Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:03-05-2016 Uruchomiony przez MIC (administrator) MIC-Komputer (04-05-2016 11:29:35) Uruchomiony z C:\Users\MIC\Downloads Załadowane profile: MIC (Dostępne profile: MIC) Platform: Windows 7 Home Premium (X64) Język: Polski (Polska) Internet Explorer Wersja 8 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe (Hewlett-Packard) C:\Windows\System32\hpservice.exe (Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (AMD) C:\Windows\System32\atieclxx.exe (CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe (CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe () C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpAgent.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe () C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-15] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-22] (IDT, Inc.) HKLM\...\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [610872 2009-07-21] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre6\bin\jusched.exe [171520 2009-09-21] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-02] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HPCam_Menu] => c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM-x32\...\Run: [DpAgent] => C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe [842816 2009-07-01] (DigitalPersona, Inc.) HKLM-x32\...\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [320056 2009-06-24] ( Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Java\jre6\bin\jusched.exe [148888 2009-09-21] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-2795166636-262961794-3709354715-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company) HKU\S-1-5-21-2795166636-262961794-3709354715-1001\...\Policies\system: [WallpaperStyle] 2 HKU\S-1-5-21-2795166636-262961794-3709354715-1001\...\MountPoints2: {788733e8-1168-11e6-b6fc-002713390585} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-18\...\Policies\system: [WallpaperStyle] 2 Lsa: [Notification Packages] scecli DPPWDFLT Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2016-05-03] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 10.0.0.2 Tcpip\..\Interfaces\{D4EE3D43-E29F-485F-928B-2733B3DA4D1E}: [DhcpNameServer] 10.0.0.2 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_PL&c=94&bd=Pavilion&pf=cnnb HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_PL&c=94&bd=Pavilion&pf=cnnb HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_PL&c=94&bd=Pavilion&pf=cnnb HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_PL&c=94&bd=Pavilion&pf=cnnb HKU\S-1-5-21-2795166636-262961794-3709354715-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_PL&c=94&bd=Pavilion&pf=cnnb HKU\S-1-5-21-2795166636-262961794-3709354715-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_PL&c=94&bd=Pavilion&pf=cnnb SearchScopes: HKLM -> DefaultScope {F2996606-D7EC-4034-8FE9-272397BA49EE} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query={searchTerms}&invocationType=tb50hpcnnbie7-pl-pl SearchScopes: HKLM -> {F2996606-D7EC-4034-8FE9-272397BA49EE} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query={searchTerms}&invocationType=tb50hpcnnbie7-pl-pl SearchScopes: HKLM-x32 -> DefaultScope {F2996606-D7EC-4034-8FE9-272397BA49EE} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query={searchTerms}&invocationType=tb50hpcnnbie7-pl-pl SearchScopes: HKLM-x32 -> {F2996606-D7EC-4034-8FE9-272397BA49EE} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query={searchTerms}&invocationType=tb50hpcnnbie7-pl-pl SearchScopes: HKU\S-1-5-21-2795166636-262961794-3709354715-1001 -> DefaultScope {F2996606-D7EC-4034-8FE9-272397BA49EE} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query={searchTerms}&invocationType=tb50hpcnnbie7-pl-pl SearchScopes: HKU\S-1-5-21-2795166636-262961794-3709354715-1001 -> {F2996606-D7EC-4034-8FE9-272397BA49EE} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query={searchTerms}&invocationType=tb50hpcnnbie7-pl-pl BHO: DigitalPersona Personal Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll [2009-07-01] (DigitalPersona, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-21] (Sun Microsystems, Inc.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated) BHO-x32: DigitalPersona Personal Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll [2009-07-01] (DigitalPersona, Inc.) BHO-x32: Pomocnik rejestracji usługi Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2009-09-21] (Sun Microsystems, Inc.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll [2009-02-06] (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll [2009-02-06] (Microsoft Corporation) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\MIC\AppData\Roaming\Mozilla\Firefox\Profiles\psdkhm39.default FF Homepage: google.pl FF Extension: Adblock Plus - C:\Users\MIC\AppData\Roaming\Mozilla\Firefox\Profiles\psdkhm39.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-05-03] FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt [2016-05-03] [Brak podpisu cyfrowego] FF HKU\S-1-5-21-2795166636-262961794-3709354715-1001\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\firefoxext ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation) R2 DpHost; C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe [322624 2009-07-01] (DigitalPersona, Inc.) [Brak podpisu cyfrowego] R2 HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [124928 2009-07-09] (Hewlett-Packard) [Brak podpisu cyfrowego] R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [Brak podpisu cyfrowego] R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-01-21] () R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [240128 2009-07-22] (IDT, Inc.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [311424 2009-05-22] (AVerMedia TECHNOLOGIES, Inc.) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-05-04] (Malwarebytes) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-05-04 11:17 - 2016-05-04 11:29 - 00014018 _____ C:\Users\MIC\Downloads\FRST.txt 2016-05-04 11:17 - 2016-05-04 11:29 - 00000000 ____D C:\FRST 2016-05-04 11:16 - 2016-05-04 11:16 - 02377216 _____ (Farbar) C:\Users\MIC\Downloads\FRST64.exe 2016-05-04 10:56 - 2016-05-04 10:57 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-05-04 10:56 - 2016-05-04 10:56 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-05-04 10:56 - 2016-05-04 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-05-04 10:55 - 2016-05-04 10:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-05-04 10:55 - 2016-05-04 10:55 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-05-04 10:55 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-05-04 10:55 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-05-04 10:55 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-05-04 10:54 - 2016-05-04 10:55 - 22851472 _____ (Malwarebytes ) C:\Users\MIC\Downloads\mbam-setup-2.2.1.1043.exe 2016-05-04 09:39 - 2016-05-04 09:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2016-05-04 06:55 - 2016-05-04 06:55 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-05-04 06:55 - 2016-05-04 06:55 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs 2016-05-04 06:55 - 2016-05-04 06:55 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs 2016-05-04 06:55 - 2009-06-10 22:30 - 00048265 _____ C:\Windows\HomePremium.xml 2016-05-03 22:29 - 2016-05-04 09:46 - 00000000 ____D C:\Users\MIC\AppData\Local\Mozilla 2016-05-03 22:29 - 2016-05-03 22:29 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-05-03 22:29 - 2016-05-03 22:29 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-05-03 22:29 - 2016-05-03 22:29 - 00000000 ____D C:\Users\MIC\AppData\Roaming\Mozilla 2016-05-03 22:29 - 2016-05-03 22:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-05-03 22:29 - 2016-05-03 22:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-05-03 22:29 - 2016-05-03 22:29 - 00000000 ____D C:\Program Files (x86)\Hp 2016-05-03 22:26 - 2016-05-03 22:29 - 00000000 ____D C:\Users\MIC\AppData\Roaming\HpUpdate 2016-05-03 22:26 - 2016-05-03 22:26 - 00000000 ____D C:\Users\MIC\AppData\LocalLow\Sun 2016-05-03 22:25 - 2016-05-03 22:25 - 00000000 ____D C:\Users\MIC\AppData\Roaming\Adobe 2016-05-03 22:22 - 2016-05-03 22:22 - 00000000 ____D C:\Users\MIC\AppData\Roaming\Macrovision 2016-05-03 22:21 - 2016-05-03 22:21 - 00001417 _____ C:\Users\MIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2016-05-03 22:21 - 2016-05-03 22:21 - 00000173 _____ C:\ProgramData\HPWALog.txt 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\Documents\Bluetooth Exchange Folder 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\AppData\Roaming\Hewlett-Packard 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\AppData\Roaming\DigitalPersona 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\AppData\Roaming\ATI 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\AppData\Local\DigitalPersona 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\AppData\Local\Broadcom 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\AppData\Local\ATI 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 _____ C:\Users\MIC\AppData\Local\QSwitch.txt 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 _____ C:\Users\MIC\AppData\Local\DSwitch.txt 2016-05-03 22:21 - 2016-05-03 22:21 - 00000000 _____ C:\Users\MIC\AppData\Local\AtStart.txt 2016-05-03 22:20 - 2016-05-03 22:21 - 00001451 _____ C:\Users\MIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-05-03 22:20 - 2016-05-03 22:20 - 00003964 _____ C:\Windows\System32\Tasks\RecoveryCDWin7 2016-05-03 22:20 - 2016-05-03 22:20 - 00003772 _____ C:\Windows\System32\Tasks\Registration 2016-05-03 22:20 - 2016-05-03 22:20 - 00003290 _____ C:\Windows\System32\Tasks\RMCreator 2016-05-03 22:20 - 2016-05-03 22:20 - 00000000 ____D C:\Users\MIC\AppData\Roaming\hpqlog 2016-05-03 22:20 - 2016-05-03 22:20 - 00000000 ____D C:\Users\MIC\AppData\Local\VirtualStore 2016-05-03 22:20 - 2016-05-03 22:20 - 00000000 ____D C:\Users\MIC\AppData\Local\Hewlett-Packard_Company 2016-05-03 22:17 - 2016-05-03 22:17 - 00000000 ____D C:\Users\MIC\AppData\Roaming\HP TCS 2016-05-03 22:17 - 2009-09-21 15:57 - 00002056 _____ C:\Users\Public\Desktop\Skype.lnk 2016-05-03 22:05 - 2016-05-03 22:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live 2016-05-03 22:04 - 2016-05-03 22:05 - 00000000 ____D C:\Program Files (x86)\Windows Live 2016-05-03 22:04 - 2016-05-03 22:04 - 00000000 ____D C:\Program Files (x86)\Windows Live SkyDrive 2016-05-03 22:03 - 2016-05-03 22:03 - 00084240 _____ C:\Users\MIC\AppData\Local\GDIPFONTCACHEV1.DAT 2016-05-03 22:03 - 2016-05-03 22:03 - 00002601 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk 2016-05-03 22:03 - 2016-05-03 22:03 - 00001193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uruchamianie zadań programu Microsoft Works.lnk 2016-05-03 22:03 - 2016-05-03 22:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works 2016-05-03 22:01 - 2016-05-03 22:01 - 00001321 _____ C:\Users\Public\Desktop\Microsoft Office - 60 Day Trial.lnk 2016-05-03 22:01 - 2016-05-03 22:01 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-05-03 22:01 - 2016-05-03 22:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Office Suite Activation Assistant 2016-05-03 22:00 - 2016-05-03 22:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2016-05-03 22:00 - 2016-05-03 22:00 - 00000000 ____D C:\Windows\PCHEALTH 2016-05-03 21:59 - 2016-05-03 21:59 - 00000000 ____D C:\Program Files\Microsoft Office 2016-05-03 21:58 - 2016-05-03 22:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2016-05-03 21:58 - 2016-05-03 21:59 - 00000000 ____D C:\Windows\SHELLNEW 2016-05-03 21:58 - 2016-05-03 21:58 - 00000000 __RHD C:\MSOCache 2016-05-03 21:58 - 2016-05-03 21:58 - 00000000 ____D C:\Users\MIC\AppData\Local\Microsoft Help 2016-05-03 21:57 - 2016-05-03 21:57 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk 2016-05-03 21:57 - 2016-05-03 21:57 - 00000000 ____D C:\ProgramData\Adobe 2016-05-03 21:57 - 2016-05-03 21:57 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-05-03 21:56 - 2016-05-03 22:21 - 00000000 ____D C:\Users\MIC\AppData\Local\Hewlett-Packard 2016-05-03 21:56 - 2016-05-03 21:56 - 00000000 __RSH C:\Windows\SysWOW64\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_QCNF9425095_E572195-241_4A_I363A_SQuanta_V33.22_F.08_T091015_WU3-0_L415_M4093_J500_7AMD_8F62_92.20_#160503_N10EC8168;168C002B_(VL095EA#AKD)_XMOBILE_CN10_Z.MRK 2016-05-03 21:56 - 2016-05-03 21:56 - 00000000 __RSH C:\Windows\system32\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_QCNF9425095_E572195-241_4A_I363A_SQuanta_V33.22_F.08_T091015_WU3-0_L415_M4093_J500_7AMD_8F62_92.20_#160503_N10EC8168;168C002B_(VL095EA#AKD)_XMOBILE_CN10_Z.MRK 2016-05-03 21:55 - 2016-05-04 06:55 - 00000000 ____D C:\Users\MIC\AppData\Roaming\Media Center Programs 2016-05-03 21:55 - 2016-05-03 22:20 - 00000000 ____D C:\Users\MIC 2016-05-03 21:55 - 2016-05-03 21:55 - 00000020 ___SH C:\Users\MIC\ntuser.ini 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Public\Documents\Moje wideo 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Public\Documents\Moje obrazy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Public\Documents\Moja muzyka 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Ustawienia lokalne 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Szablony 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Moje dokumenty 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Menu Start 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Documents\Moje wideo 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Documents\Moje obrazy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Documents\Moja muzyka 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\Dane aplikacji 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\AppData\Local\Historia 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\MIC\AppData\Local\Dane aplikacji 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Ustawienia lokalne 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Szablony 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Moje dokumenty 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Menu Start 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Documents\Moje wideo 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Documents\Moje obrazy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Documents\Moja muzyka 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\Dane aplikacji 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\AppData\Local\Historia 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dane aplikacji 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default User\Documents\Moje wideo 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default User\Documents\Moje obrazy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default User\Documents\Moja muzyka 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Historia 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dane aplikacji 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\ProgramData\Ulubione 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\ProgramData\Szablony 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\ProgramData\Pulpit 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\ProgramData\Menu Start 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\ProgramData\Dokumenty 2016-05-03 21:55 - 2016-05-03 21:55 - 00000000 _SHDL C:\ProgramData\Dane aplikacji 2016-05-03 21:55 - 2016-05-03 21:27 - 00000000 ____D C:\Users\MIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 2016-05-03 21:55 - 2012-06-03 00:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2016-05-03 21:55 - 2012-06-03 00:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2016-05-03 21:55 - 2012-06-03 00:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2016-05-03 21:55 - 2012-06-03 00:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2016-05-03 21:55 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2016-05-03 21:55 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2016-05-03 21:55 - 2009-09-21 15:46 - 00000000 ____D C:\Users\MIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery Manager 2016-05-03 21:48 - 2016-05-03 21:48 - 00000000 ____D C:\ProgramData\ATI 2016-05-03 21:31 - 2016-05-03 22:17 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services 2016-05-03 21:31 - 2016-04-21 15:05 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-05-03 21:30 - 2016-05-03 21:30 - 00001138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DigitalPersona Personal.lnk 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\tr 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\sv 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\ru 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\no 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\ko 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\ja 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\it 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\fr 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\es 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\de 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\SysWOW64\da 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\tr 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\sv 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\ru 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\no 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\ko 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\ja 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\it 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\fr 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\es 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\de 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\system32\da 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Windows\DPDrv 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\ProgramData\Macrovision 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\ProgramData\Downloaded Installations 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Program Files\DigitalPersona 2016-05-03 21:30 - 2016-05-03 21:30 - 00000000 ____D C:\Program Files (x86)\DigitalPersona 2016-05-03 21:27 - 2016-05-03 21:27 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 2016-05-03 21:27 - 2016-05-03 21:27 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 2016-05-03 21:25 - 2016-05-03 21:25 - 00002824 _____ C:\Windows\System32\Tasks\CapSchedInst 2016-05-03 21:25 - 2016-05-03 21:25 - 00002820 _____ C:\Windows\System32\Tasks\CapSvcInst 2016-05-03 21:25 - 2016-05-03 21:25 - 00002818 _____ C:\Windows\System32\Tasks\CapUninst 2016-05-03 21:24 - 2016-05-03 21:24 - 00003170 _____ C:\Windows\System32\Tasks\TVAgent 2016-05-03 21:22 - 2016-05-03 21:22 - 00003200 _____ C:\Windows\System32\Tasks\CLMLSvc 2016-05-03 21:17 - 2016-05-03 21:17 - 00003164 _____ C:\Windows\System32\Tasks\DVDAgent 2016-05-03 21:15 - 2016-05-03 21:15 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling 2016-05-03 21:11 - 2016-05-03 21:11 - 00000000 ____D C:\Program Files\WIDCOMM 2016-05-03 21:11 - 2009-07-17 22:58 - 00132648 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys 2016-05-03 21:11 - 2009-07-17 22:58 - 00098344 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys 2016-05-03 21:11 - 2009-07-17 22:58 - 00035104 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys 2016-05-03 21:11 - 2009-07-17 22:58 - 00021160 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys 2016-05-03 21:10 - 2016-05-03 22:29 - 00000000 ____D C:\Windows\Hewlett-Packard 2016-05-03 21:09 - 2016-05-03 21:09 - 00000000 ____D C:\Windows\system32\SRSLabs 2016-05-03 21:09 - 2016-05-03 21:09 - 00000000 ____D C:\Windows\Driver Cache 2016-05-03 21:09 - 2016-05-03 21:09 - 00000000 ____D C:\Program Files (x86)\AVerMedia 2016-05-03 21:09 - 2009-07-22 03:33 - 12158464 _____ (IDT, Inc.) C:\Windows\system32\idtcpl64.cpl 2016-05-03 21:09 - 2009-07-22 03:33 - 03593216 _____ (IDT, Inc.) C:\Windows\system32\stlang64.dll 2016-05-03 21:09 - 2009-07-22 03:33 - 00564224 _____ (IDT, Inc.) C:\Windows\system32\idt64mp1.exe 2016-05-03 21:09 - 2009-07-22 03:33 - 00450048 _____ (IDT, Inc.) C:\Windows\sttray64.exe 2016-05-03 21:09 - 2009-06-25 23:59 - 00160768 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTAC64.dll 2016-05-03 21:09 - 2009-05-22 08:32 - 00311424 _____ (AVerMedia TECHNOLOGIES, Inc.) C:\Windows\system32\Drivers\AVerAF15.sys 2016-05-03 21:09 - 2009-05-21 23:57 - 00436224 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTEC64.dll 2016-05-03 21:09 - 2009-05-11 11:21 - 00000350 _____ C:\Windows\system32\AP6RMHV.BIN 2016-05-03 21:09 - 2009-05-11 11:21 - 00000308 _____ C:\Windows\system32\AP6RMKV.BIN 2016-05-03 21:09 - 2009-05-11 11:21 - 00000252 _____ C:\Windows\system32\AP6RMJH.BIN 2016-05-03 21:09 - 2009-05-11 11:21 - 00000238 _____ C:\Windows\system32\AP6RMFP.BIN 2016-05-03 21:09 - 2009-05-11 11:21 - 00000189 _____ C:\Windows\system32\AP6RMKS.BIN 2016-05-03 21:09 - 2009-05-11 11:21 - 00000126 _____ C:\Windows\system32\AP6RMHR.BIN 2016-05-03 21:09 - 2009-03-02 22:58 - 00068608 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTAR64.dll 2016-05-03 21:09 - 2009-03-02 22:47 - 00090624 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTCo64.dll 2016-05-03 21:08 - 2016-05-03 21:09 - 00000000 ____D C:\Program Files\IDT 2016-05-03 21:08 - 2016-05-03 21:08 - 00000000 ____D C:\ProgramData\Atheros 2016-05-03 21:08 - 2016-05-03 21:08 - 00000000 ____D C:\Program Files (x86)\Atheros 2016-05-03 21:08 - 2009-07-22 03:33 - 01431552 _____ (IDT, Inc.) C:\Windows\system32\stapo64.dll 2016-05-03 21:08 - 2009-07-22 03:33 - 00604672 ____N (IDT, Inc.) C:\Windows\system32\stapi64.dll 2016-05-03 21:08 - 2009-07-22 03:33 - 00487936 _____ (IDT, Inc.) C:\Windows\system32\Drivers\stwrt64.sys 2016-05-03 21:08 - 2009-07-22 03:33 - 00431616 _____ (IDT, Inc.) C:\Windows\system32\stcplx64.dll 2016-05-03 21:08 - 2009-07-22 03:33 - 00209920 _____ (IDT, Inc.) C:\Windows\system32\staco64.dll 2016-05-03 21:08 - 2009-07-08 17:49 - 01484800 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2016-05-03 21:07 - 2016-05-03 21:07 - 00000000 ____D C:\Program Files (x86)\Realtek 2016-05-03 21:07 - 2016-05-03 21:07 - 00000000 ____D C:\Program Files (x86)\JMicron 2016-05-03 21:07 - 2016-05-03 21:07 - 00000000 ____D C:\Program Files (x86)\AMD 2016-05-03 21:07 - 2009-05-23 08:52 - 00215040 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2016-05-03 21:07 - 2009-03-09 06:49 - 00036408 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\usbfilter.sys 2016-05-03 21:07 - 2009-03-06 00:54 - 00067584 _____ C:\Windows\system32\RtNicProp64.dll 2016-05-03 21:06 - 2016-05-03 21:07 - 00000000 ____D C:\Program Files\DIFX 2016-05-03 21:06 - 2016-05-03 21:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf 2016-05-03 21:06 - 2016-05-03 21:06 - 00000000 ____D C:\Program Files\Validity Sensors 2016-05-03 21:05 - 2016-05-03 21:05 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01007.Wdf 2016-05-03 21:05 - 2016-05-03 21:05 - 00000000 ____D C:\Program Files\Synaptics 2016-05-03 21:04 - 2016-05-03 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center 2016-05-03 21:03 - 2016-05-03 21:04 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2016-05-03 21:03 - 2016-05-03 21:03 - 00000000 ____D C:\Program Files\ATI 2016-05-03 20:59 - 2016-05-03 20:59 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2016-05-03 20:59 - 2016-05-03 20:59 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-05-04 11:21 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-05-04 11:21 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-05-04 09:41 - 2009-09-21 15:11 - 00000000 ____D C:\ProgramData\Norton 2016-05-04 09:41 - 2009-09-21 15:11 - 00000000 ____D C:\Program Files (x86)\Norton Internet Security 2016-05-04 09:41 - 2009-09-21 15:10 - 00000000 ____D C:\Program Files (x86)\NortonInstaller 2016-05-04 06:56 - 2009-09-21 15:35 - 00000012 _____ C:\Windows\CSUP.txt 2016-05-04 06:55 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games 2016-05-04 06:55 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker 2016-05-04 06:55 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2016-05-04 06:54 - 2009-07-14 07:32 - 00032768 _____ C:\Windows\system32\config\BCD-Template 2016-05-03 22:29 - 2009-09-21 16:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2016-05-03 22:20 - 2009-07-17 01:15 - 00000000 ____D C:\SwSetup 2016-05-03 22:19 - 2009-09-21 15:09 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2016-05-03 22:17 - 2009-09-21 15:36 - 00000000 ___RD C:\Program Files (x86)\Online Services 2016-05-03 22:17 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2016-05-03 22:17 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar 2016-05-03 22:16 - 2009-07-17 01:15 - 00000000 ___HD C:\SYSTEM.SAV 2016-05-03 22:04 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2016-05-03 21:58 - 2009-09-22 00:57 - 00687828 _____ C:\Windows\system32\perfh015.dat 2016-05-03 21:58 - 2009-09-22 00:57 - 00131382 _____ C:\Windows\system32\perfc015.dat 2016-05-03 21:58 - 2009-07-14 07:13 - 01523412 _____ C:\Windows\system32\PerfStringBackup.INI 2016-05-03 21:58 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-05-03 21:55 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2016-05-03 21:55 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2016-05-03 21:55 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2016-05-03 21:53 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-05-03 21:52 - 2009-07-25 08:11 - 00000000 ____D C:\Windows\Panther 2016-05-03 21:52 - 2009-07-14 06:45 - 00284552 _____ C:\Windows\system32\FNTCACHE.DAT 2016-05-03 21:49 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep 2016-05-03 21:31 - 2009-09-22 00:43 - 00000000 ___HD C:\HP 2016-05-03 21:31 - 2009-09-21 16:40 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard 2016-05-03 21:29 - 2009-09-21 15:46 - 00000000 ____D C:\ProgramData\Temp 2016-05-03 21:29 - 2009-09-21 15:09 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-05-03 21:28 - 2009-09-21 15:58 - 00000000 ____D C:\ProgramData\CyberLink 2016-05-03 21:28 - 2009-09-21 15:06 - 00000000 ____D C:\Program Files\Hewlett-Packard 2016-05-03 21:18 - 2009-09-21 15:06 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2016-05-03 20:59 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games ==================== Pliki w katalogu głównym wybranych folderów ======= 2016-05-03 22:21 - 2016-05-03 22:21 - 0000000 _____ () C:\Users\MIC\AppData\Local\AtStart.txt 2016-05-03 22:21 - 2016-05-03 22:21 - 0000000 _____ () C:\Users\MIC\AppData\Local\DSwitch.txt 2016-05-03 22:21 - 2016-05-03 22:21 - 0000000 _____ () C:\Users\MIC\AppData\Local\QSwitch.txt 2016-05-03 22:21 - 2016-05-03 22:21 - 0000173 _____ () C:\ProgramData\HPWALog.txt 2016-05-03 21:29 - 2016-05-03 21:29 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log 2009-09-21 16:04 - 2009-09-21 16:04 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2016-05-03 21:29 - 2016-05-03 21:29 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log 2009-09-21 15:59 - 2009-09-21 16:00 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2016-05-03 21:28 - 2016-05-03 21:28 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log 2016-05-03 21:29 - 2016-05-03 21:29 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log 2009-09-21 15:58 - 2009-09-21 15:58 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2009-09-21 16:00 - 2009-09-21 16:04 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2016-05-03 21:29 - 2016-05-03 21:29 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log Niektóre pliki w TEMP: ==================== C:\Users\MIC\AppData\Local\Temp\A~NSISu_.exe C:\Users\MIC\AppData\Local\Temp\HPQSi.exe C:\Users\MIC\AppData\Local\Temp\ose00000.exe C:\Users\MIC\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_NIS.exe ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2009-07-25 07:12 ==================== Koniec FRST.txt ============================