Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 16-02-2020 Uruchomiony przez Łukasz (administrator) ŁUKASZ-KOMPUTER (21-03-2020 09:19:51) Uruchomiony z C:\Users\Łukasz\Downloads Załadowane profile: Łukasz (Dostępne profile: Łukasz) Platform: Windows 7 Home Premium Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (ALCPU -> ALCPU) C:\Program Files\Core Temp\Core Temp.exe (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe (Digital Wave Ltd -> Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Electronic Arts, Inc. -> Electronic Arts) F:\Origin\OriginThinSetupInternal.exe (Electronic Arts, Inc. -> Electronic Arts) F:\Origin\OriginWebHelperService.exe (F.lux Software LLC -> f.lux Software LLC) C:\Users\Łukasz\AppData\Local\FluxSoftware\Flux\flux.exe (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Malwarebytes Inc -> Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe (Malwarebytes Inc -> Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe (Malwarebytes Inc -> Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) [Brak podpisu cyfrowego] C:\Windows\explorer.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Nero AG -> ) C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe (Nero AG -> Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7560296 2011-12-12] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation -> Microsoft Corporation) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-15] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-29] (Intel Corporation -> Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2480816 2020-02-17] (Malwarebytes Inc -> Malwarebytes Corporation) HKLM\...\Winlogon: [Shell] C:\Windows\explorer.exe [3229696 2019-11-03] (Microsoft Corporation) [Brak podpisu cyfrowego] HKU\S-1-5-21-1908724746-673112573-3840648487-1000\...\Run: [f.lux] => C:\Users\Łukasz\AppData\Local\FluxSoftware\Flux\flux.exe [1806344 2018-07-03] (F.lux Software LLC -> f.lux Software LLC) HKU\S-1-5-21-1908724746-673112573-3840648487-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Windows -> Microsoft Corporation) GroupPolicy: Ograniczenia ? <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ============ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {1972AD4F-AC6C-476F-B735-0C0137F86483} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_Plugin.exe [1458232 2020-03-11] (Adobe Inc. -> Adobe) Task: {3C36F11F-044A-40BE-BC12-2A616C982F94} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-03-11] (Adobe Inc. -> Adobe) Task: {A3B95AAD-7B3C-4C7E-9EA9-2F6F1B8D450D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd) Task: {AA8CF5E1-C4F4-40C6-A162-97EF0012E480} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [14679256 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd) Task: {BB417EF5-EECC-4369-8D6F-0F0A6812C28C} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [410784 2016-11-15] (Microsoft Corporation -> Microsoft Corporation) Task: {C7A3AA8A-0104-4683-97F4-F748F79C1A6E} - System32\Tasks\Core Temp Autostart Łukasz => C:\Program Files\Core Temp\Core Temp.exe [998488 2018-05-20] (ALCPU -> ALCPU) Task: {E52B4D39-2C79-4DA9-973F-704E9D00067C} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [410784 2016-11-15] (Microsoft Corporation -> Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{60B932C8-0527-4AC3-B5F3-D6DC3A1D4422}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1908724746-673112573-3840648487-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1908724746-673112573-3840648487-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES007&pc=UE06 SearchScopes: HKLM-x32 -> DefaultScope - brak wartości BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2014-05-22] (Microsoft Corporation -> Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_221\bin\ssv.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2014-05-22] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) FireFox: ======== FF DefaultProfile: metegczb.default FF ProfilePath: C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\metegczb.default [2019-10-04] FF ProfilePath: C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release [2020-03-21] FF Homepage: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> www.google.pl FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: extension@tabliss.io FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: @contain-facebook FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: {506e023c-7f2b-40a3-8066-bc5deb40aebe} FF NewTabOverride: Mozilla\Firefox\Profiles\6kzthl6s.default-release -> Enabled: uBlock0@raymondhill.net FF Extension: (Facebook Container) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\@contain-facebook.xpi [2020-03-06] FF Extension: (Hoxx VPN Proxy) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\@hoxx-vpn.xpi [2020-03-16] FF Extension: (Tabliss) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\extension@tabliss.io.xpi [2019-10-09] FF Extension: (Video Downloader professional) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\ffext_basicvideoext@startpage24.xpi [2020-03-09] FF Extension: (youtube-dark) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\jid1-y4pUQrD6t1PJJa@jetpack.xpi [2020-01-23] FF Extension: (uBlock Origin) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\uBlock0@raymondhill.net.xpi [2020-03-11] FF Extension: (Worldwide Radio) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\worldwide@radio.xpi [2020-03-09] FF Extension: (Firefox Space 2) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{120c75a3-e2fe-466b-a0a5-ad2752a72bbc}.xpi [2020-01-24] FF Extension: (Dark Fox 7) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{331bc9d5-35e9-4617-94e4-0db3dc1f5696}.xpi [2020-01-24] FF Extension: (Gesturefy) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{506e023c-7f2b-40a3-8066-bc5deb40aebe}.xpi [2020-02-19] FF Extension: (FireFox Logo on Grey and Black) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{50b48dea-3731-4623-8c00-250c2b8f671f}.xpi [2020-01-24] FF Extension: (YouTube Popout Player) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{85b42b8f-49cd-4935-aeca-a6b32dd6ac9f}.xpi [2020-03-09] FF Extension: (BlueOrangeFoxAbstract) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{b207ffd9-e14f-482e-8178-d8d0e3b9870b}.xpi [2020-01-24] FF Extension: (Dark Fox 7 lite) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{cbec31ae-215c-4a9d-bad7-0d08ac6a1dfc}.xpi [2020-01-24] FF Extension: (Bright Logo on Carbonfiber) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{d8273d54-97f4-483e-b7b1-a2c1191c4ed1}.xpi [2020-01-24] FF Extension: (Dark Fox) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{e7fe4ffe-f256-4f85-906d-072fdd698585}.xpi [2019-10-04] FF Extension: (Dark Fox 2.1) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{ef45b7cb-4f23-4e83-849b-fd0de22fce55}.xpi [2020-01-24] FF Extension: (Nano Defender for Firefox) - C:\Users\Łukasz\AppData\Roaming\Mozilla\Firefox\Profiles\6kzthl6s.default-release\Extensions\{fcf60470-b210-4c17-969e-9ae01491071e}.xpi [2020-03-12] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 => nie znaleziono FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_344.dll [2020-03-11] (Adobe Inc. -> ) FF Plugin: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-09-20] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_344.dll [2020-03-11] (Adobe Inc. -> ) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin HKU\S-1-5-21-1908724746-673112573-3840648487-1000: @acestream.net/acestreamplugin,version=3.1.32 -> C:\Users\Łukasz\AppData\Roaming\ACEStream\player\npace_plugin.dll [Brak pliku] Chrome: ======= CHR Profile: C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default [2019-11-01] CHR HomePage: Default -> hxxp://www.google.pl/ CHR StartupUrls: Default -> "hxxp://www.google.pl/" CHR DefaultSearchURL: Default -> hxxps://www.google.pl/search?source=hp&ei=FlOWXf71EojfkgW1s72QBw&q={searchTerms}&btnK=Szukaj+w+Google&oq=ublock&gs_l=psy-ab.3..0j0i131j0l8.22151.23446..23714...1.0..0.173.690.6j1......0....1..gws-wiz.....0.uWR9bk-V7no&ved=0ahUKEwj-2Lyq8IDlAhWIr6QKHbVZD3IQ4dUDCAY&uact=5 CHR Extension: (Video Downloader Plus) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\baejfnndpekpkaaancgpakjaengfpopk [2019-10-03] CHR Extension: (uBlock Origin) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-10-03] CHR Extension: (Nano Defender) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggolfgbegefeeoocgjbmkembbncoadlb [2019-10-03] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03] CHR Extension: (Worldwide Radio) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofncbjjbfchlegacifnndkkbdoaedcof [2019-10-03] CHR Extension: (Chrome Media Router) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-03] CHR Extension: (Eiffel Tower) - C:\Users\Łukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppbaibkigenhdcommebegmmmpoolmpip [2019-10-03] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [246784 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> AMD) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-06-06] (Digital Wave Ltd -> Digital Wave Ltd.) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3730024 2018-08-27] (AVB Disc Soft, SIA -> Disc Soft Ltd) R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2016-09-20] (Nero AG -> Nero AG) R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [152752 2020-02-17] (Malwarebytes Inc -> Malwarebytes Corporation) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-15] (Microsoft Corporation -> Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [Brak podpisu cyfrowego] R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-15] (Microsoft Corporation -> Microsoft Corporation) S3 Origin Client Service; F:\Origin\OriginClientService.exe [2425136 2019-11-16] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; F:\Origin\OriginWebHelperService.exe [3303736 2019-11-16] (Electronic Arts, Inc. -> Electronic Arts) S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [Brak podpisu cyfrowego] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [Brak podpisu cyfrowego] S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [157480 2018-08-02] (Microsoft Corporation -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [21622784 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [665088 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== UWAGA (Brak ServiceDLL) R3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [130536 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc) R3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [395752 2011-11-03] (MCCI Internal Testing Software -> ASMedia Technology Inc) R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [104976 2016-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2018-08-30] (Disc Soft Ltd -> Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2018-08-30] (Disc Soft Ltd -> Disc Soft Ltd) R1 epp; C:\EEK\bin64\epp.sys [176128 2019-10-03] (Emsisoft Ltd -> Emsisoft Ltd) R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [153312 2020-02-17] (Malwarebytes Corporation -> Malwarebytes) S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (3am.com(Test) -> HTC, Corporation) S3 htcnprot; C:\Windows\System32\DRIVERS\htcnprot.sys [36928 2013-10-17] (HTC Corp. -> Windows (R) Win 7 DDK provider) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (Sqa.com(Test) -> QUALCOMM Incorporated) R2 mi2c; C:\Windows\system32\drivers\mi2c.sys [20784 2019-11-03] (AOC International (Europe) GmbH -> Nicomsoft Ltd.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation) R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [21504 2008-12-26] (AVnex Ltd. -> Avnex) R3 ALSysIO; \??\C:\Users\UKASZ~1\AppData\Local\Temp\ALSysIO64.sys [X] <==== UWAGA R3 esihdrv; \??\C:\Users\UKASZ~1\AppData\Local\Temp\esihdrv.sys [X] <==== UWAGA ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) =================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-03-21 09:19 - 2020-03-21 09:20 - 000023309 _____ C:\Users\Łukasz\Downloads\FRST.txt 2020-03-21 09:19 - 2020-03-21 09:19 - 002279424 _____ (Farbar) C:\Users\Łukasz\Downloads\FRST64.exe 2020-03-21 09:12 - 2020-03-21 09:12 - 008199856 _____ (Malwarebytes) C:\Users\Łukasz\Desktop\adwcleaner_8.0.3.exe 2020-03-21 09:12 - 2020-03-21 09:12 - 006312056 _____ (ESET) C:\Users\Łukasz\Downloads\sysinspector_nt64_plk.exe 2020-03-17 20:09 - 2020-03-17 20:18 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\WhatsApp 2020-03-17 20:09 - 2020-03-17 20:09 - 000002091 _____ C:\Users\Łukasz\Desktop\WhatsApp.lnk 2020-03-17 20:09 - 2020-03-17 20:09 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2020-03-17 20:09 - 2020-03-17 20:09 - 000000000 ____D C:\Users\Łukasz\AppData\Local\WhatsApp 2020-03-17 20:05 - 2020-03-17 20:07 - 127628720 _____ (WhatsApp) C:\Users\Łukasz\Downloads\WhatsAppSetup.exe 2020-03-14 20:45 - 2020-03-14 20:45 - 000051128 _____ C:\Users\Łukasz\Downloads\20200311172814-183.pdf 2020-03-14 20:45 - 2020-03-14 20:45 - 000048032 _____ C:\Users\Łukasz\Downloads\20200312123246-31.pdf 2020-03-13 14:11 - 2020-03-14 07:58 - 000000000 ____D C:\Program Files\Mozilla Firefox 2020-03-03 18:23 - 2020-03-03 18:23 - 000588412 _____ C:\Users\Łukasz\Downloads\OWU_i_OFERTA.pdf 2020-03-03 18:22 - 2020-03-03 18:22 - 000367623 _____ C:\Users\Łukasz\Downloads\REGULAMIN KLUBU_NOWY.pdf ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-03-21 09:20 - 2019-10-04 09:40 - 000000000 ____D C:\FRST 2020-03-21 09:20 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf 2020-03-21 09:15 - 2019-08-27 13:00 - 000000000 ____D C:\Users\Łukasz\AppData\LocalLow\Mozilla 2020-03-21 09:14 - 2019-06-08 18:21 - 000000000 ____D C:\Users\Łukasz\AppData\Local\HTC MediaHub 2020-03-21 09:14 - 2018-08-30 08:04 - 000000000 ____D C:\Program Files\Core Temp 2020-03-21 09:14 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-03-21 09:13 - 2019-02-02 00:42 - 000000000 ____D C:\Users\Łukasz\AppData\Local\ElevatedDiagnostics 2020-03-21 09:06 - 2009-07-14 05:45 - 000021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2020-03-21 09:06 - 2009-07-14 05:45 - 000021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2020-03-21 08:56 - 2019-02-01 23:37 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2020-03-21 08:51 - 2019-11-01 21:54 - 000000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit 2020-03-21 07:56 - 2011-04-12 14:21 - 000743484 _____ C:\Windows\system32\perfh015.dat 2020-03-21 07:56 - 2011-04-12 14:21 - 000156966 _____ C:\Windows\system32\perfc015.dat 2020-03-21 07:56 - 2009-07-14 06:13 - 001678034 _____ C:\Windows\system32\PerfStringBackup.INI 2020-03-17 20:09 - 2019-08-30 11:54 - 000000000 ____D C:\Users\Łukasz\AppData\Local\SquirrelTemp 2020-03-14 17:57 - 2019-10-04 10:00 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-03-11 15:57 - 2019-09-20 21:31 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe 2020-03-11 15:57 - 2019-09-20 21:31 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2020-03-11 15:57 - 2019-09-20 21:31 - 000004536 _____ C:\Windows\system32\Tasks\Adobe Flash Player NPAPI Notifier 2020-03-11 15:57 - 2019-09-20 21:31 - 000004382 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater 2020-03-11 15:57 - 2019-09-20 21:31 - 000000000 ____D C:\Windows\system32\Macromed 2020-03-10 22:52 - 2018-08-30 00:02 - 000000000 ____D C:\Windows\system32\MRT 2020-03-10 22:50 - 2018-08-30 00:02 - 121542864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-02-22 18:59 - 2018-08-30 09:57 - 000004128 _____ C:\Windows\system32\Tasks\CCleaner Update ==================== Pliki w katalogu głównym wybranych folderów ======== 2019-04-05 20:16 - 2019-04-05 20:16 - 000000017 _____ () C:\Users\Łukasz\AppData\Local\resmon.resmoncfg 2018-11-11 11:45 - 2018-11-11 11:45 - 000000000 _____ () C:\Users\Łukasz\AppData\Local\{D42C1416-EC80-41BF-952F-E43A65B7A715} ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\explorer.exe [2018-08-29 23:47] - [2019-11-03 02:17] - 003229696 _____ (Microsoft Corporation) D35EFB223552993DCFBD31163F6DEB51 ==================== Koniec FRST.txt ========================