Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 31-08-2019 Uruchomiony przez pan (administrator) DESKTOP-4V2MUSR (MSI MS-7917) (02-09-2019 18:42:05) Uruchomiony z F:\MPEWE3 Załadowane profile: pan (Dostępne profile: pan & DefaultAppPool) Platform: Windows 10 Pro Wersja 1809 17763.437 (X64) Język: Polski (Polska) Domyślna przeglądarka: Chrome Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [C:\Windows\system32\V0790Ext.ax] => C:\Windows\system32\RegSvr32.exe /s C:\Windows\system32\V0790Ext.ax HKLM-x32\...\Run: [V0790Mon.exe] => C:\Windows\V0790Mon.exe [43120 2015-08-24] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.) HKLM-x32\...\Run: [C:\Windows\System32\V0790Ext.ax] => C:\Windows\system32\RegSvr32.exe /s C:\Windows\System32\V0790Ext.ax HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-4206559654-666896865-3126448029-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3210528 2019-08-22] (Valve -> Valve Corporation) HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Windows\System32\osk.exe [637952 2018-09-15] (Microsoft Windows -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.132\Installer\chrmstp.exe [2019-08-30] (Google LLC -> Google LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2019-04-08] ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS -> SteelSeries ApS) GroupPolicy: Ograniczenia ? <==== UWAGA FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {0B04E381-4552-43B0-93B2-20BE215B48A2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849720 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) Task: {0FA8BCE3-C782-44FD-AF69-A5110639DA13} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877368 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) Task: {15CC697A-A3B0-485F-915A-0E6C2D18EEA0} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [849720 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) Task: {24A17057-F13A-4AD6-816A-DC10EAEAE51F} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877368 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) Task: {27CE7308-6901-443B-A1ED-CC2AAA7FA0D9} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [745664 2016-01-12] (@ByELDI -> @ByELDI) [Brak podpisu cyfrowego] Task: {30F2C5F8-BB2F-4A95-B31F-4429E32B521D} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [591160 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) Task: {31354911-9E8D-498B-93C0-5B04D0F0D710} - System32\Tasks\Opera scheduled Autoupdate 1556485492 => C:\Users\pan\AppData\Local\Programs\Opera\launcher.exe [1492568 2019-04-25] (Opera Software AS -> Opera Software) Task: {51ACCA7C-56E9-4F15-9B1F-68F182EDCD7B} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877368 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) Task: {5C014CE4-3C4C-42E7-8A85-01B1BCE6A9C3} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2045832 2019-08-19] (AVAST Software s.r.o. -> AVAST Software) Task: {71DD46F5-4347-4634-BCE7-1F714000CB65} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-08] (Google Inc -> Google LLC) Task: {F6A0E657-A0D4-463F-9ED5-741C5E26A2EE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-08] (Google Inc -> Google LLC) Task: {F826D151-6C7E-4664-87CD-4C7853975C37} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877368 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1c1b7dd4-ca0c-44af-b293-92d03854b689}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA Edge: ====== DownloadDir: C:\Users\pan\Downloads FireFox: ======== FF DefaultProfile: n914lc7u.default FF ProfilePath: C:\Users\pan\AppData\Roaming\Mozilla\Firefox\Profiles\n914lc7u.default [2019-06-29] FF Extension: (ETP Search Volume Study) - C:\Users\pan\AppData\Roaming\Mozilla\Firefox\Profiles\n914lc7u.default\Extensions\etp-search-volume-study@shield.mozilla.org.xpi [2019-05-30] FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2019-03-17] (NVIDIA Corporation -> NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2019-03-17] (NVIDIA Corporation -> NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC) Chrome: ======= CHR HomePage: Default -> hxxp://feed.snapdo.com/?publisher=Vittalia&dpid=Vittalia&co=DE&userid=c420d504-dbe9-8f92-3a7e-cea3d0923cd9&searchtype=hp&installDate={installDate} CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hp&ts=1428141442&from=cor&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F0RUVTCSUVTCS","hxxp://www.gazeta.pl/0,0.html?p=190","hxxps://www.google.com/" CHR Profile: C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default [2019-09-02] CHR DownloadDir: F:\MPEWE3 CHR Extension: (Prezentacje) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-08] CHR Extension: (Flash Video Downloader) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc [2019-07-25] CHR Extension: (Dokumenty) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-08] CHR Extension: (Dysk Google) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-04-08] CHR Extension: (YouTube) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-08] CHR Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-08-27] CHR Extension: (xt7.pl) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chddajbelbdicklppkegllobkkdcgekf [2019-06-27] CHR Extension: (Arkusze) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-08] CHR Extension: (Dokumenty Google offline) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-04-08] CHR Extension: (AdBlock) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-08-29] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-04-08] CHR Extension: (Kreissparkasse Ludwigsburg (60450050)...) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\oomdkgkdohffacdaommilacnkibmmlna [2019-04-08] CHR Extension: (Gmail) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-08] CHR Extension: (Chrome Media Router) - C:\Users\pan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-11] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [441664 2019-07-17] (Digital Wave Ltd -> Digital Wave Ltd) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5382448 2019-04-10] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [745664 2016-01-12] (@ByELDI -> @ByELDI) [Brak podpisu cyfrowego] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3830128 2019-03-05] (Microsoft Corporation -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [110944 2018-09-15] (Microsoft Corporation -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [135520 2019-07-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes) R1 HWiNFO; C:\Windows\system32\drivers\HWiNFO64A.SYS [65616 2019-05-22] (Martin Malik - REALiX -> REALiX(tm)) R3 KillerEth; C:\Windows\System32\drivers\e2xw10x64.sys [145920 2018-09-15] (Microsoft Windows -> Qualcomm Atheros, Inc.) R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-09-01] (Malwarebytes Corporation -> Malwarebytes) S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-09-01] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-09-01] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-09-01] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [116112 2019-09-01] (Malwarebytes Corporation -> Malwarebytes) R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c5dc31c3a136544a\nvlddmkm.sys [20746632 2019-03-18] (NVIDIA Corporation -> NVIDIA Corporation) R0 sptd2; C:\Windows\System32\Drivers\sptd2.sys [203296 2019-05-30] (Disc Soft Ltd -> Duplex Secure Ltd) R3 ssdevfactory; C:\Windows\System32\drivers\ssdevfactory.sys [46776 2019-02-01] (SteelSeries ApS -> ) R3 sshid; C:\Windows\System32\drivers\sshid.sys [48032 2018-12-03] (SteelSeries ApS -> SteelSeries ApS) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166752 2019-07-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 tap0901; C:\Windows\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S3 V0790Vid; C:\Windows\system32\DRIVERS\V0790Vid.sys [389128 2015-08-24] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Ltd.) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46584 2018-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [340008 2018-09-15] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [61992 2018-09-15] (Microsoft Windows -> Microsoft Corporation) S1 iuaevkok; \??\C:\Windows\system32\drivers\iuaevkok.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-09-02 18:41 - 2019-09-02 18:42 - 000000000 ____D C:\FRST 2019-09-02 18:06 - 2019-09-02 18:06 - 156309534 _____ C:\Users\pan\Desktop\motur.rar 2019-09-02 18:04 - 2019-09-02 18:04 - 000000000 ____D C:\Users\pan\Desktop\motur 2019-09-02 18:00 - 2019-09-02 18:03 - 000000000 ____D C:\Users\pan\Desktop\DCIM 2019-09-01 01:31 - 2019-09-01 01:31 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2019-09-01 01:31 - 2019-09-01 01:31 - 000116112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2019-09-01 01:31 - 2019-09-01 01:31 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2019-09-01 01:29 - 2019-09-01 01:29 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2019-09-01 01:29 - 2019-09-01 01:29 - 000000000 ____D C:\Users\pan\AppData\Local\mbam 2019-09-01 01:28 - 2019-09-01 01:31 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2019-09-01 01:28 - 2019-09-01 01:28 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2019-09-01 01:28 - 2019-09-01 01:28 - 000000000 ____D C:\Users\pan\AppData\Local\mbamtray 2019-09-01 01:28 - 2019-09-01 01:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-09-01 01:28 - 2019-09-01 01:28 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-09-01 01:28 - 2019-09-01 01:28 - 000000000 ____D C:\Program Files\Malwarebytes 2019-09-01 01:28 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys 2019-09-01 01:28 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys 2019-08-04 18:12 - 2019-08-04 18:12 - 000000000 ____D C:\Users\pan\AppData\Local\ElevatedDiagnostics ==================== Jeden miesiąc (zmodyfikowane) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-09-02 18:25 - 2018-09-15 09:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-09-02 18:00 - 2018-09-15 09:31 - 000000000 ____D C:\Windows\INF 2019-09-02 17:43 - 2019-04-08 21:37 - 000000000 ____D C:\Windows\system32\SleepStudy 2019-09-02 12:13 - 2019-04-08 22:30 - 000000000 ____D C:\Users\pan\AppData\Roaming\TS3Client 2019-09-01 22:37 - 2019-04-08 22:15 - 000000000 ____D C:\Program Files (x86)\Steam 2019-09-01 15:41 - 2019-04-08 21:44 - 000000000 ____D C:\ProgramData\NVIDIA 2019-09-01 01:40 - 2019-04-08 21:38 - 002052582 _____ C:\Windows\system32\PerfStringBackup.INI 2019-09-01 01:40 - 2018-09-15 18:43 - 000889024 _____ C:\Windows\system32\perfh015.dat 2019-09-01 01:40 - 2018-09-15 18:43 - 000198760 _____ C:\Windows\system32\perfc015.dat 2019-09-01 01:31 - 2019-04-08 21:37 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-09-01 01:30 - 2019-04-08 21:49 - 000000000 ____D C:\Program Files\KMSpico 2019-09-01 01:30 - 2019-04-08 21:42 - 000000000 ____D C:\Users\pan 2019-09-01 01:30 - 2018-09-15 08:09 - 000524288 _____ C:\Windows\system32\config\BBI 2019-09-01 01:28 - 2018-09-15 09:33 - 000000000 ___HD C:\Windows\ELAMBKUP 2019-08-30 10:38 - 2018-09-15 09:33 - 000000000 ___HD C:\Program Files\WindowsApps 2019-08-30 10:38 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\AppReadiness 2019-08-30 10:33 - 2019-04-08 22:05 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-08-30 10:33 - 2019-04-08 22:05 - 000002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-08-29 22:45 - 2019-04-09 19:12 - 000000000 ____D C:\Users\pan\AppData\Roaming\vlc 2019-08-10 09:52 - 2019-04-08 21:44 - 000003374 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4206559654-666896865-3126448029-1001 2019-08-10 09:52 - 2019-04-08 21:44 - 000000000 ___RD C:\Users\pan\OneDrive 2019-08-10 09:52 - 2019-04-08 21:42 - 000002401 _____ C:\Users\pan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-08-04 18:12 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\system32\NDF ==================== FLock ================ 2019-04-08 21:41 C:\Windows\CSC ==================== SigCheck =============================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ============================