Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:05-12-2015 Uruchomiony przez Natalia (administrator) NATALKA (05-12-2015 14:29:02) Uruchomiony z C:\Users\Natalia\Desktop Załadowane profile: Natalia (Dostępne profile: Natalia) Platform: Windows 8.1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: Chrome) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PSIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-25] (Adobe Systems Incorporated) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-03] (NVIDIA Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-06] (Apple Inc.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [Corel Photo Downloader] => "C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup HKLM-x32\...\Run: [fst_pl_89] => [X] HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-05] (AVAST Software) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation) HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\Run: [AirDroid 3] => C:\Program Files (x86)\AirDroid\AirDroid.exe /start HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\Natalia\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5585136 2015-03-31] (Disc Soft Ltd) HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\RunOnce: [Autodesk 3ds Max 2014] => C:\Autodesk\Autodesk_3ds_Max_2014_EFGJKS_Win_64bit_wi_en-US\Setup.exe /url "hxxp://trial2.autodesk.com/SWDLDNET3/2014/3DSMAX/WI/EDU/Autodesk_3ds_Max_2014_EFGJKS_Win_64bit_wi_en-US_Setup.exe" /SN 900-2 (dane wartości zawierają 77 znaków więcej). HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\Policies\Explorer: [] HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\MountPoints2: {002e5104-be0c-11e3-8262-60a44c33da09} - "G:\SETUP.EXE" HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\MountPoints2: {21f547ab-4ebd-11e4-837c-60a44c33da09} - "G:\Startme.exe" HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\MountPoints2: {352db4f2-f919-11e3-82e8-60a44c33da09} - "G:\LGAutoRun.exe" HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\MountPoints2: {97430acb-fc88-11e4-849a-60a44c33da09} - "I:\FalloutLauncher.exe" HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\MountPoints2: {97430b2a-fc88-11e4-849a-60a44c33da09} - "J:\autorun.exe" HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\MountPoints2: {97430b53-fc88-11e4-849a-60a44c33da09} - "H:\setup.exe" HKU\S-1-5-21-1440869918-637336674-2589777491-1001\...\MountPoints2: {ce0b93f1-82d9-11e5-8578-60a44c33da09} - "E:\HTC_Sync_Manager_PC.exe" AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => Brak pliku AppInit_DLLs-x32: c:\progra~2\suptab\search~1.dll => Brak pliku ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-05] (AVAST Software) ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2013-01-17] (GG Network S.A.) Startup: C:\Users\Natalia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK [2015-08-21] ShortcutTarget: Registration Heroes of Might & Magic 5.LNK -> C:\Program Files (x86)\Ubisoft\Heroes of Might and Magic V Collector Edition\registration\RegistrationReminder.exe (Brak pliku) BootExecute: GroupPolicy: Ograniczenia - Chrome <======= UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 62.179.1.61 62.179.1.63 Tcpip\..\Interfaces\{66B9B5B4-D935-4F2D-9154-5F1276B4B8AC}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{A0F6D180-9C3C-47B7-9C14-BD73A96BE1F0}: [DhcpNameServer] 62.179.1.61 62.179.1.63 Tcpip\..\Interfaces\{A679E162-6E88-456B-8FF5-68F9BFCC3BDE}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{F61FAF85-3C5F-4242-9100-51C64E499394}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hppp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hppp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hppp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hppp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-1440869918-637336674-2589777491-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1429100351&from=cor&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362&q={searchTerms} HKU\S-1-5-21-1440869918-637336674-2589777491-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKU\S-1-5-21-1440869918-637336674-2589777491-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1429100351&from=cor&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362&q={searchTerms} HKU\S-1-5-21-1440869918-637336674-2589777491-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hppp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362 HKU\S-1-5-21-1440869918-637336674-2589777491-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hppp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1436004170&z=26e8c3fba88e796efb33bc5g9z7c0qee1e1zbg1q5b&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362&q={searchTerms} SearchScopes: HKU\S-1-5-21-1440869918-637336674-2589777491-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-1440869918-637336674-2589777491-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cornl&utm_campaign=install_ie&utm_content=ds&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362&ts=1436004179&type=default&q={searchTerms} BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-05] (AVAST Software) BHO-x32: Brak nazwy -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} -> Brak pliku BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-05] (Oracle Corporation) BHO-x32: Sale Charger -> {7a38e53c-e000-41e4-9b5a-47447db81c2b} -> C:\Program Files (x86)\Sale Charger\Extensions\7a38e53c-e000-41e4-9b5a-47447db81c2b.dll => Brak pliku BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-05] (AVAST Software) BHO-x32: Digital More -> {c0b1016f-b7e5-46f0-b415-6bf9e55ab00d} -> C:\Program Files (x86)\Digital More\Extensions\c0b1016f-b7e5-46f0-b415-6bf9e55ab00d.dll => Brak pliku BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-05] (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default FF DefaultSearchEngine: mystartsearch FF SelectedSearchEngine: mystartsearch FF Homepage: hxxp://www.mystartsearch.com/?type=hp&ts=1443865678&z=4372d6f78e54e349a3111b4g8z2zbc5beqdw4z4mcz&from=cornl&uid=WDCXWD15EVDS-63V9B1_WD-WMAVU427336273362 FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @graphisoft.com/GDL Web Plug-in -> C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll [2012-07-06] () FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-05] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems) FF Plugin HKU\S-1-5-21-1440869918-637336674-2589777491-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2012-12-07] (Ubisoft) FF SearchPlugin: C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\searchplugins\istartsurf.xml [2015-09-28] FF SearchPlugin: C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\searchplugins\mystartsearch.xml [2015-10-03] FF SearchPlugin: C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\searchplugins\sweet-page.xml [2015-07-01] FF Extension: Search Enginer - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\extensions\sweetsearch@gmail.com [2015-07-09] [Brak podpisu cyfrowego] FF Extension: Default SearchProtected - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\extensions\defsearchp@gmail.com [2015-10-03] [Brak podpisu cyfrowego] FF Extension: Sale Charger - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\Extensions\{85788c43-d871-40cf-9365-686173d382bb}.xpi [2015-05-17] [Brak podpisu cyfrowego] FF Extension: Adblock Plus - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-27] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-05] FF HKLM-x32\...\Firefox\Extensions: [sweetsearch@gmail.com] - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\extensions\sweetsearch@gmail.com FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\11qa77vw.default\extensions\defsearchp@gmail.com FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-05] Chrome: ======= CHR Profile: C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Default CHR Profile: C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Prezentacje Google) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-05] CHR Extension: (Dokumenty Google) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-05] CHR Extension: (Dysk Google) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-05] CHR Extension: (YouTube) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-05] CHR Extension: (Google Search) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-05] CHR Extension: (Arkusze Google) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-05] CHR Extension: (Dokumenty Google offline) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-05] CHR Extension: (Avast Online Security) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-12-05] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-05] CHR Extension: (Gmail) - C:\Users\Natalia\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-05] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-05] ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-05] (AVAST Software) S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1277680 2015-03-31] (Disc Soft Ltd) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-03] (NVIDIA Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-03] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-03] (NVIDIA Corporation) U2 ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [177704 2007-06-05] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation) S2 Update Solution Real; "C:\Program Files (x86)\Solution Real\updateSolutionReal.exe" [X] S2 Util Solution Real; "C:\Program Files (x86)\Solution Real\bin\utilSolutionReal.exe" [X] ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-05] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-05] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-05] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-05] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-05] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [450504 2015-12-05] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-05] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-05] (AVAST Software) R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.) R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30352 2015-05-17] (Disc Soft Ltd) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31136 2015-12-05] (REALiX(tm)) R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-03] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2015-05-28] (NVIDIA Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation) S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] S1 tcfd_vw_1_10_0_24; system32\drivers\tcfd_vw_1_10_0_24.sys [X] S1 wafd_1_10_0_19; system32\drivers\wafd_1_10_0_19.sys [X] U3 pfldqpow; \??\C:\Users\Natalia\AppData\Local\Temp\pfldqpow.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-05 14:29 - 2015-12-05 14:29 - 00022471 _____ C:\Users\Natalia\Desktop\FRST.txt 2015-12-05 13:25 - 2015-12-05 14:28 - 00008377 _____ C:\Users\Natalia\Desktop\GMER.txt 2015-12-05 13:09 - 2015-12-05 13:25 - 00016732 _____ C:\Windows\ntbtlog.txt 2015-12-05 13:05 - 2015-12-05 13:05 - 00002776 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-12-05 13:05 - 2015-12-05 13:05 - 00000794 _____ C:\Users\Public\Desktop\CCleaner.lnk 2015-12-05 13:05 - 2015-12-05 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-12-05 13:05 - 2015-12-05 13:05 - 00000000 ____D C:\Program Files\CCleaner 2015-12-05 12:46 - 2015-12-05 14:29 - 00000000 ____D C:\FRST 2015-12-05 12:46 - 2015-12-05 12:54 - 00000492 _____ C:\Users\Natalia\Desktop\Fixlog.txt 2015-12-05 12:43 - 2015-12-05 12:43 - 00001198 _____ C:\Users\Natalia\Desktop\CrystalDiskInfo.lnk 2015-12-05 12:43 - 2015-12-05 12:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2015-12-05 12:43 - 2015-12-05 12:43 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo 2015-12-05 12:42 - 2015-12-05 12:42 - 00031136 _____ (REALiX(tm)) C:\Windows\system32\Drivers\HWiNFO64A.SYS 2015-12-05 12:42 - 2015-12-05 12:42 - 00000938 _____ C:\Users\Natalia\Desktop\HD Tune.lnk 2015-12-05 12:42 - 2015-12-05 12:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune 2015-12-05 12:42 - 2015-12-05 12:42 - 00000000 ____D C:\Program Files (x86)\HD Tune 2015-12-05 12:41 - 2015-12-05 12:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64 2015-12-05 12:41 - 2015-12-05 12:41 - 00000000 ____D C:\Program Files\HWiNFO64 2015-12-05 12:38 - 2015-12-05 12:38 - 00000000 ____D C:\Windows\pss 2015-12-05 12:27 - 2015-12-05 12:27 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2015-12-05 12:27 - 2015-12-05 12:27 - 00000000 ____D C:\Program Files\Common Files\AV 2015-12-05 12:26 - 2015-12-05 12:26 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-12-05 12:26 - 2015-12-05 12:26 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-12-05 12:26 - 2015-12-05 12:26 - 00000000 _____ C:\Windows\system32\RENE0FE.tmp 2015-12-05 12:25 - 2015-12-05 12:25 - 00000000 ____D C:\Users\Natalia\AppData\Roaming\Sun 2015-12-05 12:25 - 2015-12-05 12:25 - 00000000 ____D C:\Users\Natalia\.oracle_jre_usage 2015-12-05 12:25 - 2015-04-15 13:20 - 00111016 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll 2015-12-05 12:23 - 2015-12-05 12:23 - 00000000 ____D C:\Users\Natalia\Desktop\spacesniffer_1_1_4_0 2015-12-05 12:23 - 2015-12-05 12:03 - 02369024 _____ (Farbar) C:\Users\Natalia\Desktop\FRST64.exe 2015-12-05 12:23 - 2015-12-05 12:03 - 00380416 _____ C:\Users\Natalia\Desktop\GMER.exe 2015-12-05 12:23 - 2015-12-05 11:48 - 00584288 _____ (Oracle Corporation) C:\Users\Natalia\Desktop\jxpiinstall.exe 2015-12-05 12:23 - 2015-11-07 17:57 - 03907296 _____ (Crystal Dew World ) C:\Users\Natalia\Desktop\Crystal.Disk.Info.6_5_2-en_AWD_OPERA_DELETE.exe 2015-12-05 12:23 - 2014-03-16 13:28 - 01614416 _____ (BitTorrent Inc.) C:\Users\Natalia\Desktop\utorrent_windows_ver3.4.30660.exe 2015-12-05 12:23 - 2014-03-16 13:12 - 04765152 _____ (Piriform Ltd) C:\Users\Natalia\Desktop\CCleaner_setup411_allwindows.exe 2015-12-05 12:23 - 2014-01-20 20:28 - 02374320 _____ (PeerBlock, LLC ) C:\Users\Natalia\Desktop\PeerBlock-Setup_v1.2_r693.exe 2015-12-05 12:23 - 2013-09-26 20:38 - 02930656 _____ (Martin Malík - REALiX ) C:\Users\Natalia\Desktop\HWiNFO_hw64_424.exe 2015-12-05 12:23 - 2013-09-23 19:48 - 00642632 _____ (EFD Software ) C:\Users\Natalia\Desktop\HDTune_255.exe 2015-12-05 12:19 - 2015-12-05 12:19 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2015-12-05 12:07 - 2015-12-05 12:07 - 00000000 ____D C:\Users\Natalia\Documents\AirDroid 2015-11-26 10:16 - 2015-11-26 10:16 - 00501450 _____ C:\Users\Natalia\Downloads\Kamila-opis.odt 2015-11-26 10:16 - 2015-11-26 10:16 - 00025942 _____ C:\Users\Natalia\Downloads\Tabela-inwentaryzacyjna-WZÓR.odt 2015-11-22 15:31 - 2015-11-22 15:31 - 00011428 _____ C:\Users\Natalia\Downloads\VEGE_bush_plan_007.dwg 2015-11-22 13:57 - 2015-11-22 13:57 - 00012099 _____ C:\Users\Natalia\Downloads\VEGE_tree_plan_147.dwg 2015-11-19 15:15 - 2015-11-19 15:19 - 19952196 _____ C:\Users\Natalia\Downloads\wetransfer-f0af45.zip 2015-11-18 18:05 - 2015-11-18 18:05 - 00052040 _____ C:\Users\Natalia\Downloads\lista nagozalązkowych.pdf 2015-11-18 17:56 - 2015-11-18 17:56 - 00614308 _____ C:\Users\Natalia\Downloads\ochrona_przyrody USTAWA nowa 08.2015.pdf 2015-11-18 17:56 - 2015-11-18 17:56 - 00279541 _____ C:\Users\Natalia\Downloads\Rozporządzenie w sprawie zakresu.pdf 2015-11-18 17:47 - 2015-11-18 17:47 - 12352293 _____ C:\Users\Natalia\Downloads\Katalogi_przekrojow_ulic_z_elementami_zieleni[1].pdf 2015-11-18 12:14 - 2015-11-18 12:15 - 00000000 ____D C:\ProgramData\Protexis64 2015-11-18 12:11 - 2015-11-18 12:11 - 00000000 ____D C:\Program Files\Common Files\Protexis 2015-11-18 12:08 - 2015-11-18 12:14 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X7 x64 2015-11-18 11:27 - 2015-11-18 11:30 - 548056128 _____ (Acresso Software Inc. ) C:\Users\Natalia\Downloads\CorelDRAWGraphicsSuiteX7Installer_PL64Bit (1).exe 2015-11-16 18:51 - 2015-11-16 18:55 - 548056128 _____ (Acresso Software Inc. ) C:\Users\Natalia\Downloads\CorelDRAWGraphicsSuiteX7Installer_PL64Bit.exe 2015-11-16 18:42 - 2015-11-19 18:33 - 00000000 ____D C:\Users\Natalia\AppData\Local\Corel 2015-11-16 18:42 - 2015-11-19 18:32 - 00000088 __RSH C:\Windows\SysWOW64\DB92BC2148.sys 2015-11-16 18:42 - 2015-11-16 18:42 - 00000000 ____D C:\Users\Natalia\Documents\Moje pokazy Corel Show 2015-11-16 18:41 - 2015-12-05 11:36 - 00000000 ____D C:\Users\Natalia\Documents\My PSP Files 2015-11-16 18:40 - 2015-11-16 18:40 - 00000000 ____D C:\Windows\SysWOW64\Spool 2015-11-16 18:35 - 2015-11-19 18:32 - 00002828 ___SH C:\Windows\SysWOW64\KGyGaAvL.sys 2015-11-16 17:08 - 2015-11-16 18:34 - 00000000 ____D C:\Users\Natalia\Downloads\Corel Paint Shop Pro Photo X2 v12.01 2015-11-15 22:57 - 2015-11-15 22:57 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008 2015-11-15 22:57 - 2015-11-15 22:57 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008 2015-11-15 21:43 - 2015-11-15 21:44 - 62302337 _____ C:\Users\Natalia\Downloads\inwentaryzacja.psd 2015-11-15 21:02 - 2015-11-15 21:02 - 64057751 _____ C:\Users\Natalia\Downloads\wetransfer-206f13.zip 2015-11-15 20:49 - 2015-11-15 20:49 - 00000000 ____D C:\Users\Natalia\Documents\My Palettes 2015-11-15 20:48 - 2015-12-05 11:35 - 00000000 ____D C:\Users\Natalia\AppData\Roaming\Corel 2015-11-15 20:48 - 2015-11-15 20:49 - 00000000 ____D C:\ProgramData\Protexis 2015-11-13 14:24 - 2015-11-18 12:16 - 00000000 ____D C:\Users\Natalia\Documents\Corel 2015-11-13 14:24 - 2015-11-13 14:24 - 00000000 ____D C:\Users\Natalia\Documents\Visual Studio 2008 2015-11-13 14:23 - 2015-11-13 14:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0 2015-11-13 14:23 - 2015-11-13 14:23 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2015-11-13 14:20 - 2015-11-15 20:56 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X5 2015-11-13 14:13 - 2015-12-05 11:41 - 00000000 ____D C:\ProgramData\Corel 2015-11-13 14:12 - 2015-11-16 17:07 - 00000000 ____D C:\Users\Natalia\AppData\LocalLow\BitTorrent 2015-11-13 14:12 - 2015-11-13 14:19 - 00000000 ____D C:\Users\Natalia\Downloads\Corel Draw graphic suite X5 with Keygen 2015-11-13 14:11 - 2015-12-05 11:35 - 00000000 ____D C:\Program Files\Corel 2015-11-13 14:08 - 2015-11-13 14:15 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X6 2015-11-13 14:07 - 2013-07-11 15:27 - 00000000 ____D C:\Users\Natalia\Downloads\Corel Draw X6 Pt-Br + Patch [By Destrap] 2015-11-13 13:58 - 2015-11-13 14:06 - 998890933 _____ C:\Users\Natalia\Downloads\Corel Draw X6 Pt-Br + Patch [By Destrap].rar 2015-11-11 14:46 - 2015-11-03 01:23 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-11-11 12:31 - 2015-10-13 16:59 - 00397224 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2015-11-11 12:31 - 2015-10-13 16:59 - 00340872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2015-11-11 12:31 - 2015-10-13 16:59 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-11-11 12:31 - 2015-10-13 16:59 - 00120376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-11-11 12:31 - 2015-10-13 16:59 - 00106952 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2015-11-11 12:31 - 2015-10-13 16:59 - 00091416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2015-11-11 12:31 - 2015-10-11 07:36 - 00561952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-11-11 12:31 - 2015-10-11 07:36 - 00177496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-11-11 12:31 - 2015-10-10 19:40 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-11-11 12:31 - 2015-10-10 19:39 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-11-11 12:31 - 2015-10-10 19:07 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-11-11 12:31 - 2015-10-10 18:33 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-11-11 12:31 - 2015-10-10 18:27 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-11-11 12:31 - 2015-10-10 18:11 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-11-11 12:31 - 2015-10-10 17:45 - 00359424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-11-11 12:31 - 2015-09-29 13:24 - 00155480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys 2015-11-11 12:30 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-11-11 12:30 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-11-11 12:30 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-11-11 12:30 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-11-11 12:30 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-11-11 12:30 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-11-11 12:30 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-11-11 12:30 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-11-11 12:30 - 2015-10-30 23:39 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-11-11 12:30 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-11-11 12:30 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-11-11 12:30 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-11-11 12:30 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-11-11 12:30 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-11-11 12:30 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-11-11 12:30 - 2015-10-30 23:14 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-11-11 12:30 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-11-11 12:30 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-11-11 12:30 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-11-11 12:30 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-11-11 12:30 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-11-11 12:30 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-11-11 12:30 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-11-11 12:30 - 2015-10-20 22:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-11-11 12:30 - 2015-10-20 15:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-11-11 12:30 - 2015-10-20 15:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-11-11 12:30 - 2015-10-20 15:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-11-11 12:30 - 2015-10-20 15:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2015-11-11 12:30 - 2015-10-20 15:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-11-11 12:30 - 2015-10-20 15:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-11-11 12:30 - 2015-10-20 15:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-11-11 12:30 - 2015-10-20 15:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-11-11 12:30 - 2015-10-20 15:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-11-11 12:30 - 2015-10-20 15:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-11-11 12:30 - 2015-10-20 15:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-11-11 12:30 - 2015-10-15 17:08 - 00990208 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-11-11 12:30 - 2015-10-15 16:46 - 00803328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-11-11 12:30 - 2015-10-15 00:02 - 07455064 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-11-11 12:30 - 2015-10-15 00:02 - 01659560 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-11-11 12:30 - 2015-10-15 00:02 - 01519592 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-11-11 12:30 - 2015-10-15 00:02 - 01487008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-11-11 12:30 - 2015-10-15 00:02 - 01355848 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-11-11 12:30 - 2015-10-13 18:10 - 00559616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2015-11-11 12:30 - 2015-10-13 18:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-11-11 12:30 - 2015-09-12 14:47 - 00414559 _____ C:\Windows\system32\ApnDatabase.xml 2015-11-11 12:30 - 2015-09-07 17:22 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll 2015-11-11 12:30 - 2015-09-07 16:54 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll 2015-11-11 12:30 - 2015-09-07 16:30 - 01091584 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2015-11-11 12:30 - 2015-09-04 20:24 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys 2015-11-11 12:30 - 2015-08-28 23:20 - 00183368 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe 2015-11-11 12:30 - 2015-08-20 21:45 - 01380048 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-11-11 12:30 - 2015-08-20 18:48 - 01096704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-11-11 12:27 - 2015-10-17 15:19 - 04176384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-11-11 12:27 - 2015-10-08 17:08 - 01083904 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2015-11-11 12:27 - 2015-08-10 19:15 - 00845312 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2015-11-11 12:27 - 2015-08-10 19:06 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2015-11-11 12:27 - 2015-08-10 18:49 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2015-11-11 12:27 - 2015-08-10 17:56 - 00272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2015-11-11 12:27 - 2015-08-10 17:46 - 00561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2015-11-08 18:44 - 2015-11-20 00:00 - 00000194 ____H C:\Users\Natalia\Documents\Rysunek2.dwl2 2015-11-08 18:44 - 2015-11-20 00:00 - 00000044 ____H C:\Users\Natalia\Documents\Rysunek2.dwl 2015-11-08 18:18 - 2015-11-08 18:18 - 00000000 ____D C:\Users\Natalia\Documents\Autodesk Application Manager 2015-11-08 18:07 - 2015-11-08 18:07 - 00000000 ____D C:\Users\Natalia\Documents\Inventor Server SDK ACAD 2016 2015-11-08 18:06 - 2015-11-08 18:06 - 00000133 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2015-11-08 17:25 - 2015-11-08 17:26 - 17198192 _____ C:\Users\Natalia\Downloads\AutoCAD_2016_Polish_Win_32_64bit_wi_pl-PL_Setup.exe 2015-11-08 17:25 - 2015-11-08 17:25 - 00337784 _____ (Autodesk Inc.) C:\Users\Natalia\Downloads\AutoCAD_2016_Polish_Win_32_64bit_wi_pl-PL_Setup_webinstall.exe 2015-11-08 15:30 - 2015-11-08 15:30 - 00000404 _____ C:\Windows\BRWMARK.INI 2015-11-06 08:01 - 2015-11-06 08:01 - 00100067 _____ C:\Users\Natalia\Downloads\wycinka.pdf 2015-11-06 00:49 - 2015-11-06 00:49 - 00173584 _____ C:\Users\Natalia\Downloads\family20.psd 2015-11-05 23:11 - 2015-11-06 01:00 - 01183662 _____ C:\Users\Natalia\Documents\analiza uzytkownikow.pptx 2015-11-05 22:09 - 2015-11-05 22:09 - 10927639 _____ C:\Users\Natalia\Downloads\Podwórze-na-Przedmieściu-Oławskim (1).pptx 2015-11-05 22:07 - 2015-11-05 22:07 - 00540503 _____ C:\Users\Natalia\Downloads\inwentaryzacja-tabela.pdf 2015-11-05 12:04 - 2015-11-05 12:04 - 00685561 _____ C:\Users\Natalia\Downloads\opis bipoak.odt 2015-11-05 10:27 - 2015-11-05 10:27 - 00000000 ____D C:\Users\Natalia\AppData\Local\Blizzard 2015-11-05 10:26 - 2015-11-05 10:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2015-11-05 10:18 - 2015-11-11 12:34 - 00000000 ____D C:\Program Files (x86)\Hearthstone 2015-11-05 10:16 - 2015-11-25 19:23 - 00000000 ____D C:\Users\Natalia\AppData\Local\Battle.net 2015-11-05 10:16 - 2015-11-05 10:18 - 00000000 ____D C:\Users\Natalia\AppData\Roaming\Battle.net 2015-11-05 10:16 - 2015-11-05 10:16 - 00000000 ____D C:\Users\Natalia\AppData\Local\Blizzard Entertainment 2015-11-05 10:16 - 2015-11-05 10:16 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2015-11-05 10:15 - 2015-12-05 11:29 - 00000000 ____D C:\ProgramData\Battle.net ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-05 13:54 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf 2015-12-05 13:48 - 2015-04-17 20:07 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-05 13:35 - 2014-03-21 19:40 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1440869918-637336674-2589777491-1001 2015-12-05 13:12 - 2015-04-17 20:07 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-05 13:10 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-05 13:10 - 2013-08-22 14:36 - 00000000 ____D C:\Windows 2015-12-05 13:09 - 2014-03-21 19:58 - 00000000 ____D C:\ProgramData\NVIDIA 2015-12-05 13:08 - 2015-06-04 22:53 - 00000000 ____D C:\Windows\Minidump 2015-12-05 13:08 - 2014-11-11 23:10 - 00000000 ____D C:\Users\Natalia\AppData\Roaming\DAEMON Tools Lite 2015-12-05 13:08 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\ModemLogs 2015-12-05 13:08 - 2013-08-22 10:10 - 00000000 ____D C:\Windows\Panther 2015-12-05 13:02 - 2014-06-22 16:19 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-12-05 12:57 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI 2015-12-05 12:46 - 2015-01-03 19:41 - 00000000 ____D C:\Users\Natalia\AppData\LocalLow\Temp 2015-12-05 12:43 - 2015-04-17 20:07 - 00004044 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-12-05 12:43 - 2015-04-17 20:07 - 00003808 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-12-05 12:27 - 2015-07-26 11:37 - 00000000 ____D C:\Program Files (x86)\Java 2015-12-05 12:27 - 2014-04-13 17:10 - 00000000 ____D C:\ProgramData\Oracle 2015-12-05 12:26 - 2015-01-19 23:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-12-05 12:26 - 2014-06-22 16:19 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2015-12-05 12:26 - 2014-06-22 16:19 - 00450504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-12-05 12:26 - 2014-06-22 16:19 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2015-12-05 12:26 - 2014-06-22 16:19 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-12-05 12:26 - 2014-06-22 16:19 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-12-05 12:26 - 2014-06-22 16:19 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-12-05 12:26 - 2014-06-22 16:19 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2015-12-05 12:26 - 2014-06-22 16:19 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2015-12-05 12:26 - 2014-03-21 19:39 - 01825074 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-05 12:26 - 2013-08-23 00:12 - 00805918 _____ C:\Windows\system32\perfh015.dat 2015-12-05 12:26 - 2013-08-23 00:12 - 00163272 _____ C:\Windows\system32\perfc015.dat 2015-12-05 12:25 - 2015-07-27 09:35 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-12-05 12:25 - 2013-08-22 09:16 - 00000000 ____D C:\Users\Natalia 2015-12-05 12:18 - 2015-10-09 19:28 - 00000000 ____D C:\Program Files (x86)\Shure 2015-12-05 12:17 - 2014-03-21 21:13 - 00000000 ____D C:\Program Files\Autodesk 2015-12-05 12:17 - 2014-03-21 20:32 - 00000000 ____D C:\ProgramData\Autodesk 2015-12-05 12:16 - 2014-04-02 18:46 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2015-12-05 12:07 - 2015-05-26 08:48 - 00000000 ____D C:\Program Files (x86)\AirDroid 2015-12-05 12:02 - 2013-08-22 15:44 - 05243112 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-05 12:00 - 2014-04-02 18:45 - 00000000 ____D C:\Program Files (x86)\Autodesk 2015-12-05 11:58 - 2014-07-26 19:53 - 00000952 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1440869918-637336674-2589777491-1001UA.job 2015-12-05 11:58 - 2014-03-21 23:32 - 00000000 ____D C:\Users\Natalia\Documents\3dsMax 2015-12-05 11:51 - 2013-08-22 16:36 - 00000000 ___SD C:\Windows\Downloaded Program Files 2015-12-05 11:45 - 2014-06-25 21:33 - 00000000 ____D C:\Users\Natalia\AppData\Roaming\Autodesk 2015-12-05 11:41 - 2014-04-22 12:10 - 00000000 ____D C:\Users\Natalia\AppData\Local\GG 2015-12-05 11:35 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2015-12-05 11:26 - 2014-11-24 23:43 - 00000000 ____D C:\Users\Natalia\AppData\Local\Adobe 2015-11-26 22:45 - 2014-03-26 09:10 - 00000364 _____ C:\Windows\Tasks\bench-sys.job 2015-11-24 20:58 - 2014-07-26 19:53 - 00000930 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1440869918-637336674-2589777491-1001Core.job 2015-11-21 10:13 - 2014-04-15 22:08 - 00000000 ____D C:\Users\Natalia\AppData\Local\ElevatedDiagnostics 2015-11-18 18:00 - 2014-07-02 15:22 - 00000479 _____ C:\Users\Natalia\AppData\Roaming\burnaware.ini 2015-11-18 12:12 - 2014-11-26 17:39 - 00000000 ____D C:\ProgramData\Package Cache 2015-11-15 22:57 - 2014-04-07 05:39 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-11-12 11:54 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache 2015-11-11 14:30 - 2013-08-22 16:36 - 00000000 ___RD C:\Windows\ToastData 2015-11-11 14:29 - 2013-08-22 16:20 - 00000000 ____D C:\Windows\CbsTemp 2015-11-11 12:42 - 2014-03-21 21:35 - 00000000 ____D C:\Windows\system32\MRT 2015-11-11 12:36 - 2014-03-21 21:35 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-11-08 18:25 - 2014-03-21 21:14 - 00000000 ____D C:\Users\Natalia\AppData\Local\Autodesk 2015-11-08 17:26 - 2014-03-21 20:27 - 00000000 ____D C:\Autodesk 2015-11-08 16:57 - 2014-03-22 08:16 - 00000000 ____D C:\Users\Natalia\AppData\Local\cache 2015-11-06 14:46 - 2015-10-15 22:47 - 00000000 ____D C:\Users\Natalia\Desktop\studia 2015-11-05 22:05 - 2015-02-09 15:48 - 00000000 ____D C:\Users\Natalia\Desktop\dokumenty 2015-11-05 21:47 - 2014-07-24 16:31 - 00000000 ____D C:\Users\Natalia\AppData\Local\Windows Live 2015-11-05 21:09 - 2015-08-24 19:53 - 00000000 ____D C:\Users\Natalia\AppData\Roaming\Might & Magic Heroes VI ==================== Pliki w katalogu głównym wybranych folderów ======= 2014-07-02 15:22 - 2015-11-18 18:00 - 0000479 _____ () C:\Users\Natalia\AppData\Roaming\burnaware.ini 2015-11-04 22:59 - 2015-11-04 23:00 - 225111747 _____ () C:\Users\Natalia\AppData\Local\ACCCx3_3_0_151.zip 2015-05-26 16:20 - 2015-05-26 16:20 - 0001496 _____ () C:\Users\Natalia\AppData\Local\Adobe Zapisz dla Internetu 13.0 Prefs 2014-12-30 13:43 - 2014-12-30 13:46 - 0000336 _____ () C:\ProgramData\hpzinstall.log 2014-03-21 21:15 - 2014-03-21 21:15 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2015-11-08 18:06 - 2015-11-08 18:06 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2015-12-05 13:53 ==================== Koniec FRST.txt ============================