Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 30.01.2019 Uruchomiony przez Aviator (administrator) DESKTOP-QLI858D (30-01-2019 16:59:48) Uruchomiony z C:\Users\Aviator\Desktop Załadowane profile: Aviator (Dostępne profile: Aviator & DefaultAppPool) Platform: Windows 10 Pro Wersja 1803 17134.523 (X64) Język: Polski (Polska) Domyślna przeglądarka: Edge Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe () C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (VoodooSoft, LLC ) C:\Program Files\VoodooShield\VoodooShieldService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe () C:\Program Files (x86)\SmartData\masterst.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe () C:\Program Files (x86)\LightingService\AsRogAuraGpuDllServer.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.37.98.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.37.98.0_x64__kzf8qxf38zg5c\SkypeApp.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18112.14311.0_x64__8wekyb3d8bbwe\Video.UI.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (GOG.com) E:\GOG Galaxy\GalaxyClient.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe () C:\Users\Aviator\AppData\Roaming\SteamServerBrowser\SteamServerBrowser.exe (Crossgate Consulting Limited) C:\Users\Aviator\AppData\Roaming\ProductAuthenticationService\pas.exe (Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe (Overwolf LTD) C:\Program Files (x86)\Overwolf\Overwolf.exe () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe (Mega Limited) C:\Users\Aviator\AppData\Local\MEGAsync\MEGAsync.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.122.0.52\OverwolfHelper.exe (GOG.com) C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe (Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.122.0.52\OverwolfHelper64.exe (GOG.com) E:\GOG Galaxy\GalaxyClient Helper.exe (GOG.com) E:\GOG Galaxy\GalaxyClient Helper.exe (GOG.com) E:\GOG Galaxy\GOG Galaxy Notifications Renderer.exe (GOG.com) E:\GOG Galaxy\GalaxyClient Helper.exe (Overwolf LTD) C:\Program Files (x86)\Overwolf\0.122.0.52\OverwolfBrowser.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Overwolf LTD) C:\Program Files (x86)\Overwolf\0.122.0.52\OverwolfBrowser.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe () C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.37.98.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe () C:\Program Files (x86)\SmartData\performer.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (IObit) C:\Program Files (x86)\IObit\Driver Booster\5.5.1\Pub\PubMonitor.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (VoodooSoft, LLC ) C:\Program Files\VoodooShield\VoodooShield.exe () C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_1.16.1012.0_x64__8wekyb3d8bbwe\GameBar.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5889480 2018-12-14] (LogMeIn Inc.) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [GalaxyClient] => E:\GOG Galaxy\GalaxyClient.exe [7381576 2018-11-29] (GOG.com) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [729704 2018-06-20] (Disc Soft Ltd) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3133216 2019-01-05] (Valve Corporation) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [ChomikBox] => C:\Program Files (x86)\ChomikBox\ChomikBox.exe HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3113768 2019-01-29] (Electronic Arts) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1602888 2019-01-22] (Overwolf Ltd.) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [SteamServerBrowser] => C:\Users\Aviator\AppData\Roaming\SteamServerBrowser\SteamServerBrowser.exe [172488 2019-01-18] () HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [ProductAuthenticationService] => C:\Users\Aviator\AppData\Roaming\ProductAuthenticationService\pas.exe [529352 2018-12-10] (Crossgate Consulting Limited) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [35190672 2019-01-24] (Epic Games, Inc.) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [7410464 2019-01-30] (Lavasoft) HKU\S-1-5-21-239350383-861022925-3571962692-1001\...\MountPoints2: {3f3e254f-9997-11e8-b691-10bf48baec55} - "H:\setup.exe" HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\system32\bdmjpeg64.dll [75248 2017-01-26] () HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\system32\bdmpegv64.dll [75272 2017-01-26] () HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\system32\bdmpega64.acm [75784 2017-01-26] () HKLM\...\Drivers32: [VIDC.FICV] => C:\Windows\system32\ficvdec_x64.dll [652288 2013-05-28] () HKLM\...\Drivers32-x32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] () HKLM\...\Drivers32-x32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] () HKLM\...\Drivers32-x32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] () HKLM\...\Drivers32-x32: [VIDC.FICV] => C:\Windows\SysWOW64\ficvdec_x86.dll [641024 2013-05-28] () HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2018-12-12] (Google Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2018-08-05] ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe () Startup: C:\Users\Aviator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2018-08-31] ShortcutTarget: MEGAsync.lnk -> C:\Users\Aviator\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited) GroupPolicy: Ograniczenia - Windows Defender <==== UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 31.11.202.254 37.8.214.2 Tcpip\Parameters: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{8261a838-98da-11e8-b67d-806e6f6e6963}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{9aa03991-ed86-4247-8e62-4abfa051d126}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{a40f2a62-9b22-4c58-ae1e-7ad420cf5b53}: [DhcpNameServer] 31.11.202.254 37.8.214.2 Tcpip\..\Interfaces\{b14ae43c-db8d-4660-8602-1ddc6e10d1ad}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{e8e23f13-ac3b-4d1f-b486-ee4389077480}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{e8e23f13-ac3b-4d1f-b486-ee4389077480}: [DhcpNameServer] 31.11.202.254 37.8.214.2 Internet Explorer: ================== HKU\S-1-5-21-239350383-861022925-3571962692-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10477_754_190130 SearchScopes: HKU\S-1-5-21-239350383-861022925-3571962692-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-239350383-861022925-3571962692-1001 -> {BDF61FAE-9D19-40F0-8F34-688DEB334CA9} URL = hxxp://securedsearch.lavasoft.com/results.php?pr=vmn&id=webcompa&ent=ch_WCYID10477_754_190130&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2019-01-07] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2019-01-07] (Oracle Corporation) FireFox: ======== FF DefaultProfile: e0ptvrs9.default FF ProfilePath: C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default [2019-01-30] FF Homepage: Mozilla\Firefox\Profiles\e0ptvrs9.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10477_754_190130 FF NewTab: Mozilla\Firefox\Profiles\e0ptvrs9.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10477_754_190130 FF Extension: (Google NoTrack) - C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\Extensions\googlenotrack@dirtylittlehelpers.com.xpi [2018-08-05] FF Extension: (Save as PDF) - C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\Extensions\save-as-pdf-ff@pdfcrowd.com.xpi [2018-11-08] FF Extension: (Avast SafePrice) - C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\Extensions\sp@avast.com.xpi [2018-08-07] FF Extension: (uBlock Origin) - C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\Extensions\uBlock0@raymondhill.net.xpi [2019-01-26] FF Extension: (Avast Online Security) - C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\Extensions\wrc@avast.com.xpi [2019-01-28] FF Extension: (Mozilla Official) - C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\Extensions\{4cc880a2-4d4b-48e3-96e2-353e3f5996e7} [2019-01-30] [Brak podpisu cyfrowego] FF Extension: (No Coin - Block miners on the web!) - C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\Extensions\{5657c026-efc3-4860-b43b-16e4eaa8a9aa}.xpi [2018-08-05] FF SearchPlugin: C:\Users\Aviator\AppData\Roaming\Mozilla\Firefox\Profiles\e0ptvrs9.default\searchplugins\securesearch.xml [2019-01-30] FF Extension: (Brak nazwy) - C:\Program Files\Mozilla Firefox\browser\features\{A16C6B13-D41C-47BF-AAC2-FC71F1BB2363}.xpi [2018-12-17] [Brak podpisu cyfrowego] FF Extension: (Brak nazwy) - C:\Program Files\Mozilla Firefox\browser\features\{A9EBC5EC-C8AE-4002-A64A-BEA241908533}.xpi [2019-01-30] [Brak podpisu cyfrowego] FF Plugin: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2019-01-07] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2019-01-07] (Oracle Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @tools.asus.com/ASUS Update;version=3 -> C:\Program Files (x86)\ASUS\Update\1.3.101.0\npAsusUpdate3.dll [2018-08-05] (ASUSTeK Computer Inc.) FF Plugin-x32: @tools.asus.com/ASUS Update;version=9 -> C:\Program Files (x86)\ASUS\Update\1.3.101.0\npAsusUpdate3.dll [2018-08-05] (ASUSTeK Computer Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default [2019-01-30] CHR Extension: (Prezentacje) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-11-08] CHR Extension: (Dokumenty) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-08] CHR Extension: (Dysk Google) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-08] CHR Extension: (YouTube) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-08] CHR Extension: (Adobe Acrobat) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-11-08] CHR Extension: (Arkusze) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-11-08] CHR Extension: (Dokumenty Google offline) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-11-19] CHR Extension: (Counter for Messenger) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldlagicdigidgnhniajpmoddkoakdoca [2018-12-23] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-11-08] CHR Extension: (Print Friendly & PDF) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2018-11-08] CHR Extension: (Gmail) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-11-08] CHR Extension: (Chrome Media Router) - C:\Users\Aviator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-23] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblocker for Youtube™) - C:\Users\Aviator\AppData\Roaming\Opera Software\Opera Stable\Extensions\oabbdaincgidlhkmnghlfabhbpimjfbo [2019-01-30] OPR Extension: (Brak nazwy) - C:\Users\Aviator\AppData\Roaming\Opera Software\Opera Stable\Extensions\pogmclhffdfjphnjlikiijmdjpjlfodk [2018-12-17] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [382424 2018-03-16] (ASUSTeK Computer Inc.) S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [157016 2018-08-05] (ASUSTeK Computer Inc.) S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [157016 2018-08-05] (ASUSTeK Computer Inc.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8352184 2019-01-12] () S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [369720 2017-07-21] (BlueStack Systems, Inc.) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3606632 2018-06-20] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-27] (EasyAntiCheat Ltd) S3 GalaxyClientService; E:\GOG Galaxy\GalaxyClientService.exe [707144 2018-11-29] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7172680 2018-11-29] (GOG.com) R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3366344 2018-12-14] (LogMeIn Inc.) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation) S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Brak podpisu cyfrowego] R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Brak podpisu cyfrowego] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation) R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [1276376 2018-04-25] (ASUSTek Computer Inc.) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2298688 2019-01-29] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3171144 2019-01-29] (Electronic Arts) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2428232 2019-01-22] (Overwolf LTD) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Corporation) R2 Smart Monitoring; C:\Program Files (x86)\SmartData\masterst.exe [2329088 2019-01-30] () [Brak podpisu cyfrowego] S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] () R2 VoodooShieldService; C:\Program Files\VoodooShield\VoodooShieldService.exe [124928 2018-08-05] (VoodooSoft, LLC ) R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25888 2019-01-30] () S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-08-05] (Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-08-05] (Microsoft Corporation) S2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2018-03-16] () S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-06-21] (Bluestack System Inc. ) U4 Chngr; D:\CS_GO_Changer(1)\CS_GO_Changer\bin\Flo\Chngr10.sys [77040 2018-12-10] () R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2018-08-06] (Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2018-08-06] (Disc Soft Ltd) R1 GLCKIO2; C:\Windows\system32\drivers\GLCKIO2.sys [19392 2018-04-23] () R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2018-12-14] (LogMeIn Inc.) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-08-06] (REALiX(tm)) R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [261032 2019-01-30] (Malwarebytes) R3 netr28ux; C:\Windows\System32\drivers\netr28ux.sys [2224128 2018-04-12] (MediaTek Inc.) R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9db4450b8107f59a\nvlddmkm.sys [20420352 2018-12-01] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2018-11-29] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [70024 2018-11-29] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [74576 2018-11-29] (NVIDIA Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [1106256 2018-08-06] (Realtek ) R3 RtsUpx; C:\Windows\system32\drivers\RtsUpx.sys [30328 2018-08-05] (Realtek Semiconductor Corp.) R3 VSScanner; C:\Windows\System32\DRIVERS\vsscanner.sys [29752 2018-06-25] (VoodooSoft, LLC) S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46584 2018-08-05] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [340008 2018-08-05] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [61992 2018-08-05] (Microsoft Corporation) S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-01-30 16:59 - 2019-01-30 17:00 - 000026468 _____ C:\Users\Aviator\Desktop\FRST.txt 2019-01-30 16:56 - 2019-01-30 16:59 - 000000000 ____D C:\FRST 2019-01-30 16:56 - 2019-01-30 16:56 - 002428928 _____ (Farbar) C:\Users\Aviator\Desktop\FRST64.exe 2019-01-30 16:35 - 2019-01-30 16:35 - 000000000 ___HD C:\OneDriveTemp 2019-01-30 13:20 - 2019-01-30 13:20 - 000000000 ____D C:\Users\Aviator\Downloads\kingdom_come_deliverance_trainer_172_steam__gog 2019-01-30 13:17 - 2019-01-30 13:18 - 005651351 _____ C:\Users\Aviator\Downloads\kingdom_come_deliverance_trainer_172_steam__gog.zip 2019-01-30 09:52 - 2019-01-30 11:01 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\Lavasoft 2019-01-30 09:52 - 2019-01-30 09:52 - 000000000 ____D C:\Users\Aviator\AppData\Local\Lavasoft 2019-01-30 09:52 - 2019-01-30 09:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2019-01-30 09:52 - 2019-01-30 09:52 - 000000000 ____D C:\ProgramData\Lavasoft 2019-01-30 09:52 - 2019-01-30 09:52 - 000000000 ____D C:\Program Files (x86)\Lavasoft 2019-01-30 09:51 - 2019-01-30 16:34 - 000000000 ____D C:\Program Files (x86)\SmartData 2019-01-30 09:51 - 2019-01-30 10:04 - 000000000 ___HD C:\Windows\rss 2019-01-30 09:51 - 2019-01-30 10:03 - 000000000 ____D C:\Program Files (x86)\OneSystemCare 2019-01-30 09:51 - 2019-01-30 10:02 - 000000000 ____D C:\Program Files (x86)\Speedycar 2019-01-30 09:51 - 2019-01-30 09:51 - 000000000 ____D C:\ProgramData\{EE28EED9-5E56-5C4A-2E43-C9D02EA49081} 2019-01-30 09:51 - 2019-01-30 09:51 - 000000000 ____D C:\ProgramData\{19A0392D-89A2-ABC2-DA94-4127DA731876} 2019-01-30 09:50 - 2019-01-30 09:50 - 000000003 _____ C:\Users\Aviator\AppData\Local\wbem.ini 2019-01-30 09:49 - 2019-01-30 10:04 - 000000000 ____D C:\Users\Aviator\Downloads\Kingdom_Come_Deliverance_Trainer_v1_7 2019-01-30 08:49 - 2019-01-30 08:49 - 000261032 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2019-01-27 10:39 - 2019-01-27 10:39 - 000768287 _____ C:\Users\Aviator\Downloads\kingdom_come_deliverance_v12_plus_13_trainer.zip 2019-01-27 10:39 - 2019-01-27 10:39 - 000000000 ____D C:\Users\Aviator\Downloads\kingdom_come_deliverance_v12_plus_13_trainer 2019-01-27 00:50 - 2019-01-27 00:50 - 000001151 _____ C:\Users\Aviator\Desktop\Kingdom Come Deliverance The Amorous Adventures of Bold Sir Hans Capon.lnk 2019-01-27 00:50 - 2019-01-27 00:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingdom Come Deliverance The Amorous Adventures of Bold Sir Hans Capon 2019-01-26 13:58 - 2019-01-26 13:58 - 000017983 _____ C:\Users\Aviator\Desktop\Rozwiązanie umowy o pracę auto.odt 2019-01-26 13:46 - 2019-01-26 13:46 - 000015158 _____ C:\Users\Aviator\Desktop\Rozwiązanie umowy o pracę.odt 2019-01-26 13:27 - 2019-01-26 13:27 - 006102132 _____ C:\Users\Aviator\Downloads\Lato2OFL.zip 2019-01-26 13:27 - 2019-01-26 13:27 - 000000000 ____D C:\Users\Aviator\Downloads\Lato2OFL 2019-01-26 13:25 - 2019-01-26 13:25 - 001430825 _____ C:\Users\Aviator\Desktop\Auto Służbowe.pdf 2019-01-26 12:52 - 2019-01-26 12:56 - 000000000 ___RD C:\Users\Aviator\Documents\Scanned Documents 2019-01-26 12:52 - 2019-01-26 12:52 - 000000000 ____D C:\Users\Aviator\Documents\Fax 2019-01-25 21:53 - 2019-01-25 21:58 - 997492908 _____ C:\Users\Aviator\Downloads\dd_tandem_truck_pack.scs 2019-01-25 20:52 - 2019-01-25 20:53 - 122782617 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Base(1).scs 2019-01-25 20:52 - 2019-01-25 20:52 - 018363083 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Going_East.scs 2019-01-25 20:51 - 2019-01-25 20:52 - 024717632 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Scandinavia(1).scs 2019-01-25 20:51 - 2019-01-25 20:51 - 027960481 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Italia.scs 2019-01-25 20:51 - 2019-01-25 20:51 - 019432550 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Vive_La_France.scs 2019-01-25 20:50 - 2019-01-25 20:51 - 070416213 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Beyond_The_Baltic_Sea(1).scs 2019-01-24 22:34 - 2019-01-24 22:34 - 000000000 ____D C:\Users\Aviator\AppData\LocalLow\Unity 2019-01-24 17:29 - 2019-01-24 17:29 - 070416213 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Beyond_The_Baltic_Sea.scs 2019-01-24 17:16 - 2019-01-24 17:16 - 122782617 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Base.scs 2019-01-24 17:06 - 2019-01-24 17:06 - 090838272 _____ C:\Users\Aviator\Downloads\Vissta_Buss_HI___Jumbuss_360.rar 2019-01-24 16:56 - 2019-01-24 16:56 - 024717632 _____ C:\Users\Aviator\Downloads\Bus_Terminal_-_Scandinavia.scs 2019-01-24 16:52 - 2019-01-24 16:53 - 230920430 _____ C:\Users\Aviator\Downloads\SKS Buspack.scs 2019-01-23 23:32 - 2019-01-23 23:32 - 000000609 _____ C:\Users\Public\Desktop\Grand Theft Auto V.lnk 2019-01-23 23:32 - 2019-01-23 23:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games 2019-01-23 21:43 - 2019-01-26 20:03 - 000000000 ____D C:\Users\Aviator\AppData\LocalLow\uTorrent 2019-01-23 19:15 - 2019-01-23 19:37 - 013171795 _____ C:\Users\Aviator\Downloads\_JBX_Settings_v1.9.13_by_JuanBonX.zip.part 2019-01-23 19:15 - 2019-01-23 19:36 - 000000000 _____ C:\Users\Aviator\Downloads\_JBX_Settings_v1.9.13_by_JuanBonX.zip 2019-01-23 18:49 - 2019-01-23 18:49 - 002281032 _____ (crosire) C:\Users\Aviator\Downloads\ReShade_Setup_4.1.0.exe 2019-01-23 18:35 - 2019-01-23 18:35 - 000000000 ____D C:\Users\Aviator\Downloads\scania_touring_ets2_by_M_Husni_MF_d1bcf 2019-01-23 16:47 - 2019-01-30 10:03 - 000000000 ____D C:\Program Files (x86)\SkinMinerNv 2019-01-23 16:47 - 2019-01-23 16:47 - 000002529 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkinMiner NVidia.lnk 2019-01-23 16:47 - 2019-01-23 16:47 - 000002517 _____ C:\Users\Public\Desktop\SkinMiner NVidia.lnk 2019-01-21 23:05 - 2019-01-21 23:05 - 000007332 _____ C:\Users\Aviator\Downloads\ETS2_Johndoe_SiCKX_ReShade_v2.0_fakeDX11.rar 2019-01-20 18:17 - 2019-01-20 18:19 - 156118417 _____ C:\Users\Aviator\Downloads\man_tgx_euro6_byMADster_v2.2.rar 2019-01-20 18:10 - 2019-01-20 18:10 - 000000000 ____D C:\Users\Aviator\Desktop\mods 2019-01-20 18:09 - 2019-01-20 18:10 - 005767290 _____ C:\Users\Aviator\Downloads\NG-1.5.rar 2019-01-20 08:47 - 2019-01-20 08:47 - 000000000 ____D C:\Users\Public\Documents\Steam 2019-01-19 19:28 - 2019-01-19 19:28 - 000001110 _____ C:\Users\Aviator\Desktop\Euro Truck Simulator 2 Beyond the Baltic Sea.lnk 2019-01-19 19:28 - 2019-01-19 19:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Truck Simulator 2 Beyond the Baltic Sea 2019-01-19 15:00 - 2019-01-19 15:00 - 000000717 _____ C:\Users\Public\Desktop\Euro Truck Simulator 2.lnk 2019-01-19 15:00 - 2019-01-19 15:00 - 000000717 _____ C:\Users\Public\Desktop\Euro Truck Simulator 2 (x86).lnk 2019-01-19 13:50 - 2019-01-19 13:50 - 000000222 _____ C:\Users\Aviator\Desktop\Euro Truck Simulator 2.url 2019-01-17 12:40 - 2019-01-17 12:43 - 000000000 ____D C:\Users\Aviator\Desktop\ETS2_RGM-v2.1.1-with-Addons 2019-01-16 19:29 - 2019-01-16 16:26 - 534283358 _____ C:\Users\Aviator\Desktop\ETS2_RGM-v2.1.1-with-Addons.zip 2019-01-13 20:23 - 2019-01-13 20:30 - 000000000 ____D C:\Users\Aviator\Desktop\Nowy folder 2019-01-13 11:07 - 2019-01-13 11:07 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\EasyAntiCheat 2019-01-13 11:07 - 2019-01-13 11:07 - 000000000 ____D C:\ProgramData\For Honor Data 2019-01-12 23:54 - 2019-01-12 23:54 - 000000000 ____D C:\Users\Aviator\AppData\LocalLow\Smartly Dressed Games 2019-01-12 23:53 - 2019-01-12 23:53 - 000000000 ____D C:\Users\Aviator\AppData\Local\BattlEye 2019-01-12 23:01 - 2019-01-26 11:14 - 000000000 ____D C:\Users\Aviator\Documents\Euro Truck Simulator 2 2019-01-12 22:52 - 2019-01-12 22:52 - 000000222 _____ C:\Users\Aviator\Desktop\Unturned.url 2019-01-12 09:23 - 2019-01-12 09:23 - 000000410 _____ C:\Users\Aviator\Desktop\TT server maker.appref-ms 2019-01-12 09:23 - 2019-01-12 09:23 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\TT-servers 2019-01-12 09:23 - 2019-01-12 09:23 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TThread 2019-01-12 08:33 - 2018-09-20 05:12 - 001483576 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll 2019-01-11 22:57 - 2019-01-30 16:35 - 000000000 ____D C:\Users\Aviator\AppData\Local\LogMeIn Hamachi 2019-01-11 22:57 - 2019-01-11 22:57 - 000001001 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2019-01-11 22:57 - 2019-01-11 22:57 - 000000000 ____D C:\Users\Aviator\AppData\Local\LogMeIn 2019-01-11 22:57 - 2019-01-11 22:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2019-01-11 22:57 - 2019-01-11 22:57 - 000000000 ____D C:\ProgramData\LogMeIn 2019-01-11 22:57 - 2019-01-11 22:57 - 000000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2019-01-11 18:01 - 2019-01-11 18:01 - 000000000 ____D C:\Users\Aviator\Desktop\polish mod 2019-01-09 15:39 - 2019-01-01 14:50 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll 2019-01-09 15:39 - 2019-01-01 14:47 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\windowslivelogin.dll 2019-01-09 15:39 - 2019-01-01 14:46 - 012710912 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2019-01-09 15:39 - 2019-01-01 14:45 - 000714752 _____ (Microsoft Corporation) C:\Windows\system32\wlidcli.dll 2019-01-09 15:39 - 2019-01-01 14:45 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\wlidcredprov.dll 2019-01-09 15:39 - 2019-01-01 14:43 - 001364992 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvruserservice.dll 2019-01-09 15:39 - 2019-01-01 14:20 - 011902976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2019-01-09 15:39 - 2019-01-01 14:20 - 000165888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windowslivelogin.dll 2019-01-09 15:39 - 2019-01-01 14:18 - 000500736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll 2019-01-09 15:39 - 2019-01-01 14:17 - 000231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcredprov.dll 2019-01-09 15:39 - 2019-01-01 08:14 - 001221432 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2019-01-09 15:39 - 2019-01-01 08:14 - 001063224 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi 2019-01-09 15:39 - 2019-01-01 08:14 - 001029944 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2019-01-09 15:39 - 2019-01-01 08:14 - 000566568 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe 2019-01-09 15:39 - 2019-01-01 08:14 - 000134968 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll 2019-01-09 15:39 - 2019-01-01 08:14 - 000076088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys 2019-01-09 15:39 - 2019-01-01 08:13 - 003292152 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll 2019-01-09 15:39 - 2019-01-01 08:13 - 001363536 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll 2019-01-09 15:39 - 2019-01-01 08:13 - 000709728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2019-01-09 15:39 - 2019-01-01 08:13 - 000436024 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2019-01-09 15:39 - 2019-01-01 08:13 - 000170808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2019-01-09 15:39 - 2019-01-01 08:12 - 009084216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2019-01-09 15:39 - 2019-01-01 08:12 - 007520104 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2019-01-09 15:39 - 2019-01-01 08:12 - 002765344 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2019-01-09 15:39 - 2019-01-01 08:12 - 002465792 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2019-01-09 15:39 - 2019-01-01 08:12 - 002421288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2019-01-09 15:39 - 2019-01-01 08:12 - 000713272 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll 2019-01-09 15:39 - 2019-01-01 08:12 - 000268304 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll 2019-01-09 15:39 - 2019-01-01 08:12 - 000128824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys 2019-01-09 15:39 - 2019-01-01 08:12 - 000043536 _____ (Microsoft Corporation) C:\Windows\system32\browser_broker.exe 2019-01-09 15:39 - 2019-01-01 07:55 - 025856512 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll 2019-01-09 15:39 - 2019-01-01 07:50 - 022715392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2019-01-09 15:39 - 2019-01-01 07:50 - 004383744 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll 2019-01-09 15:39 - 2019-01-01 07:48 - 000342528 _____ (Microsoft Corporation) C:\Windows\system32\browserexport.exe 2019-01-09 15:39 - 2019-01-01 07:48 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys 2019-01-09 15:39 - 2019-01-01 07:48 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\Print.Workflow.Source.dll 2019-01-09 15:39 - 2019-01-01 07:47 - 000808448 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll 2019-01-09 15:39 - 2019-01-01 07:47 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe 2019-01-09 15:39 - 2019-01-01 07:46 - 000209408 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountTokenProvider.dll 2019-01-09 15:39 - 2019-01-01 07:46 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll 2019-01-09 15:39 - 2019-01-01 07:46 - 000153088 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll 2019-01-09 15:39 - 2019-01-01 07:45 - 007573504 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2019-01-09 15:39 - 2019-01-01 07:45 - 002368512 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll 2019-01-09 15:39 - 2019-01-01 07:45 - 000352768 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll 2019-01-09 15:39 - 2019-01-01 07:44 - 001708544 _____ (Microsoft Corporation) C:\Windows\system32\MSPhotography.dll 2019-01-09 15:39 - 2019-01-01 07:44 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2019-01-09 15:39 - 2019-01-01 07:44 - 000894464 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll 2019-01-09 15:39 - 2019-01-01 07:44 - 000662528 _____ (Microsoft Corporation) C:\Windows\system32\wlidprov.dll 2019-01-09 15:39 - 2019-01-01 07:44 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.Workflow.dll 2019-01-09 15:39 - 2019-01-01 07:43 - 001805312 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2019-01-09 15:39 - 2019-01-01 07:42 - 004939776 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2019-01-09 15:39 - 2019-01-01 07:42 - 002247680 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll 2019-01-09 15:39 - 2019-01-01 07:42 - 001371136 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll 2019-01-09 15:39 - 2019-01-01 07:42 - 000717312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll 2019-01-09 15:39 - 2019-01-01 07:41 - 001159680 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2019-01-09 15:39 - 2019-01-01 07:41 - 000899072 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2019-01-09 15:39 - 2019-01-01 07:41 - 000895488 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll 2019-01-09 15:39 - 2019-01-01 07:41 - 000505344 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll 2019-01-09 15:39 - 2019-01-01 07:37 - 006571584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-01-09 15:39 - 2019-01-01 07:37 - 002478664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll 2019-01-09 15:39 - 2019-01-01 07:37 - 002253696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2019-01-09 15:39 - 2019-01-01 07:37 - 001989040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2019-01-09 15:39 - 2019-01-01 07:37 - 000880048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll 2019-01-09 15:39 - 2019-01-01 07:37 - 000581808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVideoDSP.dll 2019-01-09 15:39 - 2019-01-01 07:37 - 000381240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2019-01-09 15:39 - 2019-01-01 07:29 - 022016512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2019-01-09 15:39 - 2019-01-01 07:22 - 019405312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2019-01-09 15:39 - 2019-01-01 07:17 - 000153088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll 2019-01-09 15:39 - 2019-01-01 07:16 - 005775872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2019-01-09 15:39 - 2019-01-01 07:16 - 001361408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSPhotography.dll 2019-01-09 15:39 - 2019-01-01 07:16 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll 2019-01-09 15:39 - 2019-01-01 07:15 - 005307392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2019-01-09 15:39 - 2019-01-01 07:15 - 000608768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll 2019-01-09 15:39 - 2019-01-01 07:15 - 000331264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll 2019-01-09 15:39 - 2019-01-01 07:15 - 000317440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll 2019-01-09 15:39 - 2019-01-01 07:14 - 004514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2019-01-09 15:39 - 2019-01-01 07:14 - 000578560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll 2019-01-09 15:39 - 2019-01-01 07:14 - 000330752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.Workflow.dll 2019-01-09 15:39 - 2019-01-01 07:13 - 001628160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2019-01-09 15:39 - 2019-01-01 07:13 - 000594432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll 2019-01-09 15:39 - 2019-01-01 07:13 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll 2019-01-09 15:39 - 2019-01-01 07:12 - 001036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll 2019-01-09 15:39 - 2019-01-01 07:12 - 000795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2019-01-09 15:39 - 2019-01-01 07:12 - 000778240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2019-01-09 15:39 - 2019-01-01 07:12 - 000516608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidprov.dll 2019-01-09 15:39 - 2019-01-01 06:23 - 000001310 _____ C:\Windows\system32\tcbres.wim 2019-01-09 15:39 - 2018-12-19 05:49 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll 2019-01-08 16:03 - 2019-01-08 16:03 - 000000000 ____D C:\Users\Aviator\AppData\Local\Logitech 2019-01-08 15:36 - 2019-01-08 15:36 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\Logitech 2019-01-08 15:36 - 2019-01-08 15:36 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\Logishrd 2019-01-08 15:36 - 2019-01-08 15:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2019-01-08 15:36 - 2019-01-08 15:36 - 000000000 ____D C:\Program Files\Logitech 2019-01-08 15:36 - 2019-01-08 15:36 - 000000000 ____D C:\Program Files\Common Files\Logitech 2019-01-07 19:29 - 2019-01-07 19:29 - 000110968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2019-01-07 19:29 - 2019-01-07 19:29 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\Sun 2019-01-07 19:29 - 2019-01-07 19:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2019-01-07 19:29 - 2019-01-07 19:29 - 000000000 ____D C:\Program Files\Java 2019-01-07 19:28 - 2019-01-07 19:28 - 000000000 ____D C:\Windows\system32\appmgmt 2019-01-07 17:00 - 2019-01-07 17:01 - 000000000 ____D C:\ProgramData\CheatHappens Temp 2019-01-07 16:47 - 2019-01-18 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\by.xatab 2019-01-07 16:47 - 2019-01-07 16:47 - 000000631 _____ C:\Users\Aviator\Desktop\TheLongDark.lnk 2019-01-06 19:00 - 2019-01-07 18:44 - 000001010 _____ C:\Users\Aviator\Desktop\Open Broadcaster Software.lnk 2019-01-06 19:00 - 2019-01-06 19:04 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\OBS 2019-01-06 19:00 - 2019-01-06 19:00 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2019-01-06 19:00 - 2019-01-06 19:00 - 000000000 ____D C:\Program Files\OBS 2019-01-06 19:00 - 2019-01-06 19:00 - 000000000 ____D C:\Program Files (x86)\OBS 2019-01-06 13:36 - 2019-01-06 13:36 - 000000000 ____D C:\Users\Aviator\Desktop\the_long_dark_trainer_144_44110_steam 2019-01-06 13:36 - 2019-01-06 13:35 - 005375263 _____ C:\Users\Aviator\Desktop\the_long_dark_trainer_144_44110_steam.zip 2019-01-06 10:25 - 2019-01-06 10:25 - 000000000 ____D C:\Users\Aviator\AppData\Local\Hinterland 2019-01-06 10:24 - 2019-01-06 10:24 - 000000000 ____D C:\Users\Aviator\AppData\LocalLow\Hinterland 2019-01-06 10:21 - 2019-01-06 10:21 - 000000628 _____ C:\Users\Aviator\Desktop\The Long Dark Redux.lnk 2019-01-06 10:21 - 2019-01-06 10:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Long Dark Redux 2019-01-03 22:49 - 2019-01-03 22:52 - 000000000 ____D C:\Users\Aviator\Desktop\sound 2019-01-03 20:32 - 2019-01-03 20:32 - 000000000 ____D C:\Users\Aviator\Documents\Respawn 2019-01-03 20:31 - 2019-01-03 20:31 - 000000609 _____ C:\Users\Aviator\Desktop\Titanfall 2.lnk 2019-01-03 20:31 - 2019-01-03 20:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Titanfall 2 2019-01-03 16:14 - 2019-01-03 16:14 - 000262672 _____ C:\Users\Aviator\Desktop\WebInkasent - Wydruk_szklar.pdf 2019-01-03 15:56 - 2019-01-03 15:58 - 001224692 _____ C:\Users\Aviator\Desktop\WebInkasent - Wydruk.pdf 2019-01-02 21:36 - 2019-01-02 21:36 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf ==================== Jeden miesiąc (zmodyfikowane) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-01-30 16:59 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-01-30 16:56 - 2018-08-05 19:37 - 000000000 ____D C:\ProgramData\VoodooShield 2019-01-30 16:53 - 2018-08-05 18:50 - 000000000 ____D C:\Users\Aviator\AppData\LocalLow\Mozilla 2019-01-30 16:39 - 2018-08-06 16:19 - 000003046 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (Aviator) 2019-01-30 16:36 - 2018-09-09 21:44 - 000000000 ____D C:\ProgramData\Origin 2019-01-30 16:36 - 2018-08-22 17:05 - 000000000 ____D C:\Program Files (x86)\Steam 2019-01-30 16:35 - 2018-09-20 20:32 - 000000000 ____D C:\Users\Aviator\AppData\Local\Overwolf 2019-01-30 16:35 - 2018-08-05 18:24 - 000000000 ___RD C:\Users\Aviator\OneDrive 2019-01-30 16:33 - 2018-08-05 18:57 - 000000000 ____D C:\ProgramData\NVIDIA 2019-01-30 16:33 - 2018-08-05 18:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-01-30 13:37 - 2018-04-11 22:04 - 000524288 _____ C:\Windows\system32\config\BBI 2019-01-30 13:25 - 2018-08-07 15:06 - 000000000 ____D C:\Users\Aviator\AppData\Local\CrashDumps 2019-01-30 13:10 - 2018-08-05 18:08 - 000000000 ____D C:\Windows\system32\SleepStudy 2019-01-30 10:04 - 2018-08-05 19:47 - 000000266 __RSH C:\Users\Aviator\ntuser.pol 2019-01-30 10:04 - 2018-08-05 18:19 - 000000000 ____D C:\Users\Aviator 2019-01-30 10:01 - 2018-08-05 19:29 - 000000000 ____D C:\Users\Aviator\AppData\Local\WhiteClick 2019-01-30 09:51 - 2018-08-05 19:29 - 000003220 __RSH C:\ProgramData\ntuser.pol 2019-01-30 09:51 - 2018-08-05 19:28 - 000000000 ____D C:\Users\Aviator\AppData\Local\D3DSCache 2019-01-30 09:51 - 2018-08-05 18:50 - 000000000 ____D C:\Program Files\Mozilla Firefox 2019-01-30 09:50 - 2018-08-05 19:05 - 000000000 ____D C:\Program Files\WinRAR 2019-01-30 08:49 - 2018-04-12 00:38 - 000000000 ____D C:\Windows\AppReadiness 2019-01-29 12:19 - 2018-12-17 18:58 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys 2019-01-29 11:14 - 2018-08-05 18:39 - 000000000 ____D C:\ProgramData\Packages 2019-01-29 11:14 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps 2019-01-29 11:11 - 2018-09-09 22:05 - 000000000 ____D C:\Program Files (x86)\Origin 2019-01-28 14:19 - 2018-08-06 12:21 - 000000000 ____D C:\Users\Aviator\Documents\The Witcher 3 2019-01-27 10:05 - 2018-08-05 19:48 - 000000000 ____D C:\Users\Aviator\AppData\Local\NVIDIA Corporation 2019-01-27 00:50 - 2018-08-05 19:26 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\uTorrent 2019-01-26 20:02 - 2018-08-05 18:08 - 000435976 _____ C:\Windows\system32\FNTCACHE.DAT 2019-01-25 09:54 - 2018-09-20 20:34 - 000000000 ____D C:\Program Files (x86)\Overwolf 2019-01-24 23:20 - 2018-04-12 00:38 - 000000000 ____D C:\Windows\LiveKernelReports 2019-01-24 20:25 - 2018-11-03 08:42 - 000001433 _____ C:\Users\Aviator\Desktop\The Forest.lnk 2019-01-24 19:38 - 2018-09-20 20:34 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\TS3Client 2019-01-24 18:48 - 2018-08-05 19:50 - 000002852 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-239350383-861022925-3571962692-1001 2019-01-24 18:48 - 2018-08-05 18:24 - 000002768 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2 2019-01-24 18:48 - 2018-08-05 18:19 - 000002419 _____ C:\Users\Aviator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-01-23 23:33 - 2018-08-28 21:41 - 000000000 ____D C:\Users\Aviator\Documents\Rockstar Games 2019-01-23 23:33 - 2018-08-28 21:41 - 000000000 ____D C:\Users\Aviator\AppData\Local\Rockstar Games 2019-01-23 23:32 - 2018-08-05 18:46 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2019-01-23 21:35 - 2018-08-06 06:13 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\.minecraft 2019-01-22 21:09 - 2018-10-22 13:58 - 000897872 _____ (EasyAntiCheat Oy) C:\Windows\system32\Drivers\EasyAntiCheat.sys 2019-01-22 21:09 - 2018-09-11 22:54 - 000000000 ____D C:\Users\Aviator\AppData\Local\Ubisoft Game Launcher 2019-01-22 21:01 - 2018-11-17 14:42 - 000000000 ____D C:\Users\Aviator\AppData\Local\Deployment 2019-01-22 15:45 - 2018-08-31 09:27 - 000000000 ____D C:\Users\Aviator\AppData\Local\MEGAsync 2019-01-19 19:00 - 2018-10-08 14:36 - 000000000 ____D C:\Users\Aviator\Documents\American Truck Simulator 2019-01-19 15:20 - 2018-12-24 23:06 - 000000000 ____D C:\Windows\SysWOW64\directx 2019-01-19 13:50 - 2018-08-24 13:33 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2019-01-18 18:16 - 2018-12-10 18:05 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\SteamServerBrowser 2019-01-18 11:41 - 2018-11-16 16:09 - 000000000 ____D C:\Program Files\rempl 2019-01-14 20:11 - 2018-09-15 08:19 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\obs-studio 2019-01-14 20:05 - 2018-12-14 17:47 - 000000000 ____D C:\Users\Aviator\AppData\Roaming\vlc 2019-01-13 11:07 - 2018-08-06 18:09 - 000000000 ____D C:\Users\Aviator\Documents\My Games 2019-01-13 01:14 - 2018-08-24 13:33 - 000000222 _____ C:\Users\Aviator\Desktop\For Honor.url 2019-01-12 18:38 - 2018-12-22 23:48 - 000000000 ____D C:\games 2019-01-12 08:33 - 2018-04-12 00:30 - 000000000 ____D C:\Windows\CbsTemp 2019-01-12 08:27 - 2018-08-05 18:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-01-11 22:57 - 2018-04-12 00:36 - 000000000 ____D C:\Windows\INF 2019-01-11 16:30 - 2018-08-05 18:50 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-01-11 12:20 - 2018-09-16 09:59 - 000004264 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1537088356 2019-01-11 12:20 - 2018-09-16 09:59 - 000001382 _____ C:\Users\Aviator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Przeglądarka Opera.lnk 2019-01-10 19:39 - 2018-12-25 02:36 - 000000000 ____D C:\ESD 2019-01-10 19:39 - 2018-08-05 19:07 - 000000000 ____D C:\Windows\Panther 2019-01-09 19:09 - 2018-04-12 00:38 - 000000000 ____D C:\Windows\TextInput 2019-01-09 19:09 - 2018-04-12 00:38 - 000000000 ____D C:\Windows\bcastdvr 2019-01-09 15:39 - 2018-08-05 22:08 - 000000000 ____D C:\Windows\system32\MRT 2019-01-09 15:37 - 2018-06-15 20:04 - 132790320 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe 2019-01-07 19:23 - 2018-08-06 06:13 - 000001269 _____ C:\Users\Aviator\Desktop\Minecraft.lnk 2019-01-07 18:44 - 2018-09-20 20:23 - 000002106 _____ C:\Users\Aviator\Desktop\World of Tanks.lnk 2019-01-07 18:44 - 2018-09-16 09:59 - 000001392 _____ C:\Users\Aviator\Desktop\Przeglądarka Opera.lnk 2019-01-07 18:44 - 2018-09-15 22:01 - 000002249 _____ C:\Users\Aviator\Desktop\Discord.lnk 2019-01-07 18:44 - 2018-09-11 22:54 - 000001280 _____ C:\Users\Aviator\Desktop\Uplay.lnk 2019-01-07 18:44 - 2018-08-31 09:28 - 000001137 _____ C:\Users\Aviator\Desktop\MEGAsync.lnk 2019-01-07 18:44 - 2018-08-30 23:13 - 000001308 _____ C:\Users\Aviator\Desktop\OpenIV.lnk 2019-01-07 18:44 - 2018-08-25 06:48 - 000001174 _____ C:\Users\Aviator\Desktop\Cheat Engine.lnk 2019-01-07 18:44 - 2018-08-06 07:02 - 000001521 _____ C:\Users\Aviator\Desktop\.minecraft — skrót .lnk 2019-01-04 22:45 - 2018-11-08 16:47 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2019-01-02 23:26 - 2018-09-15 18:34 - 000000219 _____ C:\Users\Aviator\Desktop\Counter-Strike Global Offensive.url 2019-01-02 20:41 - 2018-04-12 00:41 - 000835480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2019-01-02 20:41 - 2018-04-12 00:41 - 000179600 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Pliki w katalogu głównym wybranych folderów ======= 1601-01-03 21:26 - 1601-01-03 21:26 - 000060416 ____N (Microsoft Corporation) C:\Users\Aviator\oEHEYyWlJ.exe 1601-01-03 21:26 - 1601-01-03 21:26 - 000178688 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\vJhiluefEuhD.exe 2018-08-05 19:28 - 2018-08-05 19:28 - 000140800 _____ () C:\Users\Aviator\AppData\Local\installer.dat 2018-11-17 18:49 - 2018-11-17 18:49 - 000002295 _____ () C:\Users\Aviator\AppData\Local\recently-used.xbel 2018-08-06 14:31 - 2018-08-06 14:31 - 000007602 _____ () C:\Users\Aviator\AppData\Local\resmon.resmoncfg 2019-01-30 09:50 - 2019-01-30 09:50 - 000000003 _____ () C:\Users\Aviator\AppData\Local\wbem.ini Niektóre pliki w TEMP: ==================== 2019-01-30 09:51 - 2019-01-30 09:51 - 000000009 _____ () C:\Users\Aviator\AppData\Local\Temp\1548838295424.exe 2019-01-30 09:50 - 2019-01-30 09:50 - 013205167 _____ (MAL ) C:\Users\Aviator\AppData\Local\Temp\4gtb4hgqpup.exe 2019-01-24 16:57 - 2019-01-30 16:54 - 031491992 _____ (VoodooSoft, LLC ) C:\Users\Aviator\AppData\Local\Temp\InstallVoodooShield.exe ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\dllhost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\dllhost.exe => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo UWAGA: ==> Nie można uzyskać dostępu do BCD. LastRegBack: 2018-08-05 18:08 ==================== Koniec FRST.txt ============================