Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 29-05-2020 Uruchomiony przez Agata (administrator) AGATA-KOMPUTER (SAMSUNG ELECTRONICS CO., LTD. R540/SA41/E452) (29-05-2020 23:43:16) Uruchomiony z C:\Users\Agata\Desktop\fixitpc Załadowane profile: Agata Platform: Windows 7 Home Premium Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) () [Brak podpisu cyfrowego] C:\Windows\SysWOW64\atwtusb.exe <2> () [Brak podpisu cyfrowego] C:\Windows\SysWOW64\Rezip.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Brother Industries, Ltd.) [Brak podpisu cyfrowego] C:\Program Files (x86)\Brother\BrUtilities\BrLogRx.exe (Brother Industries, Ltd.) [Brak podpisu cyfrowego] C:\Program Files (x86)\Brother\SoftwareUpdateNotification\SoftwareUpdateNotificationService.exe (Brother Industries, Ltd.) [Brak podpisu cyfrowego] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) [Brak podpisu cyfrowego] C:\Program Files (x86)\Browny02\BrYNSvc.exe (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe (Intel Corporation -> Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation -> Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation -> Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (Microsoft) [Brak podpisu cyfrowego] C:\Program Files (x86)\Brother\iPrint&Scan\USBAppControl.exe (Microsoft) [Brak podpisu cyfrowego] C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <9> (Nuance Communications, Inc. -> Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc. -> Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (PreSonus) [Brak podpisu cyfrowego] C:\Program Files\PreSonus\Universal Control\PreSonusHardwareAccessService.exe (Protexis Inc. -> Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-06] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [CTFmon] => C:\Windows\System32\ctfmon.exe [9728 2009-07-14] (Microsoft Windows -> Microsoft Corporation) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [146584 2017-11-07] (Brother Industries, Ltd. -> Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2976256 2018-01-19] (Brother Industries, Ltd.) [Brak podpisu cyfrowego] HKLM-x32\...\Run: [BrotherSoftwareUpdateNotification] => C:\Program Files (x86)\Brother\SoftwareUpdateNotification\SoftwareUpdateNotificationService.exe [3581952 2017-04-05] (Brother Industries, Ltd.) [Brak podpisu cyfrowego] HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [35648 2015-01-19] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [17600 2015-01-19] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKU\S-1-5-21-233006258-18527085-3623643150-1000\...\MountPoints2: {79226059-fcd7-11e2-b934-001bb11349d0} - F:\LGAutoRun.exe HKLM\...\Windows x64\Print Processors\hpzppw71: C:\Windows\System32\spool\prtprocs\x64\hpzppw71.dll [230400 2009-07-14] (Microsoft Windows -> Hewlett-Packard Corporation) HKLM\...\Windows x64\Print Processors\sht13cPC: C:\Windows\System32\spool\prtprocs\x64\sht13cpc.dll [82856 2019-07-21] (联想图像(天津)科技有限公司 -> Windows (R) Codename Longhorn DDK provider) HKLM\...\Print\Monitors\FRITZ!fax Color Port Monitor: C:\Windows\system32\FritzColorPort64.dll [20480 2006-02-23] () [Brak podpisu cyfrowego] HKLM\...\Print\Monitors\FRITZ!fax Port Monitor: C:\Windows\system32\FritzPort64.dll [20480 2006-02-22] () [Brak podpisu cyfrowego] HKLM\...\Print\Monitors\PCL hpz3lw71: C:\Windows\system32\hpz3lw71.dll [46080 2009-07-14] (Microsoft Windows -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\sht13c Langmon: C:\Windows\system32\sht13clm.dll [61840 2019-07-21] (联想图像(天津)科技有限公司 -> ) HKLM\...\Print\Monitors\WSD Port: C:\Windows\system32\WSDMon.dll [224768 2009-07-14] (Microsoft Windows -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] -> HKLM\Software\...\Authentication\Credential Providers: [{50968FF7-10C1-4fb3-98B0-CD654D6CB97E}] -> C:\Program Files\WIDCOMM\Bluetooth Software\\BtwCP.dll [2011-08-25] (Broadcom Corporation -> Broadcom Corporation.) HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2012-07-17] (Microsoft Corporation -> Microsoft Corp.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2020-02-02] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation -> Broadcom Corporation.) ==================== Zaplanowane zadania (filtrowane) ============ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {01893C33-2821-460A-AD0C-BC9E1C8A6692} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} Task: {1E73184A-49CD-4339-98D5-DEC6025EB182} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe [7053168 2010-11-28] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) Task: {21A9FD56-5FA3-4564-9FAE-068A55177FF5} - System32\Tasks\{1B205510-0FC7-4854-A639-2277CA1D3BAF} => C:\Program Files (x86)\Skype\Phone\Skype.exe Task: {2D8BB2F9-30EE-462A-8D58-03A734461A3E} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [410784 2016-11-14] (Microsoft Corporation -> Microsoft Corporation) Task: {3054BBB5-76F7-413B-9A6B-6486C25BC762} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [3602632 2017-04-26] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) [Brak podpisu cyfrowego] Task: {38498DCC-8DE5-4FBC-B931-93C29662D975} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-03-25] (Adobe Inc. -> Adobe) Task: {4AF7A391-BDBA-41E5-BF82-AB27C1588403} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_Plugin.exe [1458232 2020-03-25] (Adobe Inc. -> Adobe) Task: {4C617067-C474-4A6D-A1DD-F0F59CE6F555} - System32\Tasks\{FF520B28-D09C-4329-9B51-8517F7A15021} => C:\Program Files (x86)\Microsoft Office\OFFICE11\POWERPNT.EXE [6421848 2011-04-20] (Microsoft Corporation -> Microsoft Corporation) Task: {569EA101-1744-491E-AAB7-B1DC1EDEB714} - System32\Tasks\AdwCleaner_onReboot => C:\Users\Agata\Downloads\adwcleaner_8.0.2.exe Task: {60DF9B01-EA62-4C92-B377-889DB93B9CA0} - System32\Tasks\JetCleanLoginCheckUpdate => D:\JetCleanPortable_1.5.0.129 program do czyszczenia\AutoUpdate.exe [1050928 2016-06-23] (BlueSprig, Inc. -> BlueSprig) Task: {7105A300-27A0-46CE-9955-AA9820E31DF6} - System32\Tasks\{CD6345FD-ACE9-4A8D-AF8C-A2419552B51F} => C:\Program Files (x86)\Corel\Corel Graphics 12\Programs\CorelPP.exe [155648 2004-06-10] (Corel Corporation) [Brak podpisu cyfrowego] Task: {7A4E0893-DA89-43D6-8E0A-ED44B1016E4E} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [356352 2010-03-29] (SAMSUNG Electronics co., LTD.) [Brak podpisu cyfrowego] Task: {813DE74B-BD1F-481D-A889-BF37B008C798} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1165920 2017-07-19] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Task: {A102BA3F-5DC0-4B0A-ADDB-C83315C3D602} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2020-05-25] (Piriform Software Ltd -> Piriform Software Ltd) Task: {A8351280-B4B1-4B3E-86D8-82EB8BAD9710} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [1749504 2010-05-06] (SAMSUNG Electronics) [Brak podpisu cyfrowego] Task: {A8EAC285-73FC-4C2D-8828-44308BB42F08} - System32\Tasks\{934CF21D-7A1C-4B78-87F8-5DFE56AB2B73} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2187344 2016-12-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) [Brak podpisu cyfrowego] Task: {BA404A94-0207-4466-B7AA-9733A601BB76} - System32\Tasks\{5B2AEA1E-C42D-4DBB-A265-B36CE63A0BC8} => C:\Program Files (x86)\Microsoft Office\OFFICE11\POWERPNT.EXE [6421848 2011-04-20] (Microsoft Corporation -> Microsoft Corporation) Task: {BCE4A354-1627-425F-90A5-30899DBAC62F} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [943984 2010-11-28] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) Task: {D1D7DC3F-DDA3-4170-AED0-C67B2CE827CF} - System32\Tasks\EasySpeedUpManager => Command(1): "%programfiles(x86)%\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe" -> /s Task: {D1D7DC3F-DDA3-4170-AED0-C67B2CE827CF} - System32\Tasks\EasySpeedUpManager => Command(2): C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [719360 [719360 2010-02-10]] (Samsung Electronics Co., Ltd.) [Brak podpisu cyfrowego] Task: {D49EAEC8-24C8-4FD6-954D-A9316F962C0B} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1179648 2018-05-31] () [Brak podpisu cyfrowego] Task: {DC1C396E-85AC-45A8-848A-89F723AD9623} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [6624768 2010-04-17] (Samsung Electronics. Co. Ltd.) [Brak podpisu cyfrowego] Task: {E791B4AB-7085-4080-80DF-1B8B34C00131} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [13797712 2020-05-25] (Piriform Ltd -> Piriform Ltd) Task: {EAF1649C-8C9F-4688-83F8-39831ADA17F0} - System32\Tasks\{F0E04983-07AF-44DB-ADCB-B3AAACF7E1CB} => C:\Program Files\Malwarebytes Anti-Malware\mbam.exe Task: {ED2DF751-B92E-4298-B757-CCDB92B25565} - System32\Tasks\{1D31D6CB-A908-40CF-9AAE-AF2AACD0947C} => C:\Program Files (x86)\Nufsoft\NatureStudio\NatureStudio.exe [2441216 2011-05-31] (Nufsoft) [Brak podpisu cyfrowego] Task: {FEA84312-C5C3-400E-BCA2-8436BFB67093} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2201192 2010-01-19] (Samsung Electronics CO., LTD. -> SEC) [Brak podpisu cyfrowego] (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.) Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.) Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.) Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4 Tcpip\..\Interfaces\{A8A3C5F9-E5DC-43E3-821F-22660015189D}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131219898028734845&GUID=EF824AA4-C6FA-2914-6BC7-7654B827F3A0 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131219898028734845&GUID=EF824AA4-C6FA-2914-6BC7-7654B827F3A0 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-233006258-18527085-3623643150-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.pl/ SearchScopes: HKU\S-1-5-21-233006258-18527085-3623643150-1000 -> {ADFCCAFC-8B85-47A9-4531-42A369A8DD30} URL = hxxps://www.google.com/search?q={searchTerms} BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.) BHO-x32: Pomocnik logowania za pomocą konta Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.) DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx FireFox: ======== FF DefaultProfile: 2tg2krhh.AGACIK-1507937948806 FF ProfilePath: C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806 [2020-05-29] FF DownloadDir: C:\Users\Agata\Downloads FF NetworkProxy: Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806 -> type", 0 FF Session Restore: Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806 -> [funkcja włączona] FF Notifications: Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806 -> hxxps://book.lufthansa.com; hxxps://www.mediaexpert.pl; hxxps://www.fixitpc.pl; hxxps://a.mp3pro.xyz FF Extension: (Brief) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\brief@mozdev.org.xpi [2019-06-30] FF Extension: (File Converter - By Online-Convert.com) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\firefox@online-convert.com.xpi [2020-05-26] FF Extension: (Auto High Quality for YouTube™) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\jid0-RjdrEcWS3Ggt4xydeqVS8WQk1Lu@jetpack.xpi [2019-10-06] FF Extension: (Użyj Google Translate) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2019-11-25] FF Extension: (translator-lite) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\jid1-f3mYMbCpz2AZYl@jetpack.xpi [2019-03-12] FF Extension: (h264ify) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\jid1-TSgSxBhncsPBWQ@jetpack.xpi [2019-09-10] FF Extension: (Deutsch (DE) Language Pack) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\langpack-de@firefox.mozilla.org.xpi [2020-05-06] FF Extension: (English (GB) Language Pack) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\langpack-en-GB@firefox.mozilla.org.xpi [2020-05-06] FF Extension: (Google Translator for Firefox) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\translator@zoli.bod.xpi [2018-12-03] FF Extension: (uBlock Origin) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\uBlock0@raymondhill.net.xpi [2020-05-29] FF Extension: (Spring Melody by M♥Donna) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{217c1bd9-5fa8-4536-b0d3-3e0411d4f067}.xpi [2020-01-17] FF Extension: (Cookie Editor) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{48df221a-8316-4d17-9191-7fc5ea5f14c0}.xpi [2019-06-13] FF Extension: (EPUBReader) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}.xpi [2019-06-29] FF Extension: (Opening Daisy Field) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{66cd2370-b747-476b-8fce-0bc4adc58926}.xpi [2019-06-13] FF Extension: (Sakura Blossoms & Birds by MaDonna) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{82f753d5-3a7c-4b9e-9bd3-675331e8250f}.xpi [2020-01-14] FF Extension: (Birds 323) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{8d026387-06ce-465d-88b2-e384bbb040ae}.xpi [2019-06-13] FF Extension: (Little Red Beret Owl by candelora) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{9be1cee2-76ce-4459-8a73-207649efc0d5}.xpi [2019-06-13] FF Extension: (orchidea-naglowek) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{9d1e4d9e-bb70-4e69-95f6-627b95f573f5}.xpi [2019-06-13] FF Extension: (Finches on a Wire) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{b016935e-df27-4736-a077-8987c170e216}.xpi [2019-06-13] FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2020-05-16] FF Extension: (Video DownloadHelper) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-03-31] FF Extension: (Lonely polar bear by CP) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{d8c48df5-94db-407e-a86f-96dd3b24d213}.xpi [2019-05-14] FF Extension: (Motyleczki) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{d9c0c0b5-841a-4401-86e0-2a4885313d54}.xpi [2019-06-13] FF Extension: (YouTube mp3 Downloader) - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\2tg2krhh.AGACIK-1507937948806\Extensions\{defe5404-0b6f-4cce-a119-ee0df858e5f9}.xpi [2019-06-23] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_344.dll [2020-03-25] (Adobe Inc. -> ) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_344.dll [2020-03-25] (Adobe Inc. -> ) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corporation -> Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.) [Brak podpisu cyfrowego] StartMenuInternet: Firefox-BBF35AF5F081D115 - C:\Users\Agata\AppData\Local\Mozilla Firefox\firefox.exe Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [202752 2010-05-05] (Microsoft Windows Hardware Compatibility Publisher -> AMD) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [314368 2018-01-18] (Brother Industries, Ltd.) [Brak podpisu cyfrowego] R2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [518944 2019-06-02] (Intel Corporation -> Intel Corporation) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes Corporation -> Malwarebytes) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation) S4 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [Brak podpisu cyfrowego] R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation) R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [77336 2015-01-19] (Nuance Communications, Inc. -> Nuance Communications, Inc.) R2 PreSonus Hardware Access Service; C:\Program Files\PreSonus\Universal Control\PreSonusHardwareAccessService.exe [492032 2019-11-08] (PreSonus) [Brak podpisu cyfrowego] R2 Rezip; C:\Windows\SysWOW64\Rezip.exe [311296 2009-03-05] () [Brak podpisu cyfrowego] S3 Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Sony Mobile Communications -> Avanquest Software) [Brak podpisu cyfrowego] R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3308896 2019-11-21] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13172752 2020-01-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 USBAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\USBAppControl.exe [12288 2019-08-09] (Microsoft) [Brak podpisu cyfrowego] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480 2012-07-17] (Microsoft Corporation -> Microsoft Corp.) R2 WorkflowAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl.exe [20480 2019-08-09] (Microsoft) [Brak podpisu cyfrowego] S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\WsAppService.exe [252816 2015-04-23] (Shenzhen Wondershare Information Technology Co., Ltd. -> Wondershare) R2 WTService; C:\Windows\SysWOW64\atwtusb.exe [861696 2010-06-15] () [Brak podpisu cyfrowego] ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [6789632 2010-05-05] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.) R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [221184 2010-05-05] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [104976 2016-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices) S3 AtiHdmiService; C:\Windows\System32\drivers\AtiHdmi.sys [116736 2010-01-29] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies, Inc.) S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [6789632 2010-05-05] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.) R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [156056 2019-05-29] (Intel Corporation -> Motorola Solutions, Inc.) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2017-01-18] (Malwarebytes Corporation -> ) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [136192 2010-04-01] (Microsoft Windows Hardware Compatibility Publisher -> ELAN Microelectronics Corp.) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [18960 2008-08-12] (Self Root CA -> SAMSUNG ELECTRONICS CO., LTD.) R0 MBAMChameleon; C:\Windows\System32\drivers\MBAMChameleon.sys [186304 2020-05-23] (Malwarebytes Corporation -> Malwarebytes) S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [110536 2020-05-23] (Malwarebytes Corporation -> Malwarebytes) S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2020-05-23] (Malwarebytes Corporation -> Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2020-05-23] (Malwarebytes Corporation -> Malwarebytes) S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [81696 2020-05-08] (Malwarebytes Corporation -> Malwarebytes) R3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [7680 2009-03-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation) S3 paeusbaudio; C:\Windows\System32\DRIVERS\paeusbaudio.sys [355568 2019-09-27] (PreSonus Audio Electronics, Inc -> ) S3 paeusbaudioks; C:\Windows\System32\DRIVERS\paeusbaudioks.sys [53488 2019-09-27] (PreSonus Audio Electronics, Inc -> ) S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2010-07-14] (Realtek Semiconductor Corp -> Windows (R) 2003 DDK 3790 provider) R1 SABI; C:\Windows\system32\Drivers\SABI.sys [13824 2010-03-31] (Microsoft Windows Hardware Compatibility Publisher -> SAMSUNG ELECTRONICS) S2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [19016 2019-05-31] (HP Inc. -> ) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [31232 2013-03-06] (OpenVPN Technologies, Inc. -> The OpenVPN Project) R3 teVirtualMIDI64; C:\Windows\System32\DRIVERS\teVirtualMIDI64.sys [41016 2016-08-31] (Tobias Erichsen -> Tobias Erichsen) R3 vhidmini; C:\Windows\System32\DRIVERS\walvhid.sys [7552 2009-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64_prewin8.sys [31920 2018-02-26] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] (Microsoft Windows Hardware Compatibility Publisher -> ) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) =================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-05-29 23:07 - 2020-05-29 23:43 - 000000000 ____D C:\Users\Agata\Desktop\fixitpc 2020-05-29 01:54 - 2020-05-29 01:54 - 000000000 ____D C:\Users\Agata\AppData\Local\Audacity 2020-05-29 00:36 - 2020-05-29 12:06 - 000027136 ____H C:\Users\Agata\Desktop\~WRL2873.tmp 2020-05-29 00:36 - 2020-05-29 11:58 - 000027136 ____H C:\Users\Agata\Desktop\~WRL1525.tmp 2020-05-29 00:36 - 2020-05-29 00:36 - 000025088 ____H C:\Users\Agata\Desktop\~WRL3679.tmp 2020-05-25 01:32 - 2020-05-25 09:52 - 000000000 ____D C:\Program Files\CCleaner 2020-05-25 01:32 - 2020-05-25 01:33 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update 2020-05-25 01:32 - 2020-05-25 01:32 - 000002802 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC 2020-05-25 01:32 - 2020-05-25 01:32 - 000000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2020-05-25 01:32 - 2020-05-25 01:32 - 000000822 _____ C:\ProgramData\Desktop\CCleaner.lnk 2020-05-25 01:32 - 2020-05-25 01:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2020-05-25 01:27 - 2020-05-25 01:27 - 015838840 _____ (Piriform Ltd) C:\Users\Agata\Downloads\ccsetup5.43.exe 2020-05-11 01:24 - 2020-05-11 01:24 - 000677795 _____ C:\Users\Agata\Desktop\PB_Kontoauszug Gebuchte Umsätze vom 02.2020 bis 11.05.2020.pdf 2020-05-11 01:04 - 2020-05-11 01:04 - 000027814 _____ C:\Users\Agata\Desktop\Deutsche Bahn Card 25_11-05-2020 .pdf 2020-05-11 00:36 - 2020-05-11 00:36 - 000087129 _____ C:\Users\Agata\Downloads\PB_Kontoauszug_KtoNr_0575959857_06-05-2020_101033.pdf 2020-04-30 17:40 - 2020-04-30 17:41 - 008196784 _____ (Malwarebytes) C:\Users\Agata\Downloads\adwcleaner_8.0.4.exe ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-05-29 23:48 - 2018-05-07 17:06 - 000000000 ____D C:\FRST 2020-05-29 23:11 - 2009-07-14 06:45 - 000022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2020-05-29 23:11 - 2009-07-14 06:45 - 000022976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2020-05-29 22:54 - 2009-07-14 04:34 - 000000886 _____ C:\Windows\win.ini 2020-05-29 11:52 - 2016-11-16 14:17 - 000000000 ____D C:\Users\Agata\AppData\LocalLow\Mozilla 2020-05-29 11:45 - 2015-10-09 17:31 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2020-05-29 11:41 - 2013-07-23 00:37 - 000065536 _____ C:\Windows\system32\Ikeext.etl 2020-05-29 11:40 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-05-29 01:58 - 2010-09-04 18:23 - 000000000 ____D C:\Users\Agata\AppData\Roaming\Audacity 2020-05-29 00:09 - 2012-08-25 16:26 - 000000000 ____D C:\Users\Agata\AppData\Roaming\Mp3tag 2020-05-28 22:53 - 2013-06-13 23:49 - 019154944 ___SH C:\Users\Agata\Desktop\Thumbs.db 2020-05-28 22:40 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf 2020-05-24 06:29 - 2010-12-18 17:57 - 000000000 ____D C:\ProgramData\Tablet 2020-05-24 06:29 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\registration 2020-05-23 22:22 - 2019-04-01 21:02 - 000000000 ____D C:\Program Files\Mozilla Firefox 2020-05-23 20:46 - 2018-01-14 13:14 - 000186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2020-05-23 20:46 - 2018-01-14 13:14 - 000110536 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2020-05-23 20:46 - 2018-01-14 13:10 - 000251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2020-05-23 20:46 - 2018-01-14 13:10 - 000043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2020-05-23 20:36 - 2010-08-30 17:23 - 000000000 ____D C:\Users\Agata 2020-05-21 23:30 - 2012-05-31 18:25 - 000000000 ____D C:\Windows\system32\Tasks\Zadania podglądu zdarzeń 2020-05-19 15:54 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF 2020-05-17 23:12 - 2011-01-18 23:44 - 008393728 ___SH C:\Users\Agata\Thumbs.db 2020-05-13 23:01 - 2013-08-13 03:00 - 000000000 ____D C:\Windows\system32\MRT 2020-05-13 22:50 - 2010-09-14 00:04 - 120636720 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-05-10 12:49 - 2009-07-14 06:45 - 000699224 _____ C:\Windows\system32\FNTCACHE.DAT 2020-05-10 12:43 - 2016-10-27 15:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-05-08 22:08 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\Setup 2020-05-08 21:59 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\oobe 2020-05-08 13:44 - 2010-09-27 01:34 - 000005642 ___SH C:\ProgramData\KGyGaAvL.sys 2020-05-08 13:34 - 2018-01-14 13:14 - 000081696 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2020-05-08 13:26 - 2010-10-05 19:47 - 000000000 ____D C:\Users\Agata\AppData\Local\ElevatedDiagnostics 2020-05-02 17:12 - 2010-06-01 23:43 - 000740688 _____ C:\Windows\system32\perfh015.dat 2020-05-02 17:12 - 2010-06-01 23:43 - 000156230 _____ C:\Windows\system32\perfc015.dat 2020-05-02 17:12 - 2009-07-14 07:13 - 001670590 _____ C:\Windows\system32\PerfStringBackup.INI ==================== Pliki w katalogu głównym wybranych folderów ======== 2019-07-10 01:38 - 2020-04-07 13:04 - 000000335 _____ () C:\Users\Agata\AppData\Roaming\FotoSketcher.ini 2016-06-05 12:32 - 2016-06-05 12:32 - 000000042 _____ () C:\Users\Agata\AppData\Roaming\WB.CFG 2014-06-25 00:03 - 2014-06-28 23:50 - 000002954 _____ () C:\Users\Agata\AppData\Roaming\wklnhst.dat 2018-08-07 12:11 - 2018-08-07 12:11 - 000003584 _____ () C:\Users\Agata\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-02-28 14:16 - 2017-02-28 14:16 - 000004096 ____H () C:\Users\Agata\AppData\Local\keyfile3.drm 2018-02-24 22:21 - 2018-02-24 22:21 - 000002363 _____ () C:\Users\Agata\AppData\Local\recently-used.xbel 2012-05-02 01:02 - 2017-12-04 18:45 - 000007614 _____ () C:\Users\Agata\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) LastRegBack: 2017-12-09 01:26 ==================== Koniec FRST.txt ========================