Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja: 03-08-2016 Uruchomiony przez klocek (administrator) QPA (05-08-2016 18:54:50) Uruchomiony z C:\Users\klocek\Downloads Załadowane profile: klocek (Dostępne profile: klocek) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Język: Polski (Polska) Internet Explorer Wersja 7 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1348904 2008-07-24] (Synaptics, Inc.) HKLM\...\Run: [UpdatePSTShortCut] => C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2008-11-26] (CyberLink Corp.) HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [206128 2008-10-10] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [UpdateP2GoShortCut] => C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [210216 2008-10-30] (CyberLink Corp.) HKLM\...\Run: [UpdatePDIRShortCut] => C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.) HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [432432 2008-12-08] (Hewlett-Packard) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [450659 2008-10-26] (IDT, Inc.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-07-04] (Advanced Micro Devices, Inc.) HKLM\...\Run: [WinampAgent] => C:\Program Files\Winamp\Winampa.exe [12288 2003-04-02] () HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\Av\avgui.exe [5351184 2016-07-22] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [NetWorx] => C:\Program Files\NetWorx\networx.exe [5322384 2016-01-21] (SoftPerfect) HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [186640 2016-07-20] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-3603805060-1314643310-2562518270-1000\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company) HKU\S-1-5-21-3603805060-1314643310-2562518270-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) IFEO: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\academy-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\blasterball3-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\buildalot2-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\chuzzle-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\deathonthenile-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\diner dash-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\dinerdash2-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\fate-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\gemshop-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\globetrotter connect.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\golf-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\granny_download-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\helplaunch.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\hpbc.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\hphc.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\hpmediasmartwebcam.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\hpsi.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\insaniquarium-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\labelprint.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\mahjong-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\mahjong_artifacts-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\maze-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\museum-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\onplay.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\pdr.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\peggle-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\penguins-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\polar-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\polarpool-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\power2go.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\powerstarter.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\slingo-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\sporecclaunch-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\tradewinds-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\treasurehunter2-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\tw3_vista-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\virtual villagers - the secret city-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\virtualvillagers-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IFEO\zuma-wt.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk [2013-01-15] ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\klocek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk [2015-07-05] ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{07353983-6C21-4A2A-888D-0D1A45F0D47A}: [DhcpNameServer] 212.2.96.51 212.2.96.52 Tcpip\..\Interfaces\{1F95587B-E78A-4517-9686-0735480BD114}: [DhcpNameServer] 212.2.96.51 212.2.96.52 Tcpip\..\Interfaces\{35F90182-8967-4F6C-BC40-8926FFFE798C}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{B1AB382B-19F1-42EA-B545-7F6C0E752E33}: [DhcpNameServer] 212.2.96.53 212.2.96.54 Tcpip\..\Interfaces\{F1B09F67-C231-41C5-99A9-24741DAE3901}: [DhcpNameServer] 212.2.96.51 212.2.96.52 Tcpip\..\Interfaces\{FD732CBC-ED34-41F0-8FC6-B3AB7DA155B8}: [DhcpNameServer] 213.158.199.1 213.158.199.5 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp220150225 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3603805060-1314643310-2562518270-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=91&bd=Pavilion&pf=cnnb HKU\S-1-5-21-3603805060-1314643310-2562518270-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=91&bd=Pavilion&pf=cnnb SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems Incorporated) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-07-01] (Oracle Corporation) BHO: AOL Toolbar BHO -> {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -> C:\Program Files\AOL\Pasek narzędzi AOL 5.0\aoltb.dll [2008-07-02] (AOL LLC) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-07-01] (Oracle Corporation) Toolbar: HKLM - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\Pasek narzędzi AOL 5.0\aoltb.dll [2008-07-02] (AOL LLC) Toolbar: HKU\S-1-5-21-3603805060-1314643310-2562518270-1000 -> AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\Pasek narzędzi AOL 5.0\aoltb.dll [2008-07-02] (AOL LLC) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_71-windows-i586.cab DPF: {CAFEEFAC-0018-0000-0071-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_71-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_71-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-08] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\klocek\AppData\Roaming\Mozilla\Firefox\Profiles\11fqohqx.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-15] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2008-08-06] (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\system32\npDeployJava1.dll [2013-11-04] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-01] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2007-11-07] (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.11.2571 -> C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll [2006-10-07] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1739 -> C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll [2006-10-07] (RealNetworks, Inc.) FF Plugin HKU\S-1-5-21-3603805060-1314643310-2562518270-1000: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-01-15] () FF HKU\S-1-5-21-3603805060-1314643310-2562518270-1000\...\Firefox\Extensions: [{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}] - C:\Program Files\DAP\DAPFireFox => nie znaleziono ==================== Usługi (filtrowane) ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe [77824 2008-06-27] (Andrea Electronics Corporation) R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [4093696 2016-07-22] (AVG Technologies CZ, s.r.o.) R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [906512 2016-07-20] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [594904 2016-07-22] (AVG Technologies CZ, s.r.o.) S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [Brak podpisu cyfrowego] S4 GtDetectSc; C:\Program Files\ERA\GlobeTrotter Connect\GtDetectSc.exe [204915 2007-11-05] (Option) [Brak podpisu cyfrowego] S4 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [Brak podpisu cyfrowego] S3 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [223232 2008-10-23] (Hewlett-Packard Development Company, L.P.) [Brak podpisu cyfrowego] S2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] () S2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2011-03-04] (Hewlett-Packard Company) [Brak podpisu cyfrowego] S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes) S2 Mobile Partner. RunOuc; C:\Program Files\Mobile Partner\UpdateDog\ouc.exe [655744 2012-09-22] () S2 Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [365952 2008-12-17] () S2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [241734 2008-09-15] () [Brak podpisu cyfrowego] S2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe [237657 2008-10-26] (IDT, Inc.) S2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego] R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [3874576 2016-06-01] (AVG Technologies CZ, s.r.o.) S2 TVCapSvc; C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] () S2 TVSched; C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] () R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [49424 2016-06-01] (AVG Technologies CZ, s.r.o.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R1 A2DDA; C:\EEK\bin\a2ddax86.sys [22056 2015-02-27] (Emsisoft GmbH) R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [Brak podpisu cyfrowego] R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [134912 2016-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [255744 2016-06-09] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [201472 2016-06-01] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [31664 2015-11-20] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [212736 2016-06-01] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [287008 2016-02-16] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [191744 2016-06-02] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [47360 2016-06-01] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [217344 2016-06-01] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-30] (AVG Technologies) R0 Avgunivx; C:\Windows\System32\DRIVERS\avgunivx.sys [65280 2016-06-01] (AVG Technologies CZ, s.r.o.) S3 cleanhlp; C:\EEK\bin\cleanhlp32.sys [50200 2015-02-27] (Emsisoft GmbH) S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-02-04] (Samsung Electronics Co., Ltd.) [Brak podpisu cyfrowego] S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [47249 2006-05-18] (FTDI Ltd.) S3 GT72NDISIPXP; C:\Windows\System32\DRIVERS\Gt51Ip.sys [95744 2007-07-09] (Option NV) S3 GT72UBUS; C:\Windows\System32\DRIVERS\gt72ubus.sys [51968 2007-06-26] (Option N.V.) S3 GTPTSER; C:\Windows\System32\DRIVERS\gtptser.sys [8064 2007-03-30] (Option N.V.) S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [96000 2012-08-20] (Huawei Technologies Co., Ltd.) S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [69760 2012-08-20] (Huawei Technologies Co., Ltd.) S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27520 2012-08-20] (Huawei Technologies Co., Ltd.) S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [145920 2013-02-20] (ITE ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2016-08-04] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-03-19] (Duplex Secure Ltd.) R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2008-01-03] (Samsung Electronics) [Brak podpisu cyfrowego] R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [31792 2016-02-15] (AVG Netherlands B.V.) R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl [87536 2008-11-28] (CyberLink Corp.) U3 ar5ps4e4; C:\Windows\system32\Drivers\ar5ps4e4.sys [0 ] (NVIDIA Corporation) <==== UWAGA (zerobajtowy plik/folder) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [249472 2012-04-20] (Huawei Technologies Co., Ltd.) S3 massfilter; system32\drivers\massfilter.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-08-05 18:54 - 2016-08-05 18:55 - 00021577 _____ C:\Users\klocek\Downloads\FRST.txt 2016-08-05 18:54 - 2016-08-05 18:54 - 00000000 ____D C:\FRST 2016-08-05 18:51 - 2016-08-05 18:52 - 01743872 _____ (Farbar) C:\Users\klocek\Downloads\FRST.exe 2016-08-05 18:37 - 2016-08-05 18:37 - 00000818 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-08-05 18:37 - 2016-08-05 18:37 - 00000806 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-08-05 18:35 - 2016-08-05 18:35 - 46369416 _____ C:\Users\klocek\Desktop\Firefox Setup 43.0.1.exe 2016-08-05 18:10 - 2016-08-05 18:10 - 00010235 _____ C:\Users\klocek\Desktop\AdwCleaner[C4].txt 2016-08-05 17:54 - 2016-08-05 17:55 - 03712064 _____ C:\Users\klocek\Desktop\adwcleaner_5.201.exe 2016-08-05 17:39 - 2016-08-05 18:49 - 00000000 ____D C:\AdwCleaner 2016-08-05 08:36 - 2016-08-05 08:36 - 00000000 ____D C:\Users\klocek\AppData\Local\ESET 2016-08-04 18:26 - 2016-08-04 18:26 - 02743336 _____ (Facebook Inc.) C:\Users\klocek\Desktop\ESET_T1058973944189195T_.exe 2016-07-28 20:17 - 2016-07-28 20:18 - 00000000 ____D C:\Users\klocek\Desktop\Nowy folder (9) 2016-07-28 19:46 - 2016-07-28 19:46 - 00000000 ____D C:\Users\klocek\Desktop\Nowy folder (8) 2016-07-27 18:22 - 2016-08-04 15:56 - 00000735 _____ C:\Users\Public\Desktop\AVG.lnk 2016-07-26 18:24 - 2016-07-26 18:29 - 00000000 ____D C:\Users\klocek\Desktop\iGO 2016-07-25 20:43 - 2016-07-25 20:44 - 00144768 _____ C:\Windows\Minidump\Mini072516-01.dmp 2016-07-25 20:43 - 2016-07-25 20:43 - 352040437 _____ C:\Windows\MEMORY.DMP 2016-07-10 02:04 - 2016-07-10 02:14 - 00000000 ____D C:\Users\klocek\Desktop\Nowy folder (4) 2016-07-08 20:35 - 2016-07-08 20:37 - 00067205 _____ C:\Users\klocek\Desktop\Ciągnik siodłowy SCANIA R420 Euro5 Retarder Standklima 2 Tank Topline z Niemiec, sprzedaż, zakup, cena, FT10670.htm 2016-07-08 20:35 - 2016-07-08 20:35 - 00000000 ____D C:\Users\klocek\Desktop\Ciągnik siodłowy SCANIA R420 Euro5 Retarder Standklima 2 Tank Topline z Niemiec, sprzedaż, zakup, cena, FT10670_pliki ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2016-08-05 18:37 - 2016-06-10 17:39 - 00000000 ____D C:\Program Files\Mozilla Firefox 2016-08-05 18:37 - 2015-02-26 19:17 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2016-08-05 18:21 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2016-08-05 18:21 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2016-08-05 18:19 - 2013-01-24 21:26 - 00000000 ____D C:\ProgramData\MFAData 2016-08-05 18:19 - 2013-01-15 20:15 - 00019322 _____ C:\ProgramData\HPWALog.txt 2016-08-05 18:18 - 2015-05-27 13:00 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-08-05 18:15 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-08-05 18:14 - 2013-01-15 19:17 - 00003204 _____ C:\Windows\bthservsdp.dat 2016-08-05 18:14 - 2006-11-02 15:01 - 00032578 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-08-05 13:23 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\inf 2016-08-04 18:48 - 2015-11-14 00:21 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-08-04 15:56 - 2015-12-14 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen 2016-08-01 20:52 - 2009-03-03 12:54 - 00712934 _____ C:\Windows\system32\perfh015.dat 2016-08-01 20:52 - 2009-03-03 12:54 - 00150310 _____ C:\Windows\system32\perfc015.dat 2016-08-01 20:52 - 2006-11-02 12:33 - 01610276 _____ C:\Windows\system32\PerfStringBackup.INI 2016-07-31 22:44 - 2015-11-30 22:03 - 00000000 ____D C:\Users\klocek\Desktop\Nowy folder (7) 2016-07-27 20:42 - 2016-02-28 20:05 - 00067691 _____ C:\Users\klocek\Desktop\Scania R490 Streamline Topline Gama Trans (MK) _ Flickr - Photo Sharing!.htm 2016-07-27 20:42 - 2016-02-28 20:05 - 00000000 ____D C:\Users\klocek\Desktop\Scania R490 Streamline Topline Gama Trans (MK) _ Flickr - Photo Sharing!_pliki 2016-07-25 21:38 - 2014-11-20 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2016-07-25 20:43 - 2015-11-08 12:08 - 00000000 ____D C:\Windows\Minidump 2016-07-15 07:18 - 2015-05-27 13:00 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2016-07-15 07:18 - 2015-05-27 13:00 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2016-07-15 07:18 - 2009-03-03 05:22 - 00000000 ____D C:\Windows\system32\Macromed ==================== Pliki w katalogu głównym wybranych folderów ======= 2013-05-12 23:54 - 2016-01-26 20:00 - 0011360 _____ () C:\Users\klocek\AppData\Roaming\SmarThruOptions.xml 2013-01-15 20:15 - 2013-01-15 20:15 - 0000000 _____ () C:\Users\klocek\AppData\Local\AtStart.txt 2013-01-18 23:10 - 2016-01-02 18:54 - 0007160 _____ () C:\Users\klocek\AppData\Local\d3d9caps.dat 2013-01-15 21:57 - 2014-08-15 09:27 - 0174080 _____ () C:\Users\klocek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-01-15 20:15 - 2013-01-15 20:15 - 0000000 _____ () C:\Users\klocek\AppData\Local\DSwitch.txt 2016-01-09 21:09 - 2016-01-09 21:09 - 0000000 _____ () C:\Users\klocek\AppData\Local\FnF4.txt 2013-01-15 20:15 - 2013-01-15 20:15 - 0000000 _____ () C:\Users\klocek\AppData\Local\QSwitch.txt 2013-01-15 20:15 - 2016-08-05 18:19 - 0019322 _____ () C:\ProgramData\HPWALog.txt Niektóre pliki w TEMP: ==================== C:\Users\klocek\AppData\Local\Temp\avguirn_081011034389.exe C:\Users\klocek\AppData\Local\Temp\avguirn_081265838713.exe C:\Users\klocek\AppData\Local\Temp\avguirn_081588379737.exe C:\Users\klocek\AppData\Local\Temp\avguirn_081856863070.exe C:\Users\klocek\AppData\Local\Temp\jre-8u91-windows-au.exe ==================== Bamital & volsnap ================= (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\Windows\explorer.exe => Plik podpisany cyfrowo C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo C:\Windows\system32\services.exe => Plik podpisany cyfrowo C:\Windows\system32\User32.dll => Plik podpisany cyfrowo C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2016-08-05 18:21 ==================== Koniec FRST.txt ============================