Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 02.01.2018 Uruchomiony przez Bula (administrator) BULA-KOMPUTER (05-01-2018 16:18:26) Uruchomiony z C:\Users\Bula\Desktop Załadowane profile: Bula (Dostępne profile: Bula) Platform: Windows 7 Ultimate Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: "D:\Programy\Firefox\firefox.exe" -osint -url "%1") Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (COMODO) C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (Electronic Arts) D:\Programy\origin\OriginWebHelperService.exe (Copyright (c) 2017 Plays.tv, LLC) C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Malwarebytes) D:\Programy\Anti-Malware\MBAMService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (Malwarebytes) D:\Programy\Anti-Malware\mbamtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (COMODO) C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Raptr, Inc) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Raptr, Inc) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe (Raptr Inc.) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_ep64.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Mozilla Corporation) D:\Programy\Firefox\firefox.exe (Copyright (c) 2017 Plays.tv, LLC) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (Mozilla Corporation) D:\Programy\Firefox\firefox.exe (Mozilla Corporation) D:\Programy\Firefox\firefox.exe (Mozilla Corporation) D:\Programy\Firefox\firefox.exe () C:\Program Files (x86)\Raptr Inc\PlaysTV\QtWebEngineProcess.exe () C:\Program Files (x86)\Raptr Inc\PlaysTV\QtWebEngineProcess.exe () C:\Program Files (x86)\Raptr Inc\PlaysTV\QtWebEngineProcess.exe () C:\Program Files (x86)\Raptr Inc\PlaysTV\QtWebEngineProcess.exe () C:\Program Files (x86)\Raptr Inc\PlaysTV\QtWebEngineProcess.exe (Raptr Inc.) C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_ep64.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) D:\Programy\Firefox\firefox.exe () C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe (Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe (Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSATray.exe (Mozilla Corporation) D:\Programy\Firefox\firefox.exe (Mozilla Corporation) D:\Programy\Firefox\firefox.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-04-30] (Intel Corporation) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM\...\Run: [BCSSync] => D:\Programy\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1490624 2017-11-21] (COMODO) HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2017-02-11] (Pixart Imaging Inc) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-11] (Intel Corporation) HKLM-x32\...\Run: [IseUI] => C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe [3632848 2017-08-08] (COMODO) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation) HKLM-x32\...\Run: [PlaysTV] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [51416 2017-12-12] (Copyright (c) 2017 Plays.tv, LLC) HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58584 2017-05-30] (Raptr, Inc) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641664 2012-04-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] => Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [131360 2017-12-19] (Intel) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG) HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-20] (Piriform Ltd) HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\Run: [SteamServerBrowser] => C:\Program Files (x86)\SteamServerBrowser\SteamServerBrowser.exe [228352 2017-02-26] () HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\MountPoints2: F - F:\HiSuiteDownLoader.exe HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\MountPoints2: {2ca853c7-830d-11e4-bd84-806e6f6e6963} - E:\ASRSetup.exe HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\MountPoints2: {57966ac1-1799-11e7-8b43-d050993d6b5d} - F:\HiSuiteDownLoader.exe HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\MountPoints2: {c2e981cd-83c0-11e4-982b-806e6f6e6963} - E:\SETUP.EXE HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\MountPoints2: {f0e1bcc0-83e6-11e4-b800-806e6f6e6963} - F:\Setup.exe HKU\S-1-5-21-557026980-2374518597-3869201236-1000\...\MountPoints2: {f97b85b6-edee-11e6-9cde-d050993d6b5d} - H:\HiSuiteDownLoader.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{084E4505-7692-4B26-AA5B-8D0F9041C501}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{3145A23F-5355-4D95-869B-42B58AE58EFB}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{926ED426-758A-4368-BE5A-2FE7D744894E}: [DhcpNameServer] 194.204.152.34 194.204.159.1 Tcpip\..\Interfaces\{A80961FD-6CAE-4C39-82B7-9C8DB462BCF3}: [DhcpNameServer] 192.168.42.129 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki HKU\S-1-5-21-557026980-2374518597-3869201236-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pl-pl/?ocid=iehp BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Programy\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Programy\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-25] (Oracle Corporation) BHO-x32: Pomocnik logowania za pomocą konta Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-25] (Oracle Corporation) Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Brak pliku FireFox: ======== FF DefaultProfile: qnrqekc5.default FF ProfilePath: C:\Users\Bula\AppData\Roaming\Mozilla\Firefox\Profiles\qnrqekc5.default [2018-01-05] FF user.js: detected! => C:\Users\Bula\AppData\Roaming\Mozilla\Firefox\Profiles\qnrqekc5.default\user.js [2015-04-11] FF Homepage: Mozilla\Firefox\Profiles\qnrqekc5.default -> www.google.pl FF Extension: (Adblock Plus) - C:\Users\Bula\AppData\Roaming\Mozilla\Firefox\Profiles\qnrqekc5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-12] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2017-12-12] () FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> D:\Programy\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2017-12-12] () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-25] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-25] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [Brak pliku] FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> D:\Programy\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [Brak pliku] FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [Brak pliku] StartMenuInternet: FIREFOX.EXE - D:\Programy\Firefox\firefox.exe Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default [2018-01-04] CHR Extension: (Prezentacje) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13] CHR Extension: (Dokumenty) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13] CHR Extension: (Dysk Google) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-18] CHR Extension: (YouTube) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-18] CHR Extension: (Google Search) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-18] CHR Extension: (Arkusze) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13] CHR Extension: (Dokumenty Google offline) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-30] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (Gmail) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-04] CHR Extension: (Chrome Media Router) - C:\Users\Bula\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-10] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2017-11-16] () R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [10880832 2017-11-21] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2876096 2017-11-21] (COMODO) R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [22304 2017-12-19] (Intel) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [408104 2017-07-19] (EasyAntiCheat Ltd) S2 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [885992 2017-12-07] () S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6943800 2015-09-15] (GOG.com) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Brak podpisu cyfrowego] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-12] (Intel Corporation) S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel Corporation) R2 isesrv; C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe [133840 2017-08-08] (COMODO) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation) S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2016-12-03] () [Brak podpisu cyfrowego] R2 MBAMService; D:\Programy\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes) S3 Microsoft SharePoint Workspace Audit Service; D:\Programy\Office14\GROOVE.EXE [51456888 2010-03-25] (Microsoft Corporation) R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG) S3 Origin Client Service; D:\Programy\origin\OriginClientService.exe [2134848 2017-11-22] (Electronic Arts) R2 Origin Web Helper Service; D:\Programy\origin\OriginWebHelperService.exe [3014472 2017-11-22] (Electronic Arts) R2 PlaysService; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [55000 2017-12-12] (Copyright (c) 2017 Plays.tv, LLC) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2017-01-31] () R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe [181992 2017-12-07] () S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [885992 2017-12-07] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-10-17] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [11174400 2012-04-06] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego] S3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [343040 2012-04-06] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego] S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [11174400 2012-04-06] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego] R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [34280 2017-11-16] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [849248 2017-11-16] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [59096 2017-11-16] (COMODO) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-12-16] (Disc Soft Ltd) R0 FACEIT; C:\Windows\System32\Drivers\FACEIT.sys [9183176 2017-12-12] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-04-30] (Intel Corporation) S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [4433696 2013-05-17] (Intel Corporation) [Brak podpisu cyfrowego] R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [122520 2017-11-16] (COMODO) S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [442368 2013-05-17] (Intel(R) Corporation) [Brak podpisu cyfrowego] R1 isedrv; C:\Windows\system32\drivers\isedrv.sys [50856 2017-08-08] (COMODO) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [118504 2012-12-18] (Qualcomm Atheros Co., Ltd.) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-05] (Malwarebytes) S3 RT61; C:\Windows\System32\DRIVERS\RT61.sys [322560 2005-07-01] (Ralink Technology Inc.) S3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation ) R3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [41512 2017-12-07] () S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203320 2012-06-04] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2017-02-11] () ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2018-01-05 16:18 - 2018-01-05 16:18 - 000022063 _____ C:\Users\Bula\Desktop\FRST.txt 2018-01-05 16:01 - 2018-01-05 16:18 - 000000000 ____D C:\FRST 2018-01-05 16:00 - 2018-01-05 16:00 - 002393088 _____ (Farbar) C:\Users\Bula\Desktop\FRST64.exe 2018-01-05 15:52 - 2018-01-05 15:52 - 000003064 _____ C:\Windows\System32\Tasks\{6C497C24-6871-4325-897E-7D18D8E2A0DC} 2018-01-05 15:17 - 2018-01-05 15:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire 2018-01-05 15:08 - 2018-01-05 15:40 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant 2018-01-05 15:08 - 2018-01-05 15:08 - 000003616 _____ C:\Windows\System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 2018-01-05 15:08 - 2018-01-05 15:08 - 000003482 _____ C:\Windows\System32\Tasks\USER_ESRV_SVC_QUEENCREEK 2018-01-05 15:08 - 2018-01-05 15:08 - 000003370 _____ C:\Windows\System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon 2018-01-05 15:08 - 2018-01-05 15:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver and Support Assistant 2018-01-05 15:08 - 2017-12-07 23:29 - 000041512 _____ C:\Windows\system32\Drivers\semav6msr64.sys 2018-01-05 15:03 - 2018-01-05 15:03 - 000000000 ____D C:\ProgramData\ATI 2018-01-05 14:59 - 2018-01-05 14:59 - 000262144 ____N C:\Windows\Minidump\010518-4305-01.dmp 2018-01-05 14:51 - 2018-01-05 14:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center 2018-01-05 14:51 - 2018-01-05 14:51 - 000000000 ____D C:\Program Files (x86)\AMD AVT 2018-01-05 14:51 - 2018-01-05 14:51 - 000000000 ____D C:\Program Files (x86)\AMD APP 2018-01-05 14:51 - 2018-01-05 14:51 - 000000000 _____ C:\Windows\SysWOW64\SET58EA.tmp 2018-01-05 14:51 - 2012-02-23 13:32 - 000095760 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2018-01-05 14:50 - 2018-01-05 14:50 - 000000000 ____D C:\Program Files (x86)\ATI Technologies 2018-01-05 14:50 - 2012-04-06 03:23 - 000245896 _____ C:\Windows\SysWOW64\atiapfxx.blb 2018-01-05 14:50 - 2012-04-06 03:23 - 000245896 _____ C:\Windows\system32\atiapfxx.blb 2018-01-05 14:50 - 2012-04-06 03:16 - 000442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2018-01-05 14:50 - 2012-04-06 03:00 - 000064000 _____ (AMD) C:\Windows\system32\coinst.dll 2018-01-05 14:50 - 2012-03-05 23:15 - 000038159 _____ C:\Windows\atiogl.xml 2018-01-05 14:49 - 2018-01-05 14:51 - 000000000 ____D C:\Program Files\ATI Technologies 2018-01-05 14:49 - 2018-01-05 14:49 - 000000000 ____D C:\Program Files\ATI 2018-01-05 14:13 - 2018-01-05 15:03 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2018-01-05 00:58 - 2018-01-05 15:03 - 000000000 ____D C:\Users\Bula\AppData\Roaming\PlaysTV 2018-01-05 00:58 - 2018-01-05 00:58 - 000002019 _____ C:\Users\Public\Desktop\Raptr.lnk 2018-01-05 00:58 - 2018-01-05 00:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Raptr 2018-01-05 00:58 - 2018-01-05 00:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved 2018-01-05 00:56 - 2018-01-05 15:03 - 000000000 ____D C:\Users\Bula\AppData\Roaming\Raptr 2018-01-05 00:56 - 2018-01-05 00:57 - 000000000 ____D C:\Program Files (x86)\Raptr 2018-01-05 00:07 - 2018-01-05 00:07 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies 2018-01-05 00:02 - 2018-01-05 00:02 - 000000000 ____D C:\Users\Bula\AppData\Local\RadeonInstaller 2018-01-04 23:49 - 2018-01-04 23:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2018-01-04 23:49 - 2018-01-04 23:49 - 000000000 ____D C:\ProgramData\MB3CoreBackup 2018-01-04 23:43 - 2018-01-04 23:43 - 000262144 ____N C:\Windows\Minidump\010418-3978-01.dmp 2018-01-04 23:22 - 2017-11-16 14:43 - 000017438 _____ C:\Windows\system32\Drivers\cmdhlp.cat 2018-01-04 23:13 - 2018-01-04 23:13 - 000262144 ____N C:\Windows\Minidump\010418-3915-01.dmp 2018-01-04 23:11 - 2018-01-04 23:11 - 000262144 ____H C:\Windows\DUMP4c7c.DMP 2018-01-04 21:34 - 2018-01-05 15:02 - 000780284 _____ C:\Windows\ntbtlog.txt 2018-01-04 21:34 - 2018-01-04 21:34 - 000262144 ____N C:\Windows\Minidump\010418-4570-01.dmp 2018-01-04 20:16 - 2018-01-04 20:16 - 000000000 ____D C:\Users\Bula\AppData\Local\ELEX 2018-01-03 19:59 - 2018-01-04 13:50 - 000000000 ____D C:\Users\Bula\AppData\LocalLow\uTorrent 2017-12-17 21:06 - 2017-12-17 21:06 - 000547208 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Rapidfire64.dll 2017-12-17 21:06 - 2017-12-17 21:06 - 000461192 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\Rapidfire.dll 2017-12-17 21:06 - 2017-12-17 21:06 - 000036232 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\RapidFireServer64.dll 2017-12-17 21:06 - 2017-12-17 21:06 - 000033160 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\RapidFireServer.dll 2017-12-17 21:03 - 2017-12-17 21:03 - 000157064 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amduve64.dll 2017-12-17 21:03 - 2017-12-17 21:03 - 000135048 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amduve32.dll 2017-12-12 18:19 - 2017-12-12 18:20 - 009183176 _____ C:\Windows\system32\Drivers\FACEIT.sys 2017-12-07 18:40 - 2017-12-07 18:40 - 000000000 ____D C:\Users\Bula\Documents\ClassicMT2 New 2017-12-07 18:38 - 2018-01-04 23:57 - 000000578 _____ C:\Users\Public\Desktop\ClassicMT2 New.lnk 2017-12-07 18:38 - 2017-12-07 18:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClassicMT2 ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2018-01-05 16:13 - 2016-12-19 00:19 - 001474832 _____ C:\Windows\system32\Drivers\sfi.dat 2018-01-05 16:03 - 2009-07-14 05:45 - 000016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-01-05 16:03 - 2009-07-14 05:45 - 000016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-01-05 16:02 - 2015-06-29 18:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com 2018-01-05 15:08 - 2014-12-15 18:09 - 000000000 ____D C:\ProgramData\Package Cache 2018-01-05 15:08 - 2014-12-14 19:40 - 000000000 ____D C:\ProgramData\Intel 2018-01-05 15:08 - 2014-12-14 19:37 - 000000000 ____D C:\Program Files\Intel 2018-01-05 15:08 - 2011-04-12 14:21 - 000134512 _____ C:\Windows\system32\perfh015.dat 2018-01-05 15:08 - 2011-04-12 14:21 - 000069380 _____ C:\Windows\system32\perfc015.dat 2018-01-05 15:08 - 2009-07-14 06:13 - 000196300 _____ C:\Windows\system32\PerfStringBackup.INI 2018-01-05 15:08 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf 2018-01-05 15:03 - 2016-11-16 20:38 - 000000000 ____D C:\Users\Bula\AppData\LocalLow\Mozilla 2018-01-05 15:03 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-01-05 14:59 - 2014-12-16 23:33 - 000000000 ____D C:\Windows\Minidump 2018-01-05 14:51 - 2014-12-15 18:12 - 000000000 ____D C:\ProgramData\AMD 2018-01-05 14:47 - 2015-01-14 14:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-01-05 00:49 - 2009-07-14 05:45 - 000425016 _____ C:\Windows\system32\FNTCACHE.DAT 2018-01-05 00:43 - 2014-12-14 00:23 - 000111496 _____ C:\Users\Bula\AppData\Local\GDIPFONTCACHEV1.DAT 2018-01-05 00:03 - 2016-09-12 20:53 - 000000000 ____D C:\Users\Bula\AppData\Local\AMD 2018-01-05 00:03 - 2016-09-12 19:18 - 000000000 ____D C:\Program Files (x86)\VulkanRT 2018-01-04 23:49 - 2017-10-31 20:53 - 000000729 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2018-01-04 21:34 - 2014-12-13 22:15 - 000000000 ____D C:\Users\Bula 2018-01-04 21:32 - 2014-12-15 20:03 - 000000000 ____D C:\Users\Bula\AppData\Roaming\uTorrent 2018-01-04 21:32 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\registration 2018-01-03 01:54 - 2016-09-12 19:16 - 000065536 _____ C:\Windows\system32\spu_storage.bin 2018-01-02 20:09 - 2016-08-04 23:13 - 000001120 _____ C:\Users\Bula\Desktop\skype.txt 2017-12-30 18:46 - 2015-06-15 17:49 - 000000116 _____ C:\Windows\NeroDigital.ini 2017-12-24 12:02 - 2015-02-05 03:55 - 000000000 ____D C:\Users\Bula\AppData\Local\screenSHU 2017-12-12 22:29 - 2014-12-14 23:16 - 000004412 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-12-12 22:29 - 2014-12-14 23:09 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-12-12 22:29 - 2014-12-14 23:09 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-12-12 22:29 - 2014-12-14 23:09 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2017-12-12 22:29 - 2014-12-14 23:09 - 000000000 ____D C:\Windows\system32\Macromed 2017-12-10 01:45 - 2015-08-18 15:52 - 000000000 ____D C:\Users\Bula\Documents\Nasze Wesele 2017-12-09 01:29 - 2017-10-19 12:57 - 000059392 _____ C:\Users\Bula\Desktop\politologia_lic_sem_iii_14.xls 2017-12-08 23:02 - 2014-12-15 01:42 - 000000000 ____D C:\ProgramData\Origin 2017-12-08 23:01 - 2014-12-15 01:48 - 000000000 ____D C:\Users\Bula\AppData\Roaming\Origin 2017-12-08 19:05 - 2009-07-14 06:08 - 000032604 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-12-07 23:47 - 2017-11-16 17:56 - 000000000 ____D C:\Users\Bula\AppData\Local\UnrealEngine 2017-12-06 01:30 - 2017-01-12 04:10 - 007209110 _____ C:\Windows\system32\Drivers\fvstore.dat 2017-12-06 01:30 - 2016-12-19 00:19 - 000000000 ____D C:\Windows\System32\Tasks\COMODO ==================== Pliki w katalogu głównym wybranych folderów ======= 2012-02-22 06:55 - 2012-02-22 06:55 - 000021243 _____ () C:\Program Files (x86)\ssudadb.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000004047 _____ () C:\Program Files (x86)\ssudadb.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000020233 _____ () C:\Program Files (x86)\ssudbus.cat 2012-02-15 23:21 - 2012-02-15 23:21 - 000007144 _____ () C:\Program Files (x86)\ssudbus.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000020233 _____ () C:\Program Files (x86)\ssudcdf.cat 2012-02-15 23:23 - 2012-02-15 23:23 - 000003624 _____ () C:\Program Files (x86)\ssudcdf.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000020239 _____ () C:\Program Files (x86)\ssuddmgr.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000005603 _____ () C:\Program Files (x86)\ssuddmgr.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000021209 _____ () C:\Program Files (x86)\ssudeadb.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000005030 _____ () C:\Program Files (x86)\ssudeadb.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000021245 _____ () C:\Program Files (x86)\ssudmarv.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000003735 _____ () C:\Program Files (x86)\ssudmarv.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000020233 _____ () C:\Program Files (x86)\ssudmdm.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000050022 _____ () C:\Program Files (x86)\ssudmdm.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000019311 _____ () C:\Program Files (x86)\ssudmtp.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000001774 _____ () C:\Program Files (x86)\ssudmtp.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000021203 _____ () C:\Program Files (x86)\ssudnd5.cat 2012-02-15 23:23 - 2012-02-15 23:23 - 000008164 _____ () C:\Program Files (x86)\ssudnd5.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000020239 _____ () C:\Program Files (x86)\ssudobex.cat 2012-02-15 23:23 - 2012-02-15 23:23 - 000005693 _____ () C:\Program Files (x86)\ssudobex.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000021215 _____ () C:\Program Files (x86)\ssudrmnet.cat 2012-02-15 23:23 - 2012-02-15 23:23 - 000004820 _____ () C:\Program Files (x86)\ssudrmnet.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000021227 _____ () C:\Program Files (x86)\ssudrmnetmp.cat 2012-02-15 23:24 - 2012-02-15 23:24 - 000005559 _____ () C:\Program Files (x86)\ssudrmnetmp.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000019313 _____ () C:\Program Files (x86)\ssudrnds.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000004303 _____ () C:\Program Files (x86)\ssudrnds.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000021243 _____ () C:\Program Files (x86)\ssudsdb.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000003493 _____ () C:\Program Files (x86)\ssudsdb.inf 2012-02-22 06:55 - 2012-02-22 06:55 - 000020239 _____ () C:\Program Files (x86)\ssudserd.cat 2012-02-15 23:22 - 2012-02-15 23:22 - 000005706 _____ () C:\Program Files (x86)\ssudserd.inf 2015-12-10 03:13 - 2015-11-19 15:27 - 000000428 _____ () C:\Users\Bula\AppData\Roaming\book.txt 2015-12-10 03:13 - 2015-11-19 15:26 - 000004134 _____ () C:\Users\Bula\AppData\Roaming\pic.jpg 2015-12-10 03:13 - 2015-11-19 15:26 - 000004134 _____ () C:\Users\Bula\AppData\Roaming\pic1.jpg 2016-12-19 00:05 - 2016-11-03 08:32 - 002594688 _____ (COMODO) C:\Users\Bula\AppData\Roaming\temp~ccavstart.exe 2016-12-19 00:05 - 2016-11-03 08:32 - 003856048 _____ (Terra Informatica Software, Inc.) C:\Users\Bula\AppData\Roaming\temp~cmdhtml.dll 2015-07-20 12:08 - 2017-10-08 18:42 - 000012800 _____ () C:\Users\Bula\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-04-04 01:33 - 2017-04-04 01:33 - 000000092 _____ () C:\Users\Bula\AppData\Local\fusioncache.dat 2015-02-04 17:01 - 2015-02-04 17:01 - 000000000 ___SH () C:\Users\Bula\AppData\Local\LumaEmu 2015-07-02 21:39 - 2016-12-18 23:11 - 000007597 _____ () C:\Users\Bula\AppData\Local\resmon.resmoncfg 2017-01-03 10:32 - 2017-01-03 10:32 - 000000000 _____ () C:\Users\Bula\AppData\Local\{F9861C58-0412-4513-BA08-16CAA4E28004} Niektóre pliki w TEMP: ==================== 2018-01-05 00:57 - 2018-01-05 00:58 - 116708576 _____ () C:\Users\Bula\AppData\Local\Temp\playstv_patch.exe 2018-01-05 00:56 - 2018-01-05 00:57 - 059621016 _____ () C:\Users\Bula\AppData\Local\Temp\raptrpatch.exe 2018-01-05 00:56 - 2018-01-05 00:56 - 000221632 _____ () C:\Users\Bula\AppData\Local\Temp\raptr_stub.exe 2018-01-04 23:15 - 2018-01-04 23:52 - 000192512 _____ () C:\Users\Bula\AppData\Local\Temp\sfamcc00001.dll 2018-01-04 23:16 - 2018-01-04 23:16 - 000192512 _____ () C:\Users\Bula\AppData\Local\Temp\sfamcc00002.dll ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll [2010-11-21 04:24] - [2015-04-03 20:48] - 001008640 _____ (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79 C:\Windows\SysWOW64\User32.dll [2010-11-21 04:24] - [2015-04-03 20:48] - 000833024 _____ (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2017-12-29 14:41 ==================== Koniec FRST.txt ============================