Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 06-10-2023
- Uruchomiony przez jk795 (administrator) XJAKOBS3 (Micro-Star International Co., Ltd. MS-7D18) (20-10-2023 00:39:34)
- Uruchomiony z C:\Users\jk795\AppData\Local\Temp\scoped_dir8796_579454795\FRST64.exe
- Załadowane profile: jk795
- Platforma: Microsoft Windows 11 Pro Insider Preview Wersja 22H2 23570.1000 (X64) Język: Angielski (Stany Zjednoczone) -> Polski (Polska)
- Domyślna przeglądarka: Opera
- Tryb startu: Normal
- ==================== Procesy (filtrowane) =================
- (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)
- (C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe ->) (Electronic Arts, Inc. -> ) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\compatibility32\EADesktop.exe
- (C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe
- (C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe ->) (Electronic Arts, Inc. -> The Qt Company Ltd.) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\QtWebEngineProcess.exe <3>
- (C:\Program Files\RogueKiller\RogueKillerSvc.exe ->) (ADLICE -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
- (C:\Users\jk795\AppData\Local\Programs\Opera GX\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\jk795\AppData\Local\Programs\Opera GX\102.0.4880.99\opera_crashreporter.exe
- (D:\Foldery\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) D:\Foldery\mbamtray.exe
- (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe
- (Electronic Arts, Inc. -> Electronic Arts) D:\EA shit\EA SPORTS FC 24\FC24.exe
- (explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2309.28.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe
- (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <10>
- (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
- (Opera Norway AS -> Opera Software) C:\Users\jk795\AppData\Local\Programs\Opera GX\opera.exe <44>
- (services.exe ->) (ADLICE -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
- (services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
- (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\EA\AC\EAAntiCheat.GameService.exe
- (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
- (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
- (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
- (services.exe ->) (Malwarebytes Inc. -> Malwarebytes) D:\Foldery\MBAMService.exe
- (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CredentialEnrollmentManager.exe
- (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe
- (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe
- (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_6724ed3503fdbc2c\Display.NvContainer\NVDisplay.Container.exe <2>
- (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_aadd853bf8841644\RtkAudUService64.exe
- (sihost.exe ->) (D80CB9E2-21E6-4D9B-8533-660C768F3C5B -> Lively) C:\Program Files\WindowsApps\12030rocksdanister.LivelyWallpaper_1.0.136.0_x86__97hta09mmv6hy\Build\Lively.exe
- (svchost.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.222.982.0_x64__zpdnekdrzrea0\XboxGameBarSpotify.exe
- (svchost.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe
- (svchost.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe
- (svchost.exe ->) (Lespeed Technology Co., Ltd -> WiseCleaner.com) D:\Pobrane\Wise Memory Optimizer\WiseMemoryOptimzer.exe
- (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2310.1001.78.0_x64__8wekyb3d8bbwe\XboxGameBarWidgets.exe
- (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_6.123.10052.0_x64__8wekyb3d8bbwe\GameBar.exe
- (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_6.123.10052.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
- (svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_523.28400.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WerFault.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
- (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI Toast Server\MSIToastServer.exe
- (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI) C:\Windows\SysWOW64\muachost.exe
- Brak dostępu do procesu -> GameBar.exe
- ==================== Rejestr (filtrowane) ===================
- (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)
- HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_aadd853bf8841644\RtkAudUService64.exe [1765176 2023-09-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
- HKLM\...\Run: [SteelSeriesGG] => C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe [13803344 2023-07-10] (SteelSeries ApS -> SteelSeries ApS)
- HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4123 2012-05-30] () [Brak podpisu cyfrowego]
- HKLM-x32\...\Run: [Live Update] => D:\Pobrane\Live Update\Live Update.exe [26327864 2021-08-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
- HKLM-x32\...\Run: [MSIRegister] => C:\Program Files (x86)\MSI\MSIRegister\MSIRegister.exe [1259008 2021-08-12] (Micro-Star INT'L CO., LTD.) [Brak podpisu cyfrowego]
- HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
- HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1028280 2017-11-10] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Run: [Opera GX Stable] => C:\Users\jk795\AppData\Local\Programs\Opera GX\launcher.exe [2687392 2023-10-14] (Opera Norway AS -> Opera Software)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Run: [Opera GX Browser Assistant] => C:\Users\jk795\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Run: [Steam] => D:\Steam\steam.exe [4375912 2023-09-29] (Valve Corp. -> Valve Corporation)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Run: [MicrosoftEdgeAutoLaunch_D4F93F81FB458F991271D738A594707C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3835840 2023-10-17] (Microsoft Corporation -> Microsoft Corporation)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [482128 2023-08-06] (AVB Disc Soft, SIA -> Disc Soft FZE LLC)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Run: [Discord] => C:\Users\jk795\AppData\Local\Discord\Update.exe [1512608 2021-09-21] (Discord Inc. -> GitHub)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [2655848 2023-10-17] (Electronic Arts, Inc. -> Electronic Arts)
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Policies\Explorer: [DisallowRun] 1
- HKU\S-1-5-21-1370774956-2404028756-174667980-1001\...\Policies\Explorer\DisallowRun: [9] mrt.exe
- HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\118.0.5993.89\Installer\chrmstp.exe [2023-10-19] (Google LLC -> Google LLC)
- Startup: C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk [2023-08-14]
- ShortcutTarget: DeepL auto-start.lnk -> C:\Users\jk795\AppData\Roaming\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe () [Brak podpisu cyfrowego]
- Startup: C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.6.lnk [2023-09-17]
- ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel(R) Software -> Intel® Corporation)
- ==================== Zaplanowane zadania (filtrowane) =================
- (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
- Task: {52AF7CCA-20EA-455D-975C-B3DF6AAA4CE9} - System32\Tasks\GoogleUpdateTaskMachineCore{6C87BB26-F1A3-42CA-9A77-B0C3AE7B8700} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162072 2023-09-13] (Google LLC -> Google LLC)
- Task: {CFCF43F3-EC4A-4D73-B5BC-1DA85422BA8D} - System32\Tasks\GoogleUpdateTaskMachineUA{309BDA2B-A011-4E72-888D-A48FE245B4B5} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162072 2023-09-13] (Google LLC -> Google LLC)
- Task: {5F7A49CE-5ACD-487F-8FAC-AB07F5BF0370} - System32\Tasks\HidHide_Updater => C:\Program Files\Nefarius Software Solutions\HidHide\HidHide_Updater.exe [1206200 2023-05-06] (Nefarius Software Solutions e.U. -> Nefarius Software Solutions e.U.)
- Task: {935E57A4-A5B4-472D-AC8C-2C97C52A6A81} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\UCPD velocity => C:\WINDOWS\system32\UCPDMgr.exe [60416 2023-10-14] (Microsoft Windows -> Microsoft Corporation)
- Task: {E6107424-1B04-49E1-8AD4-87D175C0F439} - System32\Tasks\Microsoft\Windows\ConsentUX\UnifiedConsent\UnifiedConsentSyncTask => {82AA0895-198A-4C1B-B2D1-C16894218AFB} C:\WINDOWS\System32\unifiedconsent.dll [315392 2023-10-14] (Microsoft Windows -> Microsoft Corporation)
- Task: {9BA6C6AF-A272-4A2C-949E-DCD7E84A064F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Brak pliku)
- Task: {C233813E-230C-414C-9B6B-BB4A546AAA31} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {F89F37C5-C8E0-4658-9B81-2422498BF56C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {A096E532-FFEB-43E6-BE68-E4D5C96C9780} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {24AA34B2-D79B-4695-8098-2A730C25556D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
- Task: {E916414B-60C2-450C-A8CC-77D64810395E} - System32\Tasks\MSI_Toast_Server => C:\Program Files (x86)\MSI\MSI Toast Server\MSIToastServer.exe [31904 2019-03-05] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
- Task: {99AC50F5-12D5-41B7-957E-C5DCDED6E1AC} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [1692840 2015-08-18] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
- Task: {C3D718D4-AABD-4F45-BFA6-AA36298F335F} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
- Task: {AC5F73C1-E603-4DCF-9D4F-49D0DAAEE600} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation)
- Task: {7C14481D-A9E0-41FE-88D7-4A590556EB27} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
- Task: {3F837895-1C1E-401E-BD92-59B475E92D03} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
- Task: {C462B298-FF65-4DD1-BF6C-C3BF7FC05967} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
- Task: {BA2356D1-7635-4C98-A2CB-0DF8959ADEAA} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
- Task: {5AE1E1BE-240D-464D-A606-786A89879F65} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
- Task: {650F4B39-3008-4397-A5FE-78E2F25418B1} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
- Task: {65B91E75-2358-4267-A690-6D021ECAAB06} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation)
- Task: {1ED0D669-6CE9-4811-8058-188E678E8F14} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1688940067 => C:\Users\jk795\AppData\Local\Programs\Opera GX\launcher.exe [2687392 2023-10-14] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\jk795\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
- Task: {89DAA759-0EE9-494F-B1EB-ED18567F84F9} - System32\Tasks\Opera GX scheduled Autoupdate 1688940013 => C:\Users\jk795\AppData\Local\Programs\Opera GX\launcher.exe [2687392 2023-10-14] (Opera Norway AS -> Opera Software)
- Task: {0A88EF0E-8260-40E2-B892-D234ED88F76A} - System32\Tasks\TempClean1 => C:\WINDOWS\system32\wevtutil.exe [327680 2023-10-14] (Microsoft Windows -> Microsoft Corporation) -> cl Application
- Task: {A1FF2BE4-0748-4346-94CD-4499156C32C8} - System32\Tasks\TempClean2 => C:\WINDOWS\system32\wevtutil.exe [327680 2023-10-14] (Microsoft Windows -> Microsoft Corporation) -> cl System
- Task: {F24732F1-34B0-480D-88AC-8AF938ED81E1} - System32\Tasks\TempClean3 => C:\WINDOWS\system32\vssadmin.exe [163840 2023-10-14] (Microsoft Windows -> Microsoft Corporation) -> delete shadows /all /quiet
- Task: {B4950496-8232-4A37-A1D9-6C029BF213BF} - System32\Tasks\ViGEmBus_Updater => D:\Foldery\ViGEmBus_Updater.exe [1117096 2022-09-27] (Nefarius Software Solutions e.U. -> Nefarius Software Solutions e.U.)
- Task: {2AC4465B-3E8F-46D4-B708-998911B3B5CD} - System32\Tasks\Wise Memory Optimizer Task.job => D:\Pobrane\Wise Memory Optimizer\WiseMemoryOptimzer.exe [11888560 2023-08-04] (Lespeed Technology Co., Ltd -> WiseCleaner.com)
- (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.)
- ==================== Internet (filtrowane) ====================
- (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)
- Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt
- Tcpip\Parameters: [DhcpNameServer] 31.11.173.2 89.228.4.126
- Tcpip\..\Interfaces\{efd55ee8-cfb6-4465-84ae-2c49f325fe96}: [DhcpNameServer] 31.11.173.2 89.228.4.126
- Edge:
- =======
- Edge DefaultProfile: Default
- Edge Profile: C:\Users\jk795\AppData\Local\Microsoft\Edge\User Data\Default [2023-10-20]
- Edge Extension: (Malwarebytes Browser Guard) - C:\Users\jk795\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2023-10-16]
- Edge Extension: (Dokumenty Google offline) - C:\Users\jk795\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-05]
- Edge Extension: (Edge relevant text changes) - C:\Users\jk795\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-09-17]
- Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
- Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
- Chrome:
- =======
- CHR Profile: C:\Users\jk795\AppData\Local\Google\Chrome\User Data\Default [2023-10-04]
- CHR Extension: (Dokumenty Google offline) - C:\Users\jk795\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-09-13]
- CHR Extension: (Malwarebytes Browser Guard) - C:\Users\jk795\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-09-13]
- CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\jk795\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-09-13]
- CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
- CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
- Opera:
- =======
- StartMenuInternet: (HKU\S-1-5-21-1370774956-2404028756-174667980-1001) Opera GXStable - "C:\Users\jk795\AppData\Local\Programs\Opera GX\Launcher.exe"
- ==================== Usługi (filtrowane) ===================
- (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
- S3 CloudBackupRestoreSvc; C:\WINDOWS\System32\CloudRestoreLauncher.dll [1323008 2023-10-14] (Microsoft Windows -> Microsoft Corporation)
- S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4974416 2023-08-06] (AVB Disc Soft, SIA -> Disc Soft FZE LLC)
- R3 EAAntiCheatService; C:\Program Files\EA\AC\eaanticheat.gameservice.exe [47716384 2023-08-28] (Electronic Arts, Inc. -> Electronic Arts)
- R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [11129960 2023-10-17] (Electronic Arts, Inc. -> Electronic Arts)
- R2 MBAMService; D:\Foldery\MBAMService.exe [9287968 2023-10-09] (Malwarebytes Inc. -> Malwarebytes)
- S4 MSIREGISTER_MR; C:\Program Files (x86)\MSI\MSIRegister\MSIRegisterService.exe [2023224 2021-08-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
- S4 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [113336 2017-12-21] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
- S4 MSI_LiveUpdate_Service; D:\Pobrane\Live Update\MSI_LiveUpdate_Service.exe [2210616 2021-08-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.)
- S4 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [183472 2020-03-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
- R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [16033712 2023-10-19] (ADLICE -> )
- S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [397040 2023-10-14] (Microsoft Windows Publisher -> Microsoft Corporation)
- S4 SteelSeriesUpdateService; C:\Program Files\SteelSeries\GG\SteelSeriesUpdateService.exe [35152 2023-07-10] (SteelSeries ApS -> )
- R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe [3116904 2023-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
- R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe [133584 2023-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
- R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_6724ed3503fdbc2c\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_6724ed3503fdbc2c\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
- ===================== Sterowniki (filtrowane) ===================
- (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
- S3 atvi-randgrid; C:\ProgramData\Battle.net_components\randgridauks\randgrid.sys [2986792 2023-07-10] (Activision Publishing Inc -> Activision Blizzard, Inc.)
- R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2022-12-27] (AVB Disc Soft, SIA -> Disc Soft Ltd)
- R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [63696 2023-01-14] (AVB Disc Soft, SIA -> Disc Soft Ltd)
- S1 EneIo; C:\Windows\system32\drivers\ene.sys [17624 2019-05-22] (Microsoft Windows Hardware Compatibility Publisher -> )
- R3 HidHide; C:\WINDOWS\System32\drivers\HidHide.sys [66584 2022-06-27] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.)
- S3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (Feature Integration Technology -> FINTEK Corp.)
- R3 iaLPSS2_GPIO2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_2546dafe2183e972\iaLPSS2_GPIO2_TGL.sys [131208 2021-07-15] (Intel Corporation -> Intel Corporation)
- R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [222272 2023-09-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
- S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-07-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
- R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-07-27] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
- R3 MpKsldd92e2f4; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{63946D18-BC5E-4318-878B-4D1315ECEDD0}\MpKslDrv.sys [263560 2023-10-19] (Microsoft Windows -> Microsoft Corporation)
- S3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [14288 2017-03-29] (MICRO-STAR INTERNATIONAL CO., LTD. -> MSI)
- R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation)
- R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [43472 2023-03-27] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS)
- R3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [44456 2023-03-13] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS)
- R3 SteamStreamingMicrophone; C:\WINDOWS\system32\drivers\SteamStreamingMicrophone.sys [40736 2020-06-01] (Valve Corp. -> )
- R3 SteamStreamingSpeakers; C:\WINDOWS\system32\drivers\SteamStreamingSpeakers.sys [40736 2020-06-01] (Valve Corp. -> )
- R3 SteelSeries_Sonar_VAD; C:\WINDOWS\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_da15ab44a6216a8e\SteelSeries-Sonar-VAD.sys [95440 2023-03-17] (SteelSeries ApS -> Windows (R) Win 7 DDK provider)
- U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [53696 2023-10-20] (ADLICE (Julien Ascoet) -> )
- S4 UCPD; C:\WINDOWS\System32\drivers\UCPD.sys [38176 2023-10-14] (Microsoft Windows -> Microsoft Corporation)
- R1 ViGEmBus; C:\WINDOWS\System32\drivers\ViGEmBus.sys [249400 2022-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Nefarius Software Solutions e.U.)
- S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-10-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
- R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572712 2023-10-05] (Microsoft Windows -> Microsoft Corporation)
- R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105872 2023-10-05] (Microsoft Windows -> Microsoft Corporation)
- U3 EAAntiCheat; system32\drivers\eaanticheat.sys [X]
- S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
- ==================== NetSvcs (filtrowane) ===================
- (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
- ==================== Jeden miesiąc (utworzone) (filtrowane) =========
- (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
- 2023-10-20 00:39 - 2023-10-20 00:39 - 000000000 ____D C:\FRST
- 2023-10-20 00:29 - 2023-10-20 00:29 - 000007605 _____ C:\Users\jk795\AppData\Local\Resmon.ResmonCfg
- 2023-10-19 20:59 - 2023-10-19 20:59 - 000798440 _____ C:\WINDOWS\system32\perfh015.dat
- 2023-10-19 20:59 - 2023-10-19 20:59 - 000158492 _____ C:\WINDOWS\system32\perfc015.dat
- 2023-10-19 20:56 - 2023-10-19 20:59 - 001798582 _____ C:\WINDOWS\system32\PerfStringBackup.INI
- 2023-10-19 20:55 - 2023-10-19 20:55 - 000000020 ___SH C:\Users\jk795\ntuser.ini
- 2023-10-19 20:55 - 2023-10-19 20:55 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
- 2023-10-19 19:06 - 2023-10-20 00:34 - 000000000 ____D C:\WINDOWS\system32\Tasks\Outbyte
- 2023-10-19 19:06 - 2023-10-19 20:55 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003756 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled assistant Autoupdate 1688940067
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003582 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA{309BDA2B-A011-4E72-888D-A48FE245B4B5}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003538 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1688940013
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003494 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003398 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003358 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore{6C87BB26-F1A3-42CA-9A77-B0C3AE7B8700}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003270 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003082 _____ C:\WINDOWS\system32\Tasks\Wise Memory Optimizer Task.job
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000003062 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1370774956-2404028756-174667980-1001
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002992 _____ C:\WINDOWS\system32\Tasks\HidHide_Updater
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002984 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002914 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1370774956-2404028756-174667980-1001
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002744 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002726 _____ C:\WINDOWS\system32\Tasks\ViGEmBus_Updater
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002388 _____ C:\WINDOWS\system32\Tasks\MSI_Toast_Server
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002222 _____ C:\WINDOWS\system32\Tasks\TempClean3
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002198 _____ C:\WINDOWS\system32\Tasks\TempClean1
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002188 _____ C:\WINDOWS\system32\Tasks\TempClean2
- 2023-10-19 19:06 - 2023-10-19 19:06 - 000002148 _____ C:\WINDOWS\system32\Tasks\MSISW_Host
- 2023-10-19 19:05 - 2023-10-19 19:05 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
- 2023-10-19 19:04 - 2023-10-19 20:55 - 000296160 _____ C:\WINDOWS\system32\FNTCACHE.DAT
- 2023-10-19 19:04 - 2023-10-19 20:55 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
- 2023-10-19 19:04 - 2023-10-19 20:55 - 000000000 ____D C:\Windows.old
- 2023-10-19 19:04 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
- 2023-10-19 17:50 - 2023-10-19 19:04 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Crypto
- 2023-10-19 17:50 - 2023-10-19 17:50 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\SystemCertificates
- 2023-10-19 17:50 - 2023-10-19 17:50 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Network
- 2023-10-19 17:48 - 2023-10-19 20:55 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Windows
- 2023-10-19 17:48 - 2023-10-19 20:55 - 000000000 ____D C:\Users\jk795
- 2023-10-19 17:48 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
- 2023-10-19 17:48 - 2023-10-19 19:04 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Spelling
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\Ustawienia lokalne
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\Szablony
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\Moje dokumenty
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\Menu Start
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\Dane aplikacji
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\AppData\Local\Tymczasowe pliki internetowe
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\AppData\Local\Historia
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 _SHDL C:\Users\jk795\AppData\Local\Dane aplikacji
- 2023-10-19 17:48 - 2023-10-19 17:48 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\CLR Security Config
- 2023-10-19 17:47 - 2023-10-19 17:47 - 000000000 ____D C:\WINDOWS\system32\SteelSeries
- 2023-10-19 17:46 - 2023-10-19 17:48 - 000000000 ____D C:\WINDOWS\ServiceProfiles
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\WINDOWS\addins
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\Program Files\Reference Assemblies
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\Program Files\MSBuild
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
- 2023-10-19 17:44 - 2023-10-19 17:44 - 000000000 ____D C:\Program Files (x86)\MSBuild
- 2023-10-19 17:43 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\pl
- 2023-10-19 17:43 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\pl
- 2023-10-19 16:18 - 2023-10-19 16:18 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
- 2023-10-19 16:07 - 2023-10-19 20:55 - 000000000 ___DC C:\WINDOWS\Panther
- 2023-10-14 09:34 - 2023-10-19 17:43 - 000000000 ____D C:\Program Files\Windows Photo Viewer
- 2023-10-14 09:34 - 2023-10-19 17:43 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
- 2023-10-14 09:34 - 2023-10-19 17:43 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 ___SD C:\WINDOWS\system32\AppV
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\system32\Hydrogen
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\mde
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\RemotePackages
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
- 2023-10-14 09:34 - 2023-10-14 09:34 - 000000000 ____D C:\ProgramData\ssh
- 2023-10-14 09:26 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
- 2023-10-14 09:26 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\winrm
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\WCN
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\slmgr
- 2023-10-14 09:24 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
- 2023-10-14 09:24 - 2023-10-14 09:24 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
- 2023-10-14 09:24 - 2023-10-14 09:24 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
- 2023-10-14 09:24 - 2023-10-14 09:24 - 000000000 ____D C:\WINDOWS\system32\0409
- 2023-10-14 09:24 - 2023-10-14 09:24 - 000000000 ____D C:\WINDOWS\DigitalLocker
- 2023-10-14 07:29 - 2023-10-14 07:29 - 000000000 _SHDL C:\Users\Default User
- 2023-10-14 07:29 - 2023-10-14 07:29 - 000000000 _SHDL C:\Users\All Users
- 2023-10-14 07:15 - 2023-10-19 17:54 - 000000000 ____D C:\WINDOWS\Setup
- 2023-10-14 07:12 - 2023-10-20 00:35 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
- 2023-10-14 07:12 - 2023-10-20 00:32 - 000000000 ____D C:\WINDOWS\SystemTemp
- 2023-10-14 07:12 - 2023-10-19 23:38 - 000000000 ____D C:\WINDOWS\AppReadiness
- 2023-10-14 07:12 - 2023-10-19 22:25 - 000000000 ____D C:\WINDOWS\appcompat
- 2023-10-14 07:12 - 2023-10-19 21:11 - 000000000 ___RD C:\WINDOWS\PrintDialog
- 2023-10-14 07:12 - 2023-10-19 21:10 - 000000000 ___HD C:\Program Files\WindowsApps
- 2023-10-14 07:12 - 2023-10-19 21:10 - 000000000 ____D C:\ProgramData\USOPrivate
- 2023-10-14 07:12 - 2023-10-19 20:55 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
- 2023-10-14 07:12 - 2023-10-19 20:55 - 000000000 ____D C:\WINDOWS\system32\oobe
- 2023-10-14 07:12 - 2023-10-19 20:55 - 000000000 ____D C:\WINDOWS\ServiceState
- 2023-10-14 07:12 - 2023-10-19 20:55 - 000000000 ____D C:\Program Files\Windows NT
- 2023-10-14 07:12 - 2023-10-19 19:06 - 000000000 ____D C:\Program Files\Windows Defender
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ___RD C:\Program Files (x86)
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\WebThreatDefSvc
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\spool
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\config\TxR
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\AppLocker
- 2023-10-14 07:12 - 2023-10-19 19:04 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
- 2023-10-14 07:12 - 2023-10-19 17:51 - 000000000 __RHD C:\Users\Public\Libraries
- 2023-10-14 07:12 - 2023-10-19 17:48 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
- 2023-10-14 07:12 - 2023-10-19 17:45 - 000000000 ____D C:\WINDOWS\OCR
- 2023-10-14 07:12 - 2023-10-19 17:44 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
- 2023-10-14 07:12 - 2023-10-19 17:44 - 000000000 ____D C:\WINDOWS\system32\setup
- 2023-10-14 07:12 - 2023-10-19 17:44 - 000000000 ____D C:\WINDOWS\system32\MUI
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ___SD C:\WINDOWS\system32\F12
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\Sysprep
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\Sgrm
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\migwiz
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\Dism
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\system32\Com
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\IME
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\Program Files\Common Files\System
- 2023-10-14 07:12 - 2023-10-19 17:43 - 000000000 ____D C:\Program Files (x86)\Windows Defender
- 2023-10-14 07:12 - 2023-10-14 09:36 - 000000000 ____D C:\WINDOWS\Containers
- 2023-10-14 07:12 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\SystemResources
- 2023-10-14 07:12 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\SystemApps
- 2023-10-14 07:12 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\ShellComponents
- 2023-10-14 07:12 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\security
- 2023-10-14 07:12 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\schemas
- 2023-10-14 07:12 - 2023-10-14 09:34 - 000000000 ____D C:\WINDOWS\InboxApps
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\system32\gl-ES
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\system32\eu-ES
- 2023-10-14 07:12 - 2023-10-14 09:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES
- 2023-10-14 07:12 - 2023-10-14 09:25 - 000000000 ____D C:\WINDOWS\Globalization
- 2023-10-14 07:12 - 2023-10-14 09:24 - 000000000 ___SD C:\WINDOWS\system32\dsc
- 2023-10-14 07:12 - 2023-10-14 09:24 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
- 2023-10-14 07:12 - 2023-10-14 09:24 - 000000000 ____D C:\WINDOWS\Help
- 2023-10-14 07:12 - 2023-10-14 09:24 - 000000000 ____D C:\WINDOWS\BrowserCore
- 2023-10-14 07:12 - 2023-10-14 09:24 - 000000000 ____D C:\Program Files (x86)\Windows NT
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 __SHD C:\Program Files\Windows Sidebar
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ___SD C:\WINDOWS\system32\Configuration
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\Web
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\system32\winevt
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\system32\ras
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\system32\PointOfService
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\system32\Pbr
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\SKB
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\Resources
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\Registration
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\Provisioning
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\PLA
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\Media
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\InputMethod
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\IdentityCRL
- 2023-10-14 07:12 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\DiagTrack
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___SD C:\WINDOWS\SysWOW64\lxss
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___SD C:\WINDOWS\system32\UNP
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___SD C:\WINDOWS\system32\Nui
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___SD C:\WINDOWS\system32\lxss
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___HD C:\WINDOWS\LanguageOverlayCache
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\WUModels
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\WaaS
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\Vss
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\UUS
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\tracing
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\TAPI
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\NDF
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\Keywords
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\Ipmi
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\InputMethod
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\inetsrv
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\IME
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\icsxml
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\ias
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\DriverState
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\downlevel
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\DDFs
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\config\Journal
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\Bthprops
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\appraiser
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\System
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\ShellExperiences
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\SchCache
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\rescache
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\Performance
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\ModemLogs
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\LiveKernelReports
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\L2Schemas
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\Cursors
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\Branding
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\WINDOWS\bcastdvr
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Spelling
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\ProgramData\USOShared
- 2023-10-14 07:12 - 2023-10-14 07:12 - 000000000 ____D C:\Program Files\ModifiableWindowsApps
- 2023-10-14 07:12 - 2023-10-14 07:09 - 000003103 _____ C:\WINDOWS\SysWOW64\mmc.exe.config
- 2023-10-14 07:12 - 2023-10-14 07:09 - 000003103 _____ C:\WINDOWS\system32\mmc.exe.config
- 2023-10-14 07:12 - 2023-10-14 07:09 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
- 2023-10-14 07:10 - 2023-10-20 00:39 - 000000000 ____D C:\WINDOWS\INF
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000008269 _____ C:\WINDOWS\system32\ResPriHMImageListLowCost
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000008269 _____ C:\WINDOWS\system32\ResPriHMImageList
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000008266 _____ C:\WINDOWS\system32\ResPriUHMImageList
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000008264 _____ C:\WINDOWS\system32\ResPriImageListLowCost
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000008240 _____ C:\WINDOWS\system32\ResPriLMImageList
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000008240 _____ C:\WINDOWS\system32\ResPriImageList
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000000146 _____ C:\WINDOWS\system32\UevAppMonitor.exe.config
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000000112 _____ C:\WINDOWS\SysWOW64\MixedRealityRuntime.json
- 2023-10-14 07:07 - 2023-10-14 07:07 - 000000112 _____ C:\WINDOWS\system32\MixedRealityRuntime.json
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000089761 _____ C:\WINDOWS\system32\DiskSnapshot.conf
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000061060 _____ C:\WINDOWS\SysWOW64\ctac.json
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000040448 _____ (Microsoft) C:\WINDOWS\SysWOW64\csrr.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000038400 _____ (Microsoft) C:\WINDOWS\SysWOW64\oflc-nz.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000037888 _____ (Microsoft) C:\WINDOWS\SysWOW64\fpb.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000033280 _____ (Microsoft) C:\WINDOWS\SysWOW64\cero.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000030208 _____ (Microsoft) C:\WINDOWS\SysWOW64\esrb.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000027648 _____ (Microsoft) C:\WINDOWS\SysWOW64\usk.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000027648 _____ (Microsoft) C:\WINDOWS\SysWOW64\cob-au.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000019456 _____ (Microsoft) C:\WINDOWS\SysWOW64\pegi-pt.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000019456 _____ (Microsoft) C:\WINDOWS\SysWOW64\pegi.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000017920 _____ (Microsoft) C:\WINDOWS\SysWOW64\grb.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000014336 _____ (Microsoft) C:\WINDOWS\SysWOW64\djctq.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000013824 _____ (Microsoft) C:\WINDOWS\SysWOW64\pcbp.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000004608 _____ (Microsoft) C:\WINDOWS\SysWOW64\WEB.rs
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000001820 _____ C:\WINDOWS\SysWOW64\rasctrnm.h
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000001820 _____ C:\WINDOWS\system32\rasctrnm.h
- 2023-10-14 07:06 - 2023-10-14 07:06 - 000000670 ___RH C:\WINDOWS\WindowsShell.Manifest
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000061060 _____ C:\WINDOWS\system32\ctac.json
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000049152 _____ (Microsoft) C:\WINDOWS\system32\oflc-nz.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000049152 _____ (Microsoft) C:\WINDOWS\system32\csrr.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000045056 _____ (Microsoft) C:\WINDOWS\system32\fpb.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000040960 _____ (Microsoft) C:\WINDOWS\system32\esrb.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000040960 _____ (Microsoft) C:\WINDOWS\system32\cero.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000038128 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iaLPSSi_GPIO.sys
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000036864 _____ (Microsoft) C:\WINDOWS\system32\usk.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000036864 _____ (Microsoft) C:\WINDOWS\system32\cob-au.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000028672 _____ (Microsoft) C:\WINDOWS\system32\pegi-pt.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000028672 _____ (Microsoft) C:\WINDOWS\system32\pegi.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000028672 _____ (Microsoft) C:\WINDOWS\system32\grb.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000024576 _____ (Microsoft) C:\WINDOWS\system32\pcbp.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000024576 _____ (Microsoft) C:\WINDOWS\system32\djctq.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000018215 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000012288 _____ (Microsoft) C:\WINDOWS\system32\WEB.rs
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000010576 _____ C:\WINDOWS\system32\TransformPPSToWlan.xslt
- 2023-10-14 07:05 - 2023-10-14 07:05 - 000001688 _____ C:\WINDOWS\system32\TransformPPSToWlanCredentials.xslt
- 2023-10-14 07:04 - 2023-10-19 19:06 - 081264640 _____ C:\WINDOWS\system32\config\SOFTWARE
- 2023-10-14 07:04 - 2023-10-19 19:06 - 017039360 _____ C:\WINDOWS\system32\config\SYSTEM
- 2023-10-14 07:04 - 2023-10-19 19:06 - 000786432 _____ C:\WINDOWS\system32\config\DEFAULT
- 2023-10-14 07:04 - 2023-10-19 19:06 - 000524288 _____ C:\WINDOWS\system32\config\BBI
- 2023-10-14 07:04 - 2023-10-19 19:06 - 000131072 _____ C:\WINDOWS\system32\config\SAM
- 2023-10-14 07:04 - 2023-10-19 19:06 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY
- 2023-10-14 07:04 - 2023-10-19 19:06 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
- 2023-10-14 07:04 - 2023-10-19 17:46 - 000000000 ____D C:\WINDOWS\CbsTemp
- 2023-10-14 07:04 - 2023-10-14 07:29 - 000000000 ____D C:\WINDOWS\system32\SMI
- 2023-10-14 07:03 - 2023-10-19 17:43 - 000000000 ____D C:\WINDOWS\servicing
- 2023-10-14 03:50 - 2023-10-14 03:50 - 000042464 _____ C:\Users\jk795\Downloads\Cv Jakub 2023.pdf
- 2023-10-07 08:19 - 2023-10-19 19:04 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
- 2023-10-05 03:10 - 2023-10-10 02:30 - 000000000 ____D C:\Users\jk795\OneDrive\Dokumenty\FC 24
- 2023-10-05 03:10 - 2023-10-07 21:15 - 000000000 ____D C:\ProgramData\Frostbite
- 2023-10-05 03:10 - 2023-10-05 03:10 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Electronic Arts
- 2023-10-05 03:10 - 2023-10-05 03:10 - 000000000 ____D C:\ProgramData\Electronic Arts
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\Ustawienia lokalne
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\Szablony
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\Moje dokumenty
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\Menu Start
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\Dane aplikacji
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\AppData\Local\Tymczasowe pliki internetowe
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\AppData\Local\Historia
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\Users\Default\AppData\Local\Dane aplikacji
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\ProgramData\Szablony
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\ProgramData\Pulpit
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\ProgramData\Menu Start
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\ProgramData\Dokumenty
- 2023-10-05 02:25 - 2023-10-05 02:25 - 000000000 _SHDL C:\ProgramData\Dane aplikacji
- 2023-10-05 02:23 - 2023-10-20 00:23 - 000053696 _____ C:\WINDOWS\system32\Drivers\truesight.sys
- 2023-10-05 01:52 - 2023-10-05 01:52 - 009335710 _____ C:\Users\jk795\Downloads\7D18vA8.zip
- 2023-10-05 01:34 - 2023-10-07 21:15 - 000000000 ____D C:\Program Files\EA
- 2023-10-05 01:34 - 2023-10-05 01:34 - 000000000 ____D C:\Users\jk795\AppData\Roaming\EA
- 2023-10-05 01:34 - 2023-10-05 01:34 - 000000000 ____D C:\ProgramData\eaanticheat
- 2023-10-05 01:01 - 2023-10-07 21:19 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller
- 2023-10-05 00:44 - 2023-10-19 19:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
- 2023-10-05 00:44 - 2023-10-05 00:46 - 000000000 ____D C:\ProgramData\EA Desktop
- 2023-10-05 00:44 - 2023-10-05 00:44 - 000000000 ____D C:\Users\jk795\AppData\Local\Electronic Arts
- 2023-10-05 00:44 - 2023-10-05 00:44 - 000000000 ____D C:\Users\jk795\AppData\Local\EADesktop
- 2023-10-05 00:44 - 2023-10-05 00:44 - 000000000 ____D C:\Program Files\Electronic Arts
- 2023-10-04 15:44 - 2023-10-19 19:04 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome
- 2023-10-04 15:44 - 2023-10-04 15:45 - 047667808 _____ (Adlice Software ) C:\Users\jk795\Downloads\RogueKiller_setup.exe
- 2023-10-04 15:44 - 2023-10-04 15:45 - 047667808 _____ (Adlice Software ) C:\Users\jk795\Downloads\RogueKiller_setup (1).exe
- 2023-10-04 15:29 - 2023-10-04 15:29 - 000000000 ____D C:\Users\jk795\AppData\Local\ElevatedDiagnostics
- 2023-10-04 15:19 - 2023-10-04 15:19 - 000000000 ____D C:\ProgramData\Origin
- 2023-10-03 23:34 - 2023-10-07 21:15 - 000000000 ____D C:\ProgramData\Packer
- 2023-09-27 23:53 - 2023-09-27 23:53 - 000000000 ____D C:\Users\jk795\OneDrive\Dokumenty\Immortals Fenyx Rising
- 2023-09-24 23:55 - 2023-09-24 23:55 - 000000000 ____D C:\Users\jk795\AppData\Local\Backup
- ==================== Jeden miesiąc (zmodyfikowane) ==================
- (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
- 2023-10-20 00:29 - 2023-09-13 19:55 - 000000000 ____D C:\Program Files (x86)\Google
- 2023-10-20 00:24 - 2023-07-10 06:57 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
- 2023-10-20 00:23 - 2023-07-25 00:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
- 2023-10-20 00:23 - 2023-07-25 00:56 - 000000000 ____D C:\Program Files\RogueKiller
- 2023-10-20 00:11 - 2023-07-10 00:02 - 000000000 ____D C:\Users\jk795\AppData\Local\D3DSCache
- 2023-10-19 21:40 - 2023-09-13 19:55 - 000002253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2023-10-19 21:26 - 2023-07-09 23:51 - 000000000 ____D C:\ProgramData\NVIDIA
- 2023-10-19 20:56 - 2023-07-25 00:48 - 000000000 ____D C:\Users\jk795\AppData\Local\Malwarebytes
- 2023-10-19 20:55 - 2023-07-10 08:44 - 000012288 ___SH C:\DumpStack.log.tmp
- 2023-10-19 20:55 - 2023-07-09 23:55 - 000000000 __RHD C:\Users\Public\AccountPictures
- 2023-10-19 19:04 - 2023-09-17 01:21 - 000000000 ____D C:\WINDOWS\system32\appmgmt
- 2023-10-19 19:04 - 2023-09-17 01:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
- 2023-10-19 19:04 - 2023-09-16 02:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
- 2023-10-19 19:04 - 2023-09-12 20:39 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
- 2023-10-19 19:04 - 2023-08-14 03:43 - 000000000 ____D C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
- 2023-10-19 19:04 - 2023-08-13 01:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
- 2023-10-19 19:04 - 2023-08-06 23:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\DAEMON Tools Lite
- 2023-10-19 19:04 - 2023-07-23 18:14 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
- 2023-10-19 19:04 - 2023-07-10 09:37 - 000000000 ____D C:\WINDOWS\system32\MsDtc
- 2023-10-19 19:04 - 2023-07-10 03:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
- 2023-10-19 19:04 - 2023-07-10 00:26 - 000000000 ____D C:\Program Files\Intel
- 2023-10-19 19:04 - 2023-07-10 00:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Memory Optimizer
- 2023-10-19 19:04 - 2023-07-10 00:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
- 2023-10-19 19:04 - 2023-07-09 23:56 - 000000000 ___RD C:\Users\jk795\OneDrive
- 2023-10-19 19:04 - 2023-07-09 23:51 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
- 2023-10-19 19:03 - 2023-07-09 23:55 - 000000000 ____D C:\Users\jk795\AppData\Local\Packages
- 2023-10-19 17:48 - 2023-07-24 17:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries
- 2023-10-19 17:48 - 2023-07-10 00:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
- 2023-10-19 01:31 - 2023-07-09 23:56 - 000002423 _____ C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
- 2023-10-17 20:48 - 2023-07-10 04:42 - 000000000 ____D C:\Users\jk795\AppData\Local\CrashDumps
- 2023-10-16 17:44 - 2023-07-10 00:00 - 000001434 _____ C:\Users\jk795\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Przeglądarka Opera GX.lnk
- 2023-10-12 20:53 - 2023-07-24 02:31 - 000000000 ____D C:\Users\jk795\AppData\LocalLow\Mozilla
- 2023-10-10 23:29 - 2023-07-11 21:07 - 000000000 ____D C:\WINDOWS\system32\MRT
- 2023-10-10 23:28 - 2023-07-11 21:07 - 181553176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
- 2023-10-09 18:49 - 2023-07-10 01:09 - 000000000 ____D C:\Users\jk795\AppData\Local\NVIDIA Corporation
- 2023-10-07 21:17 - 2023-08-06 03:58 - 000000000 ____D C:\Users\jk795\OneDrive\Dokumenty\FIFA 23
- 2023-10-07 13:39 - 2023-09-17 19:03 - 000000000 ____D C:\WINDOWS\pss
- 2023-10-06 03:09 - 2023-08-06 01:22 - 000000000 ____D C:\Users\jk795\AppData\Local\Origin
- 2023-10-06 01:47 - 2023-07-09 23:56 - 000000000 ____D C:\Users\jk795\AppData\Local\PlaceholderTileLogoFolder
- 2023-10-05 02:43 - 2023-07-09 23:46 - 000000000 ____D C:\ProgramData\Packages
- 2023-10-05 01:27 - 2023-07-10 03:56 - 000000000 ____D C:\ProgramData\Epic
- 2023-10-05 00:44 - 2023-07-10 00:43 - 000000000 ____D C:\ProgramData\Package Cache
- 2023-10-05 00:30 - 2023-07-10 08:44 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
- 2023-09-27 23:53 - 2023-08-06 19:04 - 000003781 _____ C:\WINDOWS\system32\Drivers\etc\hosts.rollback
- 2023-09-27 00:15 - 2023-08-04 23:46 - 000000000 ____D C:\Users\jk795\AppData\Roaming\qBittorrent
- 2023-09-26 21:30 - 2023-07-10 00:11 - 000000000 ____D C:\Users\jk795\AppData\Local\Steam
- ==================== Pliki w katalogu głównym wybranych folderów ========
- 2023-10-20 00:29 - 2023-10-20 00:29 - 000007605 _____ () C:\Users\jk795\AppData\Local\Resmon.ResmonCfg
- ==================== SigCheck ============================
- (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)
- ==================== Koniec FRST.txt ========================
Add Comment
Please, Sign In to add comment