Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 28-09-2016 Uruchomiony przez uzytkownik (administrator) ACER (08-03-2017 10:58:52) Uruchomiony z C:\Users\uzytkownik\Desktop\testy Załadowane profile: uzytkownik (Dostępne profile: uzytkownik & azartech) Platform: Windows 7 Home Premium Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (COMODO) C:\Program Files (x86)\Comodo\COMODO Secure Shopping\csssrv64.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Atheros) C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Farbar) C:\Users\uzytkownik\Desktop\testy\FRST64(1).exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe ==================== Rejestr (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16776704 2016-12-09] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1483264 2016-12-09] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894664 2013-08-23] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2938479094-77888213-175405875-1000\...\Policies\Explorer: [NoInternetOpenWith] 1 HKU\S-1-5-21-2938479094-77888213-175405875-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-2938479094-77888213-175405875-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [450048 2011-09-02] () HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2015-10-05] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe () GroupPolicy: Ograniczenia - Chrome <======= UWAGA GroupPolicy\User: Ograniczenia <======= UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{E07746B3-15D8-4FB0-9972-F70524B2EC68}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKU\S-1-5-21-2938479094-77888213-175405875-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki&utm_medium=installer&utm_campaign=instalki HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avast.com/AV772/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avast.com/AV772/search/web?q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKU\S-1-5-21-2938479094-77888213-175405875-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2938479094-77888213-175405875-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yandex.ru/?win=237&clid=2256091 SearchScopes: HKLM-x32 -> DefaultScope {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms} SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKLM-x32 -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms} SearchScopes: HKLM-x32 -> {F4137D40-259A-4FB3-B780-F8C39B303C41} URL = hxxp://yandex.ru/yandsearch?clid=2101082&text={searchTerms} SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-2938479094-77888213-175405875-1000 -> DefaultScope {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://yandex.ru/search/?win=237&clid=2256092&text={searchTerms} SearchScopes: HKU\S-1-5-21-2938479094-77888213-175405875-1000 -> Software URL = SearchScopes: HKU\S-1-5-21-2938479094-77888213-175405875-1000 -> yandex.ru-090312 URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2938479094-77888213-175405875-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms} SearchScopes: HKU\S-1-5-21-2938479094-77888213-175405875-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-2938479094-77888213-175405875-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKU\S-1-5-21-2938479094-77888213-175405875-1000 -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://yandex.ru/search/?win=237&clid=2256092&text={searchTerms} BHO: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll [2014-11-03] () BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: IeUrlFilter Class -> {2DD257A3-5028-41AE-A1E7-A12F76A08893} -> C:\Program Files (x86)\COMODO\COMODO Secure Shopping\cssbho32.dll [2016-12-21] (COMODO) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) Toolbar: HKLM - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll [2014-11-03] () Toolbar: HKLM-x32 - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX.dll [2014-11-03] () Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\uzytkownik\AppData\Roaming\Mozilla\Firefox\Profiles\2414aswj.default-1439915281956 FF DefaultSearchEngine: Google FF Homepage: hxxps://www.google.pl/webhp?ie=utf-8&oe=utf-8&gws_rd=cr&ei=dRC0V73PPMO2swGg96_oDQ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-03-07] () FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-03-07] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIUpdater.dll [2011-07-21] (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation) FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll [Brak pliku] FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2016-05-23] () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\uzytkownik\AppData\Roaming\Mozilla\Firefox\Profiles\2414aswj.default-1439915281956\searchplugins\yandex.ru-085748.xml [2016-08-14] FF SearchPlugin: C:\Users\uzytkownik\AppData\Roaming\Mozilla\Firefox\Profiles\2414aswj.default-1439915281956\searchplugins\yandex.ru-130604.xml [2016-07-12] FF SearchPlugin: C:\Users\uzytkownik\AppData\Roaming\Mozilla\Firefox\Profiles\2414aswj.default-1439915281956\searchplugins\yandex.ru-223817.xml [2016-01-05] FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01] [Brak podpisu cyfrowego] Chrome: ======= CHR Profile: C:\Users\uzytkownik\AppData\Local\Google\Chrome\User Data\Default [2016-08-14] CHR Extension: (Docs) - C:\Users\uzytkownik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-24] CHR Extension: (Szukaj w Google) - C:\Users\uzytkownik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-24] CHR HKU\S-1-5-21-2938479094-77888213-175405875-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dbaonaocldpohelilahfhnkmjankmbcc] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [bejnpnkhfgfkcpgikiinojlmdcjimobi] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [cpegcopcfajiiibidlaelhjjblpefbjk] - hxxp://clients2.google.com/service/update2/crx ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [1417856 2015-10-05] () R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [105120 2011-09-30] (Atheros Commnucations) [Brak podpisu cyfrowego] S3 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation) S3 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation) R2 csssrv; C:\Program Files (x86)\COMODO\COMODO Secure Shopping\csssrv64.exe [3210928 2016-12-21] (COMODO) S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [350064 2016-05-23] (WildTangent) S3 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [184320 2011-07-07] (Intel Corporation) [Brak podpisu cyfrowego] R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated) S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448976 2015-04-17] (TeamViewer GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe [73728 2011-10-21] (Atheros) [Brak podpisu cyfrowego] U4 CmdAgent; "C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe" [X] ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 BazisPortableCDBus; C:\Windows\System32\drivers\BazisPortableCDBus.sys [268896 2014-07-03] (SysProgs.org) R1 cmdcss; C:\Windows\system32\drivers\cmdcss.sys [111568 2016-12-21] (COMODO) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [30960 2015-05-29] (Intel Corporation) S3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2011-06-16] (Intel Corporation) R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [427520 2016-11-02] (Realsil Semiconductor Corporation) R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [31984 2013-07-30] (Synaptics Incorporated) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [Brak podpisu cyfrowego] U0 aswVmm; Brak ImagePath S4 BAPIDRV; system32\DRIVERS\BAPIDRV64.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-03-08 10:41 - 2017-03-08 10:58 - 00000000 ____D C:\FRST 2017-03-08 10:39 - 2017-03-08 10:58 - 00000000 ____D C:\Users\uzytkownik\Desktop\testy 2017-03-07 16:47 - 2017-03-07 16:47 - 00061590 _____ C:\Users\uzytkownik\Documents\cc_20170307_164712.reg 2017-03-07 16:44 - 2017-03-07 16:44 - 00000000 ____D C:\SFCFix 2017-03-07 16:36 - 2017-03-07 16:44 - 00000000 ____D C:\Users\uzytkownik\AppData\Local\niemiro 2017-03-07 16:36 - 2017-03-07 16:36 - 02884096 _____ (niemiro) C:\Users\uzytkownik\Downloads\SFCFix.exe 2017-03-07 16:26 - 2017-03-07 16:26 - 00000000 ____D C:\Program Files (x86)\Amazon 2017-03-07 15:59 - 2017-03-07 16:38 - 00000000 ____D C:\Users\uzytkownik\AppData\Roaming\Geek Uninstaller 2017-03-07 15:58 - 2017-03-07 15:59 - 22257698 _____ C:\Users\uzytkownik\Downloads\SysinternalsSuite.zip 2017-03-07 15:45 - 2017-03-07 15:45 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-03-07 15:44 - 2017-03-07 15:44 - 09261616 _____ (Piriform Ltd) C:\Users\uzytkownik\Downloads\ccsetup527.exe 2017-03-07 15:24 - 2017-03-07 15:24 - 00000000 ____D C:\Windows\Nowy folder 2017-03-07 15:15 - 2017-03-07 15:18 - 115125888 _____ (ESET) C:\Users\uzytkownik\Downloads\ess_nt64_plk.exe 2017-03-07 15:11 - 2017-03-07 15:11 - 02249472 _____ (Acer Inc.) C:\Users\uzytkownik\Downloads\HWVendorDetection.exe 2017-03-07 15:05 - 2017-03-07 15:05 - 00041683 _____ C:\ComboFix.txt 2017-03-07 14:34 - 2017-03-07 14:35 - 05660168 ____R (Swearware) C:\Users\uzytkownik\Downloads\ComboFix.exe 2017-03-07 14:34 - 2017-03-07 14:34 - 04031440 _____ C:\Users\uzytkownik\Downloads\AdwCleaner(4).exe 2017-03-07 11:38 - 2017-03-07 11:38 - 03086960 _____ C:\Users\uzytkownik\Downloads\Windows6.0-KB942288-v2-x64.msu 2017-03-07 10:57 - 2017-03-07 10:57 - 00000000 ____D C:\Users\azartech\AppData\LocalLow\iplay_en 2017-03-07 10:43 - 2017-03-07 10:43 - 00000000 ____D C:\Users\azartech\AppData\Local\EgisTec IPS 2017-03-07 10:33 - 2017-03-07 10:33 - 00114944 _____ C:\Users\azartech\AppData\Local\GDIPFONTCACHEV1.DAT 2017-03-07 10:33 - 2017-03-07 10:33 - 00001421 _____ C:\Users\azartech\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2017-03-07 10:33 - 2017-03-07 10:33 - 00000266 __RSH C:\Users\azartech\ntuser.pol 2017-03-07 10:33 - 2017-03-07 10:33 - 00000020 ___SH C:\Users\azartech\ntuser.ini 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Ustawienia lokalne 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Szablony 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Moje dokumenty 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Menu Start 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Documents\Moje wideo 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Documents\Moje obrazy 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Documents\Moja muzyka 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\Dane aplikacji 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\AppData\Local\Historia 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 _SHDL C:\Users\azartech\AppData\Local\Dane aplikacji 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Roaming\Screensaver 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Roaming\CyberLink 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Roaming\Comodo 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Roaming\AnyDesk 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Roaming\Adobe 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Local\VirtualStore 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Local\PowerCinema 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech\AppData\Local\Acer 2017-03-07 10:33 - 2017-03-07 10:33 - 00000000 ____D C:\Users\azartech 2017-03-07 10:33 - 2014-08-15 07:38 - 00000000 ____D C:\Users\azartech\AppData\Roaming\TuneUp Software 2017-03-07 10:33 - 2013-11-29 07:25 - 00000000 ____D C:\Users\azartech\AppData\Local\Microsoft Help 2017-03-07 10:33 - 2013-11-05 07:37 - 00002144 _____ C:\Users\azartech\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk 2017-03-07 10:33 - 2012-01-11 12:03 - 00000000 ____D C:\Users\azartech\AppData\Roaming\Macromedia 2017-03-07 10:33 - 2012-01-11 11:30 - 00000000 ____D C:\Users\azartech\AppData\Roaming\Media Center Programs 2017-03-06 14:56 - 2017-03-06 14:56 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\imofugc.sys 2017-03-06 14:10 - 2017-03-06 14:10 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-03-06 14:10 - 2017-03-06 14:10 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2017-03-06 14:10 - 2017-03-06 14:10 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-06 14:09 - 2017-03-06 14:09 - 00000126 _____ C:\Windows\vdcss.INI 2017-03-06 11:56 - 2017-03-07 16:04 - 00000000 ____D C:\tools 2017-03-06 11:56 - 2017-03-06 11:56 - 09750008 _____ C:\Users\uzytkownik\Downloads\tools.zip 2017-02-13 23:24 - 2017-02-13 23:25 - 00000000 ____D C:\BOXRoot 2017-02-09 09:27 - 2017-02-09 09:27 - 08981816 _____ (COMODO) C:\Windows\SysWOW64\ccav_installer.exe ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-03-08 10:50 - 2009-07-14 05:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-08 10:50 - 2009-07-14 05:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-08 10:10 - 2013-11-24 17:40 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-03-07 16:52 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-07 16:37 - 2016-11-27 16:00 - 00000000 ____D C:\Users\uzytkownik\AppData\LocalLow\Mozilla 2017-03-07 16:31 - 2016-08-15 14:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeGamePick 2017-03-07 16:31 - 2016-08-15 14:40 - 00000000 ____D C:\Program Files (x86)\FreeGamePick 2017-03-07 16:07 - 2017-01-09 20:37 - 00000000 ____D C:\Windows\System32\Tasks\COMODO 2017-03-07 16:07 - 2015-12-03 15:16 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2017-03-07 16:02 - 2012-01-11 11:59 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-03-07 16:01 - 2012-01-11 12:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer 2017-03-07 16:01 - 2012-01-11 12:42 - 00000000 ____D C:\Program Files (x86)\Acer 2017-03-07 15:59 - 2012-01-11 12:42 - 00000000 ____D C:\Program Files\Acer 2017-03-07 15:57 - 2015-08-06 06:23 - 00112536 _____ C:\Users\uzytkownik\AppData\Local\GDIPFONTCACHEV1.DAT 2017-03-07 15:55 - 2015-08-08 07:28 - 00440536 _____ C:\Windows\system32\FNTCACHE.DAT 2017-03-07 15:46 - 2012-01-11 11:59 - 00000000 ____D C:\ProgramData\BackupManager 2017-03-07 15:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-03-07 15:05 - 2014-07-03 11:37 - 00000000 ____D C:\Qoobox 2017-03-07 14:59 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2017-03-07 14:54 - 2014-07-03 11:37 - 00000000 ____D C:\Windows\erdnt 2017-03-07 14:38 - 2014-07-03 11:14 - 00000000 ____D C:\AdwCleaner 2017-03-07 11:10 - 2013-11-24 17:40 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-03-07 11:10 - 2013-11-24 17:40 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-03-07 11:10 - 2013-11-05 02:08 - 00000000 ____D C:\Windows\system32\Macromed 2017-03-07 11:10 - 2012-01-11 11:49 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-03-07 11:10 - 2012-01-11 11:49 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-03-06 14:56 - 2012-01-11 12:39 - 00000000 ____D C:\Windows\nl 2017-03-06 14:08 - 2013-11-05 02:05 - 00000000 ____D C:\Program Files (x86)\Intel 2017-03-06 14:07 - 2013-11-05 02:12 - 00000000 ____D C:\Dolby PCEE4 2017-03-06 11:52 - 2017-01-04 10:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo 2017-03-06 11:43 - 2017-01-04 10:16 - 00000000 ____D C:\Program Files (x86)\Comodo 2017-03-03 22:32 - 2015-08-08 10:10 - 00000000 ____D C:\Users\uzytkownik\AppData\Roaming\IrfanView 2017-03-03 22:32 - 2015-05-12 12:40 - 00000000 ____D C:\Users\uzytkownik\Desktop\Skróty 2017-03-03 22:32 - 2013-11-24 12:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-03-03 22:32 - 2013-11-24 12:06 - 00000000 ____D C:\Program Files\CCleaner 2017-03-03 22:32 - 2013-11-06 17:24 - 00000000 ____D C:\Users\uzytkownik\AppData\Roaming\Skype 2017-03-03 22:32 - 2013-11-05 07:12 - 00000000 ____D C:\Users\uzytkownik\AppData\Local\PowerCinema 2017-03-03 22:32 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2017-03-03 22:30 - 2014-07-03 14:08 - 00000000 ____D C:\Users\uzytkownik\AppData\Local\Mozilla 2017-03-03 15:10 - 2013-11-05 07:11 - 00000000 ____D C:\Users\uzytkownik 2017-02-22 14:02 - 2013-11-11 16:03 - 00000000 ____D C:\Users\uzytkownik\AppData\Local\CrashDumps 2017-02-09 09:27 - 2015-07-29 08:07 - 00000000 ____D C:\ProgramData\Comodo ==================== Pliki w katalogu głównym wybranych folderów ======= 2015-04-14 17:28 - 2015-04-14 17:28 - 0004387 _____ () C:\Users\uzytkownik\AppData\Roaming\4ICKFXWvzzSJFOXGf 2014-08-24 08:01 - 2014-08-25 08:25 - 0686080 ____H () C:\Users\uzytkownik\AppData\Roaming\aflbase.db 2017-03-07 15:11 - 2017-03-07 15:13 - 0034425 _____ () C:\Users\uzytkownik\AppData\Local\HWVendorDetection.log 2014-05-23 05:16 - 2014-05-23 05:16 - 0000057 _____ () C:\ProgramData\Ament.ini 2013-11-05 02:22 - 2013-11-05 02:24 - 0015141 _____ () C:\ProgramData\ArcadeDeluxe5.log 2017-01-11 13:22 - 2017-01-11 13:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2014-08-07 07:08 ==================== Koniec FRST.txt ============================