Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 24.10.2018
- Uruchomiony przez kacper (administrator) KACPER-KOMPUTER (03-11-2018 18:48:35)
- Uruchomiony z C:\Users\kacper\Downloads
- Załadowane profile: kacper (Dostępne profile: kacper & Administrator)
- Platform: Windows 7 Professional Service Pack 1 (X64) Język: Polski (Polska)
- Internet Explorer Wersja 8 (Domyślna przeglądarka: Chrome)
- Tryb startu: Normal
- Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Procesy (filtrowane) =================
- (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)
- (AMD) C:\Windows\System32\atiesrxx.exe
- (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
- (AMD) C:\Windows\System32\atieclxx.exe
- (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
- (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe
- (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
- (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
- (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
- (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
- (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
- (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
- (Mojang) C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
- (Mojang) C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
- (Oracle Corporation) C:\Program Files (x86)\Minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- () C:\Riot Games\League of Legends\RADS\projects\league_client\releases\0.0.0.170\deploy\LeagueClient.exe
- () C:\Riot Games\League of Legends\RADS\projects\league_client\releases\0.0.0.170\deploy\LeagueClientUx.exe
- () C:\Riot Games\League of Legends\RADS\projects\league_client\releases\0.0.0.170\deploy\LeagueClientUxRender.exe
- () C:\Riot Games\League of Legends\RADS\projects\league_client\releases\0.0.0.170\deploy\LeagueClientUxRender.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- ==================== Rejestr (filtrowane) ===========================
- (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671792 2014-03-14] (Realtek Semiconductor)
- HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation)
- HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-21] (Intel Corporation)
- HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587800 2017-12-19] (Oracle Corporation)
- HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3208992 2018-10-13] (Valve Corporation)
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\...\Run: [FACEIT] => C:\Users\kacper\AppData\Local\FACEITApp\update.exe [2203592 2018-10-03] ()
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\...\MountPoints2: {096374f9-7d18-11e8-a504-74d435b31d87} - E:\HiSuiteDownLoader.exe
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\...\MountPoints2: {274a0dfd-55e0-11e8-8323-74d435b31d87} - E:\HiSuiteDownLoader.exe
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\...\MountPoints2: {4933f7ca-fafa-11e7-90a2-806e6f6e6963} - D:\_AUTORUN\AUTORUN.EXE
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\...\MountPoints2: {8943ac46-faf3-11e7-965e-806e6f6e6963} - D:\Run.exe
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\...\MountPoints2: {e4af88b3-fb67-11e7-92ed-74d435b31d87} - E:\VZW_Software_upgrade_assistant.exe
- ShellExecuteHooks: Brak nazwy - {BFD98515-CD74-48A4-98E2-13D209E3EE4F} - -> Brak pliku
- GroupPolicy: Ograniczenia - Chrome <==== UWAGA
- CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA
- ==================== Internet (filtrowane) ====================
- (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)
- Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
- Tcpip\..\Interfaces\{145E3087-B381-4F11-BBFA-3B32BAC3C09A}: [DhcpNameServer] 192.168.0.1
- Internet Explorer:
- ==================
- HKU\S-1-5-21-1064051222-3806937326-4010672418-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131737061698344385&GUID=00000000-0000-0000-0000-000000000000
- SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKU\S-1-5-21-1064051222-3806937326-4010672418-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKU\S-1-5-21-1064051222-3806937326-4010672418-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKU\S-1-5-21-1064051222-3806937326-4010672418-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://pl.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10454__180616__yaie&p={searchTerms}
- BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll [2018-03-03] (Oracle Corporation)
- BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-03-03] (Oracle Corporation)
- Toolbar: HKU\S-1-5-21-1064051222-3806937326-4010672418-1000 -> Brak nazwy - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Brak pliku
- DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://files.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
- DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
- DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab
- Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
- Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
- Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
- Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
- FireFox:
- ========
- FF Plugin: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-03-03] (Oracle Corporation)
- FF Plugin: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-03-03] (Oracle Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-16] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-16] (Google Inc.)
- FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
- FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
- FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
- FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
- Chrome:
- =======
- CHR HomePage: Default -> hxxps://www.google.com/
- CHR StartupUrls: Default -> "hxxps://accounts.google.pl/accounts/SetSID?ssdc=1&sidt=ALWU2cvRiJ31GH%2BKgff9utzfww6s8tTMEAJjBpOo%2FzOYk%2FZALVi4mkkDRI2bs5oe3LdNOKnE9g8glr7Wsy%2F%2B7BlJGgMFP1iaZ5XNEXOYGaAWKWGiwv1aRXAHQOGADI7956gGBYthWwyYaON9RUvVtZAXHiynP8O2ftjlVMmUq16bvcwAMtPZvKKFci1HT8iFAh%2BEyMGUkCOJatXB6Xnr%2BhpXU%2BOQj1YN4A%3D%3D&continue=https%3A%2F%2Fwww.google.pl%2F%3Fgws_rd%3Dssl%26pli%3D1","hxxps://www.facebook.com/","hxxps://www.youtube.com/","hxxp://google.pl/"
- CHR Profile: C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default [2018-11-03]
- CHR Extension: (Prezentacje) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-08-16]
- CHR Extension: (Video Downloader professional) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeeajafchghccbnppaimjhhfpejabole [2018-10-07]
- CHR Extension: (Dokumenty) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-08-16]
- CHR Extension: (Dysk Google) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-20]
- CHR Extension: (Adblocker for Youtube™) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbfneagfdkkcpjojiigmahjplnbppkff [2018-06-17] [UpdateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
- CHR Extension: (YouTube) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-08-16]
- CHR Extension: (Arkusze) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-08-16]
- CHR Extension: (Dokumenty Google offline) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-16]
- CHR Extension: (AdBlock) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-10-10]
- CHR Extension: (TwitchAlerts Stream Labels) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmggmdngboajiakmbpdknfpdelbjbcg [2018-08-16]
- CHR Extension: (Adaware Secure) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\nladljmabboanhihfkjacnnkgjhnokhj [2018-10-25]
- CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-08-16]
- CHR Extension: (Oddshot) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\olnoeeagkgpkplnhmnnlgodjnjgckhja [2018-08-16]
- CHR Extension: (Gmail) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-08-16]
- CHR Extension: (Chrome Media Router) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-19]
- CHR Extension: (Twitch Giveaways) - C:\Users\kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\poohjpljfecljomfhhimjhddddlidhdd [2018-08-16]
- CHR Profile: C:\Users\kacper\AppData\Local\Google\Chrome\User Data\System Profile [2018-10-29]
- CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx
- ==================== Usługi (filtrowane) ====================
- (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
- S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7252656 2018-10-31] ()
- R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation)
- R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [296432 2014-04-09] (Intel Corporation)
- S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [7949768 2018-05-09] (INCA Internet Co., Ltd.)
- R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11644656 2018-09-10] (TeamViewer GmbH)
- R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
- ===================== Sterowniki (filtrowane) ======================
- (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
- R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [494864 2013-08-29] (Intel Corporation)
- S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2018-04-20] (Huawei Technologies Co., Ltd.)
- U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-04-20] (Huawei Technologies Co., Ltd.)
- R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2014-04-11] (Intel Corporation)
- S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation)
- S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50624 2017-12-05] (NVIDIA Corporation)
- S3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-12-05] (NVIDIA Corporation)
- S3 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [207840 2018-05-09] (Oracle Corporation)
- S3 VOICEMOD_Driver; C:\Windows\System32\drivers\vmdrv.sys [27648 2018-03-15] (Windows (R) Win 7 DDK provider) [Brak podpisu cyfrowego]
- S3 CtClsFlt; system32\DRIVERS\CtClsFlt.sys [X]
- S3 gdrv; \??\C:\Windows\gdrv.sys [X]
- S4 NVHDA; system32\drivers\nvhda64v.sys [X]
- S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
- ==================== NetSvcs (filtrowane) ===================
- (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
- ==================== Jeden miesiąc - utworzone pliki i foldery ========
- (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
- 2018-11-03 18:48 - 2018-11-03 18:48 - 002414592 _____ (Farbar) C:\Users\kacper\Downloads\FRST64.exe
- 2018-11-03 18:48 - 2018-11-03 18:48 - 000015633 _____ C:\Users\kacper\Downloads\FRST.txt
- 2018-11-03 18:48 - 2018-11-03 18:48 - 000000000 ____D C:\FRST
- 2018-11-02 13:50 - 2018-11-02 13:48 - 148409076 _____ C:\Users\kacper\Desktop\MEGADROP.EU - Trailer 2018 I Edycja.mp4
- 2018-11-02 13:46 - 2018-11-02 13:48 - 148409076 _____ C:\Users\kacper\Downloads\MEGADROP.EU - Trailer 2018 I Edycja.mp4
- 2018-10-31 21:01 - 2018-10-31 21:01 - 000000000 ____D C:\Users\kacper\Documents\League of Legends
- 2018-10-31 20:54 - 2018-10-31 20:54 - 086616168 _____ (Riot Games, Inc) C:\Users\kacper\Downloads\League of Legends installer EUNE.exe
- 2018-10-31 20:54 - 2018-10-31 20:54 - 000000826 _____ C:\Users\Public\Desktop\League of Legends.lnk
- 2018-10-31 20:54 - 2018-10-31 20:54 - 000000000 ____D C:\Riot Games
- 2018-10-31 20:54 - 2018-10-31 20:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
- 2018-10-31 20:47 - 2018-10-31 20:47 - 000000000 ____D C:\Users\kacper\AppData\Roaming\Gameloft
- 2018-10-31 20:47 - 2018-10-31 20:47 - 000000000 ____D C:\Users\kacper\AppData\Local\Gameloft
- 2018-10-31 20:30 - 2018-10-31 20:30 - 000000000 ____D C:\Users\kacper\AppData\LocalLow\PlayfulCorp
- 2018-10-31 17:17 - 2018-10-31 17:19 - 165475309 _____ C:\Users\kacper\Downloads\!§b§lVolsolity(2).zip
- 2018-10-31 17:10 - 2018-10-31 17:10 - 002435563 _____ C:\Users\kacper\Downloads\OptiFine_1.12.2_HD_U_E2.jar
- 2018-10-30 17:44 - 2018-11-03 11:34 - 000000000 ____D C:\Program Files (x86)\TeamViewer
- 2018-10-30 17:44 - 2018-10-30 17:44 - 020689928 _____ (TeamViewer GmbH) C:\Users\kacper\Downloads\TeamViewer_Setup.exe
- 2018-10-30 17:44 - 2018-10-30 17:44 - 000001047 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk
- 2018-10-30 17:44 - 2018-10-30 17:44 - 000001035 _____ C:\Users\Public\Desktop\TeamViewer 13.lnk
- 2018-10-30 17:44 - 2018-10-30 17:44 - 000000000 ____D C:\Users\kacper\AppData\Roaming\TeamViewer
- 2018-10-29 23:01 - 2018-10-29 23:01 - 000000000 ____D C:\Users\kacper\AppData\Local\NVIDIA Corporation
- 2018-10-29 22:46 - 2018-10-31 16:28 - 000000000 ____D C:\Users\kacper\AppData\Local\WarThunder
- 2018-10-29 22:46 - 2018-10-29 22:46 - 006434808 _____ (Gaijin Entertainment ) C:\Users\kacper\Downloads\wt_launcher_1.0.3.123-4sq7q0xpx.exe
- 2018-10-29 22:46 - 2018-10-29 22:46 - 000000000 ____D C:\Users\kacper\Documents\My Games
- 2018-10-29 18:39 - 2018-10-29 18:39 - 000000000 ____D C:\Users\kacper\AppData\Local\CrashRpt
- 2018-10-27 20:50 - 2018-10-27 20:50 - 040210008 _____ C:\Users\kacper\Downloads\vlc-3.0.4-win32.exe
- 2018-10-27 20:50 - 2018-10-27 20:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
- 2018-10-27 20:50 - 2018-10-27 20:50 - 000000000 ____D C:\Program Files (x86)\VideoLAN
- 2018-10-27 20:48 - 2018-11-03 17:52 - 000000000 ____D C:\Windows\SysWOW64\Macromed
- 2018-10-27 20:48 - 2018-10-27 20:48 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
- 2018-10-27 20:48 - 2018-10-27 20:48 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
- 2018-10-27 20:48 - 2018-10-27 20:48 - 000004590 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
- 2018-10-27 20:48 - 2018-10-27 20:48 - 000004424 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
- 2018-10-27 20:48 - 2018-10-27 20:48 - 000000000 ____D C:\Windows\system32\Macromed
- 2018-10-27 16:50 - 2018-10-27 16:54 - 000000000 ____D C:\Program Files\Highresolution Enterprises
- 2018-10-27 16:50 - 2018-10-27 16:50 - 000000000 ____D C:\Users\kacper\AppData\Roaming\Highresolution Enterprises
- 2018-10-27 13:55 - 2018-10-27 13:55 - 039333888 _____ C:\Users\kacper\Downloads\MinecraftInstaller.msi
- 2018-10-27 13:55 - 2018-10-27 13:55 - 000000961 _____ C:\Users\Public\Desktop\Minecraft.lnk
- 2018-10-27 13:55 - 2018-10-27 13:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
- 2018-10-23 20:15 - 2018-10-23 20:15 - 000000000 ____D C:\Users\kacper\AppData\Roaming\IsolatedStorage
- 2018-10-23 20:15 - 2018-10-23 20:15 - 000000000 ____D C:\Users\kacper\AppData\Local\Solvusoft_Corporation
- 2018-10-23 20:15 - 2018-10-23 20:15 - 000000000 ____D C:\ProgramData\IsolatedStorage
- 2018-10-23 20:13 - 2018-10-23 22:27 - 000000000 ____D C:\Users\kacper\Desktop\ZDJECIA
- 2018-10-23 18:19 - 2018-10-23 18:19 - 000000989 _____ C:\Users\kacper\AppData\Local\recently-used.xbel
- 2018-10-23 18:17 - 2018-10-23 18:38 - 000000000 ____D C:\Users\kacper\AppData\Local\babl-0.1
- 2018-10-23 18:17 - 2018-10-23 18:19 - 000000000 ____D C:\Users\kacper\AppData\Local\gtk-2.0
- 2018-10-23 18:17 - 2018-10-23 18:17 - 000000000 ____D C:\Users\kacper\AppData\Roaming\GIMP
- 2018-10-23 18:17 - 2018-10-23 18:17 - 000000000 ____D C:\Users\kacper\AppData\Local\GIMP
- 2018-10-23 18:17 - 2018-10-23 18:17 - 000000000 ____D C:\Users\kacper\AppData\Local\gegl-0.4
- 2018-10-23 18:16 - 2018-10-23 20:17 - 000000000 ____D C:\Program Files\GIMP 2
- 2018-10-23 14:01 - 2018-10-23 14:01 - 000049143 _____ C:\Users\kacper\Downloads\Potwierdzenie wykonania operacji_20181023_150100.pdf
- 2018-10-19 10:10 - 2018-10-19 10:10 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\obs-studio
- 2018-10-19 10:10 - 2018-10-19 10:10 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\AMD
- 2018-10-19 10:10 - 2018-10-19 10:10 - 000000000 ____D C:\Users\Administrator\AppData\Local\CEF
- 2018-10-19 10:09 - 2018-10-19 10:10 - 000000000 ____D C:\Users\Administrator\AppData\Local\AMD
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000001451 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000001417 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000266 __RSH C:\Users\Administrator\ntuser.pol
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000020 ___SH C:\Users\Administrator\ntuser.ini
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Ustawienia lokalne
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Szablony
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Moje dokumenty
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Menu Start
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Documents\Moje wideo
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Documents\Moje obrazy
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Documents\Moja muzyka
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\Dane aplikacji
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Historia
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Dane aplikacji
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 __SHD C:\Users\Administrator\IntelGraphicsProfiles
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 ____D C:\Users\Administrator\AppData\Local\Google
- 2018-10-19 10:09 - 2018-10-19 10:09 - 000000000 ____D C:\Users\Administrator
- 2018-10-19 10:09 - 2011-04-12 14:32 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Media Center Programs
- ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========
- (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
- 2018-11-03 18:46 - 2018-01-16 21:41 - 000000000 ____D C:\Users\kacper\AppData\Roaming\TS3Client
- 2018-11-03 18:34 - 2009-07-14 05:45 - 000016656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2018-11-03 18:34 - 2009-07-14 05:45 - 000016656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2018-11-03 18:27 - 2018-03-03 17:06 - 000000000 ____D C:\Users\kacper\AppData\Roaming\.minecraft
- 2018-11-03 18:12 - 2018-01-19 23:06 - 000000000 ____D C:\Users\kacper\AppData\Roaming\obs-studio
- 2018-11-03 17:50 - 2018-01-16 21:24 - 000000000 ____D C:\Program Files (x86)\Steam
- 2018-11-03 11:40 - 2011-04-12 14:21 - 000741136 _____ C:\Windows\system32\perfh015.dat
- 2018-11-03 11:40 - 2011-04-12 14:21 - 000156208 _____ C:\Windows\system32\perfc015.dat
- 2018-11-03 11:40 - 2009-07-14 06:13 - 001672612 _____ C:\Windows\system32\PerfStringBackup.INI
- 2018-11-03 11:40 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
- 2018-11-03 11:39 - 2018-09-29 18:47 - 000001259 _____ C:\Users\kacper\Desktop\nativelog.txt
- 2018-11-03 11:34 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
- 2018-11-02 20:09 - 2018-01-16 21:39 - 000065536 _____ C:\Windows\system32\spu_storage.bin
- 2018-10-31 20:48 - 2018-01-16 21:50 - 000000000 ____D C:\Users\kacper\AppData\Local\CrashDumps
- 2018-10-31 16:39 - 2018-06-14 13:23 - 000000000 ____D C:\Users\kacper\AppData\Local\BattlEye
- 2018-10-31 09:16 - 2018-01-16 21:15 - 000058016 _____ C:\Users\kacper\AppData\Local\GDIPFONTCACHEV1.DAT
- 2018-10-31 09:14 - 2009-07-14 05:45 - 000276256 _____ C:\Windows\system32\FNTCACHE.DAT
- 2018-10-30 11:00 - 2018-08-21 13:19 - 000007597 _____ C:\Users\kacper\AppData\Local\Resmon.ResmonCfg
- 2018-10-29 15:57 - 2018-09-23 12:34 - 000000000 ____D C:\Users\kacper\AppData\Local\Discord
- 2018-10-29 15:57 - 2018-06-01 13:25 - 000000000 ____D C:\Users\kacper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
- 2018-10-27 20:56 - 2018-01-20 00:12 - 000000000 ____D C:\Users\kacper\AppData\Roaming\vlc
- 2018-10-27 20:50 - 2018-01-20 00:12 - 000001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
- 2018-10-27 20:48 - 2018-06-16 22:04 - 000000000 ____D C:\Users\kacper\AppData\Local\Adobe
- 2018-10-27 16:53 - 2018-01-17 17:06 - 000000000 ____D C:\Users\kacper\AppData\Local\ElevatedDiagnostics
- 2018-10-27 13:56 - 2018-03-03 17:06 - 000000000 ____D C:\Program Files (x86)\Minecraft
- 2018-10-27 13:54 - 2018-03-04 22:42 - 000000566 _____ C:\Windows\SysWOW64\nativelog.txt
- 2018-10-27 12:36 - 2018-01-16 20:49 - 000000000 ____D C:\Users\kacper
- 2018-10-25 09:31 - 2018-01-16 21:10 - 000000000 ____D C:\Program Files (x86)\Intel
- 2018-10-25 09:30 - 2018-08-16 15:52 - 000002230 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2018-10-25 09:30 - 2018-08-16 15:52 - 000002189 _____ C:\Users\Public\Desktop\Google Chrome.lnk
- 2018-10-23 11:04 - 2018-09-23 12:34 - 000000000 ____D C:\Users\kacper\AppData\Roaming\discord
- 2018-10-19 10:09 - 2009-07-14 05:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
- 2018-10-17 10:11 - 2018-01-16 21:41 - 000000000 ____D C:\Program Files\TeamSpeak 3 Client
- ==================== Pliki w katalogu głównym wybranych folderów =======
- 2018-06-18 14:14 - 2018-06-18 14:14 - 000003584 _____ () C:\Users\kacper\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- 2018-06-16 22:41 - 2018-06-16 22:41 - 000140800 _____ () C:\Users\kacper\AppData\Local\installer.dat
- 2018-10-23 18:19 - 2018-10-23 18:19 - 000000989 _____ () C:\Users\kacper\AppData\Local\recently-used.xbel
- 2018-08-21 13:19 - 2018-10-30 11:00 - 000007597 _____ () C:\Users\kacper\AppData\Local\Resmon.ResmonCfg
- 2018-06-20 15:43 - 2018-06-20 15:43 - 000000000 _____ () C:\Users\kacper\AppData\Local\{6498B2A4-0691-41C2-8BCF-862F4CA05B32}
- ==================== Bamital & volsnap ======================
- (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)
- C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
- C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
- C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo
- C:\Windows\explorer.exe => Plik podpisany cyfrowo
- C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
- C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
- C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
- C:\Windows\system32\services.exe => Plik podpisany cyfrowo
- C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
- C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
- C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
- C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
- C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
- C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
- C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo
- C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo
- LastRegBack: 2018-10-25 13:40
- ==================== Koniec FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement