FRST.txt

Re: Logi FRST - reklamy w przeglądarce

Pliki po zaproponowanych zmianach. Problem jest jednak z odinstalowaniem "AUDIO CONVERTER PACKAGES". Włącza się instalator i do kliknięcia jest tylko przycisk zamknij. Żadnych opcji modyfikacji czy usunięcia programu.


can result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-05-2015
Ran by JACEK (administrator) on JACEK-SZKODNIK on 13-05-2015 18:12:31
Running from C:\Users\JACEK\Downloads
Loaded Profiles: JACEK (Available profiles: JACEK & UpdatusUser)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Polski (Polska)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Windows\System32\srvany.exe
() C:\Windows\KMService.exe
() C:\Windows\System32\PnkBstrA.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
() C:\Program Files\Opera\29.0.1795.47\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files\Opera\29.0.1795.47\opera.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Opera Software) C:\Program Files\Opera\launcher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [HDAudDeck] = & gt; C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [1713152 2010-02-10] (VIA)
HKLM\...\Run: [GrooveMonitor] = & gt; C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] = & gt; C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-16] (AVAST Software)
HKLM\...\Run: [Adobe ARM] = & gt; C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [gmsd_pl_67] = & gt; [X]
HKU\S-1-5-21-3278197488-367952608-486825262-1000\...\Run: [CCleaner Monitoring] = & gt; C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd)
HKU\S-1-5-21-3278197488-367952608-486825262-1000\...\MountPoints2: {074a6019-9d7a-11e0-a5db-20cf30820159} - N:\Autorun.exe
HKU\S-1-5-21-3278197488-367952608-486825262-1000\...\MountPoints2: {657cdf03-1b54-11e0-ae2a-20cf30820159} - N:\SETUP.EXE
HKU\S-1-5-21-3278197488-367952608-486825262-1000\Control Panel\Desktop\\SCRNSAVE.EXE - & gt; C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] - & gt; {472083B0-C522-11CF-8763-00608CC02F24} = & gt; C:\Program Files\AVAST Software\Avast\ashShell.dll [2014-10-16] (AVAST Software)
ShellIconOverlayIdentifiers: [GGDriveOverlay1] - & gt; {E68D0A50-3C40-4712-B90D-DCFA93FF2534} = & gt; No File
ShellIconOverlayIdentifiers: [GGDriveOverlay2] - & gt; {E68D0A51-3C40-4712-B90D-DCFA93FF2534} = & gt; No File
ShellIconOverlayIdentifiers: [GGDriveOverlay3] - & gt; {E68D0A52-3C40-4712-B90D-DCFA93FF2534} = & gt; No File
ShellIconOverlayIdentifiers: [GGDriveOverlay4] - & gt; {E68D0A53-3C40-4712-B90D-DCFA93FF2534} = & gt; No File
GroupPolicy: Group Policy on Chrome detected & lt; ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction & lt; ======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150421
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-3278197488-367952608-486825262-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150421
URLSearchHook: HKU\S-1-5-21-3278197488-367952608-486825262-1000 - (No Name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
SearchScopes: HKU\.DEFAULT - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT - & gt; {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-19 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3278197488-367952608-486825262-1000 - & gt; {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.bing.com/search?FORM=UP97DF & PC=UP97 & q={searchTerms} & src=IE-SearchBox
BHO: ALLYouTubeDownloader - & gt; {61DB16C5-B733-43F4-872E-B20DC9E72740} - & gt; C:\Program Files\ALLYouTubeDownloader\ALLYouTubeDownloader.dll [2012-10-07] (ALLCinema Ltd.)
BHO: Groove GFS Browser Helper - & gt; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - & gt; C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-03] (Oracle Corporation)
BHO: avast! Online Security - & gt; {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - & gt; C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-10-16] (AVAST Software)
BHO: Windows Live ID Sign-in Helper - & gt; {9030D464-4C02-4ABF-8ECC-5164760863C6} - & gt; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-03] (Oracle Corporation)
BHO: IplexToALLPlayer - & gt; {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - & gt; C:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll [2011-02-09] (ALLCinema Ltd.)
Toolbar: HKU\S-1-5-21-3278197488-367952608-486825262-1000 - & gt; No Name - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Users\JACEK\AppData\Roaming\Mozilla\Firefox\Profiles\jdwmw2dq.default
FF SearchEngineOrder.3: Bing
FF Homepage: www.wp.pl/?src01=dp120150421
FF Plugin: @adobe.com/FlashPlayer - & gt; C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll [2015-02-01] ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - & gt; C:\Windows\system32\npDeployJava1.dll [2013-07-03] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - & gt; C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-07-03] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - & gt; disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - & gt; C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - & gt; C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll [2013-05-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll [2013-05-10] (Google Inc.)
FF Plugin: @vividas.com/npVividasPlayer - & gt; C:\Program Files\Vividas\Player\npVividasPlayer.dll [2011-09-16] ( )
FF Plugin: Adobe Reader - & gt; C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3278197488-367952608-486825262-1000: @spoon.net/Spoon Plugin 3.33 - & gt; C:\Users\JACEK\AppData\Local\Spoon\3.33.8.445\npMozillaSpoonPlugin.dll No File
FF Plugin HKU\S-1-5-21-3278197488-367952608-486825262-1000: @unity3d.com/UnityPlayer,version=1.0 - & gt; C:\Users\JACEK\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-01-10] (Unity Technologies ApS)
FF Extension: Battlefield Heroes Updater - C:\Users\JACEK\AppData\Roaming\Mozilla\Firefox\Profiles\jdwmw2dq.default\Extensions\battlefieldheroespatcher@ea.com [2013-01-01]
FF Extension: Iplex to ALLPlayer - C:\Users\JACEK\AppData\Roaming\Mozilla\Firefox\Profiles\jdwmw2dq.default\Extensions\IplextoALL@ALLPlayer.org [2012-11-15]
FF Extension: ALLYouTubeDownloader - C:\Users\JACEK\AppData\Roaming\Mozilla\Firefox\Profiles\jdwmw2dq.default\Extensions\YouTubetoALL@ALLPlayer.org [2013-04-11]
FF Extension: Firefox Old Version Update Hotfix - C:\Users\JACEK\AppData\Roaming\Mozilla\Firefox\Profiles\jdwmw2dq.default\Extensions\firefox-hotfix@mozilla.org.xpi [2014-12-19]
FF Extension: Iplex to ALLPlayer - C:\Users\JACEK\AppData\Roaming\Mozilla\Firefox\Profiles\jdwmw2dq.default\Extensions\IplextoALL@ALLPlayer.org.xpi [2012-11-15]
FF Extension: ALLYouTubeDownloader - C:\Users\JACEK\AppData\Roaming\Mozilla\Firefox\Profiles\jdwmw2dq.default\Extensions\YouTubetoALL@ALLPlayer.org.xpi [2012-11-15]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-08-05]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-26]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-29]
FF HKU\S-1-5-21-3278197488-367952608-486825262-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\JACEK\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\JACEK\AppData\Roaming\IDM\idmmzcc5 [2011-12-11]

Chrome:
=======
CHR Profile: C:\Users\JACEK\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-16]

Opera:
=======
OPR Extension: (AdBlock) - C:\Users\JACEK\AppData\Roaming\Opera Software\Opera Stable\Extensions\aobdicepooefnbaeokijohmhjlleamfj [2015-03-11]
OPR Extension: (Browser Good) - C:\Users\JACEK\AppData\Roaming\Opera Software\Opera Stable\Extensions\flkekicndppjgcnpmlficnpadhpenlho [2015-04-20]
OPR Extension: (Assist Point) - C:\Users\JACEK\AppData\Roaming\Opera Software\Opera Stable\Extensions\jgpoafklolhgippbaembaimabcodejbe [2015-05-01]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-16] (AVAST Software)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-08-10] ()
R2 HPSLPSVC; C:\Users\JACEK\AppData\Local\Temp\7zS4DB9\hpslpsvc32.dll [701288 2011-09-17] (Hewlett-Packard Co.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 KMService; C:\Windows\system32\srvany.exe [8192 2011-05-18] () [File not signed]
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-25] (Nero AG)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-08-10] ()
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2012-11-12] ()
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [11296 2009-08-04] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-10-16] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-10-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-10-16] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-10-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-10-16] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [71944 2014-10-16] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-10-16] ()
S3 HTCAND32; C:\Windows\System32\Drivers\ANDROIDUSB.sys [25088 2009-10-26] (HTC, Corporation) [File not signed]
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2011-12-04] () [File not signed]
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181432 2012-02-24] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1119232 2010-01-11] (VIA Technologies, Inc.)
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [165376 2009-09-23] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [55040 2009-09-23] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2009-09-23] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [294912 2009-09-23] (Microsoft Corporation)
U3 ahrva06u; C:\Windows\system32\Drivers\ahrva06u.sys [0 ] (Advanced Micro Devices) & lt; ==== ATTENTION (zero size file/folder)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-13 18:12 - 2015-05-13 18:13 - 00016263 _____ () C:\Users\JACEK\Downloads\FRST.txt
2015-05-13 18:11 - 2015-05-13 18:11 - 01141248 _____ (Farbar) C:\Users\JACEK\Downloads\FRST (1).exe
2015-05-13 18:00 - 2015-05-13 18:03 - 00000000 ____D () C:\AdwCleaner
2015-05-13 18:00 - 2015-05-13 18:00 - 02209792 _____ () C:\Users\JACEK\Downloads\adwcleaner_4.204.exe
2015-05-13 16:50 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 21:35 - 2015-04-20 04:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-12 21:35 - 2015-04-20 04:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-12 21:35 - 2015-04-20 04:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-12 21:35 - 2015-04-13 05:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-12 21:35 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-12 21:35 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-12 21:35 - 2015-03-04 06:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-12 21:35 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-12 21:35 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-12 21:34 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-12 21:32 - 2015-05-12 21:32 - 00027402 _____ () C:\Users\JACEK\Downloads\jacek.txt
2015-05-12 21:21 - 2015-05-13 18:12 - 00000000 ____D () C:\FRST
2015-05-12 21:20 - 2015-05-12 21:21 - 01141248 _____ (Farbar) C:\Users\JACEK\Downloads\FRST.exe
2015-05-10 22:39 - 2015-05-13 18:08 - 00004536 _____ () C:\Windows\setupact.log
2015-05-10 22:39 - 2015-05-13 18:04 - 00002582 _____ () C:\Windows\PFRO.log
2015-05-10 22:39 - 2015-05-10 22:39 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-10 21:18 - 2015-05-10 21:18 - 00000000 ____D () C:\$WINDOWS.~LS
2015-05-05 18:43 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-26 21:46 - 2015-04-26 21:46 - 37063360 _____ (Simply Super Software ) C:\Users\JACEK\Downloads\trjsetup692.exe
2015-04-26 21:44 - 2015-04-26 21:44 - 00741672 _____ (Web software ) C:\Users\JACEK\Downloads\Trojan-Remover(13140)-dp (1).exe
2015-04-26 21:38 - 2015-04-26 21:39 - 00741672 _____ (Web software ) C:\Users\JACEK\Downloads\Trojan-Remover(13140)-dp.exe
2015-04-21 21:29 - 2015-04-21 21:29 - 00000000 ____D () C:\Users\JACEK\Downloads\backups
2015-04-21 21:26 - 2015-04-21 21:26 - 00738232 _____ (Generic internet ) C:\Users\JACEK\Downloads\HijackThis(12030)-dp (1).exe
2015-04-21 21:24 - 2015-04-21 21:24 - 00388608 _____ (Trend Micro Inc.) C:\Users\JACEK\Downloads\HijackThis_2.0.4.exe
2015-04-21 21:23 - 2015-04-21 21:23 - 00738232 _____ (Generic internet ) C:\Users\JACEK\Downloads\HijackThis(12030)-dp.exe
2015-04-16 22:05 - 2015-04-16 22:06 - 07170552 _____ () C:\Users\JACEK\Downloads\HPPSdr.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-13 18:13 - 2011-01-08 19:57 - 01450119 _____ () C:\Windows\WindowsUpdate.log
2015-05-13 18:09 - 2009-07-14 06:34 - 00020704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-13 18:09 - 2009-07-14 06:34 - 00020704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-13 18:09 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-13 18:07 - 2011-01-08 20:09 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-13 18:07 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-13 18:07 - 2009-07-14 06:33 - 00431496 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 18:05 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-13 18:04 - 2011-12-04 00:37 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-13 16:49 - 2013-08-23 20:55 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-13 16:41 - 2011-01-08 13:35 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-13 16:36 - 2011-12-04 00:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-13 16:25 - 2014-11-08 13:43 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-10 21:50 - 2011-01-08 20:00 - 00000000 ____D () C:\Users\JACEK
2015-05-10 21:49 - 2015-04-07 23:28 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-10 21:49 - 2015-03-13 21:37 - 00000000 ____D () C:\Users\JACEK\Desktop\Nowy folder
2015-05-10 21:49 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-05-10 21:49 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-05-10 19:50 - 2013-04-14 18:01 - 00000000 ____D () C:\Users\JACEK\Desktop\audi
2015-05-10 19:10 - 2011-01-08 20:05 - 01699290 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-10 19:10 - 2009-07-14 10:07 - 00751614 _____ () C:\Windows\system32\perfh015.dat
2015-05-10 19:10 - 2009-07-14 10:07 - 00162162 _____ () C:\Windows\system32\perfc015.dat
2015-04-28 21:08 - 2011-11-29 18:11 - 00000000 ____D () C:\Program Files\Opera
2015-04-21 20:54 - 2009-07-14 04:04 - 00000580 _____ () C:\Windows\win.ini
2015-04-16 22:06 - 2011-06-13 17:21 - 00000000 ____D () C:\Program Files\HP

==================== Files in the root of some directories =======

2011-02-02 19:03 - 2012-11-12 22:05 - 0138904 _____ () C:\Users\JACEK\AppData\Roaming\PnkBstrK.sys
2011-05-24 20:24 - 2011-06-10 19:47 - 0001057 _____ () C:\Users\JACEK\AppData\Roaming\vso_ts_preview.xml
2011-06-11 17:40 - 2013-05-10 22:13 - 0004608 _____ () C:\Users\JACEK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-12 22:38 - 2015-03-12 22:38 - 0613255 _____ (CMI Limited) C:\Users\JACEK\AppData\Local\nsi733.tmp
2011-06-13 17:21 - 2011-06-13 17:33 - 0001143 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\JACEK\AppData\Local\Temp\Quarantine.exe
C:\Users\JACEK\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\system32\winlogon.exe = & gt; File is digitally signed
C:\Windows\system32\wininit.exe = & gt; File is digitally signed
C:\Windows\system32\svchost.exe = & gt; File is digitally signed
C:\Windows\system32\services.exe = & gt; File is digitally signed
C:\Windows\system32\User32.dll = & gt; File is digitally signed
C:\Windows\system32\userinit.exe = & gt; File is digitally signed
C:\Windows\system32\rpcss.dll = & gt; File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys = & gt; File is digitally signed


LastRegBack: 2015-05-04 19:35

==================== End Of Log ============================


Pobierz plik - link do postu
 Szukaj w ofercie
Zamknij 
Wyszukaj w ofercie 200 tys. produktów TME