Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja:20-12-2015 Uruchomiony przez Anka (administrator) ANIA (21-12-2015 22:06:13) Uruchomiony z C:\Users\Anka\Downloads Załadowane profile: Anka (Dostępne profile: Anka) Platform: Microsoft Windows 8.1 Pro (X86) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\integratedoffice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_20_0_0_235.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_20_0_0_235.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe (Farbar) C:\Users\Anka\Downloads\FRST(1).exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-06-29] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart HKU\S-1-5-21-1417470087-3909765861-738313486-1001\...\Run: [EPSON SX100 Series] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE [188928 2008-02-05] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1417470087-3909765861-738313486-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{BEC99D7E-7F91-4010-BF2D-BF6B2CD9C772}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== BHO: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2015-01-22] (Kaspersky Lab ZAO) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02] (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-10-19] (Microsoft Corporation) BHO: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2015-01-22] (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2015-01-22] (Kaspersky Lab ZAO) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02] (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-10-19] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Anka\AppData\Roaming\Mozilla\Firefox\Profiles\k2gzr1ao.default-1450731490851 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-09] () FF Plugin: @kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2015-03-22] () FF Plugin: @kaspersky.com/online_banking_69A4E213815F42BD863D889007201D82 -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2015-03-22] () FF Plugin: @kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2015-03-22] () FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-10-19] (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-29] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-29] (NVIDIA Corporation) FF user.js: detected! => C:\Users\Anka\AppData\Roaming\Mozilla\Firefox\Profiles\k2gzr1ao.default-1450731490851\user.js [2015-12-21] FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2015-03-22] [Brak podpisu cyfrowego] FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2015-03-22] [Brak podpisu cyfrowego] FF HKLM\...\Firefox\Extensions: [content_blocker_6418E0D362104DADA084DC312DFA8ABC@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com FF HKLM\...\Firefox\Extensions: [virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2015-03-22] [Brak podpisu cyfrowego] FF HKLM\...\Firefox\Extensions: [online_banking_69A4E213815F42BD863D889007201D82@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com Chrome: ======= CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AVP15.0.1; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe [234520 2014-08-30] (Kaspersky Lab ZAO) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [915600 2015-06-29] (NVIDIA Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-06-29] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19775632 2015-06-29] (NVIDIA Corporation) R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX86\integratedoffice.exe [1250408 2012-11-02] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284520 2015-07-07] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2015-07-07] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [189136 2013-01-14] (Kaspersky Lab UK Ltd) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [143968 2014-03-31] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [37440 2014-07-02] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [24496 2012-07-27] (Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [119304 2015-01-22] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [36536 2014-08-12] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [649400 2015-03-22] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [25696 2014-02-25] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [24672 2014-03-28] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [25696 2013-08-08] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [56840 2015-01-22] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [64200 2015-01-22] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [146240 2014-07-09] (Kaspersky Lab ZAO) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2015-06-29] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad32v.sys [32912 2015-06-29] (NVIDIA Corporation) S3 s1029bus; C:\Windows\System32\drivers\s1029bus.sys [90280 2009-05-25] (MCCI Corporation) S3 s1029mdfl; C:\Windows\system32\DRIVERS\s1029mdfl.sys [15016 2009-05-25] (MCCI Corporation) S3 s1029mdm; C:\Windows\system32\DRIVERS\s1029mdm.sys [122280 2009-05-25] (MCCI Corporation) S3 s1029mgmt; C:\Windows\system32\DRIVERS\s1029mgmt.sys [115880 2009-05-25] (MCCI Corporation) S3 s1029nd5; C:\Windows\system32\DRIVERS\s1029nd5.sys [26024 2009-05-25] (MCCI Corporation) S3 s1029obex; C:\Windows\system32\DRIVERS\s1029obex.sys [111912 2009-05-25] (MCCI Corporation) S3 s1029unic; C:\Windows\System32\drivers\s1029unic.sys [116904 2009-05-25] (MCCI Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [38928 2015-07-07] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [233304 2015-07-07] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [84824 2015-07-07] (Microsoft Corporation) R3 WUDFSensorLP; C:\Windows\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation) R3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [190976 2014-11-21] (Microsoft Corporation) U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-21 22:06 - 2015-12-21 22:06 - 00011957 _____ C:\Users\Anka\Downloads\FRST.txt 2015-12-21 22:01 - 2015-12-21 22:01 - 00000000 ____D C:\AdwCleaner 2015-12-21 22:00 - 2015-12-21 22:01 - 01743360 _____ C:\Users\Anka\Downloads\adwcleaner_5.026.exe 2015-12-21 21:58 - 2015-12-21 21:58 - 00000000 ____D C:\Users\Anka\Desktop\Stare dane programu Firefox 2015-12-21 21:46 - 2015-12-21 21:47 - 00005256 _____ C:\Users\Anka\Downloads\Fixlog.txt 2015-12-20 20:29 - 2015-12-20 20:30 - 01721344 _____ (Farbar) C:\Users\Anka\Downloads\FRST(1).exe 2015-12-20 20:05 - 2015-12-20 20:05 - 00380416 _____ C:\Users\Anka\Downloads\qtokx0wv.exe 2015-12-20 19:24 - 2015-12-21 22:06 - 00000000 ____D C:\FRST 2015-12-20 19:24 - 2015-12-20 19:24 - 01721344 _____ (Farbar) C:\Users\Anka\Downloads\FRST.exe 2015-12-18 21:24 - 2015-12-20 19:27 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-12-09 18:54 - 2015-11-22 08:05 - 01469968 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-12-09 18:54 - 2015-11-22 08:05 - 01393584 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-12-09 18:54 - 2015-11-22 08:04 - 05766488 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-12-09 18:54 - 2015-11-22 08:04 - 01282528 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-12-09 18:54 - 2015-11-22 08:04 - 01269072 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-12-09 18:54 - 2015-11-22 08:04 - 01168920 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-12-09 18:54 - 2015-11-21 17:49 - 01344000 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-09 18:54 - 2015-11-21 17:40 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-09 18:54 - 2015-11-05 09:21 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-09 18:54 - 2015-10-28 16:29 - 02462720 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-12-09 18:54 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-09 18:54 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZST.DLL 2015-12-09 18:54 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-09 18:54 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-09 18:54 - 2015-10-22 16:58 - 00868864 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll 2015-12-09 18:54 - 2015-10-22 16:58 - 00200704 _____ (Microsoft Corporation) C:\Windows\system32\GlobCollationHost.dll 2015-12-09 18:54 - 2015-10-22 15:10 - 00513456 _____ C:\Windows\system32\locale.nls 2015-12-09 18:53 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-12-09 18:53 - 2015-11-08 23:44 - 01403304 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-12-09 18:53 - 2015-11-08 22:48 - 03520000 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-12-09 18:53 - 2015-11-08 21:52 - 01559552 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-12-09 18:53 - 2015-11-08 21:49 - 01087488 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-12-09 18:53 - 2015-11-08 21:42 - 01490944 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2015-12-09 18:53 - 2015-10-11 07:39 - 00382808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2015-12-09 18:53 - 2015-10-11 07:39 - 00378712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2015-12-09 18:53 - 2015-10-11 07:39 - 00377176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2015-12-09 18:53 - 2015-10-11 07:39 - 00074584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2015-12-09 18:53 - 2015-10-11 07:39 - 00023896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2015-12-09 18:53 - 2015-10-10 18:36 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2015-12-09 18:53 - 2015-10-10 18:36 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2015-12-09 18:53 - 2015-10-10 17:41 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll 2015-12-09 18:53 - 2015-10-03 20:41 - 01124384 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-12-09 18:52 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-12-09 18:52 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-12-09 18:52 - 2015-11-11 16:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2015-12-09 18:52 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-12-09 18:52 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-12-09 18:52 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-12-09 18:52 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-12-09 18:52 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-12-09 18:52 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-12-09 18:52 - 2015-11-10 00:41 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-12-09 18:52 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-12-09 18:52 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-12-09 18:52 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-12-09 18:52 - 2015-11-10 00:36 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-12-09 18:52 - 2015-11-10 00:36 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-12-09 18:52 - 2015-11-10 00:25 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-12-09 18:52 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-12-09 18:52 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-12-09 18:52 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-12-09 18:50 - 2015-11-20 23:52 - 00128568 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-12-09 18:50 - 2015-11-20 18:30 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-12-09 18:50 - 2015-11-20 17:32 - 03066880 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-12-09 18:50 - 2015-11-20 17:30 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-12-09 18:50 - 2015-11-20 17:29 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-12-09 18:50 - 2015-11-20 17:28 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2015-12-09 18:50 - 2015-11-20 17:28 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-12-09 18:50 - 2015-11-20 17:27 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-12-09 18:50 - 2015-11-20 17:24 - 02176512 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-12-09 18:50 - 2015-10-05 20:30 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\wininit.exe 2015-12-09 18:50 - 2015-10-05 20:29 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2015-12-09 18:48 - 2015-10-08 16:50 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll 2015-12-01 15:51 - 2015-07-30 14:48 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-11-30 19:16 - 2014-06-09 23:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2015-11-29 22:39 - 2015-11-29 22:39 - 00000977 _____ C:\Users\Public\Desktop\CCleaner.lnk 2015-11-29 22:39 - 2015-11-29 22:39 - 00000000 ____D C:\Program Files\CCleaner 2015-11-29 22:10 - 2015-11-29 22:10 - 00000000 ____D C:\Windows\system32\XPSViewer 2015-11-29 22:10 - 2015-11-29 22:10 - 00000000 ____D C:\Program Files\Reference Assemblies 2015-11-29 22:10 - 2015-11-29 22:10 - 00000000 ____D C:\Program Files\MSBuild 2015-11-29 22:07 - 2013-08-03 05:41 - 00778936 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2015-11-29 22:06 - 2015-11-29 22:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2015-11-29 22:03 - 2015-11-29 22:04 - 05822720 _____ (Advanced System Protector ) C:\Users\Anka\Downloads\aspsetup.exe 2015-11-26 15:47 - 2015-11-26 15:47 - 00000044 _____ C:\Users\Anka\AppData\Roaming\WB.CFG 2015-11-25 18:49 - 2015-11-25 18:49 - 00000000 ____D C:\Users\Anka\AppData\Roaming\WinRAR 2015-11-25 18:49 - 2015-11-25 18:49 - 00000000 ____D C:\Users\Anka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-25 18:49 - 2015-11-25 18:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-25 18:49 - 2015-11-25 18:49 - 00000000 ____D C:\Program Files\WinRAR 2015-11-25 18:45 - 2015-11-25 18:45 - 01786184 _____ C:\Users\Anka\Downloads\wrar530.exe 2015-11-25 18:36 - 2015-11-25 18:36 - 00000000 ____D C:\Users\Anka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Zip Opener 2015-11-25 18:36 - 2015-11-25 18:36 - 00000000 ____D C:\Users\Anka\AppData\Local\Free Zip Opener 2015-11-25 18:36 - 2015-11-25 18:36 - 00000000 ____D C:\Program Files\Free Zip Opener 2015-11-25 18:29 - 2015-11-25 18:54 - 57439563 _____ C:\Users\Anka\Downloads\filmyAnia i Tomek.rar 2015-11-25 18:29 - 2015-11-25 18:53 - 63743698 _____ C:\Users\Anka\Downloads\3Ania i Tomek.rar 2015-11-25 18:29 - 2015-11-25 18:42 - 38433785 _____ C:\Users\Anka\Downloads\1Ania i Tomek.rar 2015-11-25 18:28 - 2015-11-25 18:51 - 68173085 _____ C:\Users\Anka\Downloads\2Ania i Tomek.rar ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2015-12-21 22:03 - 2015-03-22 20:51 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-12-21 21:50 - 2015-03-22 22:23 - 00245248 ___SH C:\Users\Anka\Downloads\Thumbs.db 2015-12-21 21:48 - 2015-03-22 21:05 - 00000000 ____D C:\ProgramData\NVIDIA 2015-12-21 21:48 - 2013-08-22 08:23 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-21 21:46 - 2015-10-18 16:09 - 00000000 ____D C:\Users\Anka\AppData\LocalLow\Temp 2015-12-20 22:16 - 2015-03-23 20:18 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-12-20 21:45 - 2015-03-22 17:36 - 00000000 ____D C:\Users\Anka 2015-12-20 21:41 - 2013-08-22 09:17 - 00000000 ____D C:\Windows\rescache 2015-12-20 20:54 - 2013-08-22 09:17 - 00000000 ____D C:\Windows\LiveKernelReports 2015-12-20 19:54 - 2015-07-30 20:05 - 00000000 ____D C:\Users\Anka\AppData\Local\NVIDIA Corporation 2015-12-20 19:54 - 2015-03-23 08:57 - 00000000 ____D C:\Users\Anka\AppData\Local\NVIDIA 2015-12-20 19:32 - 2013-08-22 07:13 - 00262144 ___SH C:\Windows\system32\config\ELAM 2015-12-20 19:27 - 2015-03-23 19:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-12-20 19:24 - 2013-08-22 07:21 - 00000000 ____D C:\Windows 2015-12-19 18:38 - 2013-08-22 07:21 - 00000000 ____D C:\Windows\inf 2015-12-18 22:21 - 2013-08-22 09:05 - 00000000 ____D C:\Windows\CbsTemp 2015-12-18 22:20 - 2015-04-09 10:48 - 00000000 ___SD C:\Windows\system32\GWX 2015-12-18 17:19 - 2014-11-21 00:08 - 01825074 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-18 17:19 - 2014-11-20 23:22 - 00805918 _____ C:\Windows\system32\perfh015.dat 2015-12-18 17:19 - 2014-11-20 23:22 - 00163272 _____ C:\Windows\system32\perfc015.dat 2015-12-14 14:56 - 2015-03-23 19:47 - 00001117 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-12-14 14:55 - 2013-08-22 07:13 - 00262144 ___SH C:\Windows\system32\config\BBI 2015-12-14 14:51 - 2015-03-23 19:47 - 00001129 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-12-14 14:51 - 2015-03-22 17:36 - 00001450 _____ C:\Users\Anka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-12-14 14:46 - 2013-08-22 08:22 - 00363328 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-12 20:35 - 2015-03-26 07:38 - 00000000 ____D C:\Windows\system32\MRT 2015-12-12 20:28 - 2015-03-26 07:38 - 137798368 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-12-07 21:17 - 2013-08-22 09:17 - 00000000 ____D C:\Windows\AppReadiness 2015-12-01 18:19 - 2014-11-21 03:18 - 00826872 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-12-01 18:19 - 2014-11-21 03:18 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-11-29 22:41 - 2015-03-22 17:23 - 00000000 ____D C:\Windows\Panther 2015-11-29 22:10 - 2013-08-22 09:17 - 00000000 ____D C:\Windows\system32\MUI 2015-11-29 22:08 - 2015-10-18 16:21 - 00000000 ___HD C:\Program Files\InstallShield Installation Information ==================== Pliki w katalogu głównym wybranych folderów ======= 2015-11-26 15:47 - 2015-11-26 15:47 - 0000044 _____ () C:\Users\Anka\AppData\Roaming\WB.CFG ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2015-12-20 21:42 ==================== Koniec FRST.txt ============================