Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:16-12-2015 01 Uruchomiony przez Krzysztof (administrator) KOMPUTER (16-12-2015 14:18:03) Uruchomiony z C:\Users\Krzysztof\Desktop\FRST Załadowane profile: Krzysztof (Dostępne profile: Krzysztof) Platform: Windows 7 Professional Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 8 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Google Inc.) C:\Users\Krzysztof\AppData\Local\Google\Update\1.3.29.1\GoogleCrashHandler.exe (Google Inc.) C:\Users\Krzysztof\AppData\Local\Google\Update\1.3.29.1\GoogleCrashHandler64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-06] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-10-06] (Oracle Corporation) HKLM Group Policy restriction on software: *.zip*.js <====== UWAGA HKLM Group Policy restriction on software: *.wav*.com <====== UWAGA HKLM Group Policy restriction on software: *.pub*.jse <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.scr <====== UWAGA HKLM Group Policy restriction on software: *.docx*.exe <====== UWAGA HKLM Group Policy restriction on software: *.avi*.exe <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.wma*.scr <====== UWAGA HKLM Group Policy restriction on software: *.wma*.exe <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.js <====== UWAGA HKLM Group Policy restriction on software: *.gif*.scr <====== UWAGA HKLM Group Policy restriction on software: C:\Users\*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <====== UWAGA HKLM Group Policy restriction on software: *.gif*.exe <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.divx*.cmd <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.js <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.bat <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.divx*.jse <====== UWAGA HKLM Group Policy restriction on software: *.divx*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.exe <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.jse <====== UWAGA HKLM Group Policy restriction on software: *.doc*.com <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.bat <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.js <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.exe <====== UWAGA HKLM Group Policy restriction on software: *.zip*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.com <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.pif <====== UWAGA HKLM Group Policy restriction on software: *.png*.cmd <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.js <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== UWAGA HKLM Group Policy restriction on software: *.avi*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.pif <====== UWAGA HKLM Group Policy restriction on software: *.divx*.com <====== UWAGA HKLM Group Policy restriction on software: vssadmin.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <====== UWAGA HKLM Group Policy restriction on software: C:\Users\*.bat <====== UWAGA HKLM Group Policy restriction on software: C:\Users\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.pub*.scr <====== UWAGA HKLM Group Policy restriction on software: *.7z*.pif <====== UWAGA HKLM Group Policy restriction on software: *.docx*.bat <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.avi*.pif <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.bat <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.com <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.com <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.scr <====== UWAGA HKLM Group Policy restriction on software: *.pub*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.wav*.jse <====== UWAGA HKLM Group Policy restriction on software: *.7z*.scr <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.7z*.bat <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.js <====== UWAGA HKLM Group Policy restriction on software: *.png*.bat <====== UWAGA HKLM Group Policy restriction on software: *.rar*.cmd <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== UWAGA HKLM Group Policy restriction on software: C:\Users\*.scr <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.gif*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.txt*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.com <====== UWAGA HKLM Group Policy restriction on software: C:\Users\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.pif <====== UWAGA HKLM Group Policy restriction on software: scsvserv.exe <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.docx*.js <====== UWAGA HKLM Group Policy restriction on software: *.gif*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== UWAGA HKLM Group Policy restriction on software: *.zip*.scr <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.com <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.scr <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== UWAGA HKLM Group Policy restriction on software: *.xls*.pif <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.xls*.js <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.scr <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.rar*.exe <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.com <====== UWAGA HKLM Group Policy restriction on software: *.docx*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.com <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.com <====== UWAGA HKLM Group Policy restriction on software: syskey.exe <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.png*.js <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.wma*.com <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.scr <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.js <====== UWAGA HKLM Group Policy restriction on software: cipher.exe <====== UWAGA HKLM Group Policy restriction on software: *.xls*.bat <====== UWAGA HKLM Group Policy restriction on software: *.rar*.js <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.js <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.bat <====== UWAGA HKLM Group Policy restriction on software: *.rar*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.js <====== UWAGA HKLM Group Policy restriction on software: *.wav*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.zip*.jse <====== UWAGA HKLM Group Policy restriction on software: *.doc*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.txt*.bat <====== UWAGA HKLM Group Policy restriction on software: *.zip*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.gif*.js <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.js <====== UWAGA HKLM Group Policy restriction on software: ** <====== UWAGA HKLM Group Policy restriction on software: *.doc*.pif <====== UWAGA HKLM Group Policy restriction on software: *.png*.scr <====== UWAGA HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <====== UWAGA HKLM Group Policy restriction on software: *.xls*.exe <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.jse <====== UWAGA HKLM Group Policy restriction on software: *.xls*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.txt*.com <====== UWAGA HKLM Group Policy restriction on software: *.txt*.scr <====== UWAGA HKLM Group Policy restriction on software: *.7z*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.gif*.com <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.com <====== UWAGA HKLM Group Policy restriction on software: *.wma*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.gif*.bat <====== UWAGA HKLM Group Policy restriction on software: *.gif*.pif <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.scr <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.docx*.com <====== UWAGA HKLM Group Policy restriction on software: *.7z*.com <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.jse <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.png*.jse <====== UWAGA HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== UWAGA HKLM Group Policy restriction on software: *.rar*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <====== UWAGA HKLM Group Policy restriction on software: *.wma*.jse <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.divx*.js <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.pif <====== UWAGA HKLM Group Policy restriction on software: *.png*.com <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.bat <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.js <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.exe <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.pif <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.scr <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.pif <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.wav*.pif <====== UWAGA HKLM Group Policy restriction on software: *.wav*.exe <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.exe <====== UWAGA HKLM Group Policy restriction on software: *.doc*.jse <====== UWAGA HKLM Group Policy restriction on software: *.avi*.scr <====== UWAGA HKLM Group Policy restriction on software: C:\Users\*.js <====== UWAGA HKLM Group Policy restriction on software: *.avi*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.wma*.bat <====== UWAGA HKLM Group Policy restriction on software: *.png*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.com <====== UWAGA HKLM Group Policy restriction on software: *.rar*.pif <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.scr <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.pub*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.docx*.jse <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.com <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.bat <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.scr <====== UWAGA HKLM Group Policy restriction on software: *.txt*.exe <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== UWAGA HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== UWAGA HKLM Group Policy restriction on software: *.xls*.com <====== UWAGA HKLM Group Policy restriction on software: *.avi*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.exe <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.com <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.js <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.exe <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.doc*.js <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== UWAGA HKLM Group Policy restriction on software: *.rar*.com <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <====== UWAGA HKLM Group Policy restriction on software: *.doc*.exe <====== UWAGA HKLM Group Policy restriction on software: *.avi*.com <====== UWAGA HKLM Group Policy restriction on software: *.divx*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.7z*.exe <====== UWAGA HKLM Group Policy restriction on software: *.divx*.exe <====== UWAGA HKLM Group Policy restriction on software: *.doc*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.doc*.scr <====== UWAGA HKLM Group Policy restriction on software: *:\$Recycle.Bin <====== UWAGA HKLM Group Policy restriction on software: *.divx*.scr <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <====== UWAGA HKLM Group Policy restriction on software: *.avi*.cmd <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== UWAGA HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <====== UWAGA HKLM Group Policy restriction on software: *.zip*.com <====== UWAGA HKLM Group Policy restriction on software: %programdata%\*.cmd <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <====== UWAGA HKLM Group Policy restriction on software: *.pub*.com <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.exe <====== UWAGA HKLM Group Policy restriction on software: *.jpg*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.wmv*.jse <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.xls*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.pub*.js <====== UWAGA HKLM Group Policy restriction on software: *.7z*.jse <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.com <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.scr <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.bat <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== UWAGA HKLM Group Policy restriction on software: C:\Users\*.cmd <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.wma*.pif <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.com <====== UWAGA HKLM Group Policy restriction on software: *.txt*.js <====== UWAGA HKLM Group Policy restriction on software: *.wav*.scr <====== UWAGA HKLM Group Policy restriction on software: *.xls*.scr <====== UWAGA HKLM Group Policy restriction on software: lsassw86s.exe <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.jse <====== UWAGA HKLM Group Policy restriction on software: *.bmp*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <====== UWAGA HKLM Group Policy restriction on software: *.pub*.bat <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <====== UWAGA HKLM Group Policy restriction on software: *.7z*.js <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.jse <====== UWAGA HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.jse <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== UWAGA HKLM Group Policy restriction on software: %appdata%\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.zip*.pif <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.exe <====== UWAGA HKLM Group Policy restriction on software: *.docx*.scr <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <====== UWAGA HKLM Group Policy restriction on software: *.rtf*.pif <====== UWAGA HKLM Group Policy restriction on software: *.txt*.pif <====== UWAGA HKLM Group Policy restriction on software: %userprofile%\*.scr <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.com <====== UWAGA HKLM Group Policy restriction on software: *.mp3*.pif <====== UWAGA HKLM Group Policy restriction on software: *.jpeg*.scr <====== UWAGA HKLM Group Policy restriction on software: *.zip*.exe <====== UWAGA HKLM Group Policy restriction on software: *.wma*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.jse <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.pif <====== UWAGA HKLM Group Policy restriction on software: *.rar*.scr <====== UWAGA HKLM Group Policy restriction on software: *.png*.pif <====== UWAGA HKLM Group Policy restriction on software: *.ppt*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.wav*.js <====== UWAGA HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== UWAGA HKLM Group Policy restriction on software: *.pub*.pif <====== UWAGA HKLM Group Policy restriction on software: *.docx*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.pdf*.js <====== UWAGA HKLM Group Policy restriction on software: *.mp4*.exe <====== UWAGA HKLM Group Policy restriction on software: *.txt*.jse <====== UWAGA HKLM Group Policy restriction on software: *.pptx*.cmd <====== UWAGA HKLM Group Policy restriction on software: *.wav*.bat <====== UWAGA HKLM Group Policy restriction on software: *.xlsx*.exe <====== UWAGA HKU\S-1-5-21-270605537-1721649966-1895909746-1000\...\Run: [Google Update] => C:\Users\Krzysztof\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-10-17] (Google Inc.) HKU\S-1-5-21-270605537-1721649966-1895909746-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd) HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2015-10-21] (Microsoft Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-17] (AVAST Software) GroupPolicy: Ograniczenia - Chrome <======= UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0 Tcpip\..\Interfaces\{CFF3EA23-8868-47A1-B8B4-F9A9E9D95F04}: [DhcpNameServer] 192.168.1.1 0.0.0.0 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130944528556762000&GUID=00000000-0000-0000-0000-000000000000 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ4IA1wVQw0TbQENVF1cFQEadhQBUVtDDA1HcloNUAFDFQcVIR9aFQQTSEcFME0FCFwEURNNfWpdAEsSSX5NL04=&q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ4IA1wVQw0TbQENVF1cFQEadhQBUVtDDA1HcloNUAFDFQcVIR9aFQQTSEcFME0FCFwEURNNfXRZD0AjREZWLE1LKUwT&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ4IA1wVQw0TbQENVF1cFQEadhQBUVtDDA1HcloNUAFDFQcVIR9aFQQTSEcFME0FCFwEURNNfWpdAEsSSX5NL04=&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-270605537-1721649966-1895909746-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-10-17] (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-15] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-10-17] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-15] (Oracle Corporation) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default FF Homepage: google.pl FF Session Restore: -> [funkcja włączona] FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-15] (Oracle Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-270605537-1721649966-1895909746-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Krzysztof\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.) FF Plugin HKU\S-1-5-21-270605537-1721649966-1895909746-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Krzysztof\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.) FF SearchPlugin: C:\Users\Krzysztof\AppData\Roaming\Mozilla\Firefox\Profiles\7mrh4r8a.default\searchplugins\google-default.xml [2015-10-17] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10] Chrome: ======= CHR Profile: C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Prezentacje Google) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-14] CHR Extension: (Dokumenty Google) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-14] CHR Extension: (Dysk Google) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-14] CHR Extension: (YouTube) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-14] CHR Extension: (Google Search) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-14] CHR Extension: (Arkusze Google) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-14] CHR Extension: (Dokumenty Google offline) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-14] CHR Extension: (Avast Online Security) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-12-14] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-14] CHR Extension: (Gmail) - C:\Users\Krzysztof\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-14] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-10-17] ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-17] (AVAST Software) S2 MustangService_2015_10_10; C:\ProgramData\TempMoudleSet\MustangSer2241.exe [236816 2015-10-09] (MustangService) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-17] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-17] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-17] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-17] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-06] (AVAST Software) S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-17] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-17] (AVAST Software) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org) S3 ALSysIO; \??\C:\Users\KRZYSZ~1\AppData\Local\Temp\ALSysIO64.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-16 14:15 - 2015-12-16 14:18 - 00000000 ____D C:\FRST 2015-12-16 14:13 - 2015-12-16 14:18 - 00000000 ____D C:\Users\Krzysztof\Desktop\FRST 2015-12-16 14:13 - 2015-12-16 14:13 - 00000000 ____D C:\Users\Krzysztof\Desktop\GMER 2015-12-15 16:27 - 2015-12-15 16:27 - 00053248 _____ C:\Windows\SysWOW64\zlib.dll 2015-12-15 16:27 - 2015-12-15 16:27 - 00001212 _____ C:\Users\Public\Desktop\CryptoPrevent.lnk 2015-12-15 16:27 - 2015-12-15 16:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT 2015-12-15 16:27 - 2015-12-15 16:27 - 00000000 ____D C:\ProgramData\Foolish IT 2015-12-15 16:27 - 2015-12-15 16:27 - 00000000 ____D C:\Program Files (x86)\Foolish IT 2015-12-14 16:04 - 2015-12-14 16:04 - 00000000 ____D C:\Users\Krzysztof\AppData\Local\Rockstar Games 2015-12-14 15:50 - 2015-12-14 15:50 - 00000000 __SHD C:\ProgramData\SecuROM 2015-12-14 15:31 - 2015-12-15 22:18 - 00000000 ____D C:\AdwCleaner 2015-12-14 15:31 - 2015-12-14 15:32 - 02953520 _____ (AVAST Software) C:\Users\Krzysztof\Downloads\avast-browser-cleanup.exe 2015-12-14 15:29 - 2015-12-14 15:29 - 01740288 _____ C:\Users\Krzysztof\Downloads\adwcleaner_5.025.exe 2015-12-14 15:24 - 2015-12-14 15:24 - 01740288 _____ C:\Users\Krzysztof\Downloads\AE95.tmp 2015-12-14 14:49 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2015-12-14 14:49 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2015-12-14 14:49 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2015-12-14 14:47 - 2015-12-14 14:47 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll 2015-12-14 14:37 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2015-12-14 14:37 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2015-12-14 14:37 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2015-12-14 14:37 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2015-12-14 14:37 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2015-12-14 14:37 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2015-12-14 14:37 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2015-12-14 14:37 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2015-12-14 14:37 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2015-12-14 14:37 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2015-12-14 14:37 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2015-12-14 14:37 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2015-12-14 14:37 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2015-12-14 14:37 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2015-12-14 14:37 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2015-12-14 14:37 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2015-12-14 14:37 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2015-12-14 14:37 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2015-12-14 14:37 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2015-12-14 14:37 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2015-12-14 14:37 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2015-12-14 14:37 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2015-12-14 14:37 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2015-12-14 14:37 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2015-12-14 14:37 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2015-12-14 14:37 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2015-12-14 14:37 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2015-12-14 14:37 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2015-12-14 14:37 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2015-12-14 14:37 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2015-12-14 14:37 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2015-12-14 14:37 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2015-12-14 14:37 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2015-12-14 14:37 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2015-12-14 14:37 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2015-12-14 14:37 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2015-12-14 14:37 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2015-12-14 14:37 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2015-12-14 14:37 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2015-12-14 14:37 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2015-12-14 14:37 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2015-12-14 14:37 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2015-12-14 14:37 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2015-12-14 14:37 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2015-12-14 14:37 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2015-12-14 14:37 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2015-12-14 14:37 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2015-12-14 14:37 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2015-12-14 14:37 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2015-12-14 14:37 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2015-12-14 14:37 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2015-12-14 14:37 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2015-12-14 14:37 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2015-12-14 14:37 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2015-12-14 14:37 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2015-12-14 14:37 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2015-12-14 14:37 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2015-12-14 14:37 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2015-12-14 14:37 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2015-12-14 14:37 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2015-12-14 14:37 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2015-12-14 14:37 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2015-12-14 14:37 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2015-12-14 14:37 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2015-12-14 14:37 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2015-12-14 14:37 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2015-12-14 14:37 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2015-12-14 14:37 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2015-12-14 14:37 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2015-12-14 14:37 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2015-12-14 14:37 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2015-12-14 14:37 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2015-12-14 14:37 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2015-12-14 14:37 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2015-12-14 14:37 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2015-12-14 14:37 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2015-12-14 14:37 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2015-12-14 14:37 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2015-12-14 14:36 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2015-12-14 14:36 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2015-12-14 14:36 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2015-12-14 14:36 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2015-12-14 14:36 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2015-12-14 14:36 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2015-12-14 14:36 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2015-12-14 14:36 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2015-12-14 14:36 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2015-12-14 14:36 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2015-12-14 14:36 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2015-12-14 14:36 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2015-12-14 14:36 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2015-12-14 14:36 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2015-12-14 14:36 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2015-12-14 14:36 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2015-12-14 14:36 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2015-12-14 14:36 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2015-12-14 14:36 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2015-12-14 14:36 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2015-12-14 14:36 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2015-12-14 14:36 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2015-12-14 14:35 - 2015-12-14 14:35 - 00000000 ____D C:\Windows\SysWOW64\xlive 2015-12-14 14:35 - 2015-12-14 14:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2015-12-14 14:35 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2015-12-14 14:35 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2015-12-14 14:35 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2015-12-14 14:31 - 2015-12-14 14:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games 2015-12-14 13:44 - 2015-12-14 13:44 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2015-12-14 13:42 - 2015-12-14 13:54 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\DAEMON Tools Lite 2015-12-14 13:42 - 2015-12-14 13:42 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite 2015-12-05 13:38 - 2015-12-14 14:44 - 00000000 ____D C:\ProgramData\9a4b8b26-f4e0-4529-a5b4-93ec828f7e42 2015-12-05 13:38 - 2015-12-05 13:38 - 04208656 _____ (Piriform Ltd) C:\Users\Krzysztof\Downloads\dfsetup216.exe 2015-12-05 13:31 - 2015-12-05 13:34 - 00000000 ____D C:\Users\Krzysztof\Desktop\Floris pliki przed zmianą 2015-12-03 15:19 - 2015-12-03 15:19 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2015-12-03 15:19 - 2015-12-03 15:19 - 00000000 ____D C:\Program Files\Common Files\AV 2015-11-24 14:38 - 2015-11-24 14:36 - 00002107 _____ C:\Users\Krzysztof\Desktop\rgl_config.txt 2015-11-19 16:11 - 2015-11-19 22:56 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\Mount&Blade Warband 2015-11-19 16:10 - 2015-11-19 16:10 - 00000819 _____ C:\Users\Krzysztof\Desktop\Mount&Blade Warband.lnk 2015-11-19 16:10 - 2015-11-19 16:10 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mount&Blade Warband 2015-11-19 16:10 - 2015-11-19 16:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mount&Blade Warband 2015-11-19 16:09 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2015-11-19 16:09 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2015-11-19 16:09 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2015-11-19 16:09 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2015-11-18 21:00 - 2015-11-18 21:00 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\Adobe 2015-11-18 21:00 - 2015-11-18 21:00 - 00000000 ____D C:\Users\Krzysztof\AppData\LocalLow\Adobe 2015-11-18 21:00 - 2015-11-18 21:00 - 00000000 ____D C:\Users\Krzysztof\AppData\Local\CEF 2015-11-18 19:14 - 2015-11-18 19:14 - 00000905 _____ C:\ProgramData\Microsoft\Windows\Start Menu\µTorrent.lnk 2015-11-18 19:14 - 2015-11-18 19:14 - 00000881 _____ C:\Users\Public\Desktop\µTorrent.lnk 2015-11-18 19:13 - 2015-12-13 19:30 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\uTorrent 2015-11-18 16:34 - 2015-11-18 16:34 - 00000862 _____ C:\Users\Krzysztof\Desktop\Europa Universalis IV.lnk 2015-11-18 14:07 - 2015-11-18 14:07 - 00000835 _____ C:\Users\Krzysztof\Desktop\Victoria II.lnk 2015-11-18 14:07 - 2015-11-18 14:07 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Victotria II 2015-11-18 13:51 - 2015-12-15 15:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-11-18 13:51 - 2015-12-15 15:13 - 00000000 ____D C:\Program Files (x86)\7-Zip ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-16 14:15 - 2009-07-14 04:20 - 00000000 ____D C:\Windows 2015-12-16 13:43 - 2009-07-14 05:45 - 00016704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-12-16 13:43 - 2009-07-14 05:45 - 00016704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-12-16 13:37 - 2015-11-07 14:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-12-16 13:36 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-16 13:26 - 2015-10-17 15:09 - 00001074 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-270605537-1721649966-1895909746-1000UA.job 2015-12-16 13:26 - 2015-10-17 15:09 - 00001022 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-270605537-1721649966-1895909746-1000Core.job 2015-12-15 17:22 - 2015-10-17 15:47 - 00001090 __RSH C:\ProgramData\ntuser.pol 2015-12-15 15:27 - 2015-10-17 14:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-12-15 15:27 - 2015-10-17 14:40 - 00000000 ____D C:\Program Files (x86)\Java 2015-12-15 14:56 - 2015-10-17 14:41 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-12-15 14:56 - 2015-10-17 14:41 - 00000000 ____D C:\Users\Krzysztof\.oracle_jre_usage 2015-12-14 15:44 - 2015-10-17 14:17 - 00001555 _____ C:\Users\Krzysztof\Desktop\Google Chrome.lnk 2015-12-14 15:41 - 2015-10-17 14:27 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-12-14 15:34 - 2015-10-17 14:28 - 00001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-12-14 15:34 - 2015-10-17 14:28 - 00001049 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-12-14 15:34 - 2015-10-17 14:17 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-12-14 14:31 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-12-14 13:58 - 2015-10-17 12:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2015-12-14 13:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2015-12-06 12:40 - 2006-12-31 23:44 - 00060584 _____ C:\Users\Krzysztof\AppData\Local\GDIPFONTCACHEV1.DAT 2015-12-05 13:37 - 2015-10-17 18:50 - 00000000 ____D C:\Users\Krzysztof\AppData\Roaming\TS3Client 2015-12-05 13:22 - 2009-07-14 18:55 - 00697674 _____ C:\Windows\system32\perfh015.dat 2015-12-05 13:22 - 2009-07-14 18:55 - 00134784 _____ C:\Windows\system32\perfc015.dat 2015-12-05 13:22 - 2009-07-14 06:13 - 01549696 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-04 13:21 - 2015-10-17 15:09 - 00004052 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-270605537-1721649966-1895909746-1000UA 2015-12-04 13:21 - 2015-10-17 15:09 - 00003656 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-270605537-1721649966-1895909746-1000Core 2015-12-02 13:18 - 2015-10-17 14:27 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-11-26 22:16 - 2015-10-20 07:09 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-11-19 10:56 - 2009-07-14 05:45 - 00284504 _____ C:\Windows\system32\FNTCACHE.DAT 2015-11-18 21:00 - 2015-10-20 07:05 - 00000000 ____D C:\Users\Krzysztof\AppData\Local\Adobe 2015-11-18 16:19 - 2015-10-17 12:27 - 00000000 ____D C:\Users\Krzysztof Niektóre pliki w TEMP: ==================== C:\Users\Krzysztof\AppData\Local\Temp\{0B33B27D-1FC4-4A57-9C68-C903E5E7467F}.dll C:\Users\Krzysztof\AppData\Local\Temp\{1409E484-6349-4CBA-AB61-B7700E806AAF}.dll C:\Users\Krzysztof\AppData\Local\Temp\{1E9C0924-5933-4E8F-AF3A-FECA1C38B326}.dll C:\Users\Krzysztof\AppData\Local\Temp\{1F1C818D-AA2B-4955-83C5-4BDE1B03F1F8}.dll C:\Users\Krzysztof\AppData\Local\Temp\{230D322C-E6E1-4485-B436-142F8F3F6BE8}.dll C:\Users\Krzysztof\AppData\Local\Temp\{259DF0DF-2B6E-4616-8FB4-F2829AE255C7}.dll C:\Users\Krzysztof\AppData\Local\Temp\{30949039-6A44-4146-81C9-B0B5AD20A5C3}.dll C:\Users\Krzysztof\AppData\Local\Temp\{364502D6-3109-4861-A38F-2451AB3FF8D2}.dll C:\Users\Krzysztof\AppData\Local\Temp\{3B4BE628-746A-458B-8034-2255C333F082}.dll C:\Users\Krzysztof\AppData\Local\Temp\{3B9BDD27-2CAD-43CC-A3FF-2BE4E2F1C900}.dll C:\Users\Krzysztof\AppData\Local\Temp\{4824187D-6AE1-4140-877B-96C846125818}.dll C:\Users\Krzysztof\AppData\Local\Temp\{4ECB5012-31F8-4521-957A-C4499E6EB83D}.dll C:\Users\Krzysztof\AppData\Local\Temp\{5452B55F-2DBC-485B-85BA-98ADB3CFF689}.dll C:\Users\Krzysztof\AppData\Local\Temp\{5DE0A18E-CECD-4FD2-883F-55D0F334AE2D}.dll C:\Users\Krzysztof\AppData\Local\Temp\{67EDE885-B6D2-4DB4-8F45-BE818F4B8D1B}.dll C:\Users\Krzysztof\AppData\Local\Temp\{78F84A2C-7B86-4CB0-B65A-84BCAFD67100}.dll C:\Users\Krzysztof\AppData\Local\Temp\{79952C62-F2F4-4460-8A51-11E3262809AC}.dll C:\Users\Krzysztof\AppData\Local\Temp\{79BC629C-7680-468C-8490-A9811E825400}.dll C:\Users\Krzysztof\AppData\Local\Temp\{81CB6384-1BEA-4C2B-9220-61515018D1E5}.dll C:\Users\Krzysztof\AppData\Local\Temp\{83A1EF46-7866-45A7-A843-84E82228D506}.dll C:\Users\Krzysztof\AppData\Local\Temp\{8842998D-16C6-4CF8-9832-0FC3513135E9}.dll C:\Users\Krzysztof\AppData\Local\Temp\{8A2C8D9D-900E-4F36-9AC5-BC0C38B1DEA2}.dll C:\Users\Krzysztof\AppData\Local\Temp\{90DEB3B6-6016-481B-9B64-5DE27A395DC2}.dll C:\Users\Krzysztof\AppData\Local\Temp\{92060427-C6EF-4C9E-AB55-A08503319F08}.dll C:\Users\Krzysztof\AppData\Local\Temp\{995807D7-800F-4813-B308-DEFD36C72A63}.dll C:\Users\Krzysztof\AppData\Local\Temp\{A0C87E51-DB56-47A5-BAB1-599F666162E8}.dll C:\Users\Krzysztof\AppData\Local\Temp\{A5E002AA-A151-4B8D-8B38-2157E747477F}.dll C:\Users\Krzysztof\AppData\Local\Temp\{AE1AE028-8C71-423A-9A61-C431A0E596B9}.dll C:\Users\Krzysztof\AppData\Local\Temp\{B17D08BF-C214-4790-B5AB-B7B78B788031}.dll C:\Users\Krzysztof\AppData\Local\Temp\{B33FD78F-12D4-4BD6-A552-F2FE2E8C5780}.dll C:\Users\Krzysztof\AppData\Local\Temp\{B9B835DF-0C85-4A8F-BDFA-4EEE9B2C4406}.dll C:\Users\Krzysztof\AppData\Local\Temp\{C23413BA-EA58-4E64-AF94-2397D7F817AB}.dll C:\Users\Krzysztof\AppData\Local\Temp\{C28DE02E-F105-4541-9141-537E29929BEB}.dll C:\Users\Krzysztof\AppData\Local\Temp\{C6A02A2A-2DAB-4920-9244-CA478B597B9F}.dll C:\Users\Krzysztof\AppData\Local\Temp\{C6FEC211-2D1C-481C-91D3-CD7641F38465}.dll C:\Users\Krzysztof\AppData\Local\Temp\{CB03DEF8-AB7D-4A97-A767-30726E71B24A}.dll C:\Users\Krzysztof\AppData\Local\Temp\{CF84FC7E-E0AE-4E73-9287-6D9D4D368B02}.dll C:\Users\Krzysztof\AppData\Local\Temp\{DC636ABA-ACAB-481A-AA50-4355C177AC94}.dll C:\Users\Krzysztof\AppData\Local\Temp\{E0CFA5D0-EA44-4F15-82A9-FFC414772393}.dll C:\Users\Krzysztof\AppData\Local\Temp\{E0FAFDCF-D6F2-4BE6-A2D3-692E7885C0EF}.dll C:\Users\Krzysztof\AppData\Local\Temp\{E3D84DA8-B369-47BC-8F80-7E17F2CC0B15}.dll C:\Users\Krzysztof\AppData\Local\Temp\{E7C14436-EEC2-48DB-B171-588F34CB2F0A}.dll C:\Users\Krzysztof\AppData\Local\Temp\{EA70B493-9B2C-40E3-8332-2A84B2DB3E5E}.dll C:\Users\Krzysztof\AppData\Local\Temp\{EB2A2AFB-BF26-4A20-B558-ECE83A2E82FE}.dll C:\Users\Krzysztof\AppData\Local\Temp\{EE5DFADA-EBC9-4123-82E6-4C61F75A2B9B}.dll C:\Users\Krzysztof\AppData\Local\Temp\{F06D1D84-9841-4932-9F4D-F88AA558DB8E}.dll C:\Users\Krzysztof\AppData\Local\Temp\{F5622C45-8E6B-443A-8D4A-92B9CE10A4FA}.dll C:\Users\Krzysztof\AppData\Local\Temp\{F6B014B8-A3A8-4FEE-BA79-30170536CBA7}.dll C:\Users\Krzysztof\AppData\Local\Temp\{F6F32632-842C-40A1-A922-0A0761FE7F4D}.dll C:\Users\Krzysztof\AppData\Local\Temp\{F79416B5-1B15-4028-B280-3396BB087127}.dll C:\Users\Krzysztof\AppData\Local\Temp\{F94DD621-0AA3-4DC8-891C-2ED7525676E5}.dll C:\Users\Krzysztof\AppData\Local\Temp\{FCEEE560-7F7A-4870-B1FA-AB5298F47CA2}.dll C:\Users\Krzysztof\AppData\Local\Temp\{FDED834C-69E3-4658-AF8C-9FCE5006D977}.dll ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2015-12-13 01:20 ==================== Koniec FRST.txt ============================