Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 13.01.2019 Uruchomiony przez Gracjan (administrator) DESKTOP-ET5NQDF (14-01-2019 10:54:51) Uruchomiony z C:\Users\Gracjan\Downloads\Programs Załadowane profile: Gracjan (Dostępne profile: Gracjan) Platform: Windows 10 Home Wersja 1803 17134.228 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: Opera) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe () C:\ProgramData\DataCardService\HWDeviceService64.exe (Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe () C:\Program Files\Intel Driver and Support Assistant\SUR\SurSvc.exe () C:\Program Files (x86)\NordVPN\nordvpn-service.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Promosoft Software Limited) C:\Program Files (x86)\Secure Folders\SecureFolders.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Dominik Reichl) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe (NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe (Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSATray.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera_crashreporter.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeApp.exe (Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\SrTasks.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DataCardService\DCSHelper.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Opera Software) C:\Program Files\Opera\51.0.2830.40\opera.exe (Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\Windows-KB890830-x64-V5.68.exe (Microsoft Corporation) C:\Windows\System32\MRT.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8505088 2017-04-21] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2017-04-21] (Realtek Semiconductor) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-11-26] (AVAST Software) HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [131360 2017-09-18] (Intel) HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [3268176 2018-09-10] (Dominik Reichl) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-11-26] (AVAST Software) HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\Run: [KeePass Password Safe 2] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [3268176 2018-09-10] (Dominik Reichl) HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4042808 2018-11-16] (Tonec Inc.) HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [3003344 2018-09-11] (NordVPN) HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {25d21d74-f86c-11e8-b918-9cad97848958} - "E:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {32510a32-267f-11e7-9bd1-9cad97848958} - "E:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {445cf8fa-88c5-11e7-a05a-9cad97848958} - "E:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {45b1a51f-2682-11e7-9bd3-9cad97848958} - "E:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {46b087a7-e69f-11e8-b913-9cad97848958} - "E:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {747e4d3f-2687-11e7-9bd4-c4a64f0a4ce2} - "E:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {a12fd526-d44c-11e7-aea6-b54626d8cbf4} - "F:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {ff519978-e50e-11e8-b911-9cad97848958} - "E:\AutoRun.exe" HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\MountPoints2: {ff5199fc-e50e-11e8-b911-9cad97848958} - "E:\AutoRun.exe" HKLM\...\Drivers32: [VIDC.FPS1] => C:\WINDOWS\system32\frapsv64.dll [105984 2017-12-22] (Beepa P/L) HKLM\...\Drivers32-x32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2017-12-22] (Beepa P/L) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 Tcpip\..\Interfaces\{07ba4cb7-43aa-4b22-b631-cdfa4a3aadf1}: [NameServer] 213.158.199.1 213.158.199.5 Tcpip\..\Interfaces\{76e6f4b0-c58c-4e6c-b96b-d5a11d1f0fc4}: [DhcpNameServer] 192.168.8.1 Tcpip\..\Interfaces\{df12f035-e85a-491d-bf03-f906e71e5538}: [DhcpNameServer] 192.168.8.1 Internet Explorer: ================== BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2018-11-15] (Internet Download Manager, Tonec Inc.) BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2018-11-15] (Internet Download Manager, Tonec Inc.) FireFox: ======== FF HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Gracjan\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\Gracjan\AppData\Roaming\IDM\idmmzcc5 [2018-02-25] [Przestarzałe] [Brak podpisu cyfrowego] FF HKU\S-1-5-21-2588104020-516653695-3563437014-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Przestarzałe] FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2018-01-23] (Tracker Software Products (Canada) Ltd.) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2018-01-23] (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-10] (VideoLAN) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2018-01-23] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2018-01-23] (Tracker Software Products (Canada) Ltd.) Chrome: ======= CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-11-17] CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-11-17] Opera: ======= OPR Extension: (uBlock Origin) - C:\Users\Gracjan\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2018-12-08] OPR Extension: (Zainstaluj rozszerzenia Chrome) - C:\Users\Gracjan\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2018-12-08] OPR Extension: (IDM Integration Module) - C:\Users\Gracjan\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-12-20] OPR Extension: (chromeIPass) - C:\Users\Gracjan\AppData\Roaming\Opera Software\Opera Stable\Extensions\ompiailgknfdndiefoaoiligalphfdae [2018-12-08] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [324000 2018-11-26] (AVAST Software) S3 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2018-11-26] (AVAST Software) R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [22816 2017-09-18] (Intel) S3 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe [824592 2017-03-07] () R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [351824 2014-01-15] () R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [319096 2017-05-18] (Intel Corporation) S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [682064 2014-04-26] () R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [437200 2018-09-11] () R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2017-04-21] (Realtek Semiconductor) S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] () R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-08-18] (Synaptics Incorporated) R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel Driver and Support Assistant\SUR\SurSvc.exe [157456 2017-03-07] () S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe [824592 2017-03-07] () S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\NisSrv.exe [3917016 2018-10-24] (Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MsMpEng.exe [114208 2018-10-24] (Microsoft Corporation) S3 aswbIDSAgent; "C:\Program Files\AVAST Software\Avast\aswidsagent.exe" [X] ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37304 2019-01-05] (AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [203488 2019-01-05] (AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [220688 2019-01-05] (AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [196264 2019-01-05] (AVAST Software) R0 aswblog; C:\WINDOWS\System32\drivers\aswblog.sys [320888 2019-01-05] (AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [58160 2019-01-05] (AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [15488 2019-01-05] (AVAST Software) R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [239808 2019-01-05] (AVAST Software) S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46584 2019-01-05] (AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42488 2019-01-05] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [166472 2019-01-05] (AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111992 2019-01-05] (AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [88144 2019-01-05] (AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1034056 2019-01-05] (AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [474648 2019-01-05] (AVAST Software) S2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [218056 2019-01-05] (AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [380144 2019-01-05] (AVAST Software) S2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [303616 2017-12-20] () [Brak podpisu cyfrowego] R3 hwusb_cdcacm; C:\WINDOWS\system32\DRIVERS\ew_cdcacm.sys [124800 2014-06-11] (Huawei Technologies Co., Ltd.) R3 hwusb_wwanecm; C:\WINDOWS\System32\drivers\ew_wwanecm.sys [379392 2014-05-04] (Huawei Technologies Co., Ltd.) S2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [35328 2017-12-20] () [Brak podpisu cyfrowego] R3 netr28x; C:\WINDOWS\System32\drivers\netr28x.sys [2537984 2018-04-12] (MediaTek Inc.) S3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2017-04-21] (Realtek Semiconductor Corp.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-12] (Realtek ) R3 rtbth; C:\WINDOWS\System32\drivers\rtbth.sys [1219200 2017-04-21] (Ralink Technology, Corp.) S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2016-10-18] () R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (The OpenVPN Project) R1 tcpint; C:\WINDOWS\system32\drivers\tcpint.sys [45736 2018-10-17] (Promosoft Software Limited) S3 VSScanner; C:\WINDOWS\System32\DRIVERS\vsscanner.sys [29808 2016-08-18] (VoodooSoft, LLC) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46184 2018-10-24] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [328696 2018-10-24] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60408 2018-10-24] (Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34960 2018-02-02] (HP) R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-11-28] (Zemana Ltd.) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-01-14 10:54 - 2019-01-14 10:54 - 000000000 ____D C:\FRST 2019-01-10 17:04 - 2019-01-10 17:04 - 000000000 ____D C:\WINDOWS\system32\BleederPTDE 2019-01-10 14:38 - 2019-01-10 14:38 - 000001050 _____ C:\Users\Public\Desktop\Dark Souls - Prepare to Die Edition.lnk 2019-01-10 14:38 - 2019-01-10 14:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BANDAI NAMCO Games 2019-01-09 12:36 - 2019-01-09 12:36 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\SmartSteamEmu 2019-01-05 15:14 - 2019-01-05 15:11 - 000320888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswblog.sys 2019-01-05 15:14 - 2019-01-05 15:11 - 000220688 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys 2019-01-05 15:14 - 2019-01-05 15:11 - 000196264 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys 2019-01-05 15:14 - 2019-01-05 15:11 - 000058160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys 2019-01-05 15:14 - 2019-01-05 15:11 - 000037304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys 2019-01-05 15:12 - 2019-01-05 15:11 - 000361352 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2018-12-24 11:41 - 2018-12-24 11:42 - 000000000 ___HD C:\$WINDOWS.~BT 2018-12-20 17:59 - 2018-12-20 17:59 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\Cuphead 2018-12-20 17:55 - 2018-12-20 17:55 - 000000737 _____ C:\Users\Public\Desktop\Cuphead.lnk 2018-12-20 17:55 - 2018-12-20 17:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cuphead 2018-12-20 12:38 - 2018-12-24 10:17 - 001048576 _____ C:\WINDOWS\system32\secedit.sdb 2018-12-20 12:38 - 2018-12-24 10:17 - 000016384 _____ C:\WINDOWS\system32\secedit.jfm 2018-12-18 13:19 - 2018-12-18 13:19 - 000001763 _____ C:\Users\Public\Desktop\Gothic II Złota Edycja.lnk 2018-12-18 13:14 - 2018-12-18 13:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JoWood ==================== Jeden miesiąc (zmodyfikowane) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-01-14 10:54 - 2018-02-25 14:30 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\DMCache 2019-01-14 10:54 - 2017-11-28 17:18 - 002969432 _____ C:\WINDOWS\ZAM_Guard.krnl.trace 2019-01-14 10:53 - 2018-02-25 14:30 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\IDM 2019-01-14 10:53 - 2017-11-28 12:50 - 132790320 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2019-01-14 10:53 - 2017-11-28 12:50 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-01-14 10:52 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-01-14 10:18 - 2018-11-14 19:07 - 000000000 ____D C:\ProgramData\DataCardService 2019-01-14 10:07 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-01-14 09:41 - 2018-10-24 11:30 - 000004264 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2019-01-14 09:38 - 2017-04-17 15:04 - 000000000 __SHD C:\Users\Gracjan\IntelGraphicsProfiles 2019-01-13 21:21 - 2017-11-28 16:51 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\KeePass 2019-01-13 21:11 - 2018-11-13 12:50 - 000002546 _____ C:\WINDOWS\System32\Tasks\BlueStacksHelper 2019-01-13 21:11 - 2018-10-24 11:31 - 000000000 ____D C:\WINDOWS\System32\Tasks\Avast Software 2019-01-13 21:11 - 2018-10-17 16:18 - 000002826 _____ C:\WINDOWS\System32\Tasks\tcpint 2019-01-13 21:11 - 2018-05-24 18:53 - 000003862 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier 2019-01-13 21:11 - 2018-05-24 18:53 - 000003546 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2019-01-13 21:11 - 2018-05-24 18:53 - 000003370 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{56A7F370-BC27-4E83-9E0F-F5B5895D7E07} 2019-01-13 21:11 - 2018-05-24 18:53 - 000003348 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1511884062 2019-01-13 21:11 - 2018-05-24 18:53 - 000002856 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2588104020-516653695-3563437014-1001 2019-01-13 20:42 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-01-12 20:10 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps 2019-01-10 20:11 - 2018-05-24 18:25 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-01-10 15:10 - 2018-10-24 11:32 - 000000000 ____D C:\Users\Gracjan\AppData\Local\CrashDumps 2019-01-10 15:00 - 2018-02-25 14:30 - 000000000 ____D C:\Users\Gracjan\Downloads\Compressed 2019-01-10 14:28 - 2017-11-28 19:40 - 000000000 ____D C:\Games 2019-01-10 11:22 - 2018-10-21 14:01 - 000000004 ___SH C:\WINDOWS\system32\tcpintst1.dat 2019-01-09 13:27 - 2017-05-24 12:39 - 000000000 ____D C:\Users\Gracjan\Downloads\Gry 2019-01-09 12:36 - 2018-06-04 12:41 - 000000000 ____D C:\Users\Gracjan\Documents\NBGI 2019-01-09 12:36 - 2017-12-29 20:39 - 000000000 ____D C:\Users\Gracjan\AppData\Local\NBGI 2019-01-08 11:08 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-01-08 11:08 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Macromed 2019-01-05 15:12 - 2018-10-24 11:29 - 000474648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000380144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000218056 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000203488 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000166472 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000111992 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000088144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000046584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2019-01-05 15:12 - 2018-10-24 11:29 - 000015488 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys 2019-01-05 15:12 - 2018-04-12 00:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-01-05 15:11 - 2018-10-24 11:29 - 001034056 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2019-01-05 15:11 - 2018-10-24 11:29 - 000239808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys 2019-01-05 15:11 - 2018-10-24 11:29 - 000042488 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2019-01-03 15:03 - 2017-04-18 15:53 - 000014030 _____ C:\Users\Gracjan\Documents\Hasła.kdbx 2018-12-31 16:50 - 2018-10-17 16:17 - 000001027 _____ C:\Users\Gracjan\Desktop\Secure Folders.lnk 2018-12-30 13:43 - 2017-11-28 17:14 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\qBittorrent 2018-12-30 13:09 - 2017-11-28 17:13 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\vlc 2018-12-26 13:15 - 2018-03-14 11:27 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\TeamViewer 2018-12-25 20:05 - 2017-11-28 11:25 - 000000000 ____D C:\Users\Gracjan\AppData\Local\VirtualStore 2018-12-24 11:43 - 2018-05-24 18:53 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2018-12-24 11:42 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2018-12-23 16:16 - 2018-07-31 11:38 - 000000000 ____D C:\ProgramData\Packages 2018-12-20 19:02 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2018-12-20 17:41 - 2017-04-16 20:09 - 000000000 ____D C:\Users\Gracjan\Downloads\Filmy 2018-12-18 15:16 - 2018-02-25 14:30 - 000000000 ____D C:\Users\Gracjan\Downloads\Video 2018-12-18 13:24 - 2018-06-21 15:14 - 000000000 ____D C:\Users\Gracjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Gothic 2018-12-18 13:14 - 2017-11-28 19:41 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2018-12-15 20:20 - 2018-05-24 18:32 - 000002413 _____ C:\Users\Gracjan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-12-15 20:20 - 2017-04-15 17:28 - 000000000 ___RD C:\Users\Gracjan\OneDrive 2018-12-15 20:13 - 2017-11-28 16:33 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\wininit.exe => Plik podpisany cyfrowo C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2018-05-24 18:25 ==================== Koniec FRST.txt ============================