Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 15-03-2017 Uruchomiony przez Administrator (administrator) HP2013 (09-04-2017 18:33:45) Uruchomiony z C:\Users\Administrator.MOT-0055\Downloads Załadowane profile: Administrator (Dostępne profile: Mariusz Jagura & Administrator & DefaultAppPool) Platform: Windows 10 Pro Wersja 1607 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: Chrome) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_b20011ea53a6b83e\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (ActivIdentity) C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\acevents.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_b20011ea53a6b83e\AESTSr64.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Hewlett-Packard Development Company, L.P) C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\ramaint.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\McCSPServiceHost.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ActivIdentity) C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (CANON INC.) C:\Program Files\Canon\Canon MF Network Scanner Selector\CMFNSS6.EXE (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart Plus B210 series\Bin\ScanToPCActivationApp.exe (Spotify Ltd) C:\Users\Administrator.MOT-0055\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe (Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_6\mcapexe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (CANON INC.) C:\Program Files (x86)\Canon\OIPTonerStatus\CnTnrStsTask.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Security) C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Rejestr (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2014-03-26] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-17] (IDT, Inc.) HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard) HKLM\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2012-06-08] (LogMeIn, Inc.) HKLM\...\Run: [Windows Mobile Device Center] => C:\WINDOWS\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation) HKLM\...\Run: [acevents] => C:\Program Files\ActivIdentity\ActivClient\acevents.exe [196648 2009-06-04] (ActivIdentity) HKLM\...\Run: [accrdsub] => C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [483880 2009-06-04] (ActivIdentity) HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2944056 2011-08-17] (Hewlett-Packard Company) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [518976 2013-08-21] (Acronis) HKLM\...\Run: [MFNetworkScannerSelector] => C:\Program Files\Canon\Canon MF Network Scanner Selector\CMFNSS6.EXE [425512 2015-01-22] (CANON INC.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.) HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111640 2010-03-04] () HKLM-x32\...\Run: [File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11266048 2010-01-19] (Hewlett-Packard) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67896 2017-03-16] (Apple Inc.) HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7806192 2013-12-13] () HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1102208 2013-10-10] (Acronis International GmbH) HKLM-x32\...\Run: [Canon Toner Status] => C:\Program Files (x86)\Canon\OIPTonerStatus\CnTnrStsTask.exe [1821192 2015-02-24] (CANON INC.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Winlogon\Notify\DeviceNP: C:\Windows\SysWOW64\DeviceNP.dll [2009-12-07] (Hewlett-Packard Limited) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [HP Photosmart Plus B210 series (NET)] => C:\Program Files\HP\HP Photosmart Plus B210 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [EPSON Stylus Photo R1800] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATI9LE.EXE [211968 2007-01-12] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [IVONA ControlCenter] => C:\Program Files (x86)\IVONA\IVONA ControlCenter\IVONA ControlCenter.exe [2251128 2013-06-11] (IVONA Software Sp. z o.o.) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [Google Update] => C:\Users\Administrator.MOT-0055\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-19] (Google Inc.) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [Spotify Web Helper] => C:\Users\Administrator.MOT-0055\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-26] (Spotify Ltd) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23819304 2017-03-21] (Google) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27427808 2017-02-08] (Skype Technologies S.A.) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-03-16] (Apple Inc.) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2017-03-16] (Apple Inc.) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-03-16] (Apple Inc.) HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2685426548-363200422-3215863842-500\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-2685426548-363200422-3215863842-500\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\scrnsave.scr [37376 2016-07-16] (Microsoft Corporation) Lsa: [Notification Packages] DPPassFilter scecli ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google) ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () Startup: C:\Users\Administrator.MOT-0055\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - .lnk [2015-02-05] ShortcutTarget: Powiadomienia monitorowania tuszu - .lnk -> C:\Program Files\HP\HP Deskjet 1510 series\bin\HPStatusBL.dll (Brak pliku) Startup: C:\Users\Administrator.MOT-0055\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 1510 series.lnk [2017-02-14] ShortcutTarget: Powiadomienia monitorowania tuszu - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\bin\HPStatusBL.dll (Brak pliku) Startup: C:\Users\Administrator.MOT-0055\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Photosmart Plus B210 series (sieć).lnk [2016-01-21] ShortcutTarget: Powiadomienia monitorowania tuszu - HP Photosmart Plus B210 series (sieć).lnk -> C:\Program Files\HP\HP Photosmart Plus B210 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) Startup: C:\Users\Administrator.MOT-0055\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk [2013-03-07] ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) GroupPolicy\User: Ograniczenia <======= UWAGA GroupPolicyScripts: Ograniczenia <======= UWAGA GroupPolicyScripts\User: Ograniczenia <======= UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{3b193a56-e459-4c50-8c07-4d0af8821961}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{4cff283b-69dc-40c0-8bb6-fcfba017da81}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{7987bbeb-87ac-4c46-8ade-7d6f0251f69c}: [DhcpNameServer] 10.106.12.27 Tcpip\..\Interfaces\{a281f39a-62d1-423e-a144-341611822031}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{c53b9f72-12b4-4d61-bf2c-417df4661198}: [DhcpNameServer] 192.168.11.1 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2685426548-363200422-3215863842-500\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs HKU\S-1-5-21-2685426548-363200422-3215863842-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com URLSearchHook: HKU\S-1-5-21-2685426548-363200422-3215863842-500 - (Brak nazwy) - {00000000-6E41-4FD3-8538-502F5495E5FC} - Brak pliku SearchScopes: HKLM -> DefaultScope {0D5D2DD1-D324-4580-8DD4-E2509D769537} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM -> {0D5D2DD1-D324-4580-8DD4-E2509D769537} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {0D5D2DD1-D324-4580-8DD4-E2509D769537} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0D5D2DD1-D324-4580-8DD4-E2509D769537} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2685426548-363200422-3215863842-500 -> DefaultScope {0D5D2DD1-D324-4580-8DD4-E2509D769537} URL = SearchScopes: HKU\S-1-5-21-2685426548-363200422-3215863842-500 -> {0D5D2DD1-D324-4580-8DD4-E2509D769537} URL = SearchScopes: HKU\S-1-5-21-2685426548-363200422-3215863842-500 -> {D70D0998-8DFB-4C37-871F-D43ECCD5B914} URL = hxxp://www.search.ask.com/web?tpid=ORJ&o=100000027&pf=V7&p2=&gct=&itbv=12.10.3.24&apn_uid=62B9EAD7-DFF6-4EE2-AE4D-6C59C5D14C09&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_dbr=ff_13.0.1&doi=2014-02-02&trgb=IE&q={searchTerms}&psv=&pt=tb BHO: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2010-04-02] (DigitalPersona, Inc.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-02] (Google Inc.) BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-03-27] (McAfee, Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Brak nazwy -> {D4027C7F-154A-4066-A1AD-4243D8127440} -> Brak pliku BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard) BHO-x32: File Sanitizer for HP ProtectTools -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2010-01-19] (Hewlett-Packard) BHO-x32: HP ProtectTools Security Manager Extension -> {395610AE-C624-4f58-B89E-23733EA00F9A} -> c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2010-04-02] (DigitalPersona, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-02] (Oracle Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-02] (Google Inc.) BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-03-27] (McAfee, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-02] (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-02] (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-02] (Google Inc.) Toolbar: HKU\S-1-5-21-2685426548-363200422-3215863842-500 -> Brak nazwy - {D4027C7F-154A-4066-A1AD-4243D8127440} - Brak pliku DPF: HKLM-x32 {82E5DF24-51E8-47CD-864A-F4BD5005AA73} hxxps://www.icloud.com/system/iCloud.cab DPF: HKLM-x32 {8AA6357A-00B9-474B-A529-908CFDE3A594} hxxp://192.168.1.9/RSVideoOcx.cab DPF: HKLM-x32 {92ECE6FA-AC2E-4042-BFAE-0C8608E52A41} hxxps://www.pekaobiznes24.pl/components/1,3,0,82/SignActivXPEKAO.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-03-27] (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-03-27] (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-03-27] (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-03-27] (McAfee, Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-02] (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2017-02-28] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-02-28] (McAfee, Inc.) FireFox: ======== FF DefaultProfile: qd0pseuo.default-1378982936245 FF ProfilePath: C:\Users\Administrator.MOT-0055\AppData\Roaming\Mozilla\Firefox\Profiles\qd0pseuo.default-1378982936245 [2017-03-01] FF Homepage: Mozilla\Firefox\Profiles\qd0pseuo.default-1378982936245 -> hxxp://www.google.pl/ FF Extension: (Site Finder) - C:\Users\Administrator.MOT-0055\AppData\Roaming\Mozilla\Firefox\Profiles\qd0pseuo.default-1378982936245\Extensions\sitefinder@sitefinder.com [2014-02-21] [Brak podpisu cyfrowego] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-02-14] FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt FF Extension: (DigitalPersona Extension) - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2010-09-14] [Brak podpisu cyfrowego] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => nie znaleziono FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-18] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-02-28] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-18] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll [2012-10-04] (Adobe Systems, Inc.) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-08-13] (DivX, LLC) FF Plugin-x32: @ipcsoft.com/np_ipc1.1_plugin_normal(3-1) -> C:\Users\Administrator.MOT-0055\AppData\Roaming\WebPlugins\IPC1.1\IEFFChrome\npRSVideoIPC.dll [2015-10-27] (Raysharp) FF Plugin-x32: @IPCWebComponents -> C:\Program Files (x86)\IPCWebComponents\npIPCReg.dll [2014-11-21] () FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-02] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-02] (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-02-28] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Brak pliku] FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin-x32: Web Components -> C:\Program Files (x86)\Web Components\npWebVideoPlugin.dll [2015-03-06] () FF Plugin HKU\S-1-5-21-2685426548-363200422-3215863842-500: @citrixonline.com/appdetectorplugin -> C:\Users\Administrator.MOT-0055\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-06-19] (Citrix Online) FF Plugin HKU\S-1-5-21-2685426548-363200422-3215863842-500: @seedonk.com/SeeVWidget;version=1.1.2.0 -> C:\Program Files\iSecurityPlusPlayer\\npseev.dll [2014-02-22] (Seedonk Inc) FF Plugin HKU\S-1-5-21-2685426548-363200422-3215863842-500: @tools.google.com/Google Update;version=3 -> C:\Users\Administrator.MOT-0055\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.) FF Plugin HKU\S-1-5-21-2685426548-363200422-3215863842-500: @tools.google.com/Google Update;version=9 -> C:\Users\Administrator.MOT-0055\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default [2017-04-09] CHR Extension: (Dysk Google) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-09] CHR Extension: (Google Cast) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-03-29] CHR Extension: (Adobe Acrobat) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-05] CHR Extension: (McAfee® WebAdvisor) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-03-28] CHR Extension: (Zakładki iCloud) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2017-04-09] CHR Extension: (Dokumenty Google offline) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17] CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-01-21] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-13] CHR Extension: (Chrome Media Router) - C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-09] CHR Profile: C:\Users\Administrator.MOT-0055\AppData\Local\Google\Chrome\User Data\System Profile [2015-09-02] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-06-21] CHR HKU\S-1-5-21-2685426548-363200422-3215863842-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\ADMINI~1.MOT\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2017-04-09] CHR HKU\S-1-5-21-2685426548-363200422-3215863842-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-06-21] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-04-15] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 ac.sharedstore; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [277032 2009-06-04] (ActivIdentity) R2 AESTFilters; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_b20011ea53a6b83e\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.) R3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1752480 2017-02-24] (Intel Security) R3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2010-02-02] (McAfee, Inc.) [Brak podpisu cyfrowego] R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462088 2010-03-31] (DigitalPersona, Inc.) S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2009-12-07] (Hewlett-Packard Ltd) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [36864 2010-03-17] (Hewlett-Packard Development Company, L.P) [Brak podpisu cyfrowego] R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [90112 2010-06-14] (Hewlett-Packard Company) [Brak podpisu cyfrowego] R2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2010-02-02] (McAfee, Inc.) R2 HPFSService; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [297984 2010-01-19] (Hewlett-Packard) [Brak podpisu cyfrowego] R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.) R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [Brak podpisu cyfrowego] R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [419336 2017-02-01] (LogMeIn, Inc.) R2 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [509448 2017-02-01] (LogMeIn, Inc.) R2 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2012-06-08] (LogMeIn, Inc.) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [188264 2017-03-27] (McAfee, Inc.) R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe [994312 2017-03-13] (McAfee, Inc.) R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\\McCSPServiceHost.exe [2054080 2017-02-28] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [1344472 2017-02-24] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [241040 2017-01-18] (McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [385112 2017-01-18] (McAfee, Inc.) R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [343792 2017-01-18] (McAfee, Inc.) R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1551000 2017-03-10] (McAfee, Inc.) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2012-02-08] (Hewlett-Packard) [Brak podpisu cyfrowego] R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc) R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1104304 2016-11-15] (Intel Security, Inc.) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2012-02-08] (Hewlett-Packard) [Brak podpisu cyfrowego] S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-10-10] (Microsoft Corporation) R2 STacSV; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_b20011ea53a6b83e\STacSV64.exe [244736 2010-03-17] (IDT, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [88464 2017-01-20] (McAfee, Inc.) S3 DAMDrv; C:\WINDOWS\System32\DRIVERS\DAMDrv64.sys [40760 2009-10-21] (Hewlett-Packard Development Company L.P.) S3 FsUsbExDisk; C:\windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-03-20] () [Brak podpisu cyfrowego] S3 FTDIBUS; C:\WINDOWS\system32\drivers\ftdibus.sys [118160 2016-10-04] (Future Technology Devices International Ltd.) S3 FTSER2K; C:\WINDOWS\system32\drivers\ftser2k.sys [88752 2016-10-04] () S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [207968 2016-02-24] (McAfee, Inc.) R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [30448 2017-02-01] (LogMeIn, Inc.) S4 LMIRfsClientNP; Brak ImagePath R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [487184 2017-01-20] (McAfee, Inc.) R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [366328 2017-01-20] (McAfee, Inc.) S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85048 2017-01-23] (McAfee, Inc.) R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [518704 2017-01-20] (McAfee, Inc.) R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [923640 2017-01-20] (McAfee, Inc.) R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [498648 2017-01-19] (McAfee, Inc.) S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [109320 2017-01-19] (McAfee, Inc.) R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [110256 2017-01-20] (McAfee, Inc.) R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.) R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [254800 2017-01-20] (McAfee, Inc.) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2010-02-02] (McAfee, Inc.) R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2010-02-02] (McAfee, Inc.) R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2010-02-02] () [Brak podpisu cyfrowego] R0 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2010-02-02] (McAfee, Inc.) R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.) R0 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2010-02-02] (McAfee, Inc.) R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2010-02-02] (McAfee, Inc.) R0 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2010-02-02] (McAfee, Inc.) R0 tib; C:\WINDOWS\System32\DRIVERS\tib.sys [1120032 2016-01-20] (Acronis International GmbH) S3 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [198432 2016-01-20] (Acronis International GmbH) R0 vidsflt; C:\WINDOWS\System32\DRIVERS\vidsflt.sys [117024 2016-01-20] (Acronis International GmbH) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) U3 idsvc; Brak ImagePath S2 NPF; \??\C:\WINDOWS\SysWoW64\drivers\npf64.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-04-09 18:33 - 2017-04-09 18:34 - 00042382 _____ C:\Users\Administrator.MOT-0055\Downloads\FRST.txt 2017-04-09 18:33 - 2017-04-09 18:33 - 02424832 _____ (Farbar) C:\Users\Administrator.MOT-0055\Downloads\FRST64.exe 2017-04-09 18:33 - 2017-04-09 18:33 - 00000000 ____D C:\FRST 2017-04-09 18:32 - 2017-04-09 18:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2017-04-09 17:22 - 2017-04-09 17:22 - 00001040 _____ C:\Users\Administrator.MOT-0055\Desktop\Patrycja.lnk 2017-04-09 17:16 - 2017-04-09 17:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2017-04-09 16:08 - 2017-04-09 18:29 - 00000000 ___RD C:\Users\Administrator.MOT-0055\iCloudDrive 2017-04-09 16:08 - 2017-04-09 16:08 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iCloud 2017-04-09 16:07 - 2017-04-09 18:07 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Local\35C9B558-5DBC-49AA-961B-A288BE40A49A.aplzod 2017-04-09 14:21 - 2017-04-09 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2017-04-09 14:21 - 2017-04-09 14:21 - 00000000 ____D C:\Program Files\iTunes 2017-04-09 14:21 - 2017-04-09 14:21 - 00000000 ____D C:\Program Files\iPod 2017-04-09 14:03 - 2017-04-09 14:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2017-04-09 14:01 - 2017-04-09 14:01 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple 2017-04-09 14:01 - 2017-04-09 14:01 - 00000000 ____D C:\Program Files\Bonjour 2017-04-09 14:01 - 2017-04-09 14:01 - 00000000 ____D C:\Program Files (x86)\Bonjour 2017-04-09 14:01 - 2017-04-09 14:01 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2017-04-09 12:42 - 2017-04-09 16:48 - 00004034 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse 2017-04-09 12:42 - 2017-04-09 15:08 - 00004222 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-04-09 18:32 - 2016-10-10 17:03 - 09210922 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-04-09 18:32 - 2016-07-17 00:05 - 04437348 _____ C:\WINDOWS\system32\perfh015.dat 2017-04-09 18:32 - 2016-07-17 00:05 - 01274166 _____ C:\WINDOWS\system32\perfc015.dat 2017-04-09 18:30 - 2013-03-05 18:24 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Roaming\Skype 2017-04-09 18:29 - 2015-05-08 10:03 - 00000000 ___RD C:\Users\Administrator.MOT-0055\Dysk Google 2017-04-09 18:29 - 2014-01-28 15:41 - 00001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk 2017-04-09 18:29 - 2010-09-14 02:58 - 00000000 ____D C:\ProgramData\HPQLOG 2017-04-09 18:28 - 2016-10-10 17:20 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-04-09 18:27 - 2016-07-16 08:04 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-04-09 18:07 - 2013-03-05 14:37 - 00000000 ____D C:\Users\Administrator.MOT-0055\Documents\Pliki programu Outlook 2017-04-09 18:06 - 2016-10-10 17:04 - 00000000 ____D C:\Users\Administrator.MOT-0055 2017-04-09 18:06 - 2016-10-10 17:01 - 00448640 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-04-09 17:16 - 2013-03-19 11:06 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Local\Google 2017-04-09 17:16 - 2011-04-30 20:37 - 00000000 ____D C:\Program Files (x86)\Google 2017-04-09 17:04 - 2013-06-08 21:21 - 00000000 ____D C:\Users\Administrator.MOT-0055\Documents\Patrycja 2017-04-09 16:49 - 2010-09-14 02:53 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-04-09 16:47 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-04-09 16:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-04-09 16:32 - 2012-05-20 11:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-04-09 16:32 - 2012-05-20 11:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-04-09 16:08 - 2014-10-02 09:58 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Local\Apple Inc 2017-04-09 16:07 - 2013-03-05 13:53 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Roaming\Apple Computer 2017-04-09 16:06 - 2013-03-05 16:12 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Local\Apple 2017-04-09 15:42 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-04-09 15:10 - 2012-05-20 11:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-04-09 14:23 - 2013-03-19 11:09 - 00002278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-04-09 14:20 - 2012-03-31 15:52 - 00000000 ____D C:\Program Files\Common Files\Apple 2017-04-09 14:18 - 2016-04-18 11:42 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Roaming\FileZilla 2017-04-09 14:15 - 2014-06-17 12:53 - 00000000 ____D C:\jzk 2017-04-09 14:13 - 2016-03-12 17:47 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-04-09 14:12 - 2013-09-04 21:31 - 00000000 ____D C:\Users\Administrator.MOT-0055\AppData\Roaming\TeamViewer 2017-04-09 14:12 - 2012-12-01 10:41 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2017-04-09 14:10 - 2011-10-25 16:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Design Center 2017-04-09 14:06 - 2013-03-16 19:22 - 00000000 ____D C:\Program Files\HP 2017-04-09 14:06 - 2013-03-16 19:22 - 00000000 ____D C:\Program Files (x86)\HP 2017-04-09 14:06 - 2010-09-14 02:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2017-04-09 14:01 - 2012-03-31 15:52 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2017-04-09 12:34 - 2015-11-19 11:13 - 00000378 _____ C:\WINDOWS\Tasks\HPCeeScheduleForAdministrator.job 2017-04-09 12:34 - 2012-08-06 12:17 - 00000000 ____D C:\ProgramData\LogMeIn 2017-04-05 13:34 - 2016-10-10 17:01 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-04-05 13:27 - 2016-10-10 17:20 - 00003302 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForAdministrator 2017-04-05 13:23 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2017-04-03 19:07 - 2016-06-21 10:45 - 00000000 ____D C:\Program Files (x86)\McAfee 2017-03-28 13:53 - 2012-07-10 09:36 - 00000000 ____D C:\ProgramData\McAfee 2017-03-23 20:25 - 2016-07-16 13:47 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2017-03-23 20:25 - 2016-06-21 10:41 - 00000000 ____D C:\Program Files\Common Files\McAfee 2017-03-23 20:24 - 2016-10-10 17:20 - 00003126 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon 2017-03-23 20:24 - 2016-10-10 17:20 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee 2017-03-23 20:20 - 2016-06-21 10:45 - 00000000 ____D C:\Program Files\Common Files\AV 2017-03-11 01:12 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\spool 2017-03-10 07:17 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-03-10 07:17 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl ==================== Pliki w katalogu głównym wybranych folderów ======= 2013-03-05 17:59 - 2013-03-05 17:59 - 0000110 _____ () C:\Users\Administrator.MOT-0055\AppData\Local\fusioncache.dat 2017-02-23 17:35 - 2017-02-23 17:35 - 0001019 _____ () C:\Users\Administrator.MOT-0055\AppData\Local\recently-used.xbel 2013-06-30 23:18 - 2013-10-22 23:42 - 0007609 _____ () C:\Users\Administrator.MOT-0055\AppData\Local\Resmon.ResmonCfg 2013-03-16 19:22 - 2013-03-16 19:22 - 0000057 _____ () C:\ProgramData\Ament.ini 2011-04-30 20:38 - 2011-04-30 20:38 - 0000056 ____H () C:\ProgramData\ezsidmv.dat Niektóre pliki w TEMP: ==================== 2016-12-19 11:42 - 2016-12-01 10:31 - 0050720 _____ (HP Inc.) C:\Users\Administrator.MOT-0055\AppData\Local\Temp\ACLMInstaller.exe 2016-10-20 17:38 - 2016-10-20 17:38 - 0737856 _____ (Oracle Corporation) C:\Users\Administrator.MOT-0055\AppData\Local\Temp\jre-8u111-windows-au.exe 2017-02-02 21:59 - 2017-02-02 21:59 - 0739904 _____ (Oracle Corporation) C:\Users\Administrator.MOT-0055\AppData\Local\Temp\jre-8u121-windows-au.exe 2012-07-06 12:12 - 2013-02-26 20:28 - 0358600 _____ (Ask.com) C:\Users\Mariusz Jagura\AppData\Local\Temp\ApnStub.exe 2011-04-30 21:41 - 2010-04-10 02:00 - 0206336 ____R (Huawei Technologies Co., Ltd.) C:\Users\Mariusz Jagura\AppData\Local\Temp\DataCard_Setup64.exe 2012-07-19 16:47 - 2012-07-19 16:47 - 0245840 _____ () C:\Users\Mariusz Jagura\AppData\Local\Temp\DE1021.dll 2012-02-10 15:19 - 2012-02-10 15:19 - 0910112 _____ (Sun Microsystems, Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\firefoxjre_exe.exe 2011-04-30 18:44 - 2011-04-30 18:44 - 2832544 _____ (Adobe Systems, Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe 2011-04-30 20:37 - 2011-04-30 20:37 - 0579976 _____ () C:\Users\Mariusz Jagura\AppData\Local\Temp\GoogleChromeInstaller.exe 2011-04-26 10:32 - 2008-01-15 00:28 - 0069632 _____ (Hewlett-Packard Company) C:\Users\Mariusz Jagura\AppData\Local\Temp\HPQSi.exe 2012-02-20 17:45 - 2012-02-20 17:45 - 0909600 _____ (Sun Microsystems, Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe 2012-06-08 03:35 - 2012-06-08 03:35 - 0909104 _____ (Sun Microsystems, Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe 2012-08-29 14:07 - 2012-08-29 14:07 - 0908272 _____ (Sun Microsystems, Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe 2012-10-01 18:44 - 2012-10-01 18:44 - 0912880 _____ (Sun Microsystems, Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe 2013-01-31 20:20 - 2013-01-31 20:20 - 0915376 _____ (Sun Microsystems, Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe 2013-02-16 07:00 - 2013-02-16 07:00 - 0897448 _____ (Oracle Corporation) C:\Users\Mariusz Jagura\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe 2011-04-26 12:34 - 2010-06-25 07:11 - 0467720 _____ (Microsoft Corporation) C:\Users\Mariusz Jagura\AppData\Local\Temp\MSN1D04.exe 2011-04-30 19:54 - 2011-04-30 19:54 - 0001536 _____ () C:\Users\Mariusz Jagura\AppData\Local\Temp\NEventMessages.dll 2011-04-30 19:55 - 2011-04-30 19:55 - 0001536 _____ () C:\Users\Mariusz Jagura\AppData\Local\Temp\NOSEventMessages.dll 2011-04-30 21:41 - 2010-04-10 02:00 - 0007168 ____R () C:\Users\Mariusz Jagura\AppData\Local\Temp\ResetDevice.exe 2012-07-20 12:13 - 2012-07-20 12:12 - 3946696 _____ (Ask) C:\Users\Mariusz Jagura\AppData\Local\Temp\setup.exe 2013-01-06 19:46 - 2013-01-06 19:46 - 0224368 _____ (Adobe Systems Inc.) C:\Users\Mariusz Jagura\AppData\Local\Temp\Shockwave_Installer_FF.exe 2011-06-16 08:55 - 2012-06-21 09:39 - 25575088 _____ (Skype Technologies S.A.) C:\Users\Mariusz Jagura\AppData\Local\Temp\SkypeSetup.exe 2011-04-26 14:05 - 2010-03-06 23:39 - 1447432 _____ (PDF Complete Inc) C:\Users\Mariusz Jagura\AppData\Local\Temp\uninstall.exe ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\wininit.exe => Plik podpisany cyfrowo C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2017-04-09 15:07 ==================== Koniec FRST.txt ============================