Advertisement
Guest User

FRST.txt

a guest
Nov 3rd, 2018
73
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 40.71 KB | None | 0 0
  1. Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 24.10.2018
  2. Uruchomiony przez twujstary (administrator) DESKTOP-51EG90U (03-11-2018 12:13:13)
  3. Uruchomiony z C:\Users\twujstary\Desktop
  4. Załadowane profile: twujstary & (Dostępne profile: twujstary)
  5. Platform: Windows 10 Pro Wersja 1703 15063.726 (X64) Język: Polski (Polska)
  6. Internet Explorer Wersja 11 (Domyślna przeglądarka: Opera)
  7. Tryb startu: Normal
  8. Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
  9.  
  10. ==================== Procesy (filtrowane) =================
  11.  
  12. (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)
  13.  
  14. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
  15. (Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
  16. (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
  17. (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
  18. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
  19. (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
  20. (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
  21. (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
  22. (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
  23. (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
  24. (Amagicom AB) C:\Program Files\Mullvad VPN\resources\mullvad-daemon.exe
  25. () C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
  26. (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
  27. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
  28. (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
  29. (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
  30. (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
  31. (Valve Corporation) D:\Steam\Steam.exe
  32. (TrueCrypt Foundation) C:\Program Files\TrueCrypt\TrueCrypt.exe
  33. () C:\Program Files (x86)\SteamServerBrowser\SteamServerBrowser.exe
  34. () C:\Program Files (x86)\DFX\dfx.exe
  35. (VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
  36. () C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp32.exe
  37. () C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp64.exe
  38. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  39. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  40. (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
  41. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  42. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  43. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  44. (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
  45. (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
  46. (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
  47. (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
  48. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  49. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera_crashreporter.exe
  50. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  51. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  52. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  53. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  54. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  55. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  56. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  57. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  58. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  59. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  60. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  61. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  62. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  63.  
  64. ==================== Rejestr (filtrowane) ===========================
  65.  
  66. (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)
  67.  
  68. HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
  69. HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16781824 2017-01-11] (Realtek Semiconductor)
  70. HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
  71. HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated)
  72. HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2670056 2018-09-10] (Adobe Systems, Incorporated)
  73. HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
  74. HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2410968 2018-09-13] (Adobe Inc.)
  75. HKLM-x32\...\Run: [FxSound Enhancer] => C:\Program Files (x86)\DFX\dfx.exe [1665528 2017-06-30] ()
  76. HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [125872 2018-09-19] (VMware, Inc.)
  77. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Steam] => D:\Steam\steam.exe [3208992 2018-10-13] (Valve Corporation)
  78. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3112744 2018-09-05] (Electronic Arts)
  79. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [TrueCrypt] => C:\Program Files\TrueCrypt\TrueCrypt.exe [1516496 2017-10-07] (TrueCrypt Foundation)
  80. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Spotify] => C:\Users\twujstary\AppData\Roaming\Spotify\Spotify.exe [21325200 2018-02-15] (Spotify Ltd)
  81. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [SteamServerBrowser] => C:\Program Files (x86)\SteamServerBrowser\SteamServerBrowser.exe [228352 2017-02-26] ()
  82. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Spotify Web Helper] => C:\Users\twujstary\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-02-15] (Spotify Ltd)
  83. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Discord] => C:\Users\twujstary\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc.)
  84. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [TrueCrypt Format] => C:\Program Files\TrueCrypt\TrueCrypt Format.exe [1610704 2017-10-07] (TrueCrypt Foundation)
  85. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [Steam] => D:\Steam\steam.exe [3208992 2018-10-13] (Valve Corporation)
  86. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3112744 2018-09-05] (Electronic Arts)
  87. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [TrueCrypt] => C:\Program Files\TrueCrypt\TrueCrypt.exe [1516496 2017-10-07] (TrueCrypt Foundation)
  88. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [Spotify] => C:\Users\twujstary\AppData\Roaming\Spotify\Spotify.exe [21325200 2018-02-15] (Spotify Ltd)
  89. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [SteamServerBrowser] => C:\Program Files (x86)\SteamServerBrowser\SteamServerBrowser.exe [228352 2017-02-26] ()
  90. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [Spotify Web Helper] => C:\Users\twujstary\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-02-15] (Spotify Ltd)
  91. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [Discord] => C:\Users\twujstary\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc.)
  92. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11032018121104651\...\Run: [TrueCrypt Format] => C:\Program Files\TrueCrypt\TrueCrypt Format.exe [1610704 2017-10-07] (TrueCrypt Foundation)
  93.  
  94. ==================== Internet (filtrowane) ====================
  95.  
  96. (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)
  97.  
  98. Tcpip\Parameters: [DhcpNameServer] 89.231.1.206 217.172.224.160
  99. Tcpip\..\Interfaces\{0def86cb-752d-4576-a8ef-b1fa3d0a1eb1}: [DhcpNameServer] 89.231.1.206 217.172.224.160
  100. Tcpip\..\Interfaces\{1fac14f4-09ae-4004-b0b8-bd4412cf4495}: [DhcpNameServer] 89.231.1.206 217.172.224.160
  101. Tcpip\..\Interfaces\{6cc8b452-7038-470c-905b-099b1df240c0}: [DhcpNameServer] 89.231.1.206 217.172.224.160
  102.  
  103. Internet Explorer:
  104. ==================
  105.  
  106. FireFox:
  107. ========
  108. FF DefaultProfile: q4zkjccv.default
  109. FF ProfilePath: C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default [2018-11-02]
  110. FF Extension: (Hoxx VPN Proxy) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\@hoxx-vpn.xpi [2018-08-09]
  111. FF Extension: (HTTPS Everywhere) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\https-everywhere-eff@eff.org.xpi [2018-08-09]
  112. FF Extension: (Self-Destructing Cookies) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi [2017-04-25] [Przestarzałe]
  113. FF Extension: (Decentraleyes) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\jid1-BoFifL9Vbdl2zQ@jetpack.xpi [2018-08-09]
  114. FF Extension: (Privacy Badger) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\jid1-MnnxcxisBPnSXQ-eff@jetpack.xpi [2018-08-09]
  115. FF Extension: (uBlock Origin) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\uBlock0@raymondhill.net.xpi [2018-08-13]
  116. FF Extension: (iMEGA) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\{065ee92a-ad57-42a2-b6d5-466b6fd8e24d}.xpi [2017-07-01] [Przestarzałe]
  117. FF Extension: (StartupMaster) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\{506d044e-41fa-4cc8-9dc6-9ff70e96eebf}.xpi [2017-04-25] [Przestarzałe]
  118. FF Extension: (Greasemonkey) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2018-04-01]
  119. FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_122.dll [2018-10-10] ()
  120. FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-09-13] (Adobe Systems)
  121. FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_122.dll [2018-10-10] ()
  122. FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-08-21] (NVIDIA Corporation)
  123. FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-08-21] (NVIDIA Corporation)
  124. FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-09-13] (Adobe Systems)
  125.  
  126. Opera:
  127. =======
  128. OPR Extension: (Play HLS M3u8) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\ckblfoghkjhaclegefojbgllenffajdc [2018-10-13]
  129. OPR Extension: (DotVPN — a better way to VPN) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\hiegahbgoabbpoieploedhfnobmpgbeg [2018-05-20]
  130. OPR Extension: (Set password for your browser ( Opera lock )) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\hlimdilplebcephnbbibnldbhjhoipfh [2018-06-17]
  131. OPR Extension: (uBlock Origin) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2018-10-01]
  132. OPR Extension: (Zainstaluj rozszerzenia Chrome) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2018-10-13]
  133. OPR Extension: (Tampermonkey) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\mfdhdgbonjidekjkjmjaneanmdmpmidf [2018-07-29]
  134. OPR Extension: (Adblock Plus) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2018-11-01]
  135.  
  136. ==================== Usługi (filtrowane) ====================
  137.  
  138. (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
  139.  
  140. R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818136 2018-09-13] (Adobe Inc.)
  141. R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2910696 2018-09-10] (Adobe Systems, Incorporated)
  142. R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2704872 2018-09-10] (Adobe Systems, Incorporated)
  143. S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7361312 2018-10-03] ()
  144. S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-08-22] (EasyAntiCheat Ltd)
  145. R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
  146. R2 MullvadVPN; C:\Program Files\Mullvad VPN\resources\mullvad-daemon.exe [8315904 2018-10-16] (Amagicom AB) [Brak podpisu cyfrowego]
  147. S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2213696 2018-09-05] (Electronic Arts)
  148. R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3084104 2018-09-05] (Electronic Arts)
  149. S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-20] (Microsoft Corporation)
  150. S3 SoundBoosterService; C:\Program Files (x86)\Letasoft Sound Booster\SoundBoosterService.exe [153272 2018-08-07] (Letasoft)
  151. R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15445936 2018-09-19] ()
  152. R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
  153. R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
  154. R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
  155. R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
  156.  
  157. ===================== Sterowniki (filtrowane) ======================
  158.  
  159. (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
  160.  
  161. S3 DFX11_1; C:\Windows\system32\drivers\dfx11_1x64.sys [28008 2018-03-08] (Windows (R) Win 7 DDK provider)
  162. R3 DFX12; C:\Windows\system32\drivers\dfx12x64.sys [39048 2018-03-08] (Windows (R) Win 7 DDK provider)
  163. S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2017-11-28] (Disc Soft Ltd)
  164. S3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2017-11-28] (Disc Soft Ltd)
  165. R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [152688 2018-10-18] (Malwarebytes)
  166. R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [32840 2017-09-19] (ELAN Microelectronic Corp.)
  167. S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2017-06-29] (LogMeIn Inc.)
  168. R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-09-19] (REALiX(tm))
  169. S3 kmloop; C:\Windows\System32\drivers\loop.sys [16896 2017-03-18] (Microsoft Corporation)
  170. R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198000 2018-11-02] (Malwarebytes)
  171. R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [119136 2018-11-02] (Malwarebytes)
  172. R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [63768 2018-11-02] (Malwarebytes)
  173. R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [260480 2018-11-02] (Malwarebytes)
  174. R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [111152 2018-11-03] (Malwarebytes)
  175. R1 MpKsla5e171a7; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ADAAB0DA-3E7C-4136-971B-21571FF70A42}\MpKsla5e171a7.sys [58120 2018-11-02] (Microsoft Corporation)
  176. R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f5be1f8d25335236\nvlddmkm.sys [17212744 2018-08-22] (NVIDIA Corporation)
  177. R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
  178. S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
  179. S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [254520 2017-03-15] (QUALCOMM Incorporated)
  180. R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [984032 2017-09-19] (Realtek )
  181. S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
  182. S2 SecDrv; C:\Windows\SysWOW64\drivers\SECDRV.SYS [163644 2018-02-20] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Brak podpisu cyfrowego]
  183. S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-10-18] ()
  184. R3 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [213216 2018-10-15] (Oracle Corporation)
  185. R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [223000 2018-10-15] (Oracle Corporation)
  186. S3 VOICEMOD_Driver; C:\Windows\system32\drivers\vmdrv.sys [45408 2018-03-15] (Windows (R) Win 7 DDK provider)
  187. R0 vsock; C:\Windows\System32\DRIVERS\vsock.sys [92040 2018-06-22] (VMware, Inc.)
  188. R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-x64.sys [52576 2018-02-28] (VMware, Inc.)
  189. S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
  190. R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
  191. R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
  192. U4 npcap_wifi; Brak ImagePath
  193. S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
  194. S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X]
  195. S3 RtlWlanu; \SystemRoot\System32\drivers\rtwlanu.sys [X]
  196. S3 VBAudioVACMME; \SystemRoot\system32\DRIVERS\vbaudio_cable64_win7.sys [X]
  197. S3 VBAudioVMVAIOMME; \SystemRoot\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [X]
  198. S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
  199.  
  200. ==================== NetSvcs (filtrowane) ===================
  201.  
  202. (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
  203.  
  204.  
  205. ==================== Jeden miesiąc - utworzone pliki i foldery ========
  206.  
  207. (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
  208.  
  209. 2018-11-03 12:11 - 2018-11-03 12:11 - 000111152 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
  210. 2018-11-02 19:28 - 2018-11-02 19:28 - 000119136 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
  211. 2018-11-02 19:28 - 2018-11-02 19:28 - 000063768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
  212. 2018-11-02 19:24 - 2018-11-02 19:24 - 000260480 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
  213. 2018-11-02 19:24 - 2018-11-02 19:24 - 000000008 __RSH C:\ProgramData\ntuser.pol
  214. 2018-11-02 19:14 - 2018-11-02 19:14 - 000000000 ____D C:\Windows\Panther
  215. 2018-11-02 18:40 - 2018-11-02 19:22 - 000011660 _____ C:\Users\twujstary\Desktop\Fixlog.txt
  216. 2018-11-02 18:10 - 2018-11-02 18:40 - 000004935 _____ C:\Users\twujstary\Downloads\i.txt
  217. 2018-11-02 17:32 - 2018-11-02 17:32 - 000052792 _____ C:\Users\twujstary\Desktop\Shortcut.txt
  218. 2018-11-02 17:31 - 2018-11-02 17:32 - 000056280 _____ C:\Users\twujstary\Desktop\Addition.txt
  219. 2018-11-02 17:30 - 2018-11-03 12:14 - 000019749 _____ C:\Users\twujstary\Desktop\FRST.txt
  220. 2018-11-02 16:10 - 2018-11-02 16:14 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\.purple
  221. 2018-11-02 16:09 - 2018-11-02 16:09 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk
  222. 2018-11-02 16:08 - 2018-11-02 19:24 - 000000000 ____D C:\ProgramData\Mullvad VPN
  223. 2018-11-02 16:08 - 2018-11-02 16:19 - 000000000 ____D C:\Users\twujstary\AppData\Local\Mullvad VPN
  224. 2018-11-02 16:08 - 2018-11-02 16:09 - 000000000 ____D C:\Program Files (x86)\Pidgin
  225. 2018-11-02 16:08 - 2018-11-02 16:08 - 000001858 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mullvad VPN.lnk
  226. 2018-11-02 16:08 - 2018-11-02 16:08 - 000001846 _____ C:\Users\Public\Desktop\Mullvad VPN.lnk
  227. 2018-11-02 16:08 - 2018-11-02 16:08 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Mullvad VPN
  228. 2018-11-02 16:08 - 2018-11-02 16:08 - 000000000 ____D C:\Program Files\Mullvad VPN
  229. 2018-11-02 16:07 - 2018-11-02 16:07 - 056126080 _____ (Mullvad VPN) C:\Users\twujstary\Desktop\MullvadVPN-2018.4.exe
  230. 2018-11-02 16:04 - 2018-11-02 16:05 - 008671032 _____ C:\Users\twujstary\Downloads\pidgin-2.13.0.exe
  231. 2018-11-02 15:07 - 2018-11-02 15:07 - 000001113 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
  232. 2018-11-02 14:17 - 2018-11-02 14:17 - 000000000 ____D C:\Users\twujstary\AppData\Local\mbam
  233. 2018-11-02 14:16 - 2018-11-02 14:16 - 000198000 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
  234. 2018-11-02 14:16 - 2018-11-02 14:16 - 000001880 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
  235. 2018-11-02 14:16 - 2018-11-02 14:16 - 000000000 ____D C:\Users\twujstary\AppData\Local\mbamtray
  236. 2018-11-02 14:16 - 2018-11-02 14:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
  237. 2018-11-02 14:16 - 2018-11-02 14:16 - 000000000 ____D C:\ProgramData\Malwarebytes
  238. 2018-11-02 14:16 - 2018-10-18 09:44 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
  239. 2018-11-02 14:15 - 2018-11-02 14:16 - 078612224 _____ (Malwarebytes ) C:\Users\twujstary\Desktop\mb3-setup-consumer-3.6.1.2711-1.0.482-1.0.7607.exe
  240. 2018-11-02 14:01 - 2018-11-02 14:05 - 000000000 ____D C:\Windows\AppReadiness
  241. 2018-11-02 13:55 - 2018-11-02 13:55 - 000000000 _____ C:\Windows\SysWOW64\last.dump
  242. 2018-11-02 10:06 - 2018-11-02 10:06 - 000000000 ____D C:\Users\twujstary\Documents\Virtual Machines
  243. 2018-11-02 10:05 - 2018-11-02 10:07 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\VMware
  244. 2018-11-02 10:05 - 2018-11-02 10:07 - 000000000 ____D C:\Users\twujstary\AppData\Local\VMware
  245. 2018-11-02 10:04 - 2018-09-19 04:16 - 000374192 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
  246. 2018-11-02 10:04 - 2018-09-19 04:10 - 000099272 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
  247. 2018-11-02 10:04 - 2018-06-22 01:31 - 000092040 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
  248. 2018-11-02 10:04 - 2018-06-22 01:31 - 000046472 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
  249. 2018-11-02 10:04 - 2018-06-22 01:31 - 000042376 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
  250. 2018-11-02 10:03 - 2018-11-02 19:24 - 000000000 ____D C:\ProgramData\VMware
  251. 2018-11-02 10:03 - 2018-11-02 10:03 - 003231096 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
  252. 2018-11-02 10:03 - 2018-11-02 10:03 - 000001286 _____ C:\Users\Public\Desktop\VMware Workstation Pro.lnk
  253. 2018-11-02 10:03 - 2018-11-02 10:03 - 000001024 _____ C:\Windows\SysWOW64\%TMP%
  254. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\Users\Public\Documents\Shared Virtual Machines
  255. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
  256. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\Program Files\Common Files\VMware
  257. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\Program Files (x86)\VMware
  258. 2018-11-02 10:03 - 2018-09-19 04:17 - 001266096 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
  259. 2018-11-02 10:03 - 2018-09-19 04:16 - 000396208 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
  260. 2018-11-02 10:03 - 2018-09-19 04:16 - 000134104 _____ (VMware, Inc.) C:\Windows\system32\vnetinst.dll
  261. 2018-11-02 10:03 - 2018-09-19 04:16 - 000043992 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
  262. 2018-11-02 10:03 - 2018-09-05 22:43 - 000084752 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
  263. 2018-11-02 09:59 - 2018-11-02 10:01 - 536606728 _____ (VMware, Inc.) C:\Users\twujstary\Desktop\VMware-workstation-full-15.0.0-10134415.exe
  264. 2018-11-02 09:35 - 2018-11-02 15:09 - 000000000 ____D C:\Users\twujstary\VirtualBox VMs
  265. 2018-11-02 09:35 - 2018-11-02 15:09 - 000000000 ____D C:\Users\twujstary\.VirtualBox
  266. 2018-11-02 09:34 - 2018-11-02 15:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
  267. 2018-11-02 09:34 - 2018-11-02 09:34 - 000000000 ____D C:\Program Files\Oracle
  268. 2018-11-02 09:34 - 2018-10-15 11:27 - 000168824 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
  269. 2018-11-02 09:34 - 2018-10-15 11:26 - 000984512 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
  270. 2018-11-02 09:31 - 2018-11-02 09:31 - 114016768 _____ (Oracle Corporation) C:\Users\twujstary\Desktop\VirtualBox-5.2.20-125813-Win.exe
  271. 2018-11-02 08:49 - 2018-11-03 12:13 - 000000000 ____D C:\FRST
  272. 2018-11-02 08:49 - 2018-11-02 08:49 - 002414592 _____ (Farbar) C:\Users\twujstary\Desktop\FRST64.exe
  273. 2018-11-02 08:45 - 2018-11-02 08:46 - 048222451 _____ C:\Users\twujstary\Desktop\Desktop.rar
  274. 2018-11-02 08:41 - 2018-11-02 08:41 - 000000000 ___HD C:\$AV_AVG
  275. 2018-11-01 15:41 - 2018-11-01 16:17 - 000000000 ____D C:\Users\twujstary\Desktop\FON
  276. 2018-10-31 20:28 - 2018-10-31 20:28 - 000853504 _____ (WarGods.ro) C:\Users\twujstary\Desktop\WarGods Cheat Defender Win8.exe
  277. 2018-10-30 21:09 - 2018-10-30 21:09 - 002615821 _____ C:\Users\twujstary\Downloads\bhop_mann.rar
  278. 2018-10-29 19:57 - 2018-10-29 19:57 - 000001712 _____ C:\Users\Public\Desktop\FxSound Enhancer.lnk
  279. 2018-10-29 19:57 - 2018-10-29 19:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FxSound Enhancer
  280. 2018-10-29 19:56 - 2018-10-29 19:57 - 004121969 _____ C:\Users\twujstary\Downloads\FxSound Enhancer 13.008 Setup + Crack.rar
  281. 2018-10-27 20:55 - 2018-10-27 20:56 - 077976048 _____ (TeamSpeak Systems GmbH) C:\Users\twujstary\Desktop\TeamSpeak3-Client-win64-3.1.10.exe
  282. 2018-10-26 22:20 - 2018-10-26 22:49 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\HLSW
  283. 2018-10-26 22:20 - 2018-10-26 22:20 - 011613796 _____ (Stripf Software ) C:\Users\twujstary\Desktop\hlsw_1_4_0_2_setup.exe
  284. 2018-10-26 22:20 - 2018-10-26 22:20 - 000001024 _____ C:\Users\twujstary\Desktop\HLSW.lnk
  285. 2018-10-26 22:20 - 2018-10-26 22:20 - 000000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HLSW
  286. 2018-10-26 22:20 - 2018-10-26 22:20 - 000000000 ___SD C:\Program Files (x86)\HLSW
  287. 2018-10-26 19:46 - 2018-10-26 21:33 - 000000000 ____D C:\Users\twujstary\Documents\Assassin's Creed Syndicate
  288. 2018-10-25 21:48 - 2018-10-25 22:19 - 000000497 _____ C:\Users\twujstary\Desktop\Nowy AutoHotkey Script.ahk
  289. 2018-10-19 15:12 - 2018-10-19 15:12 - 000001038 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Przeglądarka Opera.lnk
  290. 2018-10-15 11:26 - 2018-10-15 11:26 - 000223000 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetLwf.sys
  291. 2018-10-15 11:26 - 2018-10-15 11:26 - 000213216 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp6.sys
  292. 2018-10-13 18:38 - 2018-10-13 18:38 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\obs-studio-node-server
  293. 2018-10-13 17:39 - 2018-10-13 17:39 - 001135289 _____ C:\Users\twujstary\Desktop\Nowy dokument tekstowy.txt
  294. 2018-10-13 17:38 - 2018-10-13 17:38 - 001135289 _____ C:\Users\twujstary\Desktop\Nowy dokument tekstowy.js
  295. 2018-10-12 11:17 - 2018-10-12 11:17 - 000005074 _____ C:\Users\twujstary\AppData\Local\recently-used.xbel
  296. 2018-10-10 20:14 - 2018-10-10 20:14 - 000855568 _____ C:\Users\twujstary\Documents\belmondo.xcf
  297. 2018-10-07 12:27 - 2018-10-07 12:27 - 000025092 _____ C:\Users\twujstary\Downloads\ATPP.v1.3.zip
  298. 2018-10-07 12:14 - 2018-10-07 12:14 - 000000000 ____D C:\Program Files (x86)\Auslogics
  299. 2018-10-07 12:13 - 2018-10-07 12:13 - 021221088 _____ (Auslo˜gics ) C:\Users\twujstary\Desktop\boost-speed-setup.exe
  300. 2018-10-07 12:02 - 2018-10-07 12:04 - 926056410 _____ C:\Users\twujstary\Desktop\rap.rar
  301. 2018-10-07 11:57 - 2018-10-07 11:58 - 930573556 _____ C:\Users\twujstary\Desktop\erape.rar
  302. 2018-10-07 11:52 - 2018-10-07 11:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskTrix
  303. 2018-10-07 11:52 - 2018-10-07 11:52 - 000000000 ____D C:\Program Files (x86)\DiskTrix
  304. 2018-10-07 11:51 - 2018-10-07 11:51 - 002547712 _____ C:\Users\twujstary\Desktop\UltimateDefragFREE(dobreprogramy.pl).exe
  305.  
  306. ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========
  307.  
  308. (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
  309.  
  310. 2018-11-02 22:56 - 2017-09-19 16:12 - 000000000 ____D C:\ProgramData\NVIDIA
  311. 2018-11-02 19:24 - 2017-03-23 03:19 - 000000006 ____H C:\Windows\Tasks\SA.DAT
  312. 2018-11-02 19:23 - 2017-03-18 12:40 - 000786432 _____ C:\Windows\system32\config\BBI
  313. 2018-11-02 19:19 - 2017-03-18 22:03 - 000000000 ___HD C:\Windows\system32\GroupPolicy
  314. 2018-11-02 19:19 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
  315. 2018-11-02 19:16 - 2017-03-23 03:19 - 000235432 _____ C:\Windows\system32\FNTCACHE.DAT
  316. 2018-11-02 19:14 - 2018-09-29 16:50 - 000000000 ____D C:\Users\twujstary\AppData\Local\Avg
  317. 2018-11-02 19:14 - 2018-09-29 16:47 - 000000000 ____D C:\ProgramData\AVG
  318. 2018-11-02 18:40 - 2018-09-29 16:49 - 000000000 ____D C:\Windows\System32\Tasks\AVG
  319. 2018-11-02 18:40 - 2018-05-04 17:50 - 000000000 ____D C:\Windows\System32\Tasks\Avast Software
  320. 2018-11-02 18:23 - 2018-04-01 12:34 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\slobs-client
  321. 2018-11-02 18:23 - 2017-03-23 03:28 - 003239184 _____ C:\Windows\system32\PerfStringBackup.INI
  322. 2018-11-02 18:23 - 2017-03-20 04:58 - 001524622 _____ C:\Windows\system32\perfh015.dat
  323. 2018-11-02 18:23 - 2017-03-20 04:58 - 000374940 _____ C:\Windows\system32\perfc015.dat
  324. 2018-11-02 16:34 - 2017-09-19 16:24 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\TS3Client
  325. 2018-11-02 16:19 - 2017-09-19 16:36 - 000000000 ____D C:\Users\twujstary\AppData\LocalLow\Mozilla
  326. 2018-11-02 16:13 - 2017-10-03 15:13 - 000000000 ____D C:\Users\twujstary\AppData\Local\CrashDumps
  327. 2018-11-02 16:08 - 2017-10-05 18:03 - 000000000 ____D C:\Program Files (x86)\Mullvad
  328. 2018-11-02 15:09 - 2017-03-18 22:01 - 000000000 ____D C:\Windows\INF
  329. 2018-11-02 14:13 - 2017-10-08 10:38 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\TrueCrypt
  330. 2018-11-02 14:08 - 2018-05-12 12:12 - 000000000 ____D C:\ProgramData\VMProtect Software
  331. 2018-11-02 14:08 - 2018-02-18 14:32 - 000000000 ____D C:\Program Files (x86)\WoM2
  332. 2018-11-02 14:08 - 2017-09-19 17:02 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
  333. 2018-11-02 14:07 - 2018-08-22 09:11 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VB Audio
  334. 2018-11-02 14:07 - 2018-08-22 09:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VB Audio
  335. 2018-11-02 14:07 - 2018-08-22 09:11 - 000000000 ____D C:\Program Files\VB
  336. 2018-11-02 14:07 - 2018-05-11 13:38 - 000000000 ____D C:\Users\twujstary\AppData\Local\TP-Link
  337. 2018-11-02 14:07 - 2018-04-27 19:06 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Visual Studio Setup
  338. 2018-11-02 14:07 - 2018-04-11 12:34 - 000000000 ____D C:\ProgramData\Hi-Rez Studios
  339. 2018-11-02 14:07 - 2017-09-21 14:22 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
  340. 2018-11-02 14:06 - 2018-05-11 13:39 - 000000000 ____D C:\ProgramData\TP-Link
  341. 2018-11-02 14:06 - 2018-02-14 13:16 - 000000000 ____D C:\Program Files\rempl
  342. 2018-11-02 14:06 - 2017-10-17 19:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
  343. 2018-11-02 14:05 - 2018-09-22 19:13 - 000000000 ____D C:\Program Files (x86)\Symulator Jazdy 2
  344. 2018-11-02 14:05 - 2018-05-28 15:37 - 000000000 ____D C:\Program Files\Sandboxie
  345. 2018-11-02 14:05 - 2017-09-23 03:57 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\TeamViewer
  346. 2018-11-02 14:05 - 2017-03-23 03:28 - 000000000 ____D C:\Users\twujstary\AppData\Local\Packages
  347. 2018-11-02 14:05 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
  348. 2018-11-02 14:04 - 2018-07-08 18:31 - 000000000 ____D C:\Users\twujstary\Documents\AutomaticSolution Software
  349. 2018-11-02 14:04 - 2017-09-30 13:06 - 000000000 ____D C:\Program Files\Rockstar Games
  350. 2018-11-02 14:04 - 2017-09-30 13:06 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
  351. 2018-11-02 14:02 - 2018-07-14 13:55 - 000000000 ____D C:\Program Files (x86)\MTA San Andreas 1.5
  352. 2018-11-02 14:02 - 2018-07-14 13:54 - 000000000 ____D C:\ProgramData\MTA San Andreas All
  353. 2018-11-02 14:02 - 2017-09-19 16:24 - 000000000 ____D C:\ProgramData\Package Cache
  354. 2018-11-02 14:01 - 2018-01-20 20:40 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\IrfanView
  355. 2018-11-02 14:00 - 2018-09-11 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
  356. 2018-11-02 13:59 - 2018-09-30 09:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garena
  357. 2018-11-02 13:59 - 2018-09-30 09:30 - 000000000 ____D C:\ProgramData\Garena
  358. 2018-11-02 13:59 - 2018-09-30 09:30 - 000000000 ____D C:\Program Files (x86)\Garena
  359. 2018-11-02 13:59 - 2018-09-11 13:27 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
  360. 2018-11-02 13:59 - 2017-11-28 16:16 - 000000000 ____D C:\Users\twujstary\AppData\Local\GG
  361. 2018-11-02 13:59 - 2017-10-22 15:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
  362. 2018-11-02 13:59 - 2017-09-22 18:31 - 000000000 ____D C:\Fraps
  363. 2018-11-02 13:58 - 2018-01-05 02:15 - 000000000 ____D C:\Program Files\Epic Games
  364. 2018-11-02 13:58 - 2017-11-02 13:27 - 000000000 ____D C:\ProgramData\Orbit
  365. 2018-11-02 13:58 - 2017-10-11 18:18 - 000000000 ____D C:\Users\twujstary\Documents\My Games
  366. 2018-11-02 13:57 - 2018-01-27 22:21 - 000000000 ____D C:\Program Files (x86)\Counter Strike 1.6 v23
  367. 2018-11-02 13:57 - 2017-11-09 16:19 - 000000000 ____D C:\Users\twujstary\AppData\Local\Dxtory Software
  368. 2018-11-02 13:56 - 2017-11-02 12:35 - 000000000 ____D C:\Program Files\CCleaner
  369. 2018-11-02 09:35 - 2017-03-23 03:27 - 000000000 ____D C:\Users\twujstary
  370. 2018-11-01 14:23 - 2018-09-01 21:21 - 000000000 ___RD C:\Users\twujstary\Desktop\mixtape
  371. 2018-11-01 14:23 - 2018-07-11 14:36 - 000000000 ____D C:\Users\twujstary\Documents\REAPER Media
  372. 2018-11-01 13:40 - 2018-04-11 04:09 - 000000000 ___RD C:\Users\twujstary\Desktop\rapssyyy
  373. 2018-10-31 20:18 - 2018-04-01 12:33 - 000000000 ____D C:\Program Files\Streamlabs OBS
  374. 2018-10-30 14:00 - 2018-08-07 12:24 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DFX for JRiver
  375. 2018-10-29 19:59 - 2018-08-07 12:24 - 000000000 ____D C:\Program Files (x86)\DFX
  376. 2018-10-28 14:00 - 2017-03-23 03:19 - 000000000 ____D C:\Windows\system32\SleepStudy
  377. 2018-10-27 20:57 - 2018-09-24 16:49 - 000000968 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
  378. 2018-10-27 20:57 - 2017-09-19 16:24 - 000000930 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
  379. 2018-10-23 10:44 - 2017-03-18 22:03 - 000000000 ___HD C:\Windows\ELAMBKUP
  380. 2018-10-19 15:12 - 2017-09-25 13:20 - 000000000 ____D C:\Program Files\Opera
  381. 2018-10-12 11:18 - 2017-09-26 14:26 - 000000000 ____D C:\Users\twujstary\.gimp-2.8
  382. 2018-10-12 11:17 - 2017-09-27 18:24 - 000000000 ____D C:\Users\twujstary\AppData\Local\gtk-2.0
  383. 2018-10-12 10:52 - 2017-09-19 16:35 - 000000000 ____D C:\Program Files\Mozilla Firefox
  384. 2018-10-12 10:52 - 2017-09-19 16:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
  385. 2018-10-10 13:29 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\SysWOW64\Macromed
  386. 2018-10-10 13:29 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\system32\Macromed
  387. 2018-10-09 13:17 - 2017-10-04 10:02 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Notepad++
  388. 2018-10-07 12:36 - 2018-02-24 15:39 - 000000000 ____D C:\Users\twujstary\AppData\Local\SquirrelTemp
  389. 2018-10-07 12:36 - 2017-10-17 19:47 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Sony
  390. 2018-10-07 12:36 - 2017-09-19 19:02 - 000000000 ____D C:\ProgramData\Norton
  391. 2018-10-07 12:36 - 2017-09-19 16:11 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
  392. 2018-10-07 12:36 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\LiveKernelReports
  393. 2018-10-07 12:30 - 2018-09-08 17:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed Rivals
  394. 2018-10-07 12:30 - 2018-03-31 20:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
  395. 2018-10-07 12:30 - 2018-02-09 16:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forza Horizon 3
  396. 2018-10-07 12:30 - 2017-10-21 08:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Watch_Dogs 2
  397. 2018-10-07 12:30 - 2017-10-18 12:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed Unity
  398. 2018-10-07 12:30 - 2017-10-01 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed IV Black Flag
  399. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 __RSD C:\Windows\Media
  400. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\Registration
  401. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\IME
  402. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\Help
  403. 2018-10-07 10:33 - 2018-09-22 16:06 - 000000000 ___RD C:\Users\twujstary\Creative Cloud Files
  404. 2018-10-07 10:33 - 2017-10-11 17:50 - 000000000 ____D C:\Users\twujstary\AppData\Local\Adobe
  405.  
  406. ==================== Pliki w katalogu głównym wybranych folderów =======
  407.  
  408. 2017-12-16 19:28 - 2015-02-15 15:03 - 000421888 _____ () C:\Program Files\lame_enc.dll
  409. 2017-03-18 21:59 - 2017-03-18 21:59 - 000174592 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\LeruiekwBgIiD.exe
  410. 2018-02-03 02:36 - 2018-02-03 02:36 - 000000054 _____ () C:\Users\twujstary\AppData\Roaming\updater.cfg
  411. 2018-08-22 09:26 - 2018-08-22 09:55 - 000004617 _____ () C:\Users\twujstary\AppData\Roaming\VoiceMeeterDefault.xml
  412. 2017-10-05 20:58 - 2018-02-25 15:29 - 000000600 _____ () C:\Users\twujstary\AppData\Roaming\winscp.rnd
  413. 2018-03-29 21:14 - 2018-03-29 21:14 - 000000037 ___SH () C:\Users\twujstary\AppData\Local\20986331705021ca58edc424.96250074
  414. 2018-08-12 16:00 - 2018-08-12 16:00 - 000172923 _____ () C:\Users\twujstary\AppData\Local\3AC4.tmp
  415. 2018-08-12 16:11 - 2018-08-12 16:11 - 000123332 _____ () C:\Users\twujstary\AppData\Local\4A98.tmp
  416. 2018-08-12 16:26 - 2018-08-12 16:26 - 000177678 _____ () C:\Users\twujstary\AppData\Local\74ED.tmp
  417. 2018-09-28 10:41 - 2018-09-28 10:41 - 000000000 _____ () C:\Users\twujstary\AppData\Local\oobelibMkey.log
  418. 2017-10-05 20:28 - 2018-03-29 14:24 - 000000600 _____ () C:\Users\twujstary\AppData\Local\PUTTY.RND
  419. 2018-10-12 11:17 - 2018-10-12 11:17 - 000005074 _____ () C:\Users\twujstary\AppData\Local\recently-used.xbel
  420. 2017-09-20 09:23 - 2018-03-16 14:40 - 000007606 _____ () C:\Users\twujstary\AppData\Local\Resmon.ResmonCfg
  421. 2017-12-28 03:45 - 2017-12-28 03:45 - 000000000 _____ () C:\Users\twujstary\AppData\Local\zenmap.exe.log
  422.  
  423. ==================== Bamital & volsnap ======================
  424.  
  425. (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)
  426.  
  427. C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
  428. C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
  429. C:\Windows\explorer.exe => Plik podpisany cyfrowo
  430. C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
  431. C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
  432. C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
  433. C:\Windows\system32\services.exe => Plik podpisany cyfrowo
  434. C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
  435. C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
  436. C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
  437. C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
  438. C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
  439. C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
  440. C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo
  441. C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo
  442.  
  443. LastRegBack: 2018-10-30 09:18
  444.  
  445. ==================== Koniec FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement