Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja: 03-08-2016 Uruchomiony przez Artur (administrator) ARTUR-PC (04-08-2016 15:44:59) Uruchomiony z C:\Users\Artur\Downloads Załadowane profile: Artur (Dostępne profile: Artur) Platform: Microsoft® Windows Vista™ Home Basic (X86) Język: Polski (Polska) Internet Explorer Wersja 7 (Domyślna przeglądarka: Opera) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Fujitsu Siemens Computers) C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe (Piriform Ltd) D:\Ccleaner\CCleaner.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) C:\Windows\System32\conime.exe () C:\ProgramData\DatacardService\HWDeviceService.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe () C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe () D:\PLAY\PLAY ONLINE\PLAY ONLINE.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera_crashreporter.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe (Opera Software) C:\Program Files\Opera\36.0.2130.65\opera.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-11-03] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4399104 2007-03-14] (Realtek Semiconductor) HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [630784 2016-08-02] (Motorola Inc.) HKLM\...\Run: [recinfo220] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] () HKLM\...\Run: [recinfo] => RecInfo.exe HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation) HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\Run: [CCleaner Monitoring] => D:\Ccleaner\CCleaner.exe [6602152 2015-12-08] (Piriform Ltd) HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: H - H:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {1262548c-c0e7-11e5-b8d0-00030d84a2d1} - H:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {1262548d-c0e7-11e5-b8d0-00030d84a2d1} - H:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {2a342ee2-295f-11e6-95dc-00030d84a2d1} - F:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {30d6b2f1-1ff9-11e6-ba00-00030d84a2d1} - F:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {b709aafc-5a28-11e6-bdcb-00030d84a2d1} - F:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {b709ab07-5a28-11e6-bdcb-00030d84a2d1} - F:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {b709ab13-5a28-11e6-bdcb-00030d84a2d1} - F:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {dd765901-4486-11e6-aabd-00030d84a2d1} - F:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {e089f58b-bdd6-11e5-849a-00030d84a2d1} - F:\AutoRun.exe HKU\S-1-5-21-2998196172-3041588393-2960308402-1000\...\MountPoints2: {e089f5d2-bdd6-11e5-849a-00030d84a2d1} - F:\AutoRun.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 194.204.159.1 194.204.152.34 Tcpip\..\Interfaces\{0A923684-745E-40E5-980E-0FCC6EDF1654}: [DhcpNameServer] 194.204.159.1 194.204.152.34 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-07-23] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-23] (Oracle Corporation) FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-23] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-23] (Oracle Corporation) FF Plugin: @videolan.org/vlc,version=2.2.1 -> D:\VLC Player\VLC\npvlc.dll [2015-04-13] (VideoLAN) Opera: ======= OPR Extension: (Video Downloader 2015) - C:\Users\Artur\AppData\Roaming\Opera Software\Opera Stable\Extensions\mpnpijldpdipnfbjpfjgopcdnjejgbda [2016-07-31] OPR Extension: (Adblock Plus) - C:\Users\Artur\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-06-28] ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] () S2 PLAY ONLINE. RunOuc; D:\PLAY\PLAY ONLINE\UpdateDog\ouc.exe [246112 2016-08-04] () R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2016-08-02] (Fujitsu Siemens Computers) [Brak podpisu cyfrowego] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2007-11-03] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 hid7906; C:\Windows\System32\drivers\hid7906.sys [41272 2008-08-08] (Your Corporation) S3 hid8101; C:\Windows\System32\drivers\hid8101.sys [43192 2008-08-08] (Your Corporation) S3 hid8103; C:\Windows\System32\drivers\hid8103.sys [40856 2008-08-08] (Your Corporation) R3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [89856 2016-08-04] (Huawei Technologies Co., Ltd.) R3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [66688 2016-08-04] (Huawei Technologies Co., Ltd.) R3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2016-08-04] (Huawei Technologies Co., Ltd.) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2016-06-24] (REALiX(tm)) S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.) S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [239488 2016-08-04] (Huawei Technologies Co., Ltd.) S3 h647906; system32\drivers\h647906.sys [X] S3 h648101; system32\drivers\h648101.sys [X] S3 h648103; system32\drivers\h648103.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U3 kwrcrpog; \??\C:\Users\Artur\AppData\Local\Temp\kwrcrpog.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-08-04 15:44 - 2016-08-04 15:45 - 00009153 _____ C:\Users\Artur\Downloads\FRST.txt 2016-08-04 14:17 - 2016-08-04 14:17 - 01743872 _____ (Farbar) C:\Users\Artur\Downloads\FRST.exe 2016-08-04 14:03 - 2016-08-04 14:03 - 00380928 _____ C:\Users\Artur\Downloads\yqhy9h28.exe 2016-08-04 12:52 - 2016-08-04 12:52 - 00000609 _____ C:\Users\Public\Desktop\PLAY ONLINE.lnk 2016-08-04 12:52 - 2016-08-04 12:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PLAY ONLINE 2016-08-04 12:52 - 2016-08-04 12:51 - 00861696 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00239488 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbnet.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00195200 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00102784 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00089856 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00073984 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00066688 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00026624 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00025856 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00019200 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys 2016-08-04 12:52 - 2016-08-04 12:51 - 00011136 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys 2016-08-04 12:51 - 2016-08-04 12:52 - 00000000 ____D C:\Windows\LastGood 2016-08-04 12:45 - 2016-08-04 12:45 - 00013040 _____ C:\Users\Artur\Documents\cc_20160804_124548.reg 2016-08-02 15:29 - 2016-08-02 15:57 - 00000000 ____D C:\Users\Artur\Doctor Web 2016-08-02 15:22 - 2016-08-02 15:24 - 139835824 _____ C:\Users\Artur\Downloads\0v1x6bdq.exe 2016-08-02 13:32 - 2016-08-02 13:33 - 00051232 _____ (gkweb) C:\Users\Artur\Downloads\Windows_Worms_Doors_Cleaner1.4.1[www.instalki.pl].exe 2016-08-02 12:35 - 2016-08-02 12:49 - 00000000 ____D C:\KVRT_Data 2016-08-02 12:32 - 2016-08-02 12:34 - 102528856 _____ (Kaspersky Lab ZAO) C:\Users\Artur\Downloads\KVRT.exe 2016-08-01 20:35 - 2016-08-01 20:35 - 01907824 _____ (Kaspersky Lab) C:\Users\Artur\Downloads\kis16.0.0.614en_8204.exe 2016-08-01 20:35 - 2016-08-01 20:35 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2016-08-01 20:33 - 2016-08-03 19:55 - 00080384 _____ C:\Users\Artur\Downloads\MBRCheck.exe 2016-08-01 20:06 - 2016-08-04 15:44 - 00000000 ____D C:\FRST 2016-08-01 19:37 - 2016-08-01 20:01 - 00000000 ____D C:\rsit 2016-08-01 19:37 - 2016-08-01 20:01 - 00000000 ____D C:\Program Files\trend micro 2016-08-01 19:20 - 2016-08-02 12:56 - 00000000 ____D C:\Program Files\goxskaen 2016-08-01 18:30 - 2016-08-01 18:30 - 00132597 _____ C:\Users\Artur\Downloads\Flash_Disinfector.exe 2016-07-29 16:00 - 2016-07-29 16:00 - 00015354 _____ C:\Users\Artur\Documents\cc_20160729_155958.reg 2016-07-23 12:02 - 2016-07-23 12:02 - 00000000 ____D C:\Program Files\Common Files\Java 2016-07-21 13:49 - 2016-07-30 19:51 - 02249768 _____ C:\Users\Artur\Desktop\To The stars.flp 2016-07-19 13:02 - 2016-08-04 12:39 - 00000000 ____D C:\Users\Artur\AppData\LocalLow\Unity 2016-07-19 13:02 - 2016-08-04 12:39 - 00000000 ____D C:\Users\Artur\AppData\Local\Unity 2016-07-19 12:59 - 2016-07-19 12:59 - 01091008 _____ (Unity Technologies ApS) C:\Users\Artur\Downloads\UnityWebPlayer.exe 2016-07-10 18:03 - 2016-07-20 14:08 - 02191323 _____ C:\Users\Artur\Desktop\180.flp 2016-07-10 14:55 - 2016-07-10 14:55 - 00176504 _____ C:\Users\Artur\Documents\cc_20160710_145515.reg 2016-07-09 15:42 - 2016-08-03 19:57 - 00000000 ____D C:\Users\Artur\goxskaen 2016-07-05 19:22 - 2016-07-05 19:27 - 00000000 ____D C:\Program Files\Common Files\PX Storage Engine 2016-07-05 19:12 - 2016-07-05 19:12 - 00000000 ____D C:\Users\Artur\.config ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-08-04 15:38 - 2016-01-18 15:50 - 00000992 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-08-04 14:50 - 2006-11-02 14:45 - 00003072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2016-08-04 14:50 - 2006-11-02 14:45 - 00003072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2016-08-04 14:48 - 2016-01-18 15:50 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-08-04 13:00 - 2007-10-09 09:52 - 00587672 _____ C:\Windows\system32\perfh015.dat 2016-08-04 13:00 - 2007-10-09 09:52 - 00110508 _____ C:\Windows\system32\perfc015.dat 2016-08-04 13:00 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\inf 2016-08-04 13:00 - 2006-11-02 12:33 - 01471054 _____ C:\Windows\system32\PerfStringBackup.INI 2016-08-04 12:52 - 2016-01-18 13:47 - 00000000 ____D C:\ProgramData\DatacardService 2016-08-04 12:52 - 2016-01-18 13:31 - 00000000 ____D C:\Users\Artur 2016-08-04 12:51 - 2016-01-18 13:50 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2016-08-04 12:51 - 2016-01-18 13:50 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2016-08-04 12:45 - 2016-04-05 13:15 - 00000000 ____D C:\Windows\Minidump 2016-08-04 12:42 - 2016-02-29 13:42 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-08-04 12:38 - 2016-06-27 21:30 - 00000000 ____D C:\Program Files\DSPRobotics 2016-08-04 12:38 - 2016-03-16 13:46 - 00000000 ____D C:\Users\Artur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line 2016-08-04 12:38 - 2016-03-16 13:46 - 00000000 ____D C:\Program Files\Image-Line 2016-08-04 12:37 - 2016-02-09 11:50 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2016-08-04 12:37 - 2016-02-09 11:49 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2016-08-04 11:49 - 2006-11-02 14:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-08-03 21:30 - 2006-11-02 14:58 - 00032616 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-08-02 14:22 - 2016-01-18 13:35 - 00000000 ____D C:\Program Files\Microsoft Works 2016-08-02 14:13 - 2016-05-21 17:13 - 00000000 ____D C:\Users\Artur\Desktop\Vesteris Client 2016-08-02 14:13 - 2007-11-22 03:16 - 00000000 ____D C:\Off2007HStTrial 2016-08-02 14:13 - 2007-11-22 03:09 - 00000000 ____D C:\FirstSteps 2016-08-02 10:21 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\schemas 2016-08-01 05:19 - 2016-01-22 13:20 - 00000000 ____D C:\Users\Artur\AppData\Roaming\vlc 2016-07-31 23:49 - 2006-11-02 14:35 - 00000000 ____D C:\Windows\DigitalLocker 2016-07-31 18:42 - 2016-01-20 12:56 - 00035840 _____ C:\Users\Artur\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-07-30 02:19 - 2016-05-03 18:43 - 00000000 ____D C:\Users\Artur\AppData\Roaming\{1779F9FF-5493-FFFA-897B-7FD9864D95DF} 2016-07-28 17:38 - 2016-01-18 15:38 - 00000000 ____D C:\Users\Artur\AppData\Roaming\AIMP 2016-07-26 14:24 - 2016-01-19 12:21 - 00406184 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-07-23 12:03 - 2016-01-18 16:29 - 00000000 ____D C:\ProgramData\Oracle 2016-07-23 12:02 - 2016-01-20 11:31 - 00000000 ____D C:\Program Files\Java 2016-07-23 12:02 - 2016-01-18 16:32 - 00000000 ____D C:\Users\Artur\.oracle_jre_usage 2016-07-23 12:02 - 2016-01-18 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-07-23 12:01 - 2016-01-18 16:31 - 00095808 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2016-07-22 10:43 - 2016-05-11 16:43 - 00000135 _____ C:\Users\Artur\AppData\Roaming\WB.CFG 2016-07-12 13:48 - 2016-01-18 15:50 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2016-07-12 13:48 - 2016-01-18 15:50 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2016-07-12 13:48 - 2016-01-18 13:35 - 00000000 ____D C:\Windows\system32\Macromed 2016-07-10 17:57 - 2016-06-27 21:30 - 00000000 ____D C:\Users\Artur\AppData\Roaming\FlowStone 2016-07-10 17:57 - 2016-01-18 13:53 - 00000000 ____D C:\Users\Artur\AppData\Local\VirtualStore ==================== Pliki w katalogu głównym wybranych folderów ======= 2016-05-11 16:43 - 2016-07-22 10:43 - 0000135 _____ () C:\Users\Artur\AppData\Roaming\WB.CFG 2016-01-20 12:56 - 2016-07-31 18:42 - 0035840 _____ () C:\Users\Artur\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2016-08-04 11:56 ==================== Koniec FRST.txt ============================