Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 15-07-2019 01 Uruchomiony przez Ewa (administrator) EWA (ASUSTeK COMPUTER INC. X555LA) (17-07-2019 15:54:38) Uruchomiony z C:\Users\Ewa\Desktop\Nowy folder Załadowane profile: Ewa (Dostępne profile: Ewa) Platform: Windows 8.1 (Update) (X64) Język: Polski (Polska) Domyślna przeglądarka: Chrome Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (ASUS Cloud Corporation -> ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSPanel.exe (ASUS Cloud Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSWinService.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (Atheros) [Brak podpisu cyfrowego] C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) [Brak podpisu cyfrowego] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Qualcomm Atheros -> ) [Brak podpisu cyfrowego] C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (Qualcomm Atheros -> Atheros Communications) [Brak podpisu cyfrowego] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Qualcomm Atheros -> Qualcomm Atheros) [Brak podpisu cyfrowego] C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [Brak podpisu cyfrowego] C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Spotify AB -> Spotify Ltd) C:\Users\Ewa\AppData\Roaming\Spotify\Spotify.exe (Spotify AB -> Spotify Ltd) C:\Users\Ewa\AppData\Roaming\Spotify\Spotify.exe (Spotify AB -> Spotify Ltd) C:\Users\Ewa\AppData\Roaming\Spotify\Spotify.exe (Spotify AB -> Spotify Ltd) C:\Users\Ewa\AppData\Roaming\Spotify\Spotify.exe (Spotify AB -> Spotify Ltd) C:\Users\Ewa\AppData\Roaming\Spotify\Spotify.exe (WildTangent Inc -> WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [114048 2013-10-18] (Intel(R) Software -> Intel Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation -> NVIDIA Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-09-11] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\ASUSWSLoader.exe [63272 2014-12-04] (ASUS Cloud Corporation -> ) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation -> Microsoft Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [134784 2014-06-17] (Qualcomm Atheros -> Atheros Communications) [Brak podpisu cyfrowego] HKU\S-1-5-21-1540272699-3277271125-2178347195-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (Disc Soft Ltd -> DT Soft Ltd) HKU\S-1-5-21-1540272699-3277271125-2178347195-1001\...\Run: [Spotify] => C:\Users\Ewa\AppData\Roaming\Spotify\Spotify.exe [25591712 2019-07-17] (Spotify AB -> Spotify Ltd) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe [2019-07-17] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-06-10] (Adobe Inc. -> Adobe Systems, Inc.) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{DB09678A-882B-494B-AF1C-D62CBD5F4485}] -> C:\Program Files (x86)\WildTangent Games\App\NativeUserProxy.exe [2015-02-09] (WildTangent Inc -> ) HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2014-06-17] (Qualcomm Atheros -> Qualcomm®Atheros®) [Brak podpisu cyfrowego] HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2014-06-17] (Qualcomm Atheros -> Qualcomm®Atheros®) [Brak podpisu cyfrowego] Startup: C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - .lnk [2017-08-31] ShortcutAndArgument: Powiadomienia monitorowania tuszu - .lnk -> C:\Windows\system32\RunDll32.exe => "C:\Program Files\HP\HP Deskjet 1510 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN48P1N7RQ05YR;CONNECTION=USB;MONITOR=1; Startup: C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 1510 Series Class Driver.lnk [2018-03-17] ShortcutAndArgument: Powiadomienia monitorowania tuszu - HP Deskjet 1510 Series Class Driver.lnk -> C:\Windows\system32\RunDll32.exe => "C:\Program Files\HP\HP Deskjet 1510 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN48P1N7RQ05YR;CONNECTION=USB;MONITOR=1; ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {014F7AEE-AC56-48FF-BCAA-8A7C67A3A939} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [17920 2016-08-01] () [Brak podpisu cyfrowego] Task: {0B24AD8F-5BDA-4936-841C-077B587C8CE8} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [58440 2014-04-02] (ASUSTeK Computer Inc. -> ASUS) Task: {174D3115-149D-4B5C-AA1C-F2F70520F76D} - System32\Tasks\{1C4A296F-2CA0-EDD6-E0C7-761856BD0247} => C:\Users\Ewa\AppData\Roaming\{1C4A2~1\SYNHEL~1 [Argument = /Check] Task: {41F139B5-FC8B-40A1-BA73-15777D3E1948} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [109880 2014-01-14] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {439117E1-0D18-48DC-9758-093C7F09BE58} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19723888 2014-03-27] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {447613CB-736E-4192-8616-24CB9E7B1DD7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\Windows\System32\MRT.exe [136618864 2019-07-16] (Microsoft Corporation -> Microsoft Corporation) Task: {75EA4C2B-2F2D-40FA-A665-CD3DC3FAF4C6} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1385840 2014-04-15] (Realtek Semiconductor Corp -> Realtek Semiconductor) Task: {7C9CF1F5-01D7-4F6C-B67D-5FDF63E57F04} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-04-04] (Google Inc -> Google Inc.) Task: {92794BC9-E9AE-4D33-81CE-4F1634AB2196} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-04-04] (Google Inc -> Google Inc.) Task: {9B033B3A-C4B6-4333-AF18-EC3A8E58E973} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Task: {B4108B00-5F69-4A45-B38A-24A17AC32657} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [5745672 2014-03-06] (Hewlett Packard -> Hewlett-Packard Co.) Task: {CBAE4F2E-42B2-401E-9749-999761CA3212} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671640 2014-04-10] (Realtek Semiconductor Corp -> Realtek Semiconductor) Task: {CC3C2835-541A-410C-B8E1-BBFF2D4C83BD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2017-07-24] (Apple Inc. -> Apple Inc.) Task: {DEC80AF0-8F5D-4718-A936-98CC242E6C37} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18232 2014-03-31] (ASUSTeK Computer Inc. -> AsusTek) Task: {DF4734BF-028F-4280-B923-A603ACBB058C} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1606784 2015-03-03] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) [Brak podpisu cyfrowego] Task: {E9199C56-850D-48F6-9B06-E87BF393B317} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\Overseer.exe [2281944 2019-06-04] (AVAST Software s.r.o. -> AVAST Software) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\{1C4A296F-2CA0-EDD6-E0C7-761856BD0247}.job => C:\Users\Ewa\AppData\Roaming\{1C4A2~1\SYNHEL~1/CheckEWA\Ewa0֠< <==== UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 10.128.17.2 10.128.17.3 Tcpip\..\Interfaces\{19BF1EA6-BE51-4755-BC56-7B503BF2148A}: [DhcpNameServer] 10.128.17.2 10.128.17.3 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1540272699-3277271125-2178347195-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com/?pc=ASJB HKU\S-1-5-21-1540272699-3277271125-2178347195-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB SearchScopes: HKU\S-1-5-21-1540272699-3277271125-2178347195-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1540272699-3277271125-2178347195-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll => Brak pliku BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-01-29] (EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2016-08-22] (McAfee, Inc. -> McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2016-08-22] (McAfee, Inc. -> McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2016-08-22] (McAfee, Inc. -> McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2016-08-22] (McAfee, Inc. -> McAfee, Inc.) FireFox: ======== FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2016-09-16] [Przestarzałe] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-10-23] (Intel® Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-10-23] (Intel® Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-15] (WildTangent Inc -> ) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-06-10] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR StartupUrls: Default -> "hxxps://www.google.pl/" CHR NewTab: Default -> Active:"chrome-extension://laookkfknpbbblfpciffpaejjkokdgca/dashboard.html" CHR Profile: C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default [2019-07-17] CHR Extension: (Prezentacje) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12] CHR Extension: (Dokumenty) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12] CHR Extension: (Dysk Google) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-04] CHR Extension: (YouTube) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-04] CHR Extension: (Adobe Acrobat) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-10] CHR Extension: (Arkusze) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12] CHR Extension: (Dokumenty Google offline) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-04] CHR Extension: (Momentum) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\laookkfknpbbblfpciffpaejjkokdgca [2019-07-05] CHR Extension: (Cath Kidston) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm [2016-09-19] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04] CHR Extension: (Gmail) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-23] CHR Extension: (Chrome Media Router) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-22] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-04-21] CHR HKU\S-1-5-21-1540272699-3277271125-2178347195-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-04-21] HKU\S-1-5-21-1540272699-3277271125-2178347195-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Evercine\Application\chrome.exe <==== UWAGA ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc. -> Apple Inc.) R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSWinService.exe [71168 2014-12-04] (ASUS Cloud Corporation) [Brak podpisu cyfrowego] R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [322176 2014-06-17] (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [Brak podpisu cyfrowego] R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [117704 2013-10-18] (Intel(R) Software -> Intel Corporation) R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116680 2013-10-18] (Intel(R) Software -> Intel Corporation) R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148160 2013-10-18] (Intel(R) Software -> Intel Corporation) R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [126952 2013-10-18] (Intel(R) Software -> Intel Corporation) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [347200 2015-02-09] (WildTangent Inc -> WildTangent) S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344976 2014-12-15] (Intel Corporation - pGFX -> Intel Corporation) S2 IlS; C:\ProgramData\Tencent\QQ\report\repor.dll [394752 2016-10-12] () [Brak podpisu cyfrowego] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel(R) Corporation) [Brak podpisu cyfrowego] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-10-23] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-10-23] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) S3 McAfee SiteAdvisor Service; c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [163592 2016-08-22] (McAfee, Inc. -> McAfee, Inc.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation -> NVIDIA Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-06-17] (Atheros) [Brak podpisu cyfrowego] ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 AgereSoftModem; C:\Windows\system32\DRIVERS\agrsm64.sys [1146880 2013-06-18] (Microsoft Windows -> LSI Corp) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3892224 2014-03-06] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros Communications, Inc.) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [71952 2014-03-31] (ASUSTeK Computer Inc. -> ASUS Corporation) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Broadcom Corporation -> Windows (R) Win 7 DDK provider) S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [145640 2013-10-18] (Intel(R) Software -> Intel Corporation) R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [116752 2013-10-18] (Intel(R) Software -> Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [289744 2013-10-18] (Intel(R) Software -> Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494296 2013-10-18] (Intel(R) Software -> Intel Corporation) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2017-11-26] (DT Soft Ltd -> DT Soft Ltd) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-10-23] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) S3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc. -> McAfee, Inc.) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2017-09-07] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation) U0 aswVmm; Brak ImagePath S3 e1edc438-f640-4184-a443-d2a7c37a01dc; \??\C:\OA30\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X] U0 msahci; system32\drivers\msahci.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-07-17 15:53 - 2019-07-17 15:54 - 000000000 ____D C:\FRST 2019-07-17 15:51 - 2019-07-17 15:54 - 000000000 ____D C:\Users\Ewa\Desktop\Nowy folder 2019-07-17 14:43 - 2019-07-17 14:43 - 000000000 ___RD C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2019-07-16 21:23 - 2019-06-25 05:54 - 001368080 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2019-07-16 21:23 - 2019-06-25 04:59 - 004169728 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2019-07-16 21:23 - 2019-06-25 04:36 - 000128512 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2019-07-16 21:23 - 2019-06-25 04:07 - 001994240 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2019-07-16 21:23 - 2019-06-25 03:48 - 001756160 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2019-07-16 21:23 - 2019-06-25 03:44 - 000302080 _____ (Microsoft Corporation) C:\Windows\system32\ProximityService.dll 2019-07-16 21:23 - 2019-06-25 03:42 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll 2019-07-16 21:23 - 2019-06-25 03:41 - 001085440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2019-07-16 21:23 - 2019-06-25 03:41 - 000302080 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2019-07-16 21:23 - 2019-06-25 03:39 - 001559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2019-07-16 21:23 - 2019-06-25 03:36 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2019-07-16 21:23 - 2019-06-25 03:31 - 001494016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2019-07-16 21:23 - 2019-06-25 03:28 - 000827392 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2019-07-16 21:23 - 2019-06-25 03:26 - 000238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll 2019-07-16 21:23 - 2019-06-18 06:34 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2019-07-16 21:23 - 2019-06-18 06:07 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2019-07-16 21:23 - 2019-06-18 05:59 - 005775872 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2019-07-16 21:23 - 2019-06-18 05:56 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2019-07-16 21:23 - 2019-06-18 05:56 - 000790528 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2019-07-16 21:23 - 2019-06-18 05:39 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2019-07-16 21:23 - 2019-06-18 05:29 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2019-07-16 21:23 - 2019-06-18 05:28 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2019-07-16 21:23 - 2019-06-18 05:20 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2019-07-16 21:23 - 2019-06-18 05:19 - 015311872 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2019-07-16 21:23 - 2019-06-18 05:13 - 000166912 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll 2019-07-16 21:23 - 2019-06-18 05:08 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2019-07-16 21:23 - 2019-06-18 05:07 - 004494336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2019-07-16 21:23 - 2019-06-18 05:06 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2019-07-16 21:23 - 2019-06-18 05:06 - 000269312 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2019-07-16 21:23 - 2019-06-18 05:03 - 013706752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2019-07-16 21:23 - 2019-06-18 05:03 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2019-07-16 21:23 - 2019-06-18 04:55 - 001557504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2019-07-16 21:23 - 2019-06-18 04:55 - 000214528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2019-07-16 21:23 - 2019-06-18 04:44 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2019-07-16 21:23 - 2019-06-18 04:43 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2019-07-16 21:23 - 2019-06-18 04:42 - 001349120 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2019-07-16 21:23 - 2019-06-18 04:41 - 001323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2019-07-16 21:23 - 2019-06-18 04:39 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2019-07-16 21:23 - 2019-06-18 04:33 - 000956416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll 2019-07-16 21:23 - 2019-06-15 17:22 - 000910848 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2019-07-16 21:23 - 2019-06-12 02:51 - 000169256 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2019-07-16 21:23 - 2019-06-11 15:37 - 000293888 _____ (Microsoft Corporation) C:\Windows\system32\Dism.exe 2019-07-16 21:23 - 2019-06-11 15:35 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Dism.exe 2019-07-16 21:23 - 2019-06-10 23:42 - 001712640 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2019-07-16 21:23 - 2019-06-10 23:42 - 000801792 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2019-07-16 21:23 - 2019-06-10 23:42 - 000732160 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2019-07-16 21:23 - 2019-06-10 23:42 - 000634368 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2019-07-16 21:23 - 2019-06-10 23:42 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2019-07-16 21:23 - 2019-06-10 23:42 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2019-07-16 21:23 - 2019-06-10 23:42 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2019-07-16 21:23 - 2019-06-10 23:42 - 000257024 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2019-07-16 21:23 - 2019-06-08 18:09 - 000445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2019-07-16 21:23 - 2019-06-08 17:55 - 001101824 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2019-07-16 21:23 - 2019-06-08 17:43 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2019-07-16 21:23 - 2019-06-08 17:33 - 000856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2019-07-16 21:23 - 2019-06-08 16:55 - 007035392 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2019-07-16 21:23 - 2019-06-08 16:53 - 006217216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2019-07-16 21:23 - 2019-06-07 00:49 - 007362800 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2019-07-16 21:23 - 2019-06-06 19:14 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2019-07-16 21:23 - 2019-06-02 17:42 - 000365056 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe 2019-07-16 21:23 - 2019-05-25 04:32 - 002013432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2019-07-16 21:23 - 2019-05-15 22:33 - 000333552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2019-07-16 21:23 - 2019-05-15 02:53 - 000136800 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2019-07-16 21:23 - 2019-05-14 16:18 - 003718144 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2019-07-16 20:56 - 2019-06-25 04:59 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2019-07-16 20:56 - 2019-06-25 04:24 - 000129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2019-06-26 08:13 - 2019-06-26 08:13 - 000060723 _____ C:\Users\Ewa\Downloads\SEP_INDEKS_STUD_26.06.2019.pdf 2019-06-17 12:36 - 2019-06-17 12:36 - 000298212 _____ C:\Users\Ewa\Downloads\Prezentacja-A.-Banach.pptx ==================== Jeden miesiąc (zmodyfikowane) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-07-17 15:51 - 2016-04-04 20:50 - 000000000 ____D C:\Users\Ewa\Documents\Bluetooth Folder 2019-07-17 15:32 - 2016-04-04 20:48 - 000000093 _____ C:\Users\Ewa\AppData\Roaming\sp_data.sys 2019-07-17 15:31 - 2018-12-04 01:52 - 000000000 ____D C:\Users\Ewa\AppData\Local\Spotify 2019-07-17 15:14 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\rescache 2019-07-17 14:59 - 2016-04-04 20:54 - 000003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1540272699-3277271125-2178347195-1001 2019-07-17 14:53 - 2016-10-10 23:38 - 000002252 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-07-17 14:53 - 2016-10-10 23:38 - 000002211 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-07-17 14:51 - 2016-04-04 20:58 - 000003956 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3FD00428-E243-46D5-9EDB-EFCC06014523} 2019-07-17 14:49 - 2018-12-04 01:51 - 000000000 ____D C:\Users\Ewa\AppData\Roaming\Spotify 2019-07-17 14:46 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf 2019-07-17 14:44 - 2016-04-08 00:41 - 000000000 ____D C:\Windows\system32\MRT 2019-07-17 14:44 - 2016-04-04 20:50 - 000000000 ____D C:\Users\Ewa\AppData\Roaming\Atheros 2019-07-17 14:43 - 2016-04-06 15:38 - 006767104 ___SH C:\Users\Ewa\Desktop\Thumbs.db 2019-07-17 14:42 - 2016-04-04 20:50 - 000000000 __RDO C:\Users\Ewa\OneDrive 2019-07-17 14:41 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-07-17 14:41 - 2013-08-22 16:44 - 000497776 _____ C:\Windows\system32\FNTCACHE.DAT 2019-07-16 23:14 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI 2019-07-16 23:11 - 2016-04-08 00:55 - 000000000 ____D C:\Windows\system32\appraiser 2019-07-16 23:11 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\SysWOW64\Dism 2019-07-16 23:11 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\system32\Dism 2019-07-16 22:59 - 2016-04-08 00:41 - 136618864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2019-07-16 22:28 - 2016-05-30 15:28 - 000000266 _____ C:\Windows\Tasks\{1C4A296F-2CA0-EDD6-E0C7-761856BD0247}.job 2019-07-16 20:54 - 2013-08-22 17:20 - 000000000 ____D C:\Windows\CbsTemp 2019-07-16 20:27 - 2017-11-27 21:39 - 000003160 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1540272699-3277271125-2178347195-1001 2019-07-16 20:26 - 2019-02-14 14:13 - 000002377 _____ C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive dla Firm.lnk 2019-06-22 09:57 - 2019-05-27 10:46 - 000000000 ____D C:\Users\Ewa\AppData\LocalLow\Adobe 2019-06-22 09:56 - 2016-04-04 20:47 - 000000000 ____D C:\Users\Ewa\AppData\Local\Packages 2019-06-22 09:52 - 2016-04-10 16:04 - 021028864 ___SH C:\Users\Ewa\Downloads\Thumbs.db 2019-06-21 15:23 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\NDF 2019-06-18 23:05 - 2019-06-14 13:49 - 000117868 _____ C:\Users\Ewa\Desktop\prezentacja - Ocena sposobu żywienia chorego na chorobę Leśniowskiego-Crohna.pptx 2019-06-18 15:55 - 2019-05-30 10:11 - 000000000 ____D C:\Users\Ewa\Desktop\praca licencjacka ==================== Pliki w katalogu głównym wybranych folderów ================ 2016-04-04 20:48 - 2019-07-17 15:32 - 000000093 _____ () C:\Users\Ewa\AppData\Roaming\sp_data.sys 2016-05-30 16:28 - 2016-06-01 11:28 - 000000072 _____ () C:\Users\Ewa\AppData\Roaming\WB.CFG ==================== SigCheck =============================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) LastRegBack: 2019-07-05 22:55 ==================== Koniec FRST.txt ============================