Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja: 17-08-2016 Uruchomiony przez XP (administrator) WINDOWS-XP (18-08-2016 19:01:50) Uruchomiony z C:\Documents and Settings\XP\Moje dokumenty Załadowane profile: XP (Dostępne profile: XP & UpdatusUser & Administrator) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) Język: Polski Internet Explorer Wersja 8 (Domyślna przeglądarka: Opera) Tryb startu: Safe Mode (with Networking) Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [40995440 2010-12-17] (VIA Technologies, Inc.) HKLM\...\Run: [NUSB3MON] => C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1632360 2011-07-05] () HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeCS5ServiceManager] => C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7408312 2016-06-27] (AVAST Software) HKU\S-1-5-21-789336058-492894223-682003330-1003\...\Run: [Akamai NetSession Interface] => C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.) HKU\S-1-5-21-789336058-492894223-682003330-1003\...\Run: [Avast-Browser-Cleanup] => C:\Program Files\AVAST Software\Avast\BrowserCleanup.exe [1503712 2016-05-30] (AVAST Software) HKU\S-1-5-21-789336058-492894223-682003330-1003\...\Run: [Skype] => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun HKU\S-1-5-21-789336058-492894223-682003330-1003\...\MountPoints2: {55f74b1e-5b2e-11e1-bf49-5404a67eb4f7} - L:\SETUP.EXE HKU\S-1-5-21-789336058-492894223-682003330-1003\...\MountPoints2: {a091e4e2-0f5c-11e4-86c8-5404a67eb4f7} - K:\LG_PC_Programs.exe HKU\S-1-5-21-789336058-492894223-682003330-1003\...\MountPoints2: {a9a8177c-608e-11e5-89d1-00ace9a96da8} - K:\autorun.exe HKU\S-1-5-21-789336058-492894223-682003330-1003\...\MountPoints2: {f6b6870a-1b42-11e4-86d8-5404a67eb4f7} - K:\LG_PC_Programs.exe AppInit_DLLs: C:\PROGRA~1\SupTab\SEARCH~1.DLL => Brak pliku ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-05-30] (AVAST Software) CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 213.92.190.138 213.92.190.130 Tcpip\..\Interfaces\{2D02450F-5E0E-40E9-A46A-F872E0E9F9ED}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 Tcpip\..\Interfaces\{D9465A0A-3450-481E-97CD-F664DD39B031}: [DhcpNameServer] 213.92.190.138 213.92.190.130 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKU\S-1-5-21-789336058-492894223-682003330-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t HKU\S-1-5-21-789336058-492894223-682003330-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450268068&from=mych123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t URLSearchHook: HKLM -> Domyślne = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} HKU\S-1-5-21-789336058-492894223-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "hxxp://newtab.certified-toolbar.com/nie?si=41460&tid=2938&st=newtab&ts=1365768695390&tguid=41460-2938-1365768649781-804129" <======= UWAGA SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\.DEFAULT -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\S-1-5-19 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\S-1-5-19 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\S-1-5-20 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\S-1-5-20 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {0C0E836F-9011-40CE-9033-A11C10A1FF1F} URL = SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {1D610D11-DCD0-42A4-B0A1-EF36CF1B40D7} URL = SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450268068&from=zzgbkk123&uid=wdcxwd10earx-00n0yb0_wd-wmc0t030938609386&z=4856ec7d9f6fa185c0c8718g7zcw2eao1q7b3eeq8t&q={searchTerms} SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {7C2391EC-5B56-4FE2-B4EE-A651C2B92984} URL = SearchScopes: HKU\S-1-5-21-789336058-492894223-682003330-1003 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = BHO: Brak nazwy -> {042FC685-0357-FBB9-3E95-E4957C9E8CAF} -> Brak pliku BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-30] (Adobe Systems Incorporated) BHO: Brak nazwy -> {235CC808-E1D4-22A8-7BB8-DC4107FDF25C} -> Brak pliku BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO: Brak nazwy -> {73864E9A-AC1F-C611-5D4E-F9F385EE6330} -> Brak pliku BHO: Brak nazwy -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> Brak pliku BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-05-30] (AVAST Software) BHO: Brak nazwy -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> Brak pliku BHO: Brak nazwy -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> Brak pliku DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Brak pliku FireFox: ======== FF ProfilePath: C:\Documents and Settings\XP\Dane aplikacji\Mozilla\Firefox\Profiles\zboh7wsl.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2012-04-26] (Adobe Systems, Inc.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-11] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-07-11] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [Brak pliku] FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: @ngm.nexoneu.com/NxGame -> C:\Documents and Settings\All Users\Dane aplikacji\NexonEU\NGM\npNxGameEU.dll [2014-12-31] (Nexon) FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [Brak pliku] FF Plugin: @t.garena.com/garenatalk -> J:\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-01-16] ( Garena) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-07-30] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-789336058-492894223-682003330-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll [2015-09-25] (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\XP\Dane aplikacji\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation) FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-18] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-04-15] [Brak podpisu cyfrowego] Chrome: ======= CHR dev: Chrome dev build wykryto! <======= UWAGA CHR HKLM\...\Chrome\Extension: [ajjpgnlpolfpnebjjaciccmmjnmjfjkl] - C:\Program Files\RightSurf\ajjpgnlpolfpnebjjaciccmmjnmjfjkl.crx CHR HKLM\...\Chrome\Extension: [ljnfelhdldlokjkohcmjpogkdjgbgjpj] - C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ljnfelhdldlokjkohcmjpogkdjgbgjpj.crx ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-30] (AVAST Software) S3 EasyAntiCheat; C:\WINDOWS\system32\EasyAntiCheat.exe [107552 2014-07-31] (EasyAntiCheat Ltd) R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1901576 2016-07-20] (LogMeIn Inc.) S2 HiSuiteOuc.exe; C:\Documents and Settings\All Users\Dane aplikacji\HiSuiteOuc\HiSuiteOuc.exe [117552 2015-05-20] () S2 HuaweiHiSuiteService.exe; C:\Documents and Settings\All Users\Dane aplikacji\HandSetService\HuaweiHiSuiteService.exe [154928 2015-05-20] () S2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-07-11] (Oracle Corporation) S2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [405424 2016-07-20] (LogMeIn, Inc.) S2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2255464 2011-08-03] (NVIDIA Corporation) S2 SEVPNCLIENT; J:\SoftEther VPN Client\vpnclient.exe [3563064 2015-01-11] (SoftEther VPN Project at University of Tsukuba, Japan.) S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Brak podpisu cyfrowego] S2 916e5338; "C:\WINDOWS\system32\rundll32.exe" "c:\progra~1\GSSvc.dll",service ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S1 AmdPPM; C:\WINDOWS\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices) S2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [32792 2016-05-30] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [35096 2016-05-30] (AVAST Software) S2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [91168 2016-05-30] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [64272 2016-05-30] (AVAST Software) S0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [58776 2016-05-30] (AVAST Software) S1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [815792 2016-05-30] (AVAST Software) S1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [449640 2016-05-30] (AVAST Software) S3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [187208 2016-05-30] (AVAST Software) S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [67216 2016-05-30] (AVAST Software) S0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [224616 2016-08-05] (AVAST Software) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [16384 2004-07-09] (Microsoft Corporation) S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2016-05-15] () R3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [170200 2016-08-16] (Malwarebytes) R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] () S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10112 2004-07-09] (Microsoft Corporation) R3 Neo_VPN; C:\WINDOWS\System32\DRIVERS\Neo_0016.sys [25824 2015-01-11] (SoftEther VPN Project at University of Tsukuba, Japan.) R3 nusb3hub; C:\WINDOWS\System32\DRIVERS\nusb3hub.sys [62336 2010-12-10] (Renesas Electronics Corporation) R3 nusb3xhc; C:\WINDOWS\System32\DRIVERS\nusb3xhc.sys [141440 2010-12-10] (Renesas Electronics Corporation) S3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [119528 2011-05-10] (NVIDIA Corporation) R0 sfdrv01; C:\WINDOWS\System32\drivers\sfdrv01.sys [51200 2006-03-26] (Protection Technology (StarForce)) [Brak podpisu cyfrowego] R0 sfhlp02; C:\WINDOWS\System32\drivers\sfhlp02.sys [6656 2006-03-13] (Protection Technology (StarForce)) [Brak podpisu cyfrowego] R0 sfsync02; C:\WINDOWS\System32\drivers\sfsync02.sys [19968 2005-08-10] (Protection Technology) [Brak podpisu cyfrowego] R0 sfsync04; C:\WINDOWS\System32\drivers\sfsync04.sys [50176 2006-03-24] (Protection Technology (StarForce)) [Brak podpisu cyfrowego] R0 sfvfs02; C:\WINDOWS\System32\drivers\sfvfs02.sys [66560 2005-08-24] (Protection Technology) [Brak podpisu cyfrowego] S0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [691696 2012-02-19] (Duplex Secure Ltd.) S3 VIAHdAudAddService; C:\WINDOWS\System32\drivers\viahduaa.sys [2135280 2010-10-01] (VIA Technologies, Inc.) S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [X] S3 EasyAntiCheatSys; \??\C:\WINDOWS\system32\EasyAntiCheat.sys [X] S3 GGSAFERDriver; \??\J:\Garena Plus\Room\safedrv.sys [X] U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2015-05-07] (Huawei Technologies Co., Ltd.) S4 IntelIde; Brak ImagePath S1 {57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gt; system32\drivers\{57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gt.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-08-18 18:58 - 2016-08-18 18:58 - 00000000 ____D C:\WINDOWS\CSC 2016-08-18 18:33 - 2016-05-30 22:43 - 00334280 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2016-08-18 16:46 - 2016-08-18 16:46 - 00000439 _____ C:\Documents and Settings\XP\Moje dokumenty\Addition.txt 2016-08-18 15:44 - 2016-08-18 19:02 - 00020781 _____ C:\Documents and Settings\XP\Moje dokumenty\FRST.txt 2016-08-18 15:38 - 2016-08-18 15:38 - 00000489 _____ C:\Documents and Settings\XP\Pulpit\Skrót do FRST.lnk 2016-08-18 15:30 - 2016-08-18 19:01 - 00000000 ____D C:\FRST 2016-08-18 15:22 - 2016-08-18 15:30 - 01744896 _____ (Farbar) C:\Documents and Settings\XP\Moje dokumenty\FRST.exe 2016-08-16 12:03 - 2016-08-16 12:19 - 00000188 ___SH C:\Documents and Settings\Administrator.WINDOWS-XP\ntuser.ini 2016-08-16 12:03 - 2012-02-19 20:43 - 00001599 _____ C:\Documents and Settings\Administrator.WINDOWS-XP\Menu Start\Programy\Pomoc zdalna.lnk 2016-08-16 12:03 - 2012-02-19 20:43 - 00000788 _____ C:\Documents and Settings\Administrator.WINDOWS-XP\Menu Start\Programy\Windows Media Player.lnk 2016-08-16 12:02 - 2016-08-16 12:19 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Ustawienia lokalne\Temp 2016-08-16 12:02 - 2016-08-16 12:03 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP 2016-08-16 12:02 - 2016-07-21 08:14 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Ustawienia lokalne\Dane aplikacji\LogMeIn Hamachi 2016-08-16 12:02 - 2016-07-21 08:12 - 00000000 ___HD C:\Documents and Settings\Administrator.WINDOWS-XP\Ustawienia lokalne\Dane aplikacji 2016-08-16 12:02 - 2016-05-15 10:42 - 00000000 ___HD C:\Documents and Settings\Administrator.WINDOWS-XP\Szablony 2016-08-16 12:02 - 2015-09-15 09:34 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Moje dokumenty\Visual Studio 2008 2016-08-16 12:02 - 2015-09-15 09:34 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Moje dokumenty 2016-08-16 12:02 - 2014-12-30 16:53 - 00000000 __RHD C:\Documents and Settings\Administrator.WINDOWS-XP\Dane aplikacji 2016-08-16 12:02 - 2014-12-30 16:53 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Dane aplikacji\Macromedia 2016-08-16 12:02 - 2012-10-14 16:23 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Ustawienia lokalne\Dane aplikacji\Microsoft Help 2016-08-16 12:02 - 2012-02-19 21:28 - 00000000 ___RD C:\Documents and Settings\Administrator.WINDOWS-XP\Menu Start\Programy\Autostart 2016-08-16 12:02 - 2012-02-19 21:28 - 00000000 ___RD C:\Documents and Settings\Administrator.WINDOWS-XP\Menu Start 2016-08-16 12:02 - 2012-02-19 21:28 - 00000000 ___HD C:\Documents and Settings\Administrator.WINDOWS-XP\Ustawienia lokalne 2016-08-16 12:02 - 2012-02-19 21:28 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Ulubione 2016-08-16 12:02 - 2012-02-19 21:28 - 00000000 ____D C:\Documents and Settings\Administrator.WINDOWS-XP\Pulpit 2016-08-16 12:02 - 2012-02-19 20:43 - 00000000 __SHD C:\Documents and Settings\Administrator.WINDOWS-XP\IETldCache 2016-08-16 12:02 - 2012-02-19 20:43 - 00000000 ___RD C:\Documents and Settings\Administrator.WINDOWS-XP\Menu Start\Programy\Akcesoria 2016-08-16 12:02 - 2012-02-19 20:43 - 00000000 ___RD C:\Documents and Settings\Administrator.WINDOWS-XP\Menu Start\Programy 2016-08-16 12:02 - 2012-02-19 20:42 - 00000000 __SHD C:\Documents and Settings\Administrator.WINDOWS-XP\Ustawienia lokalne\Historia 2016-08-16 12:01 - 2016-08-18 18:58 - 00290312 _____ C:\WINDOWS\ntbtlog.txt 2016-08-14 02:33 - 2016-08-14 02:33 - 00021994 _____ C:\Documents and Settings\XP\Moje dokumenty\the.king_.of_.fighters.xiii_.reloaded.torrent 2016-08-13 00:55 - 2016-08-13 00:55 - 00013660 _____ C:\Documents and Settings\XP\Moje dokumenty\The+King+Of+Fighters+XIII+%28Pc+Version%29.torrent 2016-08-12 13:34 - 2016-08-12 13:34 - 00477370 _____ C:\Documents and Settings\XP\Moje dokumenty\SPU2-X.1.4.Win32.7z 2016-08-12 13:30 - 2016-08-12 13:30 - 00479441 _____ C:\Documents and Settings\XP\Moje dokumenty\SPU2-X.2.0.Win32.7z 2016-08-12 13:25 - 2016-08-12 13:25 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\PCSX2 2016-08-12 13:14 - 2016-08-12 13:16 - 17837152 _____ C:\Documents and Settings\XP\Moje dokumenty\pcsx2-1.4.0-setup.exe 2016-08-12 02:08 - 2016-08-12 02:08 - 00013091 _____ C:\Documents and Settings\XP\Moje dokumenty\The+King+of+Fighters+XIII+%28Pc+Version+Repack%29.torrent 2016-08-12 00:18 - 2016-08-12 02:10 - 2307547221 _____ C:\Documents and Settings\XP\Moje dokumenty\Guilty Gear XX Accent Core Plus (USA).7z 2016-08-09 14:36 - 2016-08-09 15:52 - 00000000 ____D C:\Documents and Settings\XP\Moje dokumenty\Metal-Slug-collection 2016-08-09 13:54 - 2016-08-09 14:30 - 241756745 _____ C:\Documents and Settings\XP\Moje dokumenty\Metal-Slug-game-collection.rar 2016-07-30 20:12 - 2016-08-04 23:39 - 00000000 ____D C:\Program Files\Mozilla Firefox 2016-07-29 22:45 - 2016-07-30 14:31 - 00000000 ____D C:\Documents and Settings\XP\Moje dokumenty\18 2016-07-28 17:23 - 2016-08-05 08:30 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2016-07-28 17:23 - 2016-07-28 17:23 - 00000730 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk 2016-07-28 17:23 - 2016-07-28 17:23 - 00000724 _____ C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk 2016-07-28 16:38 - 2016-07-28 16:44 - 46369416 _____ C:\Documents and Settings\XP\Moje dokumenty\Firefox Setup 43.0.1 (1).exe 2016-07-28 09:51 - 2016-07-28 09:51 - 00114688 _____ C:\WINDOWS\Minidump\Mini072816-01.dmp 2016-07-21 08:12 - 2016-07-21 08:14 - 00000000 ____D C:\Documents and Settings\Default User\Ustawienia lokalne\Dane aplikacji\LogMeIn Hamachi 2016-07-21 08:12 - 2016-07-21 08:12 - 00000685 _____ C:\Documents and Settings\All Users\Pulpit\LogMeIn Hamachi.lnk 2016-07-21 08:11 - 2016-07-21 08:12 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\LogMeIn Hamachi 2016-07-21 08:11 - 2016-07-21 08:11 - 00000000 ____D C:\Program Files\LogMeIn Hamachi ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-08-18 19:02 - 2012-02-19 20:47 - 00000000 ____D C:\Documents and Settings\XP\Ustawienia lokalne\Temp 2016-08-18 18:58 - 2014-11-10 16:54 - 00000438 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2016-08-18 18:58 - 2014-07-02 16:27 - 00000000 ____D C:\Documents and Settings\UpdatusUser\Ustawienia lokalne\Dane aplikacji\LogMeIn Hamachi 2016-08-18 18:58 - 2011-06-02 19:52 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2016-08-18 18:56 - 2012-02-19 20:46 - 00032556 _____ C:\WINDOWS\SchedLgU.Txt 2016-08-18 18:56 - 2012-02-19 20:46 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-08-18 18:25 - 2012-10-27 18:58 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job 2016-08-18 18:02 - 2012-08-03 21:23 - 00001036 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-08-18 17:31 - 2012-06-11 17:34 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-08-18 16:46 - 2012-02-19 20:47 - 00000000 ___RD C:\Documents and Settings\XP\Moje dokumenty 2016-08-18 15:43 - 2016-05-31 03:07 - 00000546 _____ C:\WINDOWS\Tasks\SafeZone scheduled Autoupdate 1464656842.job 2016-08-18 15:43 - 2014-09-12 16:08 - 00000464 _____ C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1410530917.job 2016-08-18 15:43 - 2014-03-27 12:01 - 00000216 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2016-08-18 15:43 - 2012-08-03 21:23 - 00001032 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-08-18 15:38 - 2012-02-19 20:47 - 00000000 ____D C:\Documents and Settings\XP\Pulpit 2016-08-18 15:17 - 2012-02-19 21:08 - 00000188 ___SH C:\Documents and Settings\UpdatusUser\ntuser.ini 2016-08-18 15:17 - 2012-02-19 20:47 - 00000188 ___SH C:\Documents and Settings\XP\ntuser.ini 2016-08-18 15:16 - 2012-02-19 21:26 - 00000223 __RSH C:\boot.ini 2016-08-18 15:16 - 2011-06-02 19:52 - 00000757 _____ C:\WINDOWS\win.ini 2016-08-18 15:16 - 2011-06-02 19:52 - 00000227 _____ C:\WINDOWS\system.ini 2016-08-16 13:57 - 2012-02-19 20:47 - 00000000 ___RD C:\Documents and Settings\XP\Menu Start\Programy\Autostart 2016-08-16 12:05 - 2016-05-17 15:51 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-08-16 12:02 - 2012-02-19 21:27 - 00000000 ____D C:\Documents and Settings 2016-08-16 11:00 - 2013-09-06 14:10 - 00000000 ____D C:\Documents and Settings\XP\Dane aplikacji\uTorrent 2016-08-16 00:01 - 2012-02-19 20:47 - 00000000 ___HD C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji 2016-08-14 13:57 - 2014-12-10 17:21 - 00000000 ____D C:\Documents and Settings\XP\Dane aplikacji\TS3Client 2016-08-13 23:19 - 2015-07-15 02:24 - 00000992 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-08-13 12:00 - 2012-02-19 21:28 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2016-08-13 07:35 - 2016-05-03 18:10 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Package Cache 2016-08-12 13:28 - 2015-01-17 22:14 - 00000000 ____D C:\Documents and Settings\XP\Moje dokumenty\PCSX2 2016-08-12 13:27 - 2015-02-05 14:17 - 00000000 ____D C:\Documents and Settings\XP\Pulpit\Gry 2016-08-12 13:27 - 2013-04-20 14:36 - 00000000 ___HD C:\WINDOWS\msdownld.tmp 2016-08-12 13:27 - 2012-02-19 21:28 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2016-08-12 13:27 - 2012-02-19 21:22 - 00000000 ___HD C:\WINDOWS\inf 2016-08-12 13:27 - 2012-02-19 20:41 - 00000000 ____D C:\WINDOWS\system32\DirectX 2016-08-12 13:25 - 2012-02-19 21:28 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy 2016-08-11 07:53 - 2012-04-20 20:06 - 00000000 ____D C:\Program Files\Opera 2016-08-10 20:44 - 2015-06-10 21:02 - 00000000 ____D C:\Program Files\Steam 2016-08-10 12:42 - 2012-02-19 21:19 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2016-08-10 12:41 - 2013-08-15 00:28 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-08-10 12:36 - 2012-09-21 20:57 - 144884648 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-08-10 11:59 - 2012-02-19 20:47 - 00000000 ____D C:\Documents and Settings\XP 2016-08-08 15:00 - 2014-03-27 12:01 - 00000210 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job 2016-08-05 15:07 - 2013-03-24 16:58 - 00224616 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2016-07-30 20:08 - 2014-06-26 08:43 - 00000000 ____D C:\Documents and Settings\XP\Moje dokumenty\Pobrane 2016-07-28 17:52 - 2015-02-05 14:09 - 00000000 ____D C:\Documents and Settings\XP\Pulpit\Bibeloty 2016-07-28 17:52 - 2014-10-03 21:24 - 00000000 ____D C:\Documents and Settings\XP\Pulpit\Fimy 2016-07-28 17:20 - 2014-08-20 13:22 - 00000000 ____D C:\2-click run 2016-07-28 16:57 - 2014-12-31 21:46 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Nexon 2016-07-28 16:55 - 2014-05-23 18:58 - 00000000 ____D C:\Documents and Settings\XP\Moje dokumenty\My Games 2016-07-28 16:55 - 2012-02-19 20:47 - 00000000 ___RD C:\Documents and Settings\XP\Menu Start\Programy 2016-07-28 09:51 - 2012-08-09 09:40 - 00000000 ____D C:\WINDOWS\Minidump 2016-07-24 22:13 - 2012-03-19 18:34 - 00000000 ____D C:\Documents and Settings\XP\Menu Start\Programy\Steam 2016-07-21 08:12 - 2012-02-19 21:28 - 00000000 ___HD C:\Documents and Settings\Default User\Ustawienia lokalne\Dane aplikacji 2016-07-20 12:04 - 2012-04-13 12:18 - 00026176 ____H (LogMeIn, Inc.) C:\WINDOWS\system32\hamachi.sys ==================== Pliki w katalogu głównym wybranych folderów ======= 2016-05-17 17:14 - 2016-05-17 17:14 - 0000000 _____ () C:\Program Files\GUT420.tmp 2014-12-31 15:41 - 2015-12-24 16:04 - 0000132 _____ () C:\Documents and Settings\XP\Dane aplikacji\Adobe PNG Format CS5 Prefs 2014-06-25 21:32 - 2014-06-25 21:33 - 0000322 _____ () C:\Documents and Settings\XP\Dane aplikacji\aps.uninstall.scan.results 2012-10-13 22:25 - 2014-08-29 23:39 - 0045194 _____ () C:\Documents and Settings\XP\Dane aplikacji\room_v3.dat 1601-03-12 15:17 - 1601-03-12 15:17 - 0014193 _____ () C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\!Recovery_533775CAC537.html 1601-01-09 19:44 - 1601-01-09 19:44 - 0001758 _____ () C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\!Recovery_533775CAC537.txt 2014-06-25 21:28 - 2014-06-25 09:26 - 0608404 _____ (Click Me In Limited) C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\AnyProtectScannerSetup.exe 2012-02-22 14:57 - 2016-05-07 21:56 - 0221184 _____ () C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-04-10 10:04 - 2016-04-10 10:04 - 0016384 ____N () C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\onjounn.dll 2016-05-28 18:28 - 2016-05-28 18:28 - 0008311 _____ () C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\recently-used.xbel 1899-12-30 00:00 - 1899-12-30 00:00 - 2621494 ____T () C:\Documents and Settings\All Users\Dane aplikacji\533775CAC537.bmp 1601-03-12 15:17 - 1601-03-12 15:17 - 0014193 _____ () C:\Documents and Settings\All Users\Dane aplikacji\533775CAC537.html 2015-11-24 09:45 - 2016-03-17 14:38 - 0000146 _____ () C:\Documents and Settings\All Users\Dane aplikacji\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Pliki do przeniesienia lub usunięcia: ==================== C:\Documents and Settings\XP\TempWmicBatchFile.bat Niektóre pliki w TEMP: ==================== C:\Documents and Settings\XP\Ustawienia lokalne\Temp\BirdiesPl_41538.exe C:\Documents and Settings\XP\Ustawienia lokalne\Temp\curllib.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\drm_dialogs.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\jre-8u40-windows-au.exe C:\Documents and Settings\XP\Ustawienia lokalne\Temp\libeay32.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\libsasl.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\NGMDll.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\NGMResource.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\openldap.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\SettlementColossusPl_20002.exe C:\Documents and Settings\XP\Ustawienia lokalne\Temp\SkypeSetup.exe C:\Documents and Settings\XP\Ustawienia lokalne\Temp\ssleay32.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\swt-win32-3740.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\t.dll C:\Documents and Settings\XP\Ustawienia lokalne\Temp\unicows.dll ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo ==================== Koniec FRST.txt ============================