Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 10.02.2019 01 Uruchomiony przez ASKE VRUND (administrator) LAPTOP-HS8SNGFL (12-02-2019 11:36:31) Uruchomiony z F:\frst Załadowane profile: ASKE VRUND (Dostępne profile: ASKE VRUND) Platform: Windows 10 Home Wersja 1803 17134.523 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_c552e4480cba79db\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe (Robert McNeel & Associates) C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Intel Corporation) C:\Windows\System32\ibtsiva.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_c552e4480cba79db\IntelCpHDCPSvc.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_c552e4480cba79db\IntelCpHeciSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_c552e4480cba79db\igfxEM.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD14\PDVD14Serv.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_df0bea5643beeb1b\aesm_service.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_3.1.46.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.38.138.0_x64__kzf8qxf38zg5c\SkypeApp.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.38.138.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_3.1.46.0_x64__8wekyb3d8bbwe\Microsoft.Notes.DesktopBridge.exe (Mozilla Corporation) C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Lenovo(beijing) Limited) C:\Program Files\Lenovo\LenovoUtility\utility.exe (Mozilla Corporation) C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox\firefox.exe (Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Mozilla Corporation) C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox\firefox.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Users\ASKE VRUND\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (Lenovo Group Limited) C:\Users\ASKE VRUND\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation) HKLM\...\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [914344 2017-06-13] (LENOVO -> Lenovo(beijing) Limited) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [259976 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2675176 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated) HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [849920 2017-03-07] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [259976 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-21-2328004621-2233120447-1436725526-1001\...\MountPoints2: {34eeea0f-eafc-11e7-8202-f83441b4bb39} - "H:\HiSuiteDownLoader.exe" HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.96\Installer\chrmstp.exe [2019-02-08] (Google LLC -> Google Inc.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{2c9d0897-ec0b-476f-b7f1-85524d4645e1}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{ef54a01f-5004-4165-874a-b739f4778d54}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://newtab.club HKU\S-1-5-21-2328004621-2233120447-1436725526-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKU\S-1-5-21-2328004621-2233120447-1436725526-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE HKU\S-1-5-21-2328004621-2233120447-1436725526-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com URLSearchHook: HKU\S-1-5-21-2328004621-2233120447-1436725526-1001 - (Brak nazwy) - {2C6A44CB-AD42-4731-A544-3FBD3D83AB5B} - Brak pliku BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-06-15] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation -> Microsoft Corporation) FireFox: ======== FF DefaultProfile: 6moectdg.default FF ProfilePath: C:\Users\ASKE VRUND\AppData\Roaming\Mozilla\Firefox\Profiles\6moectdg.default [2019-02-12] FF user.js: detected! => C:\Users\ASKE VRUND\AppData\Roaming\Mozilla\Firefox\Profiles\6moectdg.default\user.js [2017-06-29] FF Extension: (System Table) - C:\Users\ASKE VRUND\AppData\Roaming\Mozilla\Firefox\Profiles\6moectdg.default\Extensions\383882@modext.tech.xpi [2018-06-20] FF Extension: (Facebook Container) - C:\Users\ASKE VRUND\AppData\Roaming\Mozilla\Firefox\Profiles\6moectdg.default\Extensions\@contain-facebook.xpi [2018-12-02] FF Extension: (uBlock Origin) - C:\Users\ASKE VRUND\AppData\Roaming\Mozilla\Firefox\Profiles\6moectdg.default\Extensions\uBlock0@raymondhill.net.xpi [2019-02-06] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\ASKE VRUND\AppData\Roaming\Mozilla\Firefox\Profiles\6moectdg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-01-24] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll [2019-01-08] () FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_114.dll [2019-01-08] () FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-03-01] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-22] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-22] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems) Chrome: ======= CHR DefaultProfile: Profile 1 CHR Profile: C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-02-11] CHR Extension: (Prezentacje) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-08-07] CHR Extension: (Dokumenty) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-08-07] CHR Extension: (Dysk Google) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-08-07] CHR Extension: (YouTube) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-08-07] CHR Extension: (Adobe Acrobat) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-08-07] CHR Extension: (Arkusze) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-08-07] CHR Extension: (Dokumenty Google offline) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-27] CHR Extension: (Avast Online Security) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-09-27] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-08-07] CHR Extension: (Gmail) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-08-07] CHR Extension: (Chrome Media Router) - C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-02-09] CHR Profile: C:\Users\ASKE VRUND\AppData\Local\Google\Chrome\User Data\System Profile [2019-02-11] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AESMService; C:\WINDOWS\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_df0bea5643beeb1b\aesm_service.exe [3235112 2018-03-14] (Intel(R) Software Development Products -> Intel Corporation) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2917864 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2709480 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6758976 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [357304 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) S3 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [194048 2017-04-09] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2413720 2017-06-09] (Intel(R) Rapid Storage Technology -> Intel Corporation) R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [507000 2017-04-21] (Intel Corporation - pGFX -> Intel Corporation) R2 McNeelUpdate; c:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [66904 2017-05-22] (Robert McNeel and Associates -> Robert McNeel & Associates) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [282200 2017-06-18] (Synaptics Incorporated -> Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4451616 2018-04-12] (Microsoft Corporation -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [107136 2018-09-21] (Microsoft Corporation -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-04-26] (WDKTestCert build,131474841775766162 -> Apple Inc.) R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37104 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [205400 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [225680 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [196072 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R0 aswblog; C:\WINDOWS\System32\drivers\aswblog.sys [320696 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [57960 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [15488 2019-01-07] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software) R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [249456 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42288 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [167304 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [112312 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [87944 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1034432 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [474456 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [216784 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [379952 2019-02-09] (AVAST Software s.r.o. -> AVAST Software) S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70632 2017-06-09] (Intel(R) Rapid Storage Technology -> Intel Corporation) R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [244744 2017-04-14] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) R3 IntcDAud; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [808944 2017-10-27] (Microsoft Windows Hardware Compatibility Publisher -> Intel(R) Corporation) R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [8623128 2018-04-04] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvlt.inf_amd64_a061a5d566db3269\nvlddmkm.sys [17038280 2018-03-16] (NVIDIA Corporation -> NVIDIA Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [950760 2017-06-13] (Realtek Semiconductor Corp. -> Realtek ) S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [420832 2017-04-07] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation) R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3228664 2017-04-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) R3 SynRMIHID; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys [57944 2017-06-18] (Synaptics Incorporated -> Synaptics Incorporated) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44616 2018-04-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [331680 2018-04-12] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-12] (Microsoft Windows -> Microsoft Corporation) U0 Partizan; system32\drivers\Partizan.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-02-12 08:34 - 2019-02-12 08:34 - 001390147 _____ C:\Users\ASKE VRUND\Downloads\miesieczny_styczen.pdf 2019-02-11 15:38 - 2019-02-12 11:36 - 000000000 ____D C:\FRST 2019-02-11 14:40 - 2019-02-11 14:40 - 000000000 ____D C:\ProgramData\Mozilla 2019-02-09 12:00 - 2019-02-09 11:59 - 000362888 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2019-02-05 18:08 - 2019-02-05 18:08 - 000008458 _____ C:\Users\ASKE VRUND\Desktop\druk.odt 2019-02-05 13:02 - 2019-02-05 13:02 - 036925569 _____ C:\Users\ASKE VRUND\Downloads\drive-download-20190205T120153Z-001.zip 2019-02-05 12:39 - 2019-02-05 12:39 - 000881722 _____ C:\Users\ASKE VRUND\Downloads\FS-V_19_01_4465.pdf 2019-02-04 14:30 - 2019-02-04 14:30 - 000135372 _____ C:\Users\ASKE VRUND\Downloads\list_przewozowy_0000140439273U.pdf 2019-01-31 00:11 - 2019-01-31 00:11 - 000134003 _____ C:\Users\ASKE VRUND\Downloads\list_przewozowy_0000139873280U.pdf 2019-01-29 19:40 - 2019-01-29 19:43 - 000038415 _____ C:\Users\ASKE VRUND\Desktop\wycena malowania.pdf 2019-01-19 11:27 - 2019-01-19 11:27 - 002422358 _____ C:\Users\ASKE VRUND\Downloads\wyszynskiego_gabinet_szafa2.pdf 2019-01-14 17:19 - 2019-02-09 11:59 - 000225680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys 2019-01-14 14:09 - 2019-01-14 14:09 - 002422358 _____ C:\Users\ASKE VRUND\Desktop\wyszynskiego_gabinet_szafa2.pdf ==================== Jeden miesiąc (zmodyfikowane) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-02-12 11:36 - 2018-05-19 11:53 - 000004236 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{ECFE92E5-7BA0-4E59-9E96-BF67EAD4D272} 2019-02-12 11:33 - 2017-12-24 15:18 - 000000000 ____D C:\Users\ASKE VRUND\AppData\LocalLow\Mozilla 2019-02-12 11:32 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-02-12 11:32 - 2017-12-24 05:52 - 000000000 __SHD C:\Users\ASKE VRUND\IntelGraphicsProfiles 2019-02-12 11:29 - 2018-05-19 11:53 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-02-12 11:29 - 2017-09-08 21:21 - 000000000 ____D C:\ProgramData\NVIDIA 2019-02-12 11:28 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-02-12 11:28 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2019-02-12 11:27 - 2018-08-06 20:50 - 000000000 ____D C:\Users\ASKE VRUND\AppData\Local\NtvHost 2019-02-12 11:22 - 2018-08-06 20:51 - 000000000 ____D C:\Users\ASKE VRUND\AppData\Local\GoogleChromeUserData 2019-02-12 11:22 - 2018-05-19 10:12 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-02-12 08:47 - 2018-08-06 20:51 - 000000000 ____D C:\Users\ASKE VRUND\AppData\Local\CrashDumps 2019-02-12 08:47 - 2018-05-19 11:53 - 000003852 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier 2019-02-12 08:47 - 2018-05-19 11:53 - 000003546 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2019-02-12 08:47 - 2018-05-19 11:53 - 000003496 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2019-02-12 08:47 - 2018-05-19 11:53 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2019-02-12 08:47 - 2018-05-19 11:53 - 000003272 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2019-02-12 08:47 - 2018-05-19 11:53 - 000002860 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2328004621-2233120447-1436725526-1001 2019-02-12 08:47 - 2018-05-19 11:53 - 000002830 _____ C:\WINDOWS\System32\Tasks\AdobeGCInvoker-1.0-LAPTOP-HS8SNGFL-ASKE VRUND 2019-02-12 08:47 - 2018-05-19 11:53 - 000002784 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-LAPTOP-HS8SNGFL-ASKE VRUND 2019-02-12 08:47 - 2018-05-19 11:53 - 000002770 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2019-02-12 08:47 - 2018-05-19 11:53 - 000002476 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher 2019-02-12 08:47 - 2018-05-19 11:53 - 000002476 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8 2019-02-12 08:47 - 2018-05-19 11:53 - 000002352 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON 2019-02-12 08:47 - 2018-05-19 11:53 - 000002336 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_LENOVO_MICPKEY 2019-02-12 08:47 - 2018-05-19 11:53 - 000002306 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_Dolby 2019-02-12 08:47 - 2018-05-19 11:53 - 000002302 _____ C:\WINDOWS\System32\Tasks\RTKCPL 2019-02-12 08:47 - 2018-05-19 11:53 - 000002218 _____ C:\WINDOWS\System32\Tasks\PDVDServ14 Task 2019-02-12 08:47 - 2018-05-19 11:53 - 000000000 ____D C:\WINDOWS\System32\Tasks\Avast Software 2019-02-12 07:48 - 2017-12-27 15:05 - 000000000 ____D C:\Users\ASKE VRUND\AppData\Local\Adobe 2019-02-11 22:55 - 2018-03-31 20:26 - 000000000 ____D C:\Users\ASKE VRUND\AppData\Local\SHU 2019-02-11 22:43 - 2018-05-19 11:45 - 001763504 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-02-11 22:43 - 2018-04-12 16:51 - 000783576 _____ C:\WINDOWS\system32\perfh015.dat 2019-02-11 22:43 - 2018-04-12 16:51 - 000151702 _____ C:\WINDOWS\system32\perfc015.dat 2019-02-11 22:43 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF 2019-02-11 22:30 - 2018-03-07 13:33 - 000000000 ____D C:\Users\ASKE VRUND\AppData\LocalLow\Temp 2019-02-11 22:24 - 2018-05-19 11:53 - 000004264 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2019-02-11 14:40 - 2017-12-24 15:18 - 000001299 _____ C:\Users\ASKE VRUND\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-02-11 14:40 - 2017-12-24 15:18 - 000000000 ____D C:\Users\ASKE VRUND\AppData\Local\Mozilla Firefox 2019-02-11 14:36 - 2018-05-19 10:19 - 000000000 ____D C:\Users\ASKE VRUND 2019-02-09 12:00 - 2018-04-12 00:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-02-09 11:59 - 2019-01-07 09:17 - 000320696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswblog.sys 2019-02-09 11:59 - 2019-01-07 09:17 - 000196072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys 2019-02-09 11:59 - 2019-01-07 09:17 - 000057960 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys 2019-02-09 11:59 - 2019-01-07 09:17 - 000037104 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys 2019-02-09 11:59 - 2018-10-12 18:30 - 000042288 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 001034432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 000474456 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 000379952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 000216784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 000205400 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 000167304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 000112312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2019-02-09 11:59 - 2018-01-24 08:47 - 000087944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2019-02-09 11:59 - 2018-01-12 21:41 - 000249456 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys 2019-02-08 14:40 - 2018-06-21 23:38 - 000000000 ____D C:\ProgramData\Packages 2019-02-08 14:40 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps 2019-02-08 13:56 - 2018-05-19 10:19 - 000002433 _____ C:\Users\ASKE VRUND\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-02-08 13:56 - 2017-12-24 05:55 - 000000000 ___RD C:\Users\ASKE VRUND\OneDrive 2019-02-08 02:09 - 2018-08-07 12:13 - 000002314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-01-21 14:52 - 2017-12-27 15:11 - 000000034 _____ C:\Users\ASKE VRUND\AppData\Roaming\AdobeWLCMCache.dat 2019-01-18 22:52 - 2018-01-12 09:34 - 000000000 ____D C:\Program Files\rempl 2019-01-17 08:45 - 2018-01-06 22:45 - 000000000 ____D C:\Users\ASKE VRUND\AppData\Local\LenovoServiceBridge ==================== Pliki w katalogu głównym wybranych folderów ======= 2017-12-27 15:11 - 2019-01-21 14:52 - 000000034 _____ () C:\Users\ASKE VRUND\AppData\Roaming\AdobeWLCMCache.dat ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\wininit.exe => Plik podpisany cyfrowo C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dllhost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dllhost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2018-05-19 10:11 ==================== Koniec FRST.txt ============================