Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:06-06-2016 Uruchomiony przez Inga (administrator) INGA (07-06-2016 08:33:11) Uruchomiony z C:\Users\Inga\Documents\k Załadowane profile: Inga (Dostępne profile: artur & Inga) Platform: Windows 8.1 (Update) (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: Chrome) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe () C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_FATIACE.EXE (Spotify Ltd) C:\Users\Inga\AppData\Roaming\Spotify\Spotify.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Spotify Ltd) C:\Users\Inga\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) C:\Users\Inga\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Inga\AppData\Roaming\Spotify\Spotify.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [] => [X] HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296520 2013-09-12] (TOSHIBA Corporation) HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [178016 2013-08-21] (TOSHIBA Corporation) HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144 2013-08-14] (TOSHIBA Corporation) HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-08-18] (TOSHIBA Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2778864 2014-08-06] (Synaptics Incorporated) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.) HKLM\...\Run: [EPSON Stylus DX3800] => C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIACE.EXE [98304 2005-02-08] (SEIKO EPSON CORPORATION) HKLM\...\Run: [EPSON Stylus DX3800 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIACE.EXE [98304 2005-02-08] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [383768 2002-04-12] (Alcor Micro Corp.) HKLM-x32\...\Run: [1.TPUReg] => C:\Program Files (x86)\TOSHIBA\PasswordUtility\readLM.exe [2216800 2013-03-27] (TOSHIBA) HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512 2013-07-23] (TOSHIBA) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-23] (Apple Inc.) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [67840 2016-05-19] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [814608 2016-04-04] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [186640 2016-05-18] (AVG Technologies CZ, s.r.o.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\...\Run: [Spotify Web Helper] => C:\Users\Inga\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1554032 2016-05-28] (Spotify Ltd) HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\...\Run: [AVG-Secure-Search-Update_0414c] => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2725912 2014-04-26] () HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\...\Run: [Spotify] => C:\Users\Inga\AppData\Roaming\Spotify\Spotify.exe [6859888 2016-05-28] (Spotify Ltd) HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\...\MountPoints2: {0967f913-92df-11e5-831e-001e101f3054} - "E:\AutoRun.exe" HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\...\MountPoints2: {e342a7e3-92d6-11e5-831d-54bef7653677} - "E:\AutoRun.exe" HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\...\MountPoints2: {e342a89d-92d6-11e5-831d-54bef7653677} - "E:\AutoRun.exe" HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku Startup: C:\Users\Inga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk [2015-12-07] ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 62.179.1.63 62.179.1.62 Tcpip\..\Interfaces\{3EE8E2A3-BB27-416D-8D24-F7B875C0C2D8}: [DhcpNameServer] 62.179.1.63 62.179.1.62 Tcpip\..\Interfaces\{EB517593-7AA4-4D27-8E5E-EB6DF1C6675E}: [DhcpNameServer] 62.179.1.63 62.179.1.62 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://do-search.com/?type=hppp&ts=1426106567&from=cor&uid=TOSHIBAXMQ01ABD075_63M3P5F1TXX63M3P5F1T HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://toshiba.eu/symbaloo_c HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1426106290&from=cor&uid=TOSHIBAXMQ01ABD075_63M3P5F1TXX63M3P5F1T&q={searchTerms} HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-3135212574-2383626176-3544364843-1005\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.bing.com/search?q={searchTerms} SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://www.bing.com/search?q={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3135212574-2383626176-3544364843-1005 -> DefaultScope {ielnksrch} URL = hxxp://www.bing.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-3135212574-2383626176-3544364843-1005 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-3135212574-2383626176-3544364843-1005 -> {23B39B67-78DB-430D-9400-AD68FAA371E1} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3135212574-2383626176-3544364843-1005 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3135212574-2383626176-3544364843-1005 -> {ielnksrch} URL = hxxp://www.bing.com/search?q={searchTerms} BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-06-04] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Brak nazwy -> {b608cc98-54de-4775-96c9-097de398500c} -> Brak pliku BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-06-04] (Oracle Corporation) FireFox: ======== FF ProfilePath: C:\Users\Inga\AppData\Roaming\Mozilla\Firefox\Profiles\guaerf1e.default FF Homepage: hxxps://www.google.pl/ FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-07-11] (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-06-04] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-06-04] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-25] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-05-12] () FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => nie znaleziono Chrome: ======= CHR HomePage: Default -> hxxps://www.google.no/webhp?sourceid=chrome-instant&rlz=1C1RNVH_enPL567PL568&ion=1&espv=2&ie=UTF-8 CHR StartupUrls: Default -> "hxxps://www.google.no/webhp?sourceid=chrome-instant&rlz=1C1RNVH_enPL567PL568&ion=1&espv=2&ie=UTF-8" CHR DefaultSearchURL: Default -> hxxp://do-search.com/web/?type=dspp&ts=1426106567&from=cor&uid=TOSHIBAXMQ01ABD075_63M3P5F1TXX63M3P5F1T&q={searchTerms} CHR DefaultSearchKeyword: Default -> SafeFinder CHR Profile: C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Dokumenty Google) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04] CHR Extension: (Dysk Google) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23] CHR Extension: (YouTube) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Google Search) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-13] CHR Extension: (Dokumenty Google offline) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16] CHR Extension: (AdBlock) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-06-02] CHR Extension: (Przycisk Pin It) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2016-03-08] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02] CHR Extension: (Gmail) - C:\Users\Inga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28] CHR HKLM-x32\...\Chrome\Extension: [jidkebcigjgheaahopdnlfaohgnocfai] - hxxps://clients2.google.com/service/update2/crx ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [970656 2016-04-04] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [467016 2016-04-04] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [467016 2016-04-04] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1435704 2016-04-04] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.) S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-08-22] (Windows (R) Win 7 DDK provider) [Brak podpisu cyfrowego] R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1080592 2016-05-18] (AVG Technologies CZ, s.r.o.) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [285176 2016-05-19] (Avira Operations GmbH & Co. KG) S4 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [19792 2013-09-10] () R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-12-03] (Freemake) [Brak podpisu cyfrowego] S4 GFNEXSrv; C:\Program Files (x86)\TOSHIBA\PasswordUtility\GFNEXSrv.exe [163168 2013-03-27] () S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [Brak podpisu cyfrowego] S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation) S4 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation) S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) S4 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation) S4 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910640 2015-02-27] (Electronic Arts) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-19] () S4 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-08-16] (IDT, Inc.) [Brak podpisu cyfrowego] R3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [120392 2015-11-17] (Toshiba Europe GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation) S4 HWDeviceService64.exe; "C:\ProgramData\DatacardService\HWDeviceService64.exe" -/service [X] ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3858944 2013-10-24] (Qualcomm Atheros Communications, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128664 2016-04-04] (Avira Operations GmbH & Co. KG) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-23] (AVG Technologies) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [146712 2016-04-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [35488 2016-04-04] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [78208 2016-04-04] (Avira Operations GmbH & Co. KG) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) S3 ewusbnet; C:\Windows\system32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.) S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation) R2 PEGAGFN; C:\Program Files (x86)\TOSHIBA\PasswordUtility\PEGAGFN.sys [14344 2009-09-11] (PEGATRON) S3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation ) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2014-08-06] (Synaptics Incorporated) R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows (R) Win 7 DDK provider) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 ewusbmbb; \SystemRoot\system32\DRIVERS\ewusbwwan.sys [X] S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] S1 wpnfd_1_10_0_4; system32\drivers\wpnfd_1_10_0_4.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-06-07 08:26 - 2016-06-07 08:27 - 00000000 ____D C:\Users\Inga\Documents\k 2016-06-07 08:25 - 2016-06-07 08:25 - 00000000 _____ C:\Users\Inga\Downloads\fixlist.txt 2016-06-07 08:00 - 2016-06-07 08:00 - 00593952 _____ (Duplex Secure Ltd) C:\Users\Inga\Downloads\SPTDinst-v189-x64 (1).exe 2016-06-07 07:43 - 2016-06-07 07:43 - 03480040 _____ (McAfee, Inc.) C:\Users\Inga\Downloads\MCPR (1).exe 2016-06-07 07:24 - 2016-06-07 07:24 - 03480040 _____ (McAfee, Inc.) C:\Users\Inga\Downloads\MCPR.exe 2016-06-07 06:51 - 2016-06-07 06:51 - 02895464 _____ (AVG Technologies) C:\Users\Inga\Downloads\AVG_Protection_Free_1144 (1).exe 2016-06-07 06:16 - 2016-06-07 06:16 - 00000000 ____D C:\Users\Inga\AppData\Roaming\AVG 2016-06-07 01:57 - 2016-06-07 01:57 - 00002503 _____ C:\Users\Inga\Downloads\ksiazka-adresowa-o2-inga99s@o2.pl.csv 2016-06-07 01:57 - 2016-06-07 01:57 - 00002495 _____ C:\Users\Inga\Downloads\ksiazka-adresowa-o2-inga99s@o2.pl (1).csv 2016-06-07 01:56 - 2016-06-07 01:56 - 00000000 _____ C:\Users\Inga\Desktop\k.txt 2016-06-07 00:22 - 2016-06-07 07:44 - 00000000 ____D C:\Program Files (x86)\AVG 2016-06-07 00:20 - 2016-06-07 07:42 - 00000000 ____D C:\ProgramData\Avg 2016-06-07 00:20 - 2016-06-07 07:41 - 00000000 ____D C:\Users\Inga\AppData\Local\AvgSetupLog 2016-06-07 00:20 - 2016-06-07 07:36 - 00000000 ____D C:\Users\Inga\AppData\Local\Avg 2016-06-07 00:20 - 2016-06-07 00:20 - 02895464 _____ (AVG Technologies) C:\Users\Inga\Downloads\AVG_Protection_Free_1144.exe 2016-06-07 00:00 - 2016-06-07 00:01 - 63237477 _____ C:\Users\Inga\Downloads\Poranek (1).pptx 2016-06-06 08:46 - 2016-06-06 08:46 - 00000000 ____D C:\Users\Inga\AppData\Roaming\Avira 2016-06-06 08:42 - 2016-04-04 17:07 - 00146712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2016-06-06 08:42 - 2016-04-04 17:07 - 00128664 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2016-06-06 08:42 - 2016-04-04 17:07 - 00078208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2016-06-06 08:42 - 2016-04-04 17:07 - 00035488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2016-06-06 08:40 - 2016-06-06 08:40 - 04630840 _____ (Avira Operations GmbH & Co. KG) C:\Users\Inga\Downloads\avira_en_av_3020800576_oo5hhdvrg4oy5hpnox3d_wd.exe 2016-06-06 08:38 - 2016-06-06 08:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2016-06-06 08:38 - 2016-06-06 08:42 - 00000000 ____D C:\ProgramData\Avira 2016-06-06 08:38 - 2016-06-06 08:42 - 00000000 ____D C:\Program Files (x86)\Avira 2016-06-06 08:38 - 2016-06-06 08:40 - 00001197 _____ C:\Users\Public\Desktop\Avira Launcher.lnk 2016-06-06 08:37 - 2016-06-06 08:37 - 04630840 _____ (Avira Operations GmbH & Co. KG) C:\Users\Inga\Downloads\avira_en_avprodl_57551a30b4b64__ws.exe 2016-06-05 23:28 - 2016-06-05 23:28 - 00000000 ____D C:\Users\Inga\AppData\Local\Mozilla 2016-06-05 23:26 - 2016-06-05 23:26 - 45223072 _____ C:\Users\Inga\Downloads\Firefox Setup 46.0.1.exe 2016-06-05 23:26 - 2016-06-05 23:26 - 00242240 _____ C:\Users\Inga\Downloads\Firefox Setup Stub 46.0.1.exe 2016-06-05 22:32 - 2016-06-05 22:32 - 00000076 _____ C:\Users\Inga\Downloads\IndexerVolumeGuid 2016-06-05 14:08 - 2016-06-05 14:08 - 00060588 _____ C:\Users\Inga\Desktop\FRST.txt 2016-06-05 14:07 - 2016-06-05 14:07 - 00066908 _____ C:\Users\Inga\Desktop\Shortcut.txt 2016-06-05 14:07 - 2016-06-05 14:07 - 00050008 _____ C:\Users\Inga\Desktop\Addition.txt 2016-06-05 13:57 - 2016-06-07 08:33 - 00000000 ____D C:\FRST 2016-06-05 13:56 - 2016-06-05 13:56 - 02384896 _____ (Farbar) C:\Users\Inga\Downloads\FRST64 (1).exe 2016-06-05 07:42 - 2016-06-05 07:43 - 00012201 _____ C:\Users\Inga\Desktop\gmer.txt 2016-06-05 04:03 - 2016-06-05 04:03 - 00293984 _____ C:\Windows\Minidump\060516-68890-01.dmp 2016-06-05 01:37 - 2016-06-05 01:37 - 00159072 _____ C:\Users\Inga\Desktop\OTL.Txt 2016-06-05 01:37 - 2016-06-05 01:37 - 00102878 _____ C:\Users\Inga\Desktop\Extras.Txt 2016-06-05 00:57 - 2016-06-05 01:37 - 00102878 _____ C:\Users\Inga\Downloads\Extras.Txt 2016-06-05 00:56 - 2016-06-05 00:56 - 00159072 _____ C:\Users\Inga\Downloads\OTL.Txt 2016-06-04 22:41 - 2016-06-04 22:41 - 00593952 _____ (Duplex Secure Ltd) C:\Users\Inga\Downloads\SPTDinst-v189-x64.exe 2016-06-04 22:36 - 2016-06-04 22:35 - 00601088 _____ (OldTimer Tools) C:\Users\Inga\Downloads\OTL 3.2.70.2 [1].exe 2016-06-04 22:35 - 2016-06-04 22:35 - 00991088 _____ ( ) C:\Users\Inga\Downloads\OTL 3.2.70.2.exe 2016-06-04 22:28 - 2016-06-04 22:28 - 00050477 _____ C:\Users\Inga\Downloads\Defogger (1).exe 2016-06-04 22:16 - 2016-06-04 22:16 - 00000000 _____ C:\Users\Inga\defogger_reenable 2016-06-04 22:15 - 2016-06-04 22:15 - 00050477 _____ C:\Users\Inga\Downloads\Defogger.exe 2016-06-04 20:37 - 2016-06-04 20:37 - 00380928 _____ C:\Users\Inga\Downloads\9oqerumz.exe 2016-06-04 20:22 - 2016-06-04 20:22 - 63237477 _____ C:\Users\Inga\Downloads\Poranek.pptx 2016-06-04 20:15 - 2016-06-04 20:15 - 02094279 _____ C:\Users\Inga\Downloads\Wirus ZIKA (1).pdf 2016-06-04 20:14 - 2016-06-04 20:14 - 02094279 _____ C:\Users\Inga\Downloads\Wirus ZIKA.pdf 2016-06-04 17:59 - 2016-06-07 07:26 - 00000000 ____D C:\Program Files\Common Files\AV 2016-06-04 17:59 - 2016-06-04 17:59 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2016-06-04 17:55 - 2016-06-06 09:29 - 00000000 ____D C:\ProgramData\AVAST Software 2016-06-04 17:55 - 2016-06-04 17:55 - 05066104 _____ (AVAST Software) C:\Users\Inga\Downloads\avast_free_antivirus_setup_online.exe 2016-06-04 17:12 - 2016-06-04 17:12 - 00097344 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2016-06-04 17:12 - 2016-06-04 17:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-06-04 17:12 - 2016-06-04 17:12 - 00000000 ____D C:\Program Files (x86)\Java 2016-06-04 17:09 - 2016-06-04 17:10 - 00737856 _____ (Oracle Corporation) C:\Users\Inga\Downloads\chromeinstall-8u91.exe 2016-06-03 03:57 - 2016-06-03 03:57 - 01440378 _____ C:\Users\Inga\Downloads\11эл (2).pdf 2016-06-03 03:56 - 2016-06-03 03:56 - 01440378 _____ C:\Users\Inga\Downloads\11эл (1).pdf 2016-06-03 03:55 - 2016-06-03 03:55 - 01440378 _____ C:\Users\Inga\Downloads\11эл.pdf 2016-06-03 03:50 - 2016-06-07 08:06 - 00003330 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3135212574-2383626176-3544364843-1005 2016-06-03 03:50 - 2016-06-07 08:06 - 00003278 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3135212574-2383626176-3544364843-1005 2016-05-31 06:12 - 2016-05-31 06:24 - 00000605 _____ C:\Users\Inga\Desktop\poranek.txt 2016-05-30 13:06 - 2016-05-30 13:06 - 00484352 _____ C:\Users\Inga\Downloads\analizaiinterpretacjautworu.ppt 2016-05-30 12:36 - 2016-05-30 12:36 - 02211783 _____ C:\Users\Inga\Downloads\Materialy_-_polski.zip 2016-05-30 09:08 - 2016-05-30 09:09 - 02177024 _____ C:\Users\Inga\Downloads\komputer.pps 2016-05-30 09:08 - 2016-05-30 09:09 - 02174464 _____ C:\Users\Inga\Downloads\komputer (1).pps 2016-05-30 08:14 - 2016-05-30 08:14 - 03769856 _____ C:\Users\Inga\Downloads\historia_komp_internetu.ppt 2016-05-30 01:57 - 2016-05-30 01:57 - 00809353 _____ C:\Users\Inga\Downloads\Wynalazki XX wieku (1).pptx 2016-05-30 01:46 - 2016-05-30 01:46 - 00809353 _____ C:\Users\Inga\Downloads\Wynalazki XX wieku.pptx 2016-05-29 03:01 - 2016-05-29 03:01 - 00187664 _____ C:\Users\Inga\Downloads\27.05.2016-11.06.2016_-_wersja_polska_aktualizacja (1).pdf 2016-05-29 03:00 - 2016-05-29 03:01 - 00187664 _____ C:\Users\Inga\Downloads\27.05.2016-11.06.2016_-_wersja_polska_aktualizacja.pdf 2016-05-27 12:40 - 2016-05-27 12:40 - 00000165 ____H C:\Users\Inga\Desktop\~$Najważniejsze osiągnięcia II RP.pptx 2016-05-27 06:29 - 2016-05-27 06:30 - 02656662 _____ C:\Users\Inga\Downloads\newspaper_3285 (1).pdf 2016-05-27 06:13 - 2016-05-27 06:14 - 02656662 _____ C:\Users\Inga\Downloads\newspaper_3285.pdf 2016-05-26 16:16 - 2016-05-26 16:16 - 00150927 _____ C:\Users\Inga\Downloads\img_A1aU0O 2016-05-26 16:16 - 2016-05-26 16:16 - 00089870 _____ C:\Users\Inga\Downloads\img_KcZNRu 2016-05-26 16:15 - 2016-05-26 16:16 - 00202898 _____ C:\Users\Inga\Downloads\img_iLgxmo 2016-05-25 10:54 - 2016-05-25 10:55 - 00544594 _____ C:\Users\Inga\Downloads\regulamin_inpost_paczkomaty_05-11-2015.pdf 2016-05-24 12:14 - 2016-05-24 12:14 - 03537703 _____ C:\Users\Inga\Downloads\Najważniejsze osiągnięcia II RP (2).pptx 2016-05-24 12:13 - 2016-05-28 01:50 - 06182372 _____ C:\Users\Inga\Desktop\Najważniejsze osiągnięcia II RP.pptx 2016-05-24 12:12 - 2016-05-24 12:12 - 03537800 _____ C:\Users\Inga\Downloads\Najważniejsze osiągnięcia II RP.pptx 2016-05-24 12:12 - 2016-05-24 12:12 - 03537800 _____ C:\Users\Inga\Downloads\Najważniejsze osiągnięcia II RP (1).pptx 2016-05-24 12:12 - 2016-05-24 12:12 - 03537800 _____ C:\Users\Inga\Downloads\Najważniejsze osiągnięcia II RP (1) (1).pptx 2016-05-21 03:58 - 2016-05-21 03:58 - 00814547 _____ C:\Users\Inga\Downloads\D20110151Lj.pdf 2016-05-15 17:39 - 2016-05-11 22:08 - 00829944 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-05-15 17:39 - 2016-05-11 22:08 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-05-12 10:28 - 2016-06-06 23:32 - 00001115 _____ C:\Users\Inga\Desktop\lekcje.txt 2016-05-12 02:30 - 2016-03-31 08:50 - 01307328 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-05-12 02:30 - 2016-03-31 05:40 - 00747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-05-12 02:29 - 2016-04-06 23:13 - 00561960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2016-05-12 02:29 - 2016-04-06 23:13 - 00137976 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-05-12 02:29 - 2016-04-06 20:20 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-05-12 02:29 - 2016-04-06 20:19 - 00401920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-05-12 02:29 - 2016-04-06 20:19 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-05-12 02:29 - 2016-04-06 19:49 - 00120384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-05-12 02:29 - 2016-04-06 19:40 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2016-05-12 02:29 - 2016-04-06 18:57 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-05-12 02:29 - 2016-04-06 18:52 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-05-12 02:29 - 2016-04-06 18:20 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2016-05-12 02:29 - 2016-04-06 17:48 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-05-12 02:28 - 2016-04-22 22:54 - 25816576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-05-12 02:28 - 2016-04-22 22:14 - 02893312 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-05-12 02:28 - 2016-04-22 22:08 - 06052864 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-05-12 02:28 - 2016-04-22 22:06 - 20349952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-05-12 02:28 - 2016-04-22 21:29 - 02285568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-05-12 02:28 - 2016-04-22 21:19 - 15414784 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-05-12 02:28 - 2016-04-22 20:54 - 13811200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-05-12 02:28 - 2016-04-22 20:52 - 02596864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-05-12 02:28 - 2016-04-22 20:40 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-05-12 02:28 - 2016-04-22 20:27 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-05-12 02:28 - 2016-04-22 20:24 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-05-12 02:28 - 2016-04-10 09:48 - 00738096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2016-05-12 02:28 - 2016-04-10 09:48 - 00613624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2016-05-12 02:28 - 2016-03-29 03:42 - 07446368 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-05-12 02:28 - 2016-02-27 20:28 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2016-05-12 02:28 - 2016-02-27 19:57 - 03273728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2016-05-12 02:28 - 2016-02-27 19:19 - 03820544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2016-05-12 02:28 - 2016-02-27 18:32 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2016-05-12 02:27 - 2016-04-22 22:15 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-05-12 02:27 - 2016-04-22 22:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-05-12 02:27 - 2016-04-22 21:35 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-05-12 02:27 - 2016-04-22 21:24 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2016-05-12 02:27 - 2016-04-22 21:23 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-05-12 02:27 - 2016-04-22 21:17 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-05-12 02:27 - 2016-04-22 21:14 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-05-12 02:27 - 2016-04-22 21:14 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-05-12 02:27 - 2016-04-22 21:14 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-05-12 02:27 - 2016-04-22 21:12 - 02131968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-05-12 02:27 - 2016-04-22 20:58 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-05-12 02:27 - 2016-04-22 20:58 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2016-05-12 02:27 - 2016-04-22 20:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-05-12 02:27 - 2016-04-22 20:52 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-05-12 02:27 - 2016-04-22 20:52 - 00330752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-05-12 02:27 - 2016-04-22 20:51 - 02056192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-05-12 02:27 - 2016-04-22 20:29 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-05-12 02:27 - 2016-04-22 20:23 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-05-12 02:25 - 2016-04-10 06:21 - 01763376 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2016-05-12 02:25 - 2016-04-10 06:21 - 01489088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2016-05-12 02:25 - 2016-04-10 06:14 - 01380600 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2016-05-12 02:25 - 2016-04-10 00:07 - 01097728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2016-05-12 02:25 - 2016-04-09 23:58 - 00534016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll 2016-05-12 02:25 - 2016-04-09 23:50 - 00375296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll 2016-05-12 02:25 - 2016-03-12 02:49 - 02466136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2016-05-12 02:25 - 2016-03-12 02:47 - 00160160 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL 2016-05-12 02:25 - 2016-03-10 19:03 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dsparse.dll 2016-05-12 02:25 - 2016-03-10 18:55 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2016-05-12 02:25 - 2016-03-10 18:48 - 00024064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsparse.dll 2016-05-12 02:25 - 2016-03-10 18:42 - 00413696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2016-05-12 02:25 - 2016-03-05 19:44 - 00148480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll 2016-05-12 02:25 - 2016-03-05 19:04 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll 2016-05-12 02:24 - 2016-04-11 08:21 - 00074584 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys 2016-05-12 02:24 - 2016-04-10 07:37 - 01549144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2016-05-12 02:24 - 2016-04-10 01:29 - 04169216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-05-12 02:24 - 2016-03-16 03:58 - 00442712 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-05-12 02:24 - 2016-03-16 03:58 - 00332632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-05-12 02:24 - 2016-03-14 18:50 - 00316760 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2016-05-12 02:24 - 2016-03-12 02:47 - 00121912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IPHLPAPI.DLL 2016-05-12 02:24 - 2016-03-10 18:52 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll 2016-05-11 09:27 - 2016-05-11 09:27 - 736571392 _____ C:\Users\Inga\Downloads\Mandriva Linux One 2009.iso 2016-05-11 09:24 - 2016-05-11 09:24 - 01018368 _____ ( ) C:\Users\Inga\Downloads\Mandriva Linux One 2009.exe 2016-05-11 09:22 - 2016-06-04 18:22 - 00000000 ____D C:\Users\Inga\AppData\Roaming\PriceFountainUpdateVer 2016-05-11 09:21 - 2016-06-05 23:28 - 00000000 ____D C:\Users\Inga\AppData\Roaming\Mozilla 2016-05-11 09:21 - 2016-06-04 23:09 - 00000000 ____D C:\ProgramData\Logic Handler 2016-05-11 09:21 - 2016-05-15 17:40 - 00002397 _____ C:\Windows\SysWOW64\findit.xml 2016-05-11 09:21 - 2016-05-11 09:21 - 06494208 _____ C:\Users\Inga\AppData\Roaming\agent.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 01626652 _____ C:\Users\Inga\AppData\Roaming\Alphais.tst 2016-05-11 09:21 - 2016-05-11 09:21 - 00127488 _____ C:\Users\Inga\AppData\Roaming\Installer.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 00126464 _____ C:\Users\Inga\AppData\Roaming\noah.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 00065232 _____ C:\Users\Inga\AppData\Roaming\Config.xml 2016-05-11 09:21 - 2016-05-11 09:21 - 00018432 _____ C:\Users\Inga\AppData\Roaming\Main.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 00014448 _____ C:\Users\Inga\AppData\Roaming\InstallationConfiguration.xml 2016-05-11 09:21 - 2016-05-11 09:21 - 00005568 _____ C:\Users\Inga\AppData\Roaming\md.xml 2016-05-11 09:20 - 2016-05-11 09:20 - 01018368 _____ ( ) C:\Users\Inga\Downloads\ImgBurn 2.5.8.0.exe 2016-05-11 09:05 - 2016-05-11 09:05 - 00000000 ____D C:\Users\Inga\AppData\Roaming\IDT 2016-05-10 18:12 - 2016-05-10 18:12 - 00000000 ____D C:\Users\Inga\Downloads\PSTools (1) 2016-05-10 18:08 - 2016-05-10 18:08 - 01686759 _____ C:\Users\Inga\Downloads\PSTools (1).zip 2016-05-10 18:01 - 2016-05-10 18:01 - 01686759 _____ C:\Users\Inga\Downloads\PSTools.zip 2016-05-10 18:01 - 2016-05-10 18:01 - 00000000 ____D C:\Users\Inga\Downloads\PSTools ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-06-07 08:08 - 2014-01-31 20:54 - 00000000 ____D C:\Users\Inga\AppData\Roaming\Spotify 2016-06-07 08:07 - 2013-12-22 21:40 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3135212574-2383626176-3544364843-1005 2016-06-07 08:04 - 2014-01-31 20:54 - 00000000 ____D C:\Users\Inga\AppData\Local\Spotify 2016-06-07 08:02 - 2014-04-25 07:30 - 00000384 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_0414c_rmv.job 2016-06-07 08:02 - 2014-04-25 07:30 - 00000384 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_0414c_rel.job 2016-06-07 08:02 - 2014-01-17 21:34 - 00000000 __RDO C:\Users\Inga\SkyDrive 2016-06-07 08:02 - 2013-11-30 17:29 - 00001062 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-06-07 08:01 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-06-07 08:01 - 2013-08-22 15:25 - 00524288 ___SH C:\Windows\system32\config\BBI 2016-06-07 07:58 - 2013-11-30 17:29 - 00001066 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-06-07 07:45 - 2013-08-22 17:36 - 00000000 ___HD C:\Windows\ELAMBKUP 2016-06-07 07:45 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf 2016-06-07 07:37 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\tracing 2016-06-07 07:36 - 2013-12-22 22:03 - 00000000 ____D C:\ProgramData\MFAData 2016-06-07 07:21 - 2013-12-22 21:36 - 00000000 ____D C:\Users\Inga\AppData\Roaming\Real 2016-06-07 07:21 - 2013-11-30 17:25 - 00000000 ____D C:\ProgramData\Real 2016-06-07 07:16 - 2014-01-10 12:24 - 00000000 ____D C:\ProgramData\Adobe 2016-06-07 06:18 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\ELAM 2016-06-07 06:09 - 2014-11-23 05:38 - 00000000 ____D C:\Users\Inga\Documents\ploks 2016-06-07 00:10 - 2013-12-22 21:28 - 00000000 ____D C:\Users\Inga 2016-06-06 20:06 - 2014-05-10 00:28 - 01673728 ___SH C:\Users\Inga\Desktop\Thumbs.db 2016-06-06 08:38 - 2013-10-09 14:34 - 00000000 ____D C:\ProgramData\Package Cache 2016-06-05 23:28 - 2013-11-30 17:02 - 00000000 ____D C:\Users\artur 2016-06-05 22:33 - 2013-09-19 19:02 - 01825074 _____ C:\Windows\system32\PerfStringBackup.INI 2016-06-05 22:33 - 2013-08-28 16:28 - 00807160 _____ C:\Windows\system32\perfh015.dat 2016-06-05 22:33 - 2013-08-28 16:28 - 00163478 _____ C:\Windows\system32\perfc015.dat 2016-06-05 22:29 - 2014-05-10 03:48 - 01191424 ___SH C:\Users\Inga\Downloads\Thumbs.db 2016-06-05 10:48 - 2015-03-12 04:56 - 00000000 ____D C:\Users\Inga\AppData\Local\Windows Live 2016-06-05 04:03 - 2014-01-17 21:30 - 00000000 ____D C:\Windows\Minidump 2016-06-05 04:02 - 2014-05-15 23:33 - 981013394 _____ C:\Windows\MEMORY.DMP 2016-06-04 10:50 - 2016-01-16 12:22 - 00003072 ____H C:\Users\Inga\Desktop\photothumb.db 2016-06-04 10:49 - 2015-08-27 20:30 - 00000000 ____D C:\Users\Inga\Desktop\ksiazki 2016-06-04 10:49 - 2015-07-08 23:24 - 00000000 ____D C:\Users\Inga\Desktop\dokumenty 2016-06-04 10:37 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness 2016-06-03 09:22 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps 2016-06-01 14:09 - 2015-10-30 21:56 - 00000000 ___HD C:\$WINDOWS.~BT 2016-06-01 13:14 - 2013-09-20 20:34 - 00000000 ____D C:\Windows\Panther 2016-05-31 07:08 - 2013-12-22 21:40 - 00003964 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{285A6F94-D24D-4978-97FD-B2723E66BCEA} 2016-05-30 06:20 - 2014-10-25 19:51 - 00000000 ____D C:\Users\Inga\Desktop\Szkoła 2016-05-29 01:22 - 2015-03-10 20:43 - 00000163 _____ C:\Users\Inga\AppData\Roaming\WB.CFG 2016-05-26 18:08 - 2015-09-28 23:56 - 00000000 ___RD C:\Users\Inga\Documents\Scanned Documents 2016-05-26 16:29 - 2014-11-21 03:50 - 00000000 ____D C:\Users\Inga\Desktop\przepisy 2016-05-26 06:05 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp 2016-05-26 05:58 - 2015-04-04 20:46 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2016-05-26 05:58 - 2015-04-04 20:46 - 00000000 ___SD C:\Windows\system32\GWX 2016-05-16 15:56 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache 2016-05-15 19:24 - 2013-12-22 21:35 - 00001465 _____ C:\Users\Inga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-05-15 19:24 - 2013-11-30 17:05 - 00001477 _____ C:\Users\artur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-05-15 18:11 - 2016-04-20 00:36 - 00002389 _____ C:\Users\Inga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive dla Firm.lnk 2016-05-15 18:11 - 2015-03-12 04:56 - 00003170 _____ C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3135212574-2383626176-3544364843-1005 2016-05-15 17:37 - 2013-08-22 16:44 - 00488048 _____ C:\Windows\system32\FNTCACHE.DAT 2016-05-15 17:28 - 2014-12-13 04:10 - 00000000 ____D C:\Windows\system32\appraiser 2016-05-15 17:28 - 2013-08-22 21:11 - 00000000 ____D C:\Program Files\Windows Journal 2016-05-13 03:52 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF 2016-05-13 03:19 - 2013-11-30 17:29 - 00002192 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-05-13 03:19 - 2013-11-30 17:29 - 00002180 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-05-12 02:54 - 2013-12-05 08:20 - 00000000 ____D C:\Windows\system32\MRT 2016-05-12 02:38 - 2013-12-05 08:20 - 139319312 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-05-12 02:21 - 2016-04-13 18:49 - 01737088 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-05-12 02:21 - 2016-04-13 18:49 - 01663184 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2016-05-12 02:21 - 2016-04-13 18:49 - 01523208 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2016-05-12 02:21 - 2016-04-13 18:49 - 01501488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-05-12 02:21 - 2016-04-13 18:49 - 01490120 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2016-05-12 02:21 - 2016-04-13 18:49 - 01358952 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2016-05-12 02:21 - 2016-04-13 18:49 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll 2016-05-11 08:55 - 2015-04-16 20:38 - 00000000 ____D C:\ProgramData\Oracle 2016-05-11 08:54 - 2016-03-31 06:12 - 00000000 ____D C:\Users\Inga\.oracle_jre_usage 2016-05-10 23:53 - 2013-11-30 17:29 - 00004038 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-05-10 23:53 - 2013-11-30 17:29 - 00003802 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-05-10 17:17 - 2014-03-06 16:38 - 00000000 ____D C:\Users\Inga\Documents\Pliki programu Outlook ==================== Pliki w katalogu głównym wybranych folderów ======= 2016-05-11 09:21 - 2016-05-11 09:21 - 6494208 _____ () C:\Users\Inga\AppData\Roaming\agent.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 1626652 _____ () C:\Users\Inga\AppData\Roaming\Alphais.tst 2016-05-11 09:21 - 2016-05-11 09:21 - 0065232 _____ () C:\Users\Inga\AppData\Roaming\Config.xml 2016-05-11 09:21 - 2016-05-11 09:21 - 0014448 _____ () C:\Users\Inga\AppData\Roaming\InstallationConfiguration.xml 2016-05-11 09:21 - 2016-05-11 09:21 - 0127488 _____ () C:\Users\Inga\AppData\Roaming\Installer.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 0018432 _____ () C:\Users\Inga\AppData\Roaming\Main.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 0005568 _____ () C:\Users\Inga\AppData\Roaming\md.xml 2016-05-11 09:21 - 2016-05-11 09:21 - 0126464 _____ () C:\Users\Inga\AppData\Roaming\noah.dat 2016-05-11 09:21 - 2016-05-11 09:21 - 0032038 _____ () C:\Users\Inga\AppData\Roaming\uninstall_temp.ico 2015-03-10 20:43 - 2016-05-29 01:22 - 0000163 _____ () C:\Users\Inga\AppData\Roaming\WB.CFG 2015-03-11 22:42 - 2015-03-11 22:42 - 0385602 _____ () C:\Users\Inga\AppData\Local\5D515C96_stp.CIS 2015-03-11 22:42 - 2015-03-11 22:42 - 0000220 _____ () C:\Users\Inga\AppData\Local\5D515C96_stp.CIS.part 2015-03-12 02:51 - 2015-04-03 05:04 - 0005632 _____ () C:\Users\Inga\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-05-05 21:47 - 2016-05-05 21:47 - 0003270 _____ () C:\Users\Inga\AppData\Local\recently-used.xbel 2014-02-16 16:41 - 2016-04-21 00:51 - 4776856 _____ ((c) PC Cleaners Inc) C:\ProgramData\pclunst.exe Pliki do przeniesienia lub usunięcia: ==================== C:\ProgramData\pclunst.exe Niektóre pliki w TEMP: ==================== C:\Users\artur\AppData\Local\Temp\lowproc.exe C:\Users\artur\AppData\Local\Temp\ose00000.exe C:\Users\artur\AppData\Local\Temp\stubhelper.dll C:\Users\Inga\AppData\Local\Temp\AdBlock_instalator_sciagnij.exe C:\Users\Inga\AppData\Local\Temp\appshat_generic.exe C:\Users\Inga\AppData\Local\Temp\avgnt.exe C:\Users\Inga\AppData\Local\Temp\cabex.dll C:\Users\Inga\AppData\Local\Temp\DataCard_Setup64.exe C:\Users\Inga\AppData\Local\Temp\dfr334B.tmp.exe C:\Users\Inga\AppData\Local\Temp\dfrC2DE.tmp.exe C:\Users\Inga\AppData\Local\Temp\FreemakeVideoConverterFull.exe C:\Users\Inga\AppData\Local\Temp\FreeVideoEditor.exe C:\Users\Inga\AppData\Local\Temp\ICReinstall_greys-anatomy-crash-into-me-part-2-pol-4.exe C:\Users\Inga\AppData\Local\Temp\jre-8u60-windows-au.exe C:\Users\Inga\AppData\Local\Temp\jre-8u71-windows-au.exe C:\Users\Inga\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Inga\AppData\Local\Temp\jre-8u91-windows-au.exe C:\Users\Inga\AppData\Local\Temp\pcup10676.exe C:\Users\Inga\AppData\Local\Temp\pcup11697.exe C:\Users\Inga\AppData\Local\Temp\pcup12130.exe C:\Users\Inga\AppData\Local\Temp\pcup12138.exe C:\Users\Inga\AppData\Local\Temp\pcup1351.exe C:\Users\Inga\AppData\Local\Temp\pcup13535.exe C:\Users\Inga\AppData\Local\Temp\pcup14213.exe C:\Users\Inga\AppData\Local\Temp\pcup14267.exe C:\Users\Inga\AppData\Local\Temp\pcup14647.exe C:\Users\Inga\AppData\Local\Temp\pcup15139.exe C:\Users\Inga\AppData\Local\Temp\pcup15351.exe C:\Users\Inga\AppData\Local\Temp\pcup15437.exe C:\Users\Inga\AppData\Local\Temp\pcup15537.exe C:\Users\Inga\AppData\Local\Temp\pcup16017.exe C:\Users\Inga\AppData\Local\Temp\pcup16226.exe C:\Users\Inga\AppData\Local\Temp\pcup16238.exe C:\Users\Inga\AppData\Local\Temp\pcup16495.exe C:\Users\Inga\AppData\Local\Temp\pcup17172.exe C:\Users\Inga\AppData\Local\Temp\pcup17705.exe C:\Users\Inga\AppData\Local\Temp\pcup20196.exe C:\Users\Inga\AppData\Local\Temp\pcup2084.exe C:\Users\Inga\AppData\Local\Temp\pcup21494.exe C:\Users\Inga\AppData\Local\Temp\pcup22029.exe C:\Users\Inga\AppData\Local\Temp\pcup24095.exe C:\Users\Inga\AppData\Local\Temp\pcup24366.exe C:\Users\Inga\AppData\Local\Temp\pcup24397.exe C:\Users\Inga\AppData\Local\Temp\pcup25371.exe C:\Users\Inga\AppData\Local\Temp\pcup25494.exe C:\Users\Inga\AppData\Local\Temp\pcup25561.exe C:\Users\Inga\AppData\Local\Temp\pcup25922.exe C:\Users\Inga\AppData\Local\Temp\pcup26361.exe C:\Users\Inga\AppData\Local\Temp\pcup27096.exe C:\Users\Inga\AppData\Local\Temp\pcup27211.exe C:\Users\Inga\AppData\Local\Temp\pcup27752.exe C:\Users\Inga\AppData\Local\Temp\pcup28871.exe C:\Users\Inga\AppData\Local\Temp\pcup30284.exe C:\Users\Inga\AppData\Local\Temp\pcup30962.exe C:\Users\Inga\AppData\Local\Temp\pcup4742.exe C:\Users\Inga\AppData\Local\Temp\pcup5522.exe C:\Users\Inga\AppData\Local\Temp\pcup7005.exe C:\Users\Inga\AppData\Local\Temp\pcup8520.exe C:\Users\Inga\AppData\Local\Temp\Quarantine.exe C:\Users\Inga\AppData\Local\Temp\ResetDevice.exe C:\Users\Inga\AppData\Local\Temp\setup.exe C:\Users\Inga\AppData\Local\Temp\SHSetup.exe C:\Users\Inga\AppData\Local\Temp\sqlite3.dll C:\Users\Inga\AppData\Local\Temp\SupplyVapidity.dll C:\Users\Inga\AppData\Local\Temp\tu17p84.exe C:\Users\Inga\AppData\Local\Temp\unelevate.exe C:\Users\Inga\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe C:\Users\Inga\AppData\Local\Temp\~extncp01.exe C:\Users\Inga\AppData\Local\Temp\~extncp18467.exe ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2016-06-01 03:21 ==================== Koniec FRST.txt ============================