Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 29-06-2016 Uruchomiony przez R (administrator) R-KOMPUTER (01-07-2016 16:24:14) Uruchomiony z C:\Users\R\Desktop Załadowane profile: R (Dostępne profile: R) Platform: Windows 7 Professional Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka nie została wykryta!) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe () C:\Windows\SysWOW64\srvany.exe () C:\Windows\KMService.exe (DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe () C:\Program Files (x86)\Wifisrv\WifiService.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avpui.exe (DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCTray.exe (DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCTray64.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Jerzy Znamirowski) C:\Program Files (x86)\HEXelon MAX 6\hexelon.exe (Sony) C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe (Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SOLIDWORKS (2)\sldworks_fs.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe (Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe (Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe (Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe (Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe (Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe (Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe (Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe (Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-05-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2770432 2016-02-12] (VIA) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2380480 2016-06-08] (Adobe Systems Incorporated) HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.) HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4177784 2016-01-15] (Disc Soft Ltd) HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [3670472 2015-07-28] (ALLPlayer Group Ltd.) HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\Run: [Napisy24Update] => "C:\Program Files (x86)\Napisy24\Napisy24Update.exe" "sleep" HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\Run: [HEXelon MAX] => C:\Program Files (x86)\HEXelon MAX 6\hexelon.exe [2816512 2007-06-28] (Jerzy Znamirowski) HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\Run: [XperiaCompanionAgent] => C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [2033536 2016-04-11] (Sony) HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\Run: [XperiaCompanion] => C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [2033536 2016-04-11] (Sony) HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\MountPoints2: {773f850a-dbd0-11e5-866d-00e04c156405} - G:\SETUP.EXE HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\MountPoints2: {773f8750-dbd0-11e5-866d-00e04c156405} - H:\SETUP.EXE HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\MountPoints2: {9537ef81-11e6-11e6-97ba-00e04c156405} - G:\setup.exe HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\...\MountPoints2: {f17c0ad1-064f-11e6-a4ad-00e04c156405} - G:\Startme.exe ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] () ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2009-02-09] (Autodesk, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk [2016-04-25] ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks 2013 Fast Start.lnk [2016-02-25] ShortcutTarget: SolidWorks 2013 Fast Start.lnk -> C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS 2016 Fast Start.lnk [2016-03-23] ShortcutTarget: SOLIDWORKS 2016 Fast Start.lnk -> C:\Windows\Installer\{768F3B65-1695-47B7-9002-B11400CB111D}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Pobieracz w tle.lnk [2016-03-23] ShortcutTarget: SolidWorks Pobieracz w tle.lnk -> C:\Program Files (x86)\Common Files\Menedżer instalacji SOLIDWORKS\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 Tcpip\..\Interfaces\{D9CC1A1A-B0F1-48E5-84FD-35925B2E4032}: [DhcpNameServer] 192.168.100.1 Internet Explorer: ================== HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-2593204490-2210076326-4199956363-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.bing.com/search?q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope - brak wartości BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2015-12-07] (AO Kaspersky Lab) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-28] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO-x32: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-12-07] (AO Kaspersky Lab) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-28] (Oracle Corporation) Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2015-12-07] (AO Kaspersky Lab) Toolbar: HKLM-x32 - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-12-07] (AO Kaspersky Lab) FireFox: ======== FF ProfilePath: C:\Users\R\AppData\Roaming\Mozilla\Firefox\Profiles\0vhexfq5.default FF Homepage: search.mpc.am FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_192.dll [2016-06-17] () FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-06-08] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_192.dll [2016-06-17] () FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-28] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-28] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-27] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-06-08] (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-05-27] (Adobe Systems Inc.) FF Extension: Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox [2016-06-29] FF HKLM-x32\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox Chrome: ======= CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka CHR HKLM-x32\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [737984 2016-06-03] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2021592 2016-04-05] (Adobe Systems, Incorporated) R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego] R2 AVP16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe [194000 2015-12-07] (Kaspersky Lab ZAO) S3 CoordinatorServiceHost; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS (2)\swScheduler\DTSCoordinatorService.exe [80792 2016-02-10] (Dassault Systèmes SolidWorks Corporation) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1369464 2016-01-15] (Disc Soft Ltd) R2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2016-03-23] () [Brak podpisu cyfrowego] R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [350688 2016-06-27] (DotC United Inc) S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [1050904 2013-12-11] () [Brak podpisu cyfrowego] S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2016-02-25] (SolidWorks) [Brak podpisu cyfrowego] R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2016-02-17] (VIA Technologies, Inc.) S3 vssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\vssbridge64.exe [144640 2015-07-09] (AO Kaspersky Lab) R2 WifiSrv; C:\Program Files (x86)\Wifisrv\WifiService.exe [219392 2015-12-16] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-01-18] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R1 160WifiNetPro; C:\Program Files (x86)\Wifisrv\160WifiNetPro64.sys [129784 2015-12-16] () R0 amdide64; C:\Windows\System32\DRIVERS\amdide64.sys [11944 2016-02-17] (Advanced Micro Devices Inc.) R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO) R3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [33592 2016-02-17] (Dev47Apps) R3 DroidCamVideo; C:\Windows\System32\DRIVERS\droidcamvideo.sys [229432 2016-02-17] (Dev47Apps) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-02-18] (Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-02-18] (Disc Soft Ltd) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2016-04-19] (Sony Mobile Communications) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-17] (REALiX(tm)) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-22] (Kaspersky Lab ZAO) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [70000 2015-06-27] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [77728 2016-06-29] (AO Kaspersky Lab) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [181640 2015-12-07] (AO Kaspersky Lab) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [237480 2016-06-28] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [943536 2016-06-29] (AO Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [49240 2016-06-29] (AO Kaspersky Lab) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [41144 2015-06-06] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [41352 2015-12-07] (AO Kaspersky Lab) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-06-11] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [103096 2015-06-16] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [187056 2015-06-23] (Kaspersky Lab ZAO) R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-06-27] (DotC United Inc) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2016-02-17] () U5 RegDeleteEx; C:\Windows\system32\drivers\RegDeleteEx.sys [14456 2016-06-29] (NoVirusThanks Company Srl) R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation ) R0 wifinetmini; C:\Windows\System32\wifinetmini64.sys [16624 2015-12-02] () R0 WofAdk; C:\Windows\System32\drivers\wofadk.sys [221888 2015-10-29] (Microsoft Corporation) U4 klkbdflt2; system32\DRIVERS\klkbdflt2.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-07-01 16:23 - 2016-07-01 16:23 - 00000000 ____D C:\Users\R\Desktop\Stare dane programu Firefox 2016-07-01 16:19 - 2016-07-01 16:19 - 00010571 _____ C:\Users\R\Desktop\bookmarks.html 2016-07-01 16:19 - 2016-07-01 16:19 - 00006300 _____ C:\Users\R\Desktop\bookmarks-2016-07-01.json 2016-07-01 16:10 - 2016-07-01 16:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC 2016-06-30 23:49 - 2016-06-30 23:49 - 00001089 _____ C:\Users\R\Downloads\wynik_zlecenia_8554300911.csv 2016-06-30 22:57 - 2016-06-30 22:57 - 00000073 _____ C:\Users\R\Downloads\wyniki_badania_STAWSKI_RAFAŁ_OB.csv 2016-06-30 22:11 - 2016-06-30 22:11 - 00000491 _____ C:\Users\R\Downloads\wyniki_badania_STAWSKI_RAFAŁ_Morfologia_krwi.csv 2016-06-29 21:14 - 2016-06-29 21:14 - 00408188 _____ C:\Users\R\Downloads\5_Zal_B_Tab_Oplat_i_Prowizji (1).pdf 2016-06-29 21:12 - 2016-06-29 21:12 - 00000000 ____D C:\Users\R\AppData\Roaming\MCorp 2016-06-29 21:07 - 2016-06-29 21:07 - 00003623 _____ C:\Users\R\Desktop\AdwCleaner[C11].txt 2016-06-29 21:05 - 2016-06-29 21:05 - 00003450 _____ C:\Users\R\Desktop\AdwCleaner[S14].txt 2016-06-29 21:02 - 2016-07-01 16:10 - 00000000 ____D C:\ProgramData\boost_interprocess 2016-06-29 20:38 - 2016-06-29 20:38 - 00000000 ____D C:\Users\R\Documents\Pliki programu Outlook 2016-06-29 20:27 - 2016-06-29 20:27 - 00000000 ____D C:\Users\R\Desktop\a 2016-06-29 20:22 - 2016-06-30 16:24 - 00019100 _____ C:\Users\R\Desktop\Fixlog.txt 2016-06-29 20:22 - 2016-06-29 20:22 - 00000000 ____D C:\Users\R\Desktop\FRST-OlderVersion 2016-06-29 20:12 - 2016-06-29 20:12 - 00000000 ____D C:\Program Files (x86)\rukeoy7z 2016-06-29 20:00 - 2016-06-29 20:00 - 00014456 _____ (NoVirusThanks Company Srl) C:\Windows\system32\Drivers\RegDeleteEx.sys 2016-06-29 19:55 - 2016-06-29 19:55 - 00001085 _____ C:\Users\R\Desktop\Registry DeleteEx.lnk 2016-06-29 19:55 - 2016-06-29 19:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NoVirusThanks 2016-06-29 19:55 - 2016-06-29 19:55 - 00000000 ____D C:\Program Files\NoVirusThanks 2016-06-29 19:54 - 2016-06-29 19:54 - 01351456 _____ (NoVirusThanks Company Srl ) C:\Users\R\Desktop\registry_deleteex_setup.exe 2016-06-29 19:34 - 2016-06-29 19:34 - 00408188 _____ C:\Users\R\Downloads\5_Zal_B_Tab_Oplat_i_Prowizji.pdf 2016-06-29 18:45 - 2016-06-29 18:45 - 00341034 _____ C:\Users\R\Desktop\gmer.txt 2016-06-29 18:22 - 2016-06-29 21:09 - 00062209 _____ C:\Users\R\Desktop\Shortcut.txt 2016-06-29 18:22 - 2016-06-29 18:22 - 00380928 _____ C:\Users\R\Desktop\ilclow41.exe 2016-06-29 18:21 - 2016-06-29 21:09 - 00037592 _____ C:\Users\R\Desktop\Addition.txt 2016-06-29 18:20 - 2016-07-01 16:24 - 00021013 _____ C:\Users\R\Desktop\FRST.txt 2016-06-29 18:19 - 2016-07-01 16:24 - 00000000 ____D C:\FRST 2016-06-29 18:19 - 2016-06-29 20:22 - 02390016 _____ (Farbar) C:\Users\R\Desktop\FRST64.exe 2016-06-28 23:57 - 2016-07-01 16:23 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2016-06-28 23:57 - 2016-06-29 00:09 - 00943536 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2016-06-28 23:57 - 2016-06-28 23:57 - 00002442 _____ C:\Users\R\Desktop\Bezpieczne pieniądze.lnk 2016-06-28 23:57 - 2016-06-28 23:57 - 00002150 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2016-06-28 23:57 - 2016-06-28 23:57 - 00000000 ____D C:\Windows\ELAMBKUP 2016-06-28 23:57 - 2016-06-28 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2016-06-28 23:57 - 2016-06-28 23:57 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2016-06-28 23:57 - 2015-12-07 19:54 - 00181640 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2016-06-28 23:57 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2016-06-28 23:55 - 2016-06-28 23:56 - 162692312 _____ (Kaspersky Lab) C:\Users\R\Downloads\kis16.0.0.614pl-pl.exe 2016-06-28 23:52 - 2016-06-28 23:54 - 00000000 ____D C:\Users\R\AppData\Roaming\Winamp 2016-06-28 23:52 - 2016-06-28 23:52 - 00000993 _____ C:\Users\Public\Desktop\Winamp.lnk 2016-06-28 23:52 - 2016-06-28 23:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp 2016-06-28 23:52 - 2016-06-28 23:52 - 00000000 ____D C:\Program Files (x86)\Winamp 2016-06-28 23:52 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2016-06-28 23:52 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2016-06-28 23:51 - 2016-06-28 23:51 - 17163336 _____ (Nullsoft, Inc.) C:\Users\R\Downloads\winamp5666_full_all.exe 2016-06-28 20:25 - 2016-06-28 20:25 - 00098246 _____ C:\Users\R\Downloads\Biznes-plan_Stanisław Stawski (2).odt 2016-06-28 20:07 - 2016-06-28 20:07 - 00098246 _____ C:\Users\R\Downloads\Biznes-plan_Stanisław Stawski.odt 2016-06-28 20:07 - 2016-06-28 20:07 - 00098246 _____ C:\Users\R\Downloads\Biznes-plan_Stanisław Stawski (1).odt 2016-06-28 18:56 - 2016-06-28 18:56 - 02870984 _____ (ESET) C:\Users\R\Desktop\esetsmartinstaller_plk.exe 2016-06-28 18:56 - 2016-06-28 18:56 - 00000000 ____D C:\Program Files (x86)\ESET 2016-06-28 18:46 - 2016-06-28 18:47 - 00000000 ____D C:\Users\R\Desktop\załączniki 2016-06-27 19:48 - 2016-06-27 19:48 - 03703360 _____ C:\Users\R\Desktop\adwcleaner_5.200.exe 2016-06-27 19:24 - 2016-06-27 19:24 - 00000000 ____D C:\Windows\system32\fis 2016-06-27 19:23 - 2016-05-26 10:51 - 04761392 _____ () C:\Users\R\AppData\Roaming\usbboxlite_4001_o_8209_hn.exe 2016-06-27 19:22 - 2016-06-27 19:22 - 00000000 ____D C:\ProgramData\160WiFi 2016-06-27 19:21 - 2016-06-27 19:25 - 00000000 ____D C:\Program Files (x86)\Wifisrv 2016-06-27 19:21 - 2016-06-27 19:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\160WiFi 2016-06-27 19:21 - 2016-05-16 08:57 - 10167000 _____ (深圳市驱动人生软件技术有限公司) C:\Users\R\AppData\Roaming\160wifi_wcid-6089.exe 2016-06-27 19:21 - 2015-12-02 04:24 - 00238080 ____R C:\Windows\system32\wifinetinit64.dll 2016-06-27 19:21 - 2015-12-02 04:24 - 00016624 ____R C:\Windows\system32\wifinetmini64.sys 2016-06-27 19:16 - 2016-06-30 16:15 - 00000000 ____D C:\Program Files (x86)\mpck 2016-06-27 19:16 - 2016-06-29 15:45 - 00000000 ____D C:\Users\R\AppData\Local\Apps\2.0 2016-06-27 19:14 - 2016-06-28 23:08 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner 2016-06-27 19:14 - 2016-06-27 19:17 - 00060136 ____N (DotC United Inc) C:\Windows\system32\Drivers\MPCKpt.sys 2016-06-27 19:05 - 2016-06-27 19:05 - 04571912 _____ C:\Users\R\Downloads\removewat-2-2-7_downloader.exe 2016-06-23 20:22 - 2016-06-23 20:22 - 00000000 ____D C:\Users\R\Desktop\zrzut pen drive 2016-06-23 16:35 - 2016-06-23 16:35 - 02745975 _____ C:\Users\R\Downloads\Presentation_Group_Nokia_Alcatel_Lucent_Poland_20160419-1 (1).pdf 2016-06-23 16:10 - 2016-06-23 16:10 - 02745975 _____ C:\Users\R\Downloads\Presentation_Group_Nokia_Alcatel_Lucent_Poland_20160419-1.pdf 2016-06-23 16:10 - 2016-06-23 16:10 - 00275238 _____ C:\Users\R\Downloads\NATEK presentation - Work IT with us 20160606.pdf 2016-06-23 16:09 - 2016-06-23 16:09 - 00045933 _____ C:\Users\R\Downloads\Affidavit Letter.odt 2016-06-22 21:17 - 2016-06-22 21:17 - 00919367 _____ C:\Users\R\Downloads\Regulamin przyznawania środków finansowych na rozwój przedsiębiorczości (2).pdf 2016-06-22 21:16 - 2016-06-22 21:16 - 00919367 _____ C:\Users\R\Downloads\Regulamin przyznawania środków finansowych na rozwój przedsiębiorczości (1).pdf 2016-06-22 17:48 - 2016-06-22 17:48 - 00207605 _____ C:\Users\R\Downloads\576ab3584aa59.pdf 2016-06-22 17:48 - 2016-06-22 17:48 - 00095258 _____ C:\Users\R\Downloads\Gwarancja (1).pdf 2016-06-21 22:11 - 2016-06-21 22:11 - 00919367 _____ C:\Users\R\Downloads\Regulamin przyznawania środków finansowych na rozwój przedsiębiorczości.pdf 2016-06-21 20:56 - 2016-06-21 20:56 - 00228400 _____ C:\Users\R\Downloads\biznesplan dla wypożyczalni sprzętu rowerowego.pdf 2016-06-21 17:10 - 2016-06-21 17:12 - 00000000 ____D C:\Users\R\Desktop\zrzut sandisk 2016-06-21 17:05 - 2016-06-21 17:06 - 00000000 ____D C:\Users\R\Desktop\ZRZUT KRZYS PENDRIVE 2016-06-21 17:05 - 2016-06-21 17:05 - 00000000 ____D C:\Users\R\Desktop\BERTSCH SPRAWDZIC 2016-06-21 16:54 - 2016-06-21 16:54 - 00095258 _____ C:\Users\R\Downloads\Gwarancja.pdf 2016-06-21 16:52 - 2016-06-21 16:52 - 00207599 _____ C:\Users\R\Downloads\faktura_1000272532.pdf 2016-06-20 20:02 - 2016-06-21 17:15 - 00000000 ____D C:\Users\R\Desktop\InTechMet 2016-06-20 19:51 - 2016-06-20 20:02 - 00000000 ____D C:\Users\R\Desktop\Anwil różne 2016-06-17 17:35 - 2016-06-17 17:35 - 00036579 _____ C:\Users\R\Downloads\b14.jpeg 2016-06-17 16:41 - 2015-11-03 22:33 - 13369305 _____ C:\Users\R\Desktop\John Walkenbach - Excel 2013 PL. Programowanie w VBA dla bystrzaków - Wydanie III [Ebook PL].pdf 2016-06-16 21:55 - 2016-06-16 21:55 - 03703360 _____ C:\Users\R\Desktop\adwcleaner.pl 5.200.exe 2016-06-16 17:43 - 2016-06-20 19:56 - 00000000 ____D C:\Users\R\Desktop\przydatne 2016-06-13 21:33 - 2016-06-20 20:12 - 00000000 ____D C:\Users\R\Desktop\Zrzut pen drive 13-06-2016 2016-06-13 21:18 - 2016-06-13 21:18 - 00000000 ____D C:\Users\R\Downloads\Boguslaw.woloszanski.-.zolnierze.honoru._sluchowisko.pl_._up.by.equalizer_ 2016-06-13 19:16 - 2016-06-13 19:16 - 01526190 _____ C:\Users\R\Downloads\CV_Rafał Stawski_PL.pdf 2016-06-13 17:31 - 2016-06-13 21:17 - 946036221 _____ C:\Users\R\Downloads\Boguslaw.woloszanski.-.zolnierze.honoru._sluchowisko.pl_._up.by.equalizer_.rar 2016-06-12 23:15 - 2016-06-12 23:15 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2016-06-07 17:40 - 2016-06-07 17:40 - 00001044 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk 2016-06-07 17:40 - 2016-06-07 17:40 - 00000000 ____D C:\Users\R\Documents\Adobe 2016-06-07 17:33 - 2016-06-07 17:45 - 00000000 ____D C:\Program Files\Common Files\Adobe 2016-06-07 17:33 - 2016-06-07 17:33 - 00002211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CC 2015.lnk 2016-06-07 17:32 - 2016-06-07 17:42 - 00000000 ____D C:\Program Files\Adobe 2016-06-07 17:30 - 2016-06-07 17:30 - 00798912 _____ (Adobe Systems Incorporated) C:\Users\R\Downloads\CreativeCloudSet-Up (4).exe 2016-06-07 17:13 - 2016-06-07 17:13 - 00798912 _____ (Adobe Systems Incorporated) C:\Users\R\Downloads\CreativeCloudSet-Up (3).exe 2016-06-07 17:09 - 2016-06-07 17:09 - 00798912 _____ (Adobe Systems Incorporated) C:\Users\R\Downloads\CreativeCloudSet-Up (2).exe 2016-06-07 16:45 - 2016-06-07 16:45 - 01839904 _____ C:\Users\R\Downloads\crack.zip 2016-06-07 16:45 - 2016-06-07 16:45 - 00000000 ____D C:\Users\R\Downloads\crack 2016-06-07 16:32 - 2016-06-07 16:32 - 00798912 _____ (Adobe Systems Incorporated) C:\Users\R\Downloads\CreativeCloudSet-Up (1).exe 2016-06-07 16:29 - 2016-07-01 16:10 - 00000000 ___RD C:\Users\R\Creative Cloud Files 2016-06-07 16:27 - 2016-06-07 16:27 - 00000000 ____D C:\Users\R\Documents\Moje palety 2016-06-07 16:22 - 2016-06-07 16:22 - 00000000 ____D C:\Program Files (x86)\gs 2016-06-07 16:21 - 2016-06-07 16:21 - 00000000 ____D C:\Users\Public\Documents\Corel 2016-06-07 16:21 - 2016-06-07 16:21 - 00000000 ____D C:\ProgramData\VsTelemetry 2016-06-07 16:20 - 2016-06-07 16:25 - 00000000 ____D C:\Users\R\Documents\Corel 2016-06-07 16:20 - 2016-06-07 16:24 - 00000000 ____D C:\ProgramData\Corel 2016-06-07 16:20 - 2016-06-07 16:23 - 00000000 ____D C:\Users\R\AppData\Roaming\Corel 2016-06-07 16:18 - 2016-06-07 16:18 - 12504256 _____ (Corel Corporation) C:\Users\R\Downloads\CorelDRAWGraphicsSuiteX8Installer_RW.exe 2016-06-07 16:18 - 2016-06-07 16:18 - 00000000 ____D C:\ProgramData\UniqueId 2016-06-01 19:27 - 2016-06-01 19:27 - 02771494 _____ C:\Users\R\Downloads\screamer044.exe 2016-06-01 19:27 - 2016-06-01 19:27 - 00000000 ____D C:\Users\R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Screamer Radio 2016-06-01 19:27 - 2016-06-01 19:27 - 00000000 ____D C:\Users\R\AppData\Local\Screamer Radio ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-07-01 16:12 - 2011-04-12 14:17 - 00739694 _____ C:\Windows\system32\perfh015.dat 2016-07-01 16:12 - 2011-04-12 14:17 - 00155268 _____ C:\Windows\system32\perfc015.dat 2016-07-01 16:12 - 2009-07-14 07:13 - 01668226 _____ C:\Windows\system32\PerfStringBackup.INI 2016-07-01 16:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-07-01 16:10 - 2016-02-18 18:08 - 00000000 ____D C:\Users\R\AppData\Local\Adobe 2016-07-01 16:10 - 2016-02-12 18:36 - 00000000 ____D C:\Users\R\AppData\Roaming\Skype 2016-07-01 16:08 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-07-01 16:08 - 2009-07-14 06:45 - 00036768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-07-01 16:08 - 2009-07-14 06:45 - 00036768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-06-30 23:58 - 2016-05-18 18:14 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-06-29 21:06 - 2016-02-17 00:45 - 00000000 ____D C:\AdwCleaner 2016-06-29 21:00 - 2016-02-12 18:48 - 00000000 ____D C:\Windows\Minidump 2016-06-29 19:15 - 2016-02-12 18:48 - 1512010345 _____ C:\Windows\MEMORY.DMP 2016-06-29 00:09 - 2015-06-11 19:32 - 00049240 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klim6.sys 2016-06-29 00:09 - 2015-06-06 08:51 - 00077728 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\kldisk.sys 2016-06-28 23:59 - 2015-12-07 19:54 - 00237480 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys 2016-06-28 23:42 - 2011-04-12 14:24 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-06-28 23:15 - 2016-02-18 17:21 - 00000000 ____D C:\Users\R\AppData\Local\CrashDumps 2016-06-27 19:24 - 2016-02-18 23:59 - 00001008 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2016-06-27 19:24 - 2016-02-18 23:59 - 00000996 _____ C:\Users\Public\Desktop\Opera.lnk 2016-06-27 19:24 - 2016-02-14 23:19 - 00000997 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-06-27 19:24 - 2016-02-12 18:33 - 00001001 _____ C:\Users\R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-06-27 19:11 - 2016-02-14 23:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-06-21 20:54 - 2016-03-07 19:13 - 00000000 ____D C:\Users\R\Desktop\Dokumenty firma- projekt 2016-06-21 16:23 - 2016-05-11 20:23 - 00000108 _____ C:\Users\R\AppData\Roaming\WB.CFG 2016-06-20 20:02 - 2016-03-22 23:18 - 00000000 ____D C:\Users\R\Desktop\SPRAWA SĄDOWA 2016-06-20 20:02 - 2016-03-06 22:44 - 00000000 ____D C:\Users\R\Desktop\Działka 2016-06-19 21:33 - 2016-02-24 18:04 - 00000992 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-06-17 19:58 - 2016-05-18 18:14 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-06-17 19:58 - 2016-02-24 18:04 - 00003982 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2016-06-17 19:58 - 2016-02-18 18:08 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-06-17 19:58 - 2016-02-18 18:08 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-06-15 16:19 - 2016-02-18 23:59 - 00003892 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1455832776 2016-06-15 16:19 - 2016-02-18 23:59 - 00000000 ____D C:\Program Files (x86)\Opera 2016-06-12 23:17 - 2016-02-17 00:03 - 00000037 _____ C:\ProgramData\droidcam-settings 2016-06-12 23:15 - 2016-02-22 22:52 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-06-12 23:15 - 2016-02-14 23:14 - 00000000 ____D C:\ProgramData\Package Cache 2016-06-07 20:47 - 2016-02-12 18:33 - 00000000 ____D C:\Users\R 2016-06-07 17:45 - 2016-03-10 19:53 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2016-06-07 17:45 - 2016-02-12 18:33 - 00000000 ____D C:\Users\R\AppData\Roaming\Adobe 2016-06-07 17:38 - 2016-02-22 22:51 - 00000000 ____D C:\ProgramData\Adobe 2016-06-07 17:28 - 2016-02-25 20:43 - 00000000 ____D C:\Temp 2016-06-07 17:27 - 2016-02-12 18:24 - 00612664 _____ C:\Windows\system32\FNTCACHE.DAT 2016-06-07 17:10 - 2016-02-12 18:33 - 00000000 ____D C:\Users\R\AppData\Local\VirtualStore 2016-06-07 16:22 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2016-06-07 16:20 - 2016-02-12 19:25 - 00178280 _____ C:\Users\R\AppData\Local\GDIPFONTCACHEV1.DAT 2016-06-07 15:57 - 2016-03-10 19:51 - 00000000 ___RD C:\Users\R\diablo00080@wp.pl Creative Cloud Files 2016-06-07 15:56 - 2016-02-18 22:47 - 00000000 ____D C:\Users\R\AppData\Roaming\GG 2016-06-02 23:25 - 2016-02-18 22:46 - 00000000 ____D C:\Users\R\AppData\Local\GG 2016-06-02 21:23 - 2016-02-22 22:52 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk ==================== Pliki w katalogu głównym wybranych folderów ======= 2016-06-27 19:21 - 2016-05-16 08:57 - 10167000 _____ (深圳市驱动人生软件技术有限公司) C:\Users\R\AppData\Roaming\160wifi_wcid-6089.exe 2016-03-10 19:53 - 2016-04-20 16:16 - 0000034 _____ () C:\Users\R\AppData\Roaming\AdobeWLCMCache.dat 2016-06-27 19:23 - 2016-05-26 10:51 - 4761392 _____ () C:\Users\R\AppData\Roaming\usbboxlite_4001_o_8209_hn.exe 2016-05-11 20:23 - 2016-06-21 16:23 - 0000108 _____ () C:\Users\R\AppData\Roaming\WB.CFG 2016-02-17 00:03 - 2016-06-12 23:17 - 0000037 _____ () C:\ProgramData\droidcam-settings Niektóre pliki w TEMP: ==================== C:\Users\R\AppData\Local\Temp\libeay32.dll C:\Users\R\AppData\Local\Temp\msvcr120.dll C:\Users\R\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2016-06-27 17:44 ==================== Koniec FRST.txt ============================