016-01-09 02:17 - 001065984 _____ () C:\Users\Andrzej\AppData\Local\file__0.localstorage
2016-12-30 00:16 - 2016-12-30 00:16 - 000000001 _____ () C:\Users\Andrzej\AppData\Local\llftool.4.40.agreement
2015-07-14 18:33 - 2015-07-14 18:33 - 000000000 ___SH () C:\Users\Andrzej\AppData\Local\LumaEmu
2016-11-21 15:43 - 2016-11-21 15:43 - 000007687 _____ () C:\Users\Andrzej\AppData\Local\recently-used.xbel
2015-05-23 12:55 - 2018-09-14 23:31 - 000007604 _____ () C:\Users\Andrzej\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2016-12-14 01:22] - [2018-11-17 08:03] - 001008640 _____ (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79

C:\Windows\SysWOW64\User32.dll
[2016-12-14 01:22] - [2018-11-17 08:03] - 000833024 _____ (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE

C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

==================== BCD ================================

Mened�er rozruchu oprogramowania uk�adowego
-------------------------------------------
Identyfikator {fwbootmgr}
displayorder {12c19f42-e9bf-11e8-8bb6-84cd5c02048e}
{12c19f3c-e9bf-11e8-8bb6-84cd5c02048e}
{12c19f3e-e9bf-11e8-8bb6-84cd5c02048e}
{12c19f40-e9bf-11e8-8bb6-84cd5c02048e}
{12c19f41-e9bf-11e8-8bb6-84cd5c02048e}
{12c19f3b-e9bf-11e8-8bb6-84cd5c02048e}
{12c19f3f-e9bf-11e8-8bb6-84cd5c02048e}
{12c19f3d-e9bf-11e8-8bb6-84cd5c02048e}
{bef98dd8-e9f7-11e8-83ce-806e6f6e6963}
{bootmgr}
timeout 1

Mened�er rozruchu systemu Windows
---------------------------------
Identyfikator {bootmgr}
device partition=\Device\HarddiskVolume11
path \EFI\MICROSOFT\BOOT\BOOTMGFW.EFI
description Windows Boot Manager
locale pl-PL
inherit {globalsettings}
default {current}
resumeobject {12c19f43-e9bf-11e8-8bb6-84cd5c02048e}
displayorder {12c19f44-e9bf-11e8-8bb6-84cd5c02048e}
{current}
toolsdisplayorder {memdiag}
timeout 30

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f3b-e9bf-11e8-8bb6-84cd5c02048e}
description TSSTcorp CDDVDW SH-224DB
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f3c-e9bf-11e8-8bb6-84cd5c02048e}
description M4-CT064M4SSD2
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f3d-e9bf-11e8-8bb6-84cd5c02048e}
description TOSHIBA MD04ACA400
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f3e-e9bf-11e8-8bb6-84cd5c02048e}
description Crucial_CT500MX200SSD1
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f3f-e9bf-11e8-8bb6-84cd5c02048e}
description TOSHIBA DT01ACA200
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f40-e9bf-11e8-8bb6-84cd5c02048e}
description OCZ-ARC100
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f41-e9bf-11e8-8bb6-84cd5c02048e}
description Mass Storage Device 1.00
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {12c19f42-e9bf-11e8-8bb6-84cd5c02048e}
device partition=\Device\HarddiskVolume11
path \EFI\UBUNTU\GRUBX64.EFI
description ubuntu
custom:250000c2 1

Aplikacja oprogramowania uk�adowego (101fffff)
---------------------------------------------
Identyfikator {bef98dd8-e9f7-11e8-83ce-806e6f6e6963}
device partition=\Device\HarddiskVolume11
path \EFI\UBUNTU\SHIMX64.EFI
description ubuntu

Modu� �aduj�cy rozruchu systemu Windows
---------------------------------------
Identyfikator {12c19f44-e9bf-11e8-8bb6-84cd5c02048e}
device partition=F:
path \Windows\system32\winload.efi
description Windows 10
locale pl-PL
inherit {bootloadersettings}
recoverysequence {12c19f45-e9bf-11e8-8bb6-84cd5c02048e}
custom:15000066 3
recoveryenabled Yes
custom:16000060 Yes
custom:17000077 352321653
osdevice partition=F:
systemroot \Windows
resumeobject {12c19f43-e9bf-11e8-8bb6-84cd5c02048e}
nx OptIn
custom:250000c2 1

Modu� �aduj�cy rozruchu systemu Windows
---------------------------------------
Identyfikator {12c19f45-e9bf-11e8-8bb6-84cd5c02048e}
device ramdisk=[\Device\HarddiskVolume10]\Recovery\WindowsRE\Winre.wim,{12c19f46-e9bf-11e8-8bb6-84cd5c02048e}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale pl-pl
inherit {bootloadersettings}
custom:15000065 3
osdevice ramdisk=[\Device\HarddiskVolume10]\Recovery\WindowsRE\Winre.wim,{12c19f46-e9bf-11e8-8bb6-84cd5c02048e}
systemroot \windows
nx OptIn
custom:250000c2 1
winpe Yes

Modu� �aduj�cy rozruchu systemu Windows
---------------------------------------
Identyfikator {current}
device partition=C:
path \Windows\system32\winload.efi
description Windows 7
locale pl-PL
osdevice partition=C:
systemroot \Windows
resumeobject {fd9dc796-e9f4-11e8-bd4d-806e6f6e6963}
nx OptIn
pae Default
sos No
debug No

Wznawianie ze stanu hibernacji
------------------------------
Identyfikator {12c19f43-e9bf-11e8-8bb6-84cd5c02048e}
device partition=F:
path \Windows\system32\winresume.efi
description Windows Resume Application
locale pl-PL
inherit {resumeloadersettings}
recoverysequence {12c19f45-e9bf-11e8-8bb6-84cd5c02048e}
recoveryenabled Yes
custom:16000060 Yes
custom:17000077 352321653
filedevice partition=F:
filepath \hiberfil.sys
custom:25000008 1
debugoptionenabled No

Wznawianie ze stanu hibernacji
------------------------------
Identyfikator {fd9dc796-e9f4-11e8-bd4d-806e6f6e6963}
device partition=C:
path \Windows\system32\winresume.efi
description Microsoft Windows
locale pl-PL
inherit {resumeloadersettings}
filedevice partition=C:
filepath \hiberfil.sys
debugoptionenabled No

Modu� testuj�cy pami�� systemu Windows
--------------------------------------
Identyfikator {memdiag}
device partition=\Device\HarddiskVolume11
path \EFI\Microsoft\Boot\memtest.efi
description Diagnostyka pami�ci systemu Windows
locale pl-PL
inherit {globalsettings}
badmemoryaccess Yes

Ustawienia us�ug EMS
--------------------
Identyfikator {emssettings}
bootems No

Ustawienia debugera
-------------------
Identyfikator {dbgsettings}
debugtype 4

Uszkodzenia pami�ci RAM
-----------------------
Identyfikator {badmemory}

Ustawienia globalne
-------------------
Identyfikator {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}

Ustawienia modu�u �aduj�cego rozruchu
-------------------------------------
Identyfikator {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}

Ustawienia funkcji hypervisor
-----------------------------
Identyfikator {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200

Ustawienia modu�u �aduj�cego wznawiania
---------------------------------------
Identyfikator {resumeloadersettings}
inherit {globalsettings}

Opcje urz�dzenia
----------------
Identyfikator {12c19f46-e9bf-11e8-8bb6-84cd5c02048e}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume10
ramdisksdipath \Recovery\WindowsRE\boot.sdi


LastRegBack: 2018-11-14 00:17

==================== End of FRST.txt ============================