Advertisement
Guest User

Untitled

a guest
Aug 11th, 2018
700
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 33.75 KB | None | 0 0
  1. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.08.2018
  2. Ran by Dawid (administrator) on DESKTOP-I4PON84 (12-08-2018 00:41:02)
  3. Running from C:\Users\Dawid\Desktop
  4. Loaded Profiles: Dawid (Available Profiles: Dawid)
  5. Platform: Windows 10 Pro Version 1803 17134.165 (X64) Language: Angielski (Stany Zjednoczone)
  6. Internet Explorer Version 11 (Default browser: Chrome)
  7. Boot Mode: Normal
  8. Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
  9.  
  10. ==================== Processes (All) =================
  11. (Microsoft Corporation) C:\Windows\System32\smss.exe
  12. (Microsoft Corporation) C:\Windows\System32\csrss.exe
  13. (Microsoft Corporation) C:\Windows\System32\wininit.exe
  14. (Microsoft Corporation) C:\Windows\System32\services.exe
  15. (Microsoft Corporation) C:\Windows\System32\lsass.exe
  16. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  17. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  18. (Microsoft Corporation) C:\Windows\System32\fontdrvhost.exe
  19. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  20. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  21. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  22. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  23. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  24. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  25. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  26. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  27. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  28. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  29. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  30. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  31. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  32. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  33. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  34. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  35. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  36. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  37. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  38. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  39. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  40. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  41. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  42. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  43. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  44. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  45. (Microsoft Corporation) C:\Windows\System32\dasHost.exe
  46. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  47. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  48. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  49. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  50. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  51. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  52. (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
  53. (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
  54. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  55. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  56. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  57. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  58. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  59. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  60. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  61. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  62. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  63. (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
  64. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  65. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  66. (Microsoft Corporation) C:\Windows\System32\SecurityHealthService.exe
  67. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  68. (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe
  69. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  70. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  71. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  72. (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  73. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  74. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  75. (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\NisSrv.exe
  76. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  77. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  78. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  79. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  80. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  81. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  82. (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
  83. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  84. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  85. (Microsoft Corporation) C:\Windows\System32\SgrmBroker.exe
  86. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  87. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  88. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  89. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  90. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  91. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  92. (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe
  93. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  94. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  95. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  96. (Microsoft Corporation) C:\Windows\System32\audiodg.exe
  97. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  98. (Microsoft Corporation) C:\Windows\System32\csrss.exe
  99. (Microsoft Corporation) C:\Windows\System32\winlogon.exe
  100. (Microsoft Corporation) C:\Windows\System32\fontdrvhost.exe
  101. (Microsoft Corporation) C:\Windows\System32\dwm.exe
  102. (Microsoft Corporation) C:\Windows\System32\sihost.exe
  103. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  104. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  105. (Microsoft Corporation) C:\Windows\System32\taskhostw.exe
  106. (Microsoft Corporation) C:\Windows\System32\ctfmon.exe
  107. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  108. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  109. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  110. (Microsoft Corporation) C:\Windows\explorer.exe
  111. (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
  112. () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe
  113. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  114. (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
  115. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  116. (Malwarebytes) C:\Users\Dawid\Desktop\adwcleaner_7.2.2.exe
  117. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
  118. (Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
  119. (Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
  120. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  121. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  122. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  123. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  124. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  125. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  126. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  127. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
  128. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
  129. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
  130. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
  131. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  132. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  133. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  134. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  135. (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MpCmdRun.exe
  136. (Disc Soft Ltd) G:\PROGRAMY\DAEMON Tools Lite\DTShellHlp.exe
  137. (Disc Soft Ltd) G:\PROGRAMY\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
  138. (Plumbytes Software Lp) C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe
  139. (Plumbytes Software Lp) C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\Plumbytes.exe
  140. (Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
  141. (Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
  142. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  143. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  144. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  145. (Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
  146. (Piriform Ltd) G:\PROGRAMY\CCleaner\CCleaner64.exe
  147. (Microsoft Corporation) C:\Windows\System32\svchost.exe
  148. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  149. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  150. (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
  151. (Farbar) C:\Users\Dawid\Desktop\FRST64.exe
  152.  
  153. ==================== Registry (Whitelisted) ===========================
  154.  
  155. (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
  156.  
  157. HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
  158. HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18388936 2018-04-05] (Realtek Semiconductor)
  159. HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
  160. HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [316392 2018-05-11] (Adobe Systems, Incorporated)
  161. HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242904 2018-06-21] (AVAST Software)
  162. HKLM\...\Run: [Plumbytes Anti-Malware] => C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\Plumbytes.exe [2189304 2018-06-13] (Plumbytes Software Lp)
  163. HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] ()
  164. HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2407008 2017-09-20] (Adobe Systems Incorporated)
  165. HKLM-x32\...\Run: [Discord] => C:\ProgramData\SquirrelMachineInstalls\Discord.exe [57954808 2018-03-04] (Discord Inc.)
  166. HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5885352 2018-05-30] (LogMeIn Inc.)
  167. HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
  168. HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
  169. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\...\Run: [DAEMON Tools Lite Automount] => G:\PROGRAMY\DAEMON Tools Lite\DTAgent.exe [5263040 2018-01-30] (Disc Soft Ltd)
  170. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3206432 2018-08-09] (Valve Corporation)
  171. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\...\Run: [Discord] => C:\Users\Dawid\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc.)
  172. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\...\Run: [CCleaner Monitoring] => G:\PROGRAMY\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd)
  173. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\...\Run: [EpicGamesLauncher] => G:\GRY\EpicGames\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32973712 2018-07-26] (Epic Games, Inc.)
  174. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\...\RunOnce: [Application Restart #0] => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MSI)
  175. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\...\Winlogon: [Shell] C:\Windows\System32\cmd.exe [273920 2018-04-12] (Microsoft Corporation) <==== ATTENTION
  176.  
  177. ==================== Internet (All) ====================
  178.  
  179. (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
  180.  
  181. Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [54784 2018-04-12] (Microsoft Corporation)
  182. Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2018-04-12] (Microsoft Corporation)
  183. Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2018-04-12] (Microsoft Corporation)
  184. Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [64000 2018-04-12] (Microsoft Corporation)
  185. Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  186. Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [24064 2018-04-12] (Microsoft Corporation)
  187. Winsock: Catalog5 07 C:\WINDOWS\SysWOW64\wshbth.dll [51712 2018-04-12] (Microsoft Corporation)
  188. Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  189. Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  190. Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  191. Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  192. Winsock: Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  193. Winsock: Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  194. Winsock: Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  195. Winsock: Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  196. Winsock: Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  197. Winsock: Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  198. Winsock: Catalog9 11 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  199. Winsock: Catalog9 12 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  200. Winsock: Catalog9 13 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  201. Winsock: Catalog9 14 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-12] (Microsoft Corporation)
  202. Winsock: Catalog5-x64 01 C:\Windows\system32\napinsp.dll [67072 2018-04-12] (Microsoft Corporation)
  203. Winsock: Catalog5-x64 02 C:\Windows\system32\pnrpnsp.dll [84992 2018-04-12] (Microsoft Corporation)
  204. Winsock: Catalog5-x64 03 C:\Windows\system32\pnrpnsp.dll [84992 2018-04-12] (Microsoft Corporation)
  205. Winsock: Catalog5-x64 04 C:\Windows\system32\NLAapi.dll [80896 2018-04-12] (Microsoft Corporation)
  206. Winsock: Catalog5-x64 05 C:\Windows\System32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  207. Winsock: Catalog5-x64 06 C:\Windows\System32\winrnr.dll [31232 2018-04-12] (Microsoft Corporation)
  208. Winsock: Catalog5-x64 07 C:\Windows\System32\wshbth.dll [63488 2018-04-12] (Microsoft Corporation)
  209. Winsock: Catalog9-x64 01 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  210. Winsock: Catalog9-x64 02 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  211. Winsock: Catalog9-x64 03 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  212. Winsock: Catalog9-x64 04 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  213. Winsock: Catalog9-x64 05 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  214. Winsock: Catalog9-x64 06 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  215. Winsock: Catalog9-x64 07 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  216. Winsock: Catalog9-x64 08 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  217. Winsock: Catalog9-x64 09 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  218. Winsock: Catalog9-x64 10 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  219. Winsock: Catalog9-x64 11 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  220. Winsock: Catalog9-x64 12 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  221. Winsock: Catalog9-x64 13 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  222. Winsock: Catalog9-x64 14 C:\Windows\system32\mswsock.dll [401968 2018-04-12] (Microsoft Corporation)
  223. Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
  224. Tcpip\..\Interfaces\{05f01c30-ae2c-40f5-8921-a70a42555589}: [NameServer] 8.8.8.8
  225. Tcpip\..\Interfaces\{53a907c7-0068-11e8-8286-806e6f6e6963}: [NameServer] 8.8.8.8
  226. Tcpip\..\Interfaces\{8b6d7d5f-d3fa-423c-859b-89fb128a3299}: [DhcpNameServer] 192.168.1.1
  227. Tcpip\..\Interfaces\{ae28c06c-3666-4e8d-82a3-78eef270980e}: [NameServer] 8.8.8.8
  228. Tcpip\..\Interfaces\{cb38fbd2-c1d4-4382-beac-84460fe58627}: [NameServer] 8.8.8.8
  229. Tcpip\..\Interfaces\{f9daa187-0eab-47aa-806a-b94a0f5010ab}: [NameServer] 8.8.8.8
  230. Tcpip\..\Interfaces\{f9daa187-0eab-47aa-806a-b94a0f5010ab}: [DhcpNameServer] 192.168.0.1
  231.  
  232. Internet Explorer:
  233. ==================
  234. HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
  235. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
  236. HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
  237. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
  238. HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
  239. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
  240. HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
  241. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
  242. HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
  243. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  244. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
  245. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
  246. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
  247. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
  248. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
  249. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
  250. HKU\S-1-5-21-3848223809-3660055808-2796009117-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
  251. URLSearchHook: HKU\S-1-5-21-3848223809-3660055808-2796009117-1001 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
  252. URLSearchHook: HKU\S-1-5-21-3848223809-3660055808-2796009117-1001 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  253. SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  254. SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  255. SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  256. SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  257. SearchScopes: HKU\S-1-5-21-3848223809-3660055808-2796009117-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
  258. SearchScopes: HKU\S-1-5-21-3848223809-3660055808-2796009117-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
  259. Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2018-07-06] (Microsoft Corporation)
  260. Handler-x32: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2018-07-06] (Microsoft Corporation)
  261. Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll [2018-07-06] (Microsoft Corporation)
  262. Handler-x32: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll [2018-07-06] (Microsoft Corporation)
  263. Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll [2018-04-12] (Microsoft Corporation)
  264. Handler-x32: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll [2018-04-12] (Microsoft Corporation)
  265. Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2018-07-06] (Microsoft Corporation)
  266. Handler-x32: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2018-07-06] (Microsoft Corporation)
  267. Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2018-07-06] (Microsoft Corporation)
  268. Handler-x32: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2018-07-06] (Microsoft Corporation)
  269. Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2018-07-06] (Microsoft Corporation)
  270. Handler-x32: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2018-07-06] (Microsoft Corporation)
  271. Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2018-07-06] (Microsoft Corporation)
  272. Handler-x32: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2018-07-06] (Microsoft Corporation)
  273. Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2018-05-15] (Microsoft Corporation)
  274. Handler-x32: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll [2018-05-15] (Microsoft Corporation)
  275. Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2018-07-06] (Microsoft Corporation)
  276. Handler-x32: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2018-07-06] (Microsoft Corporation)
  277. Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2018-07-06] (Microsoft Corporation)
  278. Handler-x32: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2018-07-06] (Microsoft Corporation)
  279. Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2018-07-06] (Microsoft Corporation)
  280. Handler-x32: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2018-07-06] (Microsoft Corporation)
  281. Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll [2018-04-12] (Microsoft Corporation)
  282. Handler-x32: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll [2018-04-12] (Microsoft Corporation)
  283. Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2018-07-06] (Microsoft Corporation)
  284. Handler-x32: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2018-07-06] (Microsoft Corporation)
  285. Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2018-05-15] (Microsoft Corporation)
  286. Handler-x32: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll [2018-05-15] (Microsoft Corporation)
  287. Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2018-07-06] (Microsoft Corporation)
  288. Handler-x32: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2018-07-06] (Microsoft Corporation)
  289. Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2018-06-08] (Microsoft Corporation)
  290. Handler-x32: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2018-06-08] (Microsoft Corporation)
  291. Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll [2018-04-12] (Microsoft Corporation)
  292. Handler-x32: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll [2018-04-12] (Microsoft Corporation)
  293. Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2018-07-06] (Microsoft Corporation)
  294. Handler-x32: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2018-07-06] (Microsoft Corporation)
  295. Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2018-06-08] (Microsoft Corporation)
  296. Handler-x32: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2018-06-08] (Microsoft Corporation)
  297. Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll [2018-04-12] (Microsoft Corporation)
  298. Filter-x32: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll [2018-04-12] (Microsoft Corporation)
  299. Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll [2018-04-12] (Microsoft Corporation)
  300. Filter-x32: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll [2018-04-12] (Microsoft Corporation)
  301. Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll [2018-04-12] (Microsoft Corporation)
  302. Filter-x32: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll [2018-04-12] (Microsoft Corporation)
  303. StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe
  304.  
  305. Edge:
  306. ======
  307. Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [2018-04-12]
  308. Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [2018-04-12]
  309.  
  310. FireFox:
  311. ========
  312. FF DefaultProfile: j6co5fv1.default
  313. FF ProfilePath: C:\Users\Dawid\AppData\Roaming\Mozilla\Firefox\Profiles\j6co5fv1.default [2018-08-12]
  314. FF Extension: (TLS 1.3 gradual roll-out) - C:\Users\Dawid\AppData\Roaming\Mozilla\Firefox\Profiles\j6co5fv1.default\features\{86c6c052-61f7-428c-bc98-a98442d2ba83}\tls13-rollout-bug1442042@mozilla.org.xpi [2018-04-12] [Legacy]
  315. FF Extension: (Default) - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2018-04-12] [Legacy] [not signed]
  316. FF Extension: (Activity Stream) - C:\Program Files\Mozilla Firefox\browser\features\activity-stream@mozilla.org.xpi [2018-04-12] [Legacy] [not signed]
  317. FF Extension: (Application Update Service Helper) - C:\Program Files\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi [2018-04-12] [Legacy] [not signed]
  318. FF Extension: (Pocket) - C:\Program Files\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi [2018-04-12] [Legacy] [not signed]
  319. FF Extension: (Follow-on Search Telemetry) - C:\Program Files\Mozilla Firefox\browser\features\followonsearch@mozilla.com.xpi [2018-04-12] [Legacy] [not signed]
  320. FF Extension: (Form Autofill) - C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi [2018-04-12] [Legacy] [not signed]
  321. FF Extension: (Photon onboarding) - C:\Program Files\Mozilla Firefox\browser\features\onboarding@mozilla.org.xpi [2018-04-12] [Legacy] [not signed]
  322. FF Extension: (Firefox Screenshots) - C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi [2018-02-07] [Legacy] [not signed]
  323. FF Extension: (Shield Recipe Client) - C:\Program Files\Mozilla Firefox\browser\features\shield-recipe-client@mozilla.org.xpi [2018-04-12] [Legacy] [not signed]
  324. FF Extension: (Web Compat) - C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi [2018-04-12] [Legacy] [not signed]
  325. FF HKLM\...\Mozilla Firefox 59.0.2\Extensions: [Components] - C:\Program Files\Mozilla Firefox\components => not found
  326. FF HKLM\...\Mozilla Firefox 59.0.2\Extensions: [Plugins] - C:\Program Files\Mozilla Firefox\plugins => not found
  327. FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_30_0_0_134.dll [2018-07-15] ()
  328. FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-09-20] (Adobe Systems)
  329. FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_134.dll [2018-07-15] ()
  330. FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-06-01] (NVIDIA Corporation)
  331. FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-06-01] (NVIDIA Corporation)
  332. FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
  333. FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
  334. FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
  335. FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-09-20] (Adobe Systems)
  336. StartMenuInternet: Firefox-308046B0AF4A39CB - "C:\Program Files\Mozilla Firefox\firefox.exe"
  337. FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\channel-prefs.js [2018-02-07]
  338.  
  339. Chrome:
  340. =======
  341. CHR StartupUrls: Default -> "","hxxp://google.pl/"
  342. CHR DefaultSearchURL: Default -> {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:iOSSearchLanguage}{google:searchClient}{google:sourceId}{google:contextualSearchVersion}ie={inputEncoding}
  343. CHR DefaultSearchKeyword: Default -> google.pl_
  344. CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
  345. CHR Profile: C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default [2018-08-12]
  346. CHR Extension: (Prezentacje) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-23]
  347. CHR Extension: (Dokumenty) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-23]
  348. CHR Extension: (Dysk Google) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-23]
  349. CHR Extension: (YouTube) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-23]
  350. CHR Extension: (Adblock Plus) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-07-18]
  351. CHR Extension: (Adobe Acrobat) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-07-06]
  352. CHR Extension: (Arkusze) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-23]
  353. CHR Extension: (Dokumenty Google offline) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-23]
  354. CHR Extension: (No Coin - Block miners on the web!) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\gojamcfopckidlocpkbelmpjcgmbgjcl [2018-03-21]
  355. CHR Extension: (Google Keep – notatki i listy) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2018-08-09]
  356. CHR Extension: (SmallringFX DarkBlue Theme) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfijmgohofmpjlcgmjplbpmkpchdhpk [2018-06-03]
  357. CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-02]
  358. CHR Extension: (Gmail) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-23]
  359. CHR Extension: (Chrome Media Router) - C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-08-05]
  360. CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
  361. StartMenuInternet: Google Chrome - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
  362. CHR crx: C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\default_apps\docs.crx [2018-08-08]
  363. CHR crx: C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\default_apps\drive.crx [2018-08-08]
  364. CHR crx: C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\default_apps\gmail.crx [2018-08-08]
  365. CHR crx: C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\default_apps\youtube.crx [2018-08-08]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement