Advertisement
Guest User

FRST.txt

a guest
Nov 2nd, 2018
1,080
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 37.39 KB | None | 0 0
  1. Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 24.10.2018
  2. Uruchomiony przez twujstary (administrator) DESKTOP-51EG90U (02-11-2018 17:30:46)
  3. Uruchomiony z C:\Users\twujstary\Desktop
  4. Załadowane profile: twujstary (Dostępne profile: twujstary)
  5. Platform: Windows 10 Pro Wersja 1703 15063.726 (X64) Język: Polski (Polska)
  6. Internet Explorer Wersja 11 (Domyślna przeglądarka: Opera)
  7. Tryb startu: Normal
  8. Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
  9.  
  10. ==================== Procesy (filtrowane) =================
  11.  
  12. (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)
  13.  
  14. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
  15. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
  16. (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
  17. (Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
  18. (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
  19. (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
  20. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
  21. (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
  22. (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
  23. (Valve Corporation) D:\Steam\Steam.exe
  24. (TrueCrypt Foundation) C:\Program Files\TrueCrypt\TrueCrypt.exe
  25. () C:\Program Files (x86)\SteamServerBrowser\SteamServerBrowser.exe
  26. () C:\Program Files (x86)\DFX\dfx.exe
  27. () C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp32.exe
  28. () C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp64.exe
  29. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  30. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  31. (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
  32. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  33. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  34. (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
  35. (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
  36. (Microsoft Corporation) C:\Windows\System32\dllhost.exe
  37. (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
  38. () C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
  39. (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
  40. (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
  41. (Mozilla Corporation) C:\Users\twujstary\Desktop\Tor Browser\Browser\firefox.exe
  42. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  43. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  44. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera_crashreporter.exe
  45. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  46. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  47. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  48. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  49. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  50. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  51. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  52. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  53. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  54. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  55. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  56. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  57. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  58. (Valve) D:\Steam\steamapps\common\Half-Life\hl.exe
  59. (Valve Corporation) D:\Steam\GameOverlayUI.exe
  60. (Valve Corporation) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
  61. (Opera Software) C:\Program Files\Opera\56.0.3051.52\opera.exe
  62. (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
  63.  
  64. ==================== Rejestr (filtrowane) ===========================
  65.  
  66. (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)
  67.  
  68. HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
  69. HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16781824 2017-01-11] (Realtek Semiconductor)
  70. HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
  71. HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated)
  72. HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2670056 2018-09-10] (Adobe Systems, Incorporated)
  73. HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
  74. HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2410968 2018-09-13] (Adobe Inc.)
  75. HKLM-x32\...\Run: [FxSound Enhancer] => C:\Program Files (x86)\DFX\dfx.exe [1665528 2017-06-30] ()
  76. HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [125872 2018-09-19] (VMware, Inc.)
  77. HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA
  78. HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
  79. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Steam] => D:\Steam\steam.exe [3208992 2018-10-13] (Valve Corporation)
  80. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3112744 2018-09-05] (Electronic Arts)
  81. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [TrueCrypt] => C:\Program Files\TrueCrypt\TrueCrypt.exe [1516496 2017-10-07] (TrueCrypt Foundation)
  82. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Spotify] => C:\Users\twujstary\AppData\Roaming\Spotify\Spotify.exe [21325200 2018-02-15] (Spotify Ltd)
  83. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [SteamServerBrowser] => C:\Program Files (x86)\SteamServerBrowser\SteamServerBrowser.exe [228352 2017-02-26] ()
  84. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Spotify Web Helper] => C:\Users\twujstary\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-02-15] (Spotify Ltd)
  85. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [Discord] => C:\Users\twujstary\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc.)
  86. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\Run: [TrueCrypt Format] => C:\Program Files\TrueCrypt\TrueCrypt Format.exe [1610704 2017-10-07] (TrueCrypt Foundation)
  87. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\MountPoints2: {77c6f116-d2ac-11e7-875f-88ad43fe0bc2} - "G:\setup.exe"
  88. HKU\S-1-5-21-1043391465-3389820748-3846585623-1001\...\MountPoints2: {ff899eb7-ec24-11e7-8760-88ad43fe0bc2} - "H:\Autorun.exe"
  89. BootExecute: autocheck autochk * sdnclean64.exe
  90. GroupPolicy: Ograniczenia ? <==== UWAGA
  91.  
  92. ==================== Internet (filtrowane) ====================
  93.  
  94. (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)
  95.  
  96. Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt
  97. Tcpip\..\Interfaces\{0def86cb-752d-4576-a8ef-b1fa3d0a1eb1}: [DhcpNameServer] 89.231.1.206 217.172.224.160
  98. Tcpip\..\Interfaces\{1fac14f4-09ae-4004-b0b8-bd4412cf4495}: [DhcpNameServer] 89.231.1.206 217.172.224.160
  99. Tcpip\..\Interfaces\{6cc8b452-7038-470c-905b-099b1df240c0}: [DhcpNameServer] 89.231.1.206 217.172.224.160
  100.  
  101. Internet Explorer:
  102. ==================
  103. SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
  104. SearchScopes: HKU\S-1-5-21-1043391465-3389820748-3846585623-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
  105.  
  106. FireFox:
  107. ========
  108. FF DefaultProfile: q4zkjccv.default
  109. FF ProfilePath: C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default [2018-10-18]
  110. FF Extension: (Hoxx VPN Proxy) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\@hoxx-vpn.xpi [2018-08-09]
  111. FF Extension: (HTTPS Everywhere) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\https-everywhere-eff@eff.org.xpi [2018-08-09]
  112. FF Extension: (Self-Destructing Cookies) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi [2017-04-25] [Przestarzałe]
  113. FF Extension: (Decentraleyes) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\jid1-BoFifL9Vbdl2zQ@jetpack.xpi [2018-08-09]
  114. FF Extension: (Privacy Badger) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\jid1-MnnxcxisBPnSXQ-eff@jetpack.xpi [2018-08-09]
  115. FF Extension: (uBlock Origin) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\uBlock0@raymondhill.net.xpi [2018-08-13]
  116. FF Extension: (iMEGA) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\{065ee92a-ad57-42a2-b6d5-466b6fd8e24d}.xpi [2017-07-01] [Przestarzałe]
  117. FF Extension: (StartupMaster) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\{506d044e-41fa-4cc8-9dc6-9ff70e96eebf}.xpi [2017-04-25] [Przestarzałe]
  118. FF Extension: (Greasemonkey) - C:\Users\twujstary\AppData\Roaming\Mozilla\Firefox\Profiles\q4zkjccv.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2018-04-01]
  119. FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_122.dll [2018-10-10] ()
  120. FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-09-13] (Adobe Systems)
  121. FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_122.dll [2018-10-10] ()
  122. FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-08-21] (NVIDIA Corporation)
  123. FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-08-21] (NVIDIA Corporation)
  124. FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-09-13] (Adobe Systems)
  125.  
  126. Opera:
  127. =======
  128. OPR Extension: (Play HLS M3u8) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\ckblfoghkjhaclegefojbgllenffajdc [2018-10-13]
  129. OPR Extension: (DotVPN — a better way to VPN) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\hiegahbgoabbpoieploedhfnobmpgbeg [2018-05-20]
  130. OPR Extension: (Set password for your browser ( Opera lock )) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\hlimdilplebcephnbbibnldbhjhoipfh [2018-06-17]
  131. OPR Extension: (uBlock Origin) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2018-10-01]
  132. OPR Extension: (Zainstaluj rozszerzenia Chrome) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2018-10-13]
  133. OPR Extension: (Tampermonkey) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\mfdhdgbonjidekjkjmjaneanmdmpmidf [2018-07-29]
  134. OPR Extension: (Adblock Plus) - C:\Users\twujstary\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2018-11-01]
  135.  
  136. ==================== Usługi (filtrowane) ====================
  137.  
  138. (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
  139.  
  140. HKLM\SYSTEM\CurrentControlSet\Services\avgSP <==== UWAGA (Rootkit!)
  141. HKLM\SYSTEM\CurrentControlSet\Services\avgMonFlt <==== UWAGA (Rootkit!)
  142. HKLM\SYSTEM\CurrentControlSet\Services\avgSnx <==== UWAGA (Rootkit!)
  143.  
  144. R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818136 2018-09-13] (Adobe Inc.)
  145. R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2910696 2018-09-10] (Adobe Systems, Incorporated)
  146. R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2704872 2018-09-10] (Adobe Systems, Incorporated)
  147. S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7361312 2018-10-03] ()
  148. S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-08-22] (EasyAntiCheat Ltd)
  149. R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
  150. S2 MullvadVPN; C:\Program Files\Mullvad VPN\resources\mullvad-daemon.exe [8315904 2018-10-16] (Amagicom AB) [Brak podpisu cyfrowego]
  151. S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2213696 2018-09-05] (Electronic Arts)
  152. R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3084104 2018-09-05] (Electronic Arts)
  153. S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-20] (Microsoft Corporation)
  154. S3 SoundBoosterService; C:\Program Files (x86)\Letasoft Sound Booster\SoundBoosterService.exe [153272 2018-08-07] (Letasoft)
  155. R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15445936 2018-09-19] ()
  156. S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
  157. S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
  158. R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
  159. R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
  160.  
  161. ===================== Sterowniki (filtrowane) ======================
  162.  
  163. ==================== NetSvcs (filtrowane) ===================
  164.  
  165. (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
  166.  
  167.  
  168. ==================== Jeden miesiąc - utworzone pliki i foldery ========
  169.  
  170. (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
  171.  
  172. 2018-11-02 17:30 - 2018-11-02 17:31 - 000015141 _____ C:\Users\twujstary\Desktop\FRST.txt
  173. 2018-11-02 16:10 - 2018-11-02 16:14 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\.purple
  174. 2018-11-02 16:09 - 2018-11-02 16:09 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk
  175. 2018-11-02 16:08 - 2018-11-02 16:19 - 000000000 ____D C:\Users\twujstary\AppData\Local\Mullvad VPN
  176. 2018-11-02 16:08 - 2018-11-02 16:09 - 000000000 ____D C:\ProgramData\Mullvad VPN
  177. 2018-11-02 16:08 - 2018-11-02 16:09 - 000000000 ____D C:\Program Files (x86)\Pidgin
  178. 2018-11-02 16:08 - 2018-11-02 16:08 - 000001858 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mullvad VPN.lnk
  179. 2018-11-02 16:08 - 2018-11-02 16:08 - 000001846 _____ C:\Users\Public\Desktop\Mullvad VPN.lnk
  180. 2018-11-02 16:08 - 2018-11-02 16:08 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Mullvad VPN
  181. 2018-11-02 16:08 - 2018-11-02 16:08 - 000000000 ____D C:\Program Files\Mullvad VPN
  182. 2018-11-02 16:07 - 2018-11-02 16:07 - 056126080 _____ (Mullvad VPN) C:\Users\twujstary\Desktop\MullvadVPN-2018.4.exe
  183. 2018-11-02 16:04 - 2018-11-02 16:05 - 008671032 _____ C:\Users\twujstary\Downloads\pidgin-2.13.0.exe
  184. 2018-11-02 15:19 - 2018-11-02 15:19 - 000111152 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
  185. 2018-11-02 15:07 - 2018-11-02 15:07 - 000001113 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
  186. 2018-11-02 14:17 - 2018-11-02 14:17 - 000063768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
  187. 2018-11-02 14:17 - 2018-11-02 14:17 - 000000000 ____D C:\Users\twujstary\AppData\Local\mbam
  188. 2018-11-02 14:16 - 2018-11-02 14:16 - 000260480 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
  189. 2018-11-02 14:16 - 2018-11-02 14:16 - 000198000 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
  190. 2018-11-02 14:16 - 2018-11-02 14:16 - 000119136 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
  191. 2018-11-02 14:16 - 2018-11-02 14:16 - 000001880 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
  192. 2018-11-02 14:16 - 2018-11-02 14:16 - 000000000 ____D C:\Users\twujstary\AppData\Local\mbamtray
  193. 2018-11-02 14:16 - 2018-11-02 14:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
  194. 2018-11-02 14:16 - 2018-11-02 14:16 - 000000000 ____D C:\ProgramData\Malwarebytes
  195. 2018-11-02 14:16 - 2018-10-18 09:44 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
  196. 2018-11-02 14:15 - 2018-11-02 14:16 - 078612224 _____ (Malwarebytes ) C:\Users\twujstary\Desktop\mb3-setup-consumer-3.6.1.2711-1.0.482-1.0.7607.exe
  197. 2018-11-02 14:01 - 2018-11-02 14:05 - 000000000 ____D C:\Windows\AppReadiness
  198. 2018-11-02 13:55 - 2018-11-02 13:55 - 000000000 _____ C:\Windows\SysWOW64\last.dump
  199. 2018-11-02 10:06 - 2018-11-02 10:06 - 000000000 ____D C:\Users\twujstary\Documents\Virtual Machines
  200. 2018-11-02 10:05 - 2018-11-02 10:07 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\VMware
  201. 2018-11-02 10:05 - 2018-11-02 10:07 - 000000000 ____D C:\Users\twujstary\AppData\Local\VMware
  202. 2018-11-02 10:04 - 2018-09-19 04:16 - 000374192 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
  203. 2018-11-02 10:04 - 2018-09-19 04:10 - 000099272 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
  204. 2018-11-02 10:04 - 2018-06-22 01:31 - 000092040 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
  205. 2018-11-02 10:04 - 2018-06-22 01:31 - 000046472 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
  206. 2018-11-02 10:04 - 2018-06-22 01:31 - 000042376 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
  207. 2018-11-02 10:03 - 2018-11-02 10:04 - 000000000 ____D C:\ProgramData\VMware
  208. 2018-11-02 10:03 - 2018-11-02 10:03 - 003231096 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
  209. 2018-11-02 10:03 - 2018-11-02 10:03 - 000001286 _____ C:\Users\Public\Desktop\VMware Workstation Pro.lnk
  210. 2018-11-02 10:03 - 2018-11-02 10:03 - 000001024 _____ C:\Windows\SysWOW64\%TMP%
  211. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\Users\Public\Documents\Shared Virtual Machines
  212. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
  213. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\Program Files\Common Files\VMware
  214. 2018-11-02 10:03 - 2018-11-02 10:03 - 000000000 ____D C:\Program Files (x86)\VMware
  215. 2018-11-02 10:03 - 2018-09-19 04:17 - 001266096 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
  216. 2018-11-02 10:03 - 2018-09-19 04:16 - 000396208 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
  217. 2018-11-02 10:03 - 2018-09-19 04:16 - 000134104 _____ (VMware, Inc.) C:\Windows\system32\vnetinst.dll
  218. 2018-11-02 10:03 - 2018-09-19 04:16 - 000043992 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
  219. 2018-11-02 10:03 - 2018-09-05 22:43 - 000084752 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
  220. 2018-11-02 09:59 - 2018-11-02 10:01 - 536606728 _____ (VMware, Inc.) C:\Users\twujstary\Desktop\VMware-workstation-full-15.0.0-10134415.exe
  221. 2018-11-02 09:35 - 2018-11-02 15:09 - 000000000 ____D C:\Users\twujstary\VirtualBox VMs
  222. 2018-11-02 09:35 - 2018-11-02 15:09 - 000000000 ____D C:\Users\twujstary\.VirtualBox
  223. 2018-11-02 09:34 - 2018-11-02 15:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
  224. 2018-11-02 09:34 - 2018-11-02 09:34 - 000000000 ____D C:\Program Files\Oracle
  225. 2018-11-02 09:34 - 2018-10-15 11:27 - 000168824 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
  226. 2018-11-02 09:34 - 2018-10-15 11:26 - 000984512 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
  227. 2018-11-02 09:31 - 2018-11-02 09:31 - 114016768 _____ (Oracle Corporation) C:\Users\twujstary\Desktop\VirtualBox-5.2.20-125813-Win.exe
  228. 2018-11-02 08:49 - 2018-11-02 17:30 - 000000000 ____D C:\FRST
  229. 2018-11-02 08:49 - 2018-11-02 08:49 - 002414592 _____ (Farbar) C:\Users\twujstary\Desktop\FRST64.exe
  230. 2018-11-02 08:45 - 2018-11-02 08:46 - 048222451 _____ C:\Users\twujstary\Desktop\Desktop.rar
  231. 2018-11-02 08:41 - 2018-11-02 08:41 - 000000000 ___HD C:\$AV_AVG
  232. 2018-11-01 15:41 - 2018-11-01 16:17 - 000000000 ____D C:\Users\twujstary\Desktop\FON
  233. 2018-10-31 20:28 - 2018-10-31 20:28 - 000853504 _____ (WarGods.ro) C:\Users\twujstary\Desktop\WarGods Cheat Defender Win8.exe
  234. 2018-10-30 21:09 - 2018-10-30 21:09 - 002615821 _____ C:\Users\twujstary\Downloads\bhop_mann.rar
  235. 2018-10-29 19:57 - 2018-10-29 19:57 - 000001712 _____ C:\Users\Public\Desktop\FxSound Enhancer.lnk
  236. 2018-10-29 19:57 - 2018-10-29 19:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FxSound Enhancer
  237. 2018-10-29 19:56 - 2018-10-29 19:57 - 004121969 _____ C:\Users\twujstary\Downloads\FxSound Enhancer 13.008 Setup + Crack.rar
  238. 2018-10-27 20:55 - 2018-10-27 20:56 - 077976048 _____ (TeamSpeak Systems GmbH) C:\Users\twujstary\Desktop\TeamSpeak3-Client-win64-3.1.10.exe
  239. 2018-10-26 22:20 - 2018-10-26 22:49 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\HLSW
  240. 2018-10-26 22:20 - 2018-10-26 22:20 - 011613796 _____ (Stripf Software ) C:\Users\twujstary\Desktop\hlsw_1_4_0_2_setup.exe
  241. 2018-10-26 22:20 - 2018-10-26 22:20 - 000001024 _____ C:\Users\twujstary\Desktop\HLSW.lnk
  242. 2018-10-26 22:20 - 2018-10-26 22:20 - 000000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HLSW
  243. 2018-10-26 22:20 - 2018-10-26 22:20 - 000000000 ___SD C:\Program Files (x86)\HLSW
  244. 2018-10-26 19:46 - 2018-10-26 21:33 - 000000000 ____D C:\Users\twujstary\Documents\Assassin's Creed Syndicate
  245. 2018-10-25 21:48 - 2018-10-25 22:19 - 000000497 _____ C:\Users\twujstary\Desktop\Nowy AutoHotkey Script.ahk
  246. 2018-10-23 10:44 - 2018-10-23 10:44 - 001028696 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw9ac40e78d83f6162.tmp
  247. 2018-10-23 10:44 - 2018-10-23 10:44 - 000467760 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw938557e574038fbb.tmp
  248. 2018-10-23 10:44 - 2018-10-23 10:44 - 000380992 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\aswc11af9d71f927177.tmp
  249. 2018-10-23 10:44 - 2018-10-23 10:44 - 000346616 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\aswf53e384aec0d0bea.tmp
  250. 2018-10-23 10:44 - 2018-10-23 10:44 - 000230880 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw54646024c9abdb9b.tmp
  251. 2018-10-23 10:44 - 2018-10-23 10:44 - 000208488 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw36d092c8b78c1d0e.tmp
  252. 2018-10-23 10:44 - 2018-10-23 10:44 - 000202296 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw76a6b54488b37a2b.tmp
  253. 2018-10-23 10:44 - 2018-10-23 10:44 - 000201264 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\aswba4b1a3ec80a3664.tmp
  254. 2018-10-23 10:44 - 2018-10-23 10:44 - 000163224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\aswed06398c7bd8b75a.tmp
  255. 2018-10-23 10:44 - 2018-10-23 10:44 - 000111816 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw15254cc6333403bd.tmp
  256. 2018-10-23 10:44 - 2018-10-23 10:44 - 000087968 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw3a2472c05b9ce870.tmp
  257. 2018-10-23 10:44 - 2018-10-23 10:44 - 000059520 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\aswe7515b873e150931.tmp
  258. 2018-10-23 10:44 - 2018-10-23 10:44 - 000046920 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw45a6706bfaa41670.tmp
  259. 2018-10-23 10:44 - 2018-10-23 10:44 - 000042312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\asw 75aaa3342e2bd4b.tmp
  260. 2018-10-23 10:44 - 2018-09-29 16:48 - 000015344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\aswb16346bc71189269.tmp
  261. 2018-10-19 15:12 - 2018-10-19 15:12 - 000001038 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Przeglądarka Opera.lnk
  262. 2018-10-15 11:26 - 2018-10-15 11:26 - 000223000 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetLwf.sys
  263. 2018-10-15 11:26 - 2018-10-15 11:26 - 000213216 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp6.sys
  264. 2018-10-13 18:38 - 2018-10-13 18:38 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\obs-studio-node-server
  265. 2018-10-13 17:39 - 2018-10-13 17:39 - 001135289 _____ C:\Users\twujstary\Desktop\Nowy dokument tekstowy.txt
  266. 2018-10-13 17:38 - 2018-10-13 17:38 - 001135289 _____ C:\Users\twujstary\Desktop\Nowy dokument tekstowy.js
  267. 2018-10-12 11:17 - 2018-10-12 11:17 - 000005074 _____ C:\Users\twujstary\AppData\Local\recently-used.xbel
  268. 2018-10-10 20:14 - 2018-10-10 20:14 - 000855568 _____ C:\Users\twujstary\Documents\belmondo.xcf
  269. 2018-10-07 12:27 - 2018-10-07 12:27 - 000025092 _____ C:\Users\twujstary\Downloads\ATPP.v1.3.zip
  270. 2018-10-07 12:14 - 2018-10-07 12:14 - 000000000 ____D C:\Program Files (x86)\Auslogics
  271. 2018-10-07 12:13 - 2018-10-07 12:13 - 021221088 _____ (Auslo˜gics ) C:\Users\twujstary\Desktop\boost-speed-setup.exe
  272. 2018-10-07 12:02 - 2018-10-07 12:04 - 926056410 _____ C:\Users\twujstary\Desktop\rap.rar
  273. 2018-10-07 11:57 - 2018-10-07 11:58 - 930573556 _____ C:\Users\twujstary\Desktop\erape.rar
  274. 2018-10-07 11:52 - 2018-10-07 11:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskTrix
  275. 2018-10-07 11:52 - 2018-10-07 11:52 - 000000000 ____D C:\Program Files (x86)\DiskTrix
  276. 2018-10-07 11:51 - 2018-10-07 11:51 - 002547712 _____ C:\Users\twujstary\Desktop\UltimateDefragFREE(dobreprogramy.pl).exe
  277.  
  278. ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========
  279.  
  280. (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
  281.  
  282. 2018-11-02 16:34 - 2017-09-19 16:24 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\TS3Client
  283. 2018-11-02 16:19 - 2017-09-19 16:36 - 000000000 ____D C:\Users\twujstary\AppData\LocalLow\Mozilla
  284. 2018-11-02 16:13 - 2017-10-03 15:13 - 000000000 ____D C:\Users\twujstary\AppData\Local\CrashDumps
  285. 2018-11-02 16:08 - 2017-10-05 18:03 - 000000000 ____D C:\Program Files (x86)\Mullvad
  286. 2018-11-02 15:09 - 2017-03-18 22:01 - 000000000 ____D C:\Windows\INF
  287. 2018-11-02 14:13 - 2017-10-08 10:38 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\TrueCrypt
  288. 2018-11-02 14:08 - 2018-05-12 12:12 - 000000000 ____D C:\ProgramData\VMProtect Software
  289. 2018-11-02 14:08 - 2018-02-18 14:32 - 000000000 ____D C:\Program Files (x86)\WoM2
  290. 2018-11-02 14:08 - 2017-09-19 17:02 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
  291. 2018-11-02 14:07 - 2018-08-22 09:11 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VB Audio
  292. 2018-11-02 14:07 - 2018-08-22 09:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VB Audio
  293. 2018-11-02 14:07 - 2018-08-22 09:11 - 000000000 ____D C:\Program Files\VB
  294. 2018-11-02 14:07 - 2018-05-11 13:38 - 000000000 ____D C:\Users\twujstary\AppData\Local\TP-Link
  295. 2018-11-02 14:07 - 2018-04-27 19:06 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Visual Studio Setup
  296. 2018-11-02 14:07 - 2018-04-11 12:34 - 000000000 ____D C:\ProgramData\Hi-Rez Studios
  297. 2018-11-02 14:07 - 2017-09-21 14:22 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
  298. 2018-11-02 14:06 - 2018-05-11 13:39 - 000000000 ____D C:\ProgramData\TP-Link
  299. 2018-11-02 14:06 - 2018-02-14 13:16 - 000000000 ____D C:\Program Files\rempl
  300. 2018-11-02 14:06 - 2017-10-17 19:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
  301. 2018-11-02 14:05 - 2018-09-22 19:13 - 000000000 ____D C:\Program Files (x86)\Symulator Jazdy 2
  302. 2018-11-02 14:05 - 2018-05-28 15:37 - 000000000 ____D C:\Program Files\Sandboxie
  303. 2018-11-02 14:05 - 2017-09-23 03:57 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\TeamViewer
  304. 2018-11-02 14:05 - 2017-03-23 03:28 - 000000000 ____D C:\Users\twujstary\AppData\Local\Packages
  305. 2018-11-02 14:05 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
  306. 2018-11-02 14:04 - 2018-07-08 18:31 - 000000000 ____D C:\Users\twujstary\Documents\AutomaticSolution Software
  307. 2018-11-02 14:04 - 2017-09-30 13:06 - 000000000 ____D C:\Program Files\Rockstar Games
  308. 2018-11-02 14:04 - 2017-09-30 13:06 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
  309. 2018-11-02 14:02 - 2018-07-14 13:55 - 000000000 ____D C:\Program Files (x86)\MTA San Andreas 1.5
  310. 2018-11-02 14:02 - 2018-07-14 13:54 - 000000000 ____D C:\ProgramData\MTA San Andreas All
  311. 2018-11-02 14:02 - 2017-09-19 16:24 - 000000000 ____D C:\ProgramData\Package Cache
  312. 2018-11-02 14:01 - 2018-01-20 20:40 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\IrfanView
  313. 2018-11-02 14:00 - 2018-09-11 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
  314. 2018-11-02 13:59 - 2018-09-30 09:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garena
  315. 2018-11-02 13:59 - 2018-09-30 09:30 - 000000000 ____D C:\ProgramData\Garena
  316. 2018-11-02 13:59 - 2018-09-30 09:30 - 000000000 ____D C:\Program Files (x86)\Garena
  317. 2018-11-02 13:59 - 2018-09-11 13:27 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
  318. 2018-11-02 13:59 - 2017-11-28 16:16 - 000000000 ____D C:\Users\twujstary\AppData\Local\GG
  319. 2018-11-02 13:59 - 2017-10-22 15:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
  320. 2018-11-02 13:59 - 2017-09-22 18:31 - 000000000 ____D C:\Fraps
  321. 2018-11-02 13:58 - 2018-01-05 02:15 - 000000000 ____D C:\Program Files\Epic Games
  322. 2018-11-02 13:58 - 2017-11-02 13:27 - 000000000 ____D C:\ProgramData\Orbit
  323. 2018-11-02 13:58 - 2017-10-11 18:18 - 000000000 ____D C:\Users\twujstary\Documents\My Games
  324. 2018-11-02 13:57 - 2018-01-27 22:21 - 000000000 ____D C:\Program Files (x86)\Counter Strike 1.6 v23
  325. 2018-11-02 13:57 - 2017-11-09 16:19 - 000000000 ____D C:\Users\twujstary\AppData\Local\Dxtory Software
  326. 2018-11-02 13:56 - 2017-11-02 12:35 - 000000000 ____D C:\Program Files\CCleaner
  327. 2018-11-02 10:03 - 2017-03-20 04:58 - 001511068 _____ C:\Windows\system32\perfh015.dat
  328. 2018-11-02 10:03 - 2017-03-20 04:58 - 000370754 _____ C:\Windows\system32\perfc015.dat
  329. 2018-11-02 09:35 - 2017-03-23 03:27 - 000000000 ____D C:\Users\twujstary
  330. 2018-11-01 23:55 - 2017-09-19 16:12 - 000000000 ____D C:\ProgramData\NVIDIA
  331. 2018-11-01 14:23 - 2018-09-01 21:21 - 000000000 ___RD C:\Users\twujstary\Desktop\mixtape
  332. 2018-11-01 14:23 - 2018-07-11 14:36 - 000000000 ____D C:\Users\twujstary\Documents\REAPER Media
  333. 2018-11-01 13:40 - 2018-04-11 04:09 - 000000000 ___RD C:\Users\twujstary\Desktop\rapssyyy
  334. 2018-10-31 20:39 - 2018-04-01 12:34 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\slobs-client
  335. 2018-10-31 20:18 - 2018-04-01 12:33 - 000000000 ____D C:\Program Files\Streamlabs OBS
  336. 2018-10-31 20:18 - 2017-03-23 03:28 - 003204182 _____ C:\Windows\system32\PerfStringBackup.INI
  337. 2018-10-30 18:11 - 2018-05-04 17:50 - 000000000 ____D C:\Windows\System32\Tasks\Avast Software
  338. 2018-10-30 14:00 - 2018-08-07 12:24 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DFX for JRiver
  339. 2018-10-29 19:59 - 2018-08-07 12:24 - 000000000 ____D C:\Program Files (x86)\DFX
  340. 2018-10-28 14:00 - 2017-03-23 03:19 - 000000000 ____D C:\Windows\system32\SleepStudy
  341. 2018-10-27 20:57 - 2018-09-24 16:49 - 000000968 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
  342. 2018-10-27 20:57 - 2017-09-19 16:24 - 000000930 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
  343. 2018-10-27 16:07 - 2017-03-23 03:19 - 000000006 ____H C:\Windows\Tasks\SA.DAT
  344. 2018-10-23 10:44 - 2017-03-18 22:03 - 000000000 ___HD C:\Windows\ELAMBKUP
  345. 2018-10-19 15:12 - 2017-09-25 13:20 - 000000000 ____D C:\Program Files\Opera
  346. 2018-10-12 11:18 - 2017-09-26 14:26 - 000000000 ____D C:\Users\twujstary\.gimp-2.8
  347. 2018-10-12 11:17 - 2017-09-27 18:24 - 000000000 ____D C:\Users\twujstary\AppData\Local\gtk-2.0
  348. 2018-10-12 10:52 - 2017-09-19 16:35 - 000000000 ____D C:\Program Files\Mozilla Firefox
  349. 2018-10-12 10:52 - 2017-09-19 16:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
  350. 2018-10-10 13:29 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\SysWOW64\Macromed
  351. 2018-10-10 13:29 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\system32\Macromed
  352. 2018-10-09 13:17 - 2017-10-04 10:02 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Notepad++
  353. 2018-10-07 12:36 - 2018-02-24 15:39 - 000000000 ____D C:\Users\twujstary\AppData\Local\SquirrelTemp
  354. 2018-10-07 12:36 - 2017-10-17 19:47 - 000000000 ____D C:\Users\twujstary\AppData\Roaming\Sony
  355. 2018-10-07 12:36 - 2017-09-19 19:02 - 000000000 ____D C:\ProgramData\Norton
  356. 2018-10-07 12:36 - 2017-09-19 16:11 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
  357. 2018-10-07 12:36 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\LiveKernelReports
  358. 2018-10-07 12:30 - 2018-09-08 17:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed Rivals
  359. 2018-10-07 12:30 - 2018-03-31 20:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
  360. 2018-10-07 12:30 - 2018-02-09 16:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forza Horizon 3
  361. 2018-10-07 12:30 - 2017-10-21 08:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Watch_Dogs 2
  362. 2018-10-07 12:30 - 2017-10-18 12:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed Unity
  363. 2018-10-07 12:30 - 2017-10-01 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed IV Black Flag
  364. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 __RSD C:\Windows\Media
  365. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\Registration
  366. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\IME
  367. 2018-10-07 12:21 - 2017-03-18 22:03 - 000000000 ____D C:\Windows\Help
  368. 2018-10-07 10:33 - 2018-09-22 16:06 - 000000000 ___RD C:\Users\twujstary\Creative Cloud Files
  369. 2018-10-07 10:33 - 2017-10-11 17:50 - 000000000 ____D C:\Users\twujstary\AppData\Local\Adobe
  370. 2018-10-03 08:11 - 2018-07-21 14:49 - 000000000 ____D C:\Users\twujstary\AppData\Local\BattlEye
  371.  
  372. ==================== Pliki w katalogu głównym wybranych folderów =======
  373.  
  374. 2017-12-16 19:28 - 2015-02-15 15:03 - 000421888 _____ () C:\Program Files\lame_enc.dll
  375. 2017-03-18 21:59 - 2017-03-18 21:59 - 000174592 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\LeruiekwBgIiD.exe
  376. 2018-02-03 02:36 - 2018-02-03 02:36 - 000000054 _____ () C:\Users\twujstary\AppData\Roaming\updater.cfg
  377. 2018-08-22 09:26 - 2018-08-22 09:55 - 000004617 _____ () C:\Users\twujstary\AppData\Roaming\VoiceMeeterDefault.xml
  378. 2017-10-05 20:58 - 2018-02-25 15:29 - 000000600 _____ () C:\Users\twujstary\AppData\Roaming\winscp.rnd
  379. 2018-03-29 21:14 - 2018-03-29 21:14 - 000000037 ___SH () C:\Users\twujstary\AppData\Local\20986331705021ca58edc424.96250074
  380. 2018-08-12 16:00 - 2018-08-12 16:00 - 000172923 _____ () C:\Users\twujstary\AppData\Local\3AC4.tmp
  381. 2018-08-12 16:11 - 2018-08-12 16:11 - 000123332 _____ () C:\Users\twujstary\AppData\Local\4A98.tmp
  382. 2018-08-12 16:26 - 2018-08-12 16:26 - 000177678 _____ () C:\Users\twujstary\AppData\Local\74ED.tmp
  383. 2018-09-28 10:41 - 2018-09-28 10:41 - 000000000 _____ () C:\Users\twujstary\AppData\Local\oobelibMkey.log
  384. 2017-10-05 20:28 - 2018-03-29 14:24 - 000000600 _____ () C:\Users\twujstary\AppData\Local\PUTTY.RND
  385. 2018-10-12 11:17 - 2018-10-12 11:17 - 000005074 _____ () C:\Users\twujstary\AppData\Local\recently-used.xbel
  386. 2017-09-20 09:23 - 2018-03-16 14:40 - 000007606 _____ () C:\Users\twujstary\AppData\Local\Resmon.ResmonCfg
  387. 2017-12-28 03:45 - 2017-12-28 03:45 - 000000000 _____ () C:\Users\twujstary\AppData\Local\zenmap.exe.log
  388.  
  389. Niektóre pliki w TEMP:
  390. ====================
  391. 2018-11-02 14:01 - 2018-01-20 20:40 - 000141280 _____ (Irfan Skiljan, IrfanView) C:\Users\twujstary\AppData\Local\Temp\iv_uninstall.exe
  392.  
  393. ==================== Bamital & volsnap ======================
  394.  
  395. (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)
  396.  
  397. C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
  398. C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
  399. C:\Windows\explorer.exe => Plik podpisany cyfrowo
  400. C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
  401. C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
  402. C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
  403. C:\Windows\system32\services.exe => Plik podpisany cyfrowo
  404. C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
  405. C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
  406. C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
  407. C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
  408. C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
  409. C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
  410. C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo
  411. C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo
  412.  
  413. LastRegBack: 2018-10-30 09:18
  414.  
  415. ==================== Koniec FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement