REKLAMA

FRST.txt

PC stacjonarny - Zawirusowany komputer, proszę o sprawdzenie logów FRST

Komputer przeskanowany został MBAM, oraz AdwCleaner'em, nie można przywrócic komputera do wcześniejszego stanu, oraz wyskakuje okno setup.exe informujące o braku jakiegoś pliku. Bardzo proszę o sprawdzenie logów FRST


Pobierz plik - link do postu

Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja: 28-09-2016
Uruchomiony przez admin (administrator) PATRYK (30-09-2016 09:15:15)
Uruchomiony z C:\Documents and Settings\admin\Pulpit
Załadowane profile: admin (Dostępne profile: admin)
Platform: Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) Język: Polski
Internet Explorer Wersja 8 (Domyślna przeglądarka: FF)
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
() C:\Program Files\AnyDesk\AnyDesk.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Internet Manager\W800_DT_PL\BackgroundService\ServiceManager.exe
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
(HP) C:\WINDOWS\system32\HPSIsvc.exe
(Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
() C:\Documents and Settings\All Users\Dane aplikacji\HandSetService\HuaweiHiSuiteService.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(HP) C:\WINDOWS\system32\HPZipm12.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\27_ssconn\conn\ss_conn_service.exe
() C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
() C:\Program Files\EaseUS\Todo Backup\bin\TodoBackupService.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
() C:\Program Files\Hostless Modem\USB device MF63\CheckNDISPort_df.exe
() C:\Program Files\Hostless Modem\USB device MF63\CancelAutoPlay_df.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files\Internet Manager\W800_DT_PL\BackgroundService\ModemListener.exe
(Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe
(Microsoft Corporation) C:\PROGRA~1\MI3AA1~1\rapimgr.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
Brak dostępu do procesu - & gt; explorer.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe


==================== Rejestr (filtrowane) ====================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\...\Run: [RTHDCPL] = & gt; C:\WINDOWS\RTHDCPL.EXE [16859136 2008-03-26] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] = & gt; C:\WINDOWS\ALCMTR.EXE [69632 2016-01-23] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NvCplDaemon] = & gt; C:\WINDOWS\system32\NvCpl.dll [15517984 2013-03-22] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] = & gt; C:\WINDOWS\system32\NvMcTray.dll [108832 2013-03-22] (NVIDIA Corporation)
HKLM\...\Run: [CheckNDISPortF0acE3] = & gt; C:\Program Files\Hostless Modem\USB device MF63\CheckNDISPort_df.exe [459008 2013-08-28] ()
HKLM\...\Run: [CancelAutoPlay_df] = & gt; C:\Program Files\Hostless Modem\USB device MF63\CancelAutoPlay_df.exe [446208 2013-08-28] ()
HKLM\...\Run: [iTunesHelper] = & gt; C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-12] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] = & gt; C:\Program Files\QuickTime\qttask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [DT_PL Kingfisher ModemListener] = & gt; C:\Program Files\Internet Manager\W800_DT_PL\BackgroundService\ModemListener.exe [159056 2014-05-16] ()
HKLM\...\Run: [Systemmonitor] = & gt; C:\Program Files\Common Files\windows monitor\ogtxcdlve.exe [0 ] ()
Winlogon\Notify\Antiwpa: C:\WINDOWS\system32\antiwpa.dll [2008-06-19] ()
Winlogon\Notify\gemsafe: C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll [2006-11-16] (Gemplus)
Winlogon\Notify\RailNotification:
Winlogon\Notify\WgaLogon: WgaLogon.dll [X]
HKU\S-1-5-19\...\Run: [KB976002-v5] = & gt; C:\WINDOWS\system32\advpack.dll [128512 2014-04-19] (Microsoft Corporation)
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\Run: [H/PC Connection Agent] = & gt; C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation)
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\Run: [BlueStacks Agent] = & gt; C:\Program Files\Bluestacks\HD-Agent.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\Run: [DAEMON Tools Lite Automount] = & gt; C:\Program Files\DAEMON Tools Lite\DTAgent.exe [3576664 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\Run: [] = & gt; [X]
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\Run: [Systemmonitor] = & gt; C:\Program Files\Common Files\windows monitor\ogtxcdlve.exe [0 ] ()
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\Run: [Wondershare Helper Compact.exe] = & gt; " C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelperSetup.exe "
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: G - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {0ecfe7bc-2665-11e6-a0e7-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {2d95fc40-7e57-11e6-a167-00183701f62a} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {2e9017fd-1103-11e5-a48a-806d6172696f} - E:\setup.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {37269da2-1757-11e6-a0cf-00183701f62a} - G:\Startme.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {3b2343a4-52d7-11e5-9e9e-00183701f62a} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {3b2343a6-52d7-11e5-9e9e-00183701f62a} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {3b2343ab-52d7-11e5-9e9e-022e4004757c} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {729ffc74-1f24-11e6-a0dc-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {780d6202-4802-11e6-a125-00183701f62a} - G:\autorun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {8351e49c-3d08-11e6-a111-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {91403521-2fa1-11e5-9e7b-00183701f62a} - G:\setup.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {9140352b-2fa1-11e5-9e7b-00183701f62a} - F:\sources\SetupError.exe x64
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {9512d3c3-0af2-11e6-85db-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {b59018fa-7f30-11e6-a168-00183701f62a} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {b5a8ffd1-c020-11e5-a09c-00183701f62a} - H:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {bdc1665e-7cb3-11e6-a166-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {beb2aa6f-7052-11e6-a15b-00183701f62a} - G:\autorun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {cc6fbf13-20c1-11e6-a0dd-00183701f62a} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {cc6fbf17-20c1-11e6-a0dd-00183701f62a} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {cc6fbf45-20c1-11e6-a0dd-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {d33798a3-40e0-11e5-9e89-00183701f62a} - F:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {d33798a5-40e0-11e5-9e89-00183701f62a} - F:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {d33798a7-40e0-11e5-9e89-00183701f62a} - F:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {dba76074-4f13-11e6-a130-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {dba7607c-4f13-11e6-a130-00183701f62a} - G:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {f8abe171-34f6-11e5-9e7e-00183701f62a} - H:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\MountPoints2: {f8abe177-34f6-11e5-9e7e-00183701f62a} - F:\AutoRun.exe
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\Control Panel\Desktop\\SCRNSAVE.EXE - & gt; none
HKU\S-1-5-18\...\Run: [KB976002-v5] = & gt; C:\WINDOWS\system32\advpack.dll [128512 2014-04-19] (Microsoft Corporation)
IFEO\rstrui.exe: [Debugger] cpcn.exe
SecurityProviders: msapsspc.dll, schannel.dll, msnsspc.dll, digest.dll
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2014-04-19] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] - & gt; {472083B0-C522-11CF-8763-00608CC02F24} = & gt; Brak pliku
Startup: C:\Documents and Settings\admin\Menu Start\Programy\Autostart\TeamViewer 11.lnk [2016-04-06]
ShortcutTarget: TeamViewer 11.lnk - & gt; C:\Program Files\TeamViewer\TeamViewer.exe (Brak pliku)
Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\EPSON Status Monitor 3 Environment Check.lnk [2016-06-03]
ShortcutTarget: EPSON Status Monitor 3 Environment Check.lnk - & gt; C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE (SEIKO EPSON CORPORATION)
AlternateShell:

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{05CC1F3D-665B-4197-AEC1-95872F628DA9}: [DhcpNameServer] 192.168.1.1 0.0.0.0

Internet Explorer:
==================
HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yandex.ru/?win=212 & clid=2100767-002
SearchScopes: HKU\S-1-5-21-1614895754-2049760794-1801674531-1005 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/search/?win=212 & clid=2100768-002 & text={searchTerms}
SearchScopes: HKU\S-1-5-21-1614895754-2049760794-1801674531-1005 - & gt; {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/search/?win=212 & clid=2100768-002 & text={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-04-07] (Oracle Corporation)
BHO: Office Document Cache Handler - & gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} - & gt; C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO: Free Download Manager - & gt; {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - & gt; C:\Program Files\Free Download Manager\iefdm2.dll [2015-05-14] (FreeDownloadManager.ORG)
BHO: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-07] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1614895754-2049760794-1801674531-1005 - & gt; Brak nazwy - {093F479D-712E-46CD-9E06-62E734A05F68} - Brak pliku
DPF: {FD3BEB0C-AB43-4253-9146-C371D48FBE0D} hxxp://xmeye.net/cloud/video/web.cab

FireFox:
========
FF ProfilePath: C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\eqve2xyd.default
FF SelectedSearchEngine: Яндекс
FF Homepage: hxxp://google.pl/
FF Plugin: @adobe.com/FlashPlayer - & gt; C:\WINDOWS\system32\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-14] ()
FF Plugin: @Apple.com/iTunes,version=1.0 - & gt; C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin: @DVR/npmedia,version=3.1.0.5 - & gt; C:\Program Files\webrec\WEB30\DVR32\3.1.0.5\npmedia.dll [2014-08-18] ()
FF Plugin: @DVR/npTimeGrid,version=3.1.0.5 - & gt; C:\Program Files\webrec\WEB30\DVR32\3.1.0.5\npTimeGrid.dll [2014-08-18] (Unauthorized copy)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - & gt; C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - & gt; C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp - & gt; C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf - & gt; C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=11.77.2 - & gt; C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.77.2 - & gt; C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-07] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-04-19] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - & gt; C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - & gt; C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - & gt; C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin - & gt; C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2014-11-19] ( )
FF Plugin: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin: JFGuide - & gt; C:\Program Files\NetSurveillance\CMS\npGuide.dll [2015-03-11] ()
FF Plugin: JFWeb - & gt; C:\Program Files\NetSurveillance\CMS\npWebPlugin.dll [2015-03-11] ()
FF SearchPlugin: C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\eqve2xyd.default\searchplugins\yandex.ru-151505.xml [2016-01-20]
FF Extension: (Adblock Plus) - C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\eqve2xyd.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-29]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-06-12] [Brak podpisu cyfrowego]
FF HKLM\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Brak podpisu cyfrowego]
FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_Z\Bin\addon = & gt; nie znaleziono
FF HKU\S-1-5-21-1614895754-2049760794-1801674531-1005\...\Firefox\Extensions: [fdm_ffext@freedownloadmanager.org] - C:\Documents and Settings\All Users\Dane aplikacji\Free Download Manager\Firefox\Extensions\2.0.19
FF Extension: (Free Download Manager extension) - C:\Documents and Settings\All Users\Dane aplikacji\Free Download Manager\Firefox\Extensions\2.0.19 [2016-01-12]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-09-09]

Chrome:
=======
CHR HomePage: Default - & gt; hxxp://www.google.com/
CHR StartupUrls: Default - & gt; " hxxp://google.pl/ "
CHR Profile: C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default [2016-09-28]
CHR Extension: (Prezentacje Google) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-23]
CHR Extension: (Free Download Manager Chrome extension) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2016-07-15]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-23]
CHR Extension: (Dysk Google) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-23]
CHR Extension: (YouTube) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-23]
CHR Extension: (Tampermonkey) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2016-09-26]
CHR Extension: (Arkusze Google) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-23]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-10]
CHR Extension: (AdBlock) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-09-26]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-23]
CHR Extension: (Gmail) - C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-23]
CHR HKLM\...\Chrome\Extension: [ahmpjcflkgiildlgicmcieglgoilbfdp] - hxxps://clients2.google.com/service/update2/crx

==================== Usługi (filtrowane) ====================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 6to4; C:\WINDOWS\System32\6to4svc.dll [100864 2014-04-19] (Microsoft Corporation)
R2 AnyDesk; C:\Program Files\AnyDesk\AnyDesk.exe [1456288 2016-04-18] ()
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1034584 2015-06-18] (Disc Soft Ltd)
R2 DT_PL Kingfisher Modem Device Helper; C:\Program Files\Internet Manager\W800_DT_PL\BackgroundService\ServiceManager.exe [58192 2013-06-18] ()
R2 EaseUS Agent; C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe [36904 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd)
R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-06-27] (Nero AG)
R2 HuaweiHiSuiteService.exe; C:\Documents and Settings\All Users\Dane aplikacji\HandSetService\HuaweiHiSuiteService.exe [154928 2016-02-16] ()
S2 KMService; C:\WINDOWS\system32\srvany.exe [8192 2015-08-21] () [Brak podpisu cyfrowego]
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [Brak podpisu cyfrowego]
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [69632 2006-03-03] (HP) [Brak podpisu cyfrowego]
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155520 2015-06-10] (Avanquest Software)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)

===================== Sterowniki (filtrowane) ======================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

S3 AndnetBus; C:\WINDOWS\System32\DRIVERS\lgandnetbus.sys [24576 2015-05-12] (LG Electronics Inc.)
S3 AndNetDiag; C:\WINDOWS\System32\DRIVERS\lgandnetdiag.sys [25088 2015-05-12] (LG Electronics Inc.)
S3 ANDNetModem; C:\WINDOWS\System32\DRIVERS\lgandnetmodem.sys [30208 2015-05-12] (LG Electronics Inc.)
S3 androidusb; C:\WINDOWS\System32\Drivers\wsadb.sys [34216 2016-09-29] (Google Inc)
S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R3 dtlitescsibus; C:\WINDOWS\System32\DRIVERS\dtlitescsibus.sys [25016 2015-07-29] (Disc Soft Ltd)
S1 DumpDrv; C:\WINDOWS\system32\Drivers\DumpDrv.sys [9472 2014-04-19] (Microsoft Corporation)
R3 Egatebus; C:\WINDOWS\System32\drivers\egatebus.sys [15328 2006-05-19] (Axalto)
S3 Egatecard; C:\WINDOWS\System32\Drivers\egate.sys [18880 2006-05-19] (Axalto)
R3 Egaterdr; C:\WINDOWS\System32\drivers\egaterdr.sys [13440 2006-05-19] (Axalto)
R0 EUBAKUP; C:\WINDOWS\System32\drivers\eubakup.sys [52008 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd)
R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [40744 2015-12-10] ()
R1 EUDSKACS; C:\WINDOWS\system32\drivers\eudskacs.sys [14888 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd)
R1 EUFDDISK; C:\WINDOWS\system32\drivers\EuFdDisk.sys [188840 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\DRIVERS\ew_usbccgpfilter.sys [15360 2016-02-16] (Huawei Technologies Co., Ltd.)
S3 FTDIBUS; C:\WINDOWS\System32\drivers\ftdibus.sys [62216 2012-04-13] (FTDI Ltd.)
S3 ggsomc; C:\WINDOWS\System32\DRIVERS\ggsomc.sys [26328 2015-07-13] (Sony Mobile Communications)
S3 GTwinUSB; C:\WINDOWS\System32\Drivers\GTwinUSB.sys [61840 2004-06-28] (Gemplus)
S3 HP1210FAX; C:\WINDOWS\System32\Drivers\HPM1210FAX.sys [13824 2011-04-15] () [Brak podpisu cyfrowego]
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2005-10-22] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2005-10-22] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2006-04-13] (HP)
S3 massfilter; C:\WINDOWS\System32\drivers\massfilter.sys [9216 2011-08-10] (MBB Incorporated) [Brak podpisu cyfrowego]
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2015-10-12] (Riverbed Technology, Inc.)
R0 nvatabus; C:\WINDOWS\System32\DRIVERS\nvatabus.sys [105472 2007-05-14] (NVIDIA Corporation) [Brak podpisu cyfrowego]
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [145952 2008-11-12] (NVIDIA Corporation)
S3 Rockusb; C:\WINDOWS\System32\DRIVERS\rockusb.sys [46160 2013-07-11] (Fuzhou Rockchip Electronics Co,Ltd.)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R3 Serial; C:\WINDOWS\System32\DRIVERS\nuvserial.sys [76288 2014-01-12] (Nuvoton Technology Corp.)
R1 Tcpip6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [226880 2014-04-19] (Microsoft Corporation)
S3 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation)
S3 ZTEusbmdm6k; C:\WINDOWS\System32\DRIVERS\ZTEusbmdm6k.sys [107648 2011-08-10] (ZTE Incorporated) [Brak podpisu cyfrowego]
S3 ZTEusbnmea; C:\WINDOWS\System32\DRIVERS\ZTEusbnmea.sys [107648 2011-08-10] (ZTE Incorporated) [Brak podpisu cyfrowego]
S3 ZTEusbser6k; C:\WINDOWS\System32\DRIVERS\ZTEusbser6k.sys [107648 2011-08-10] (ZTE Incorporated) [Brak podpisu cyfrowego]
S3 zte_cdc_acm; C:\WINDOWS\System32\DRIVERS\zte_cdc_acm.sys [67968 2011-08-10] (ZTE) [Brak podpisu cyfrowego]
S3 zte_cpo; C:\WINDOWS\System32\DRIVERS\zte_cpo.sys [9984 2011-08-10] (ZTE) [Brak podpisu cyfrowego]
U0 aswVmm; Brak ImagePath
U2 CertPropSvc; Brak ImagePath
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 filtertdidriver; system32\drivers\ewfiltertdidriver.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 hwusb_cdcacm; system32\DRIVERS\ew_cdcacm.sys [X]
S3 hwusb_cdcecm; system32\DRIVERS\ew_cdcecm.sys [X]
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2016-02-16] (Huawei Technologies Co., Ltd.)
S4 IntelIde; Brak ImagePath
U5 phunter; C:\WINDOWS\system32\unikey.sys [13816 2016-07-21] ()
U5 Sdbus; C:\Windows\System32\Drivers\Sdbus.sys [80384 2014-04-19] (Microsoft Corporation)
S3 USBCCID; system32\DRIVERS\usbccid.sys [X]
U1 WS2IFSL; Brak ImagePath

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-09-30 09:15 - 2016-09-30 09:15 - 00025584 _____ C:\Documents and Settings\admin\Pulpit\FRST.txt
2016-09-30 09:14 - 2016-09-30 09:15 - 00000000 ____D C:\FRST
2016-09-30 09:13 - 2016-09-30 09:13 - 01754624 _____ (Farbar) C:\Documents and Settings\admin\Pulpit\FRST.exe
2016-09-29 14:42 - 2016-09-29 14:42 - 00034216 _____ (Google Inc) C:\WINDOWS\system32\Drivers\wsadb.sys
2016-09-29 14:42 - 2016-09-29 14:42 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_wsadb_01007.Wdf
2016-09-29 14:40 - 2016-09-29 14:40 - 00000000 ____D C:\Program Files\Common Files\Wondershare
2016-09-29 14:40 - 2016-09-29 14:40 - 00000000 ____D C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Wondershare
2016-09-29 14:39 - 2016-09-29 14:40 - 00000000 ____D C:\Documents and Settings\admin\Dane aplikacji\Wondershare
2016-09-29 14:39 - 2016-09-29 14:39 - 00001828 _____ C:\Documents and Settings\All Users\Pulpit\Wondershare Dr.Fone for Android.lnk
2016-09-29 14:39 - 2016-09-29 14:39 - 00000000 ___HD C:\Program Files\DrFoneAndroid_Temp
2016-09-29 14:39 - 2016-09-29 14:39 - 00000000 ____D C:\Program Files\Wondershare
2016-09-29 14:39 - 2016-09-29 14:39 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Wondershare
2016-09-29 14:39 - 2016-09-29 14:39 - 00000000 ____D C:\Documents and Settings\admin\Pulpit\ss
2016-09-28 15:42 - 2016-07-22 13:48 - 06500888 _____ (Geek Uninstaller) C:\Documents and Settings\admin\Pulpit\geek.exe
2016-09-28 15:34 - 2016-09-28 15:34 - 04216840 _____ (Microsoft Corporation) C:\Documents and Settings\admin\Pulpit\vcredist_x86.exe
2016-09-28 15:22 - 2016-09-28 15:22 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Windows Genuine Advantage
2016-09-28 15:22 - 2016-09-28 15:22 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Office Genuine Advantage
2016-09-28 15:21 - 2016-09-28 15:21 - 00000000 ____D C:\Documents and Settings\admin\Pulpit\Legalizacja XP [n21]
2016-09-28 15:21 - 2008-06-19 20:53 - 00060416 _____ C:\WINDOWS\system32\antiwpa.dll
2016-09-28 15:20 - 2016-09-28 15:20 - 00521348 _____ C:\Documents and Settings\admin\Pulpit\Legalizacja XP [n21].rar
2016-09-28 12:41 - 2016-09-28 15:57 - 00000000 ____D C:\Documents and Settings\admin\Dane aplikacji\Geek Uninstaller
2016-09-28 12:38 - 2016-09-28 12:38 - 00000000 ____D C:\Documents and Settings\All Users\Kaspersky Lab Setup Files
2016-09-27 16:52 - 2016-09-27 16:52 - 00000973 _____ C:\Documents and Settings\All Users\Pulpit\Konwerter Wideo Apowersoft.lnk
2016-09-27 16:52 - 2016-09-27 16:52 - 00000000 ____D C:\Program Files\Apowersoft
2016-09-27 16:52 - 2016-09-27 16:52 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Apowersoft
2016-09-27 16:52 - 2016-09-27 16:52 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Apowersoft
2016-09-27 16:52 - 2016-09-27 16:52 - 00000000 ____D C:\Documents and Settings\admin\Moje dokumenty\Apowersoft
2016-09-27 16:52 - 2016-09-27 16:52 - 00000000 ____D C:\Documents and Settings\admin\Dane aplikacji\Apowersoft
2016-09-27 16:52 - 2015-10-12 12:05 - 00282360 _____ (Riverbed Technology, Inc.) C:\WINDOWS\system32\wpcap.dll
2016-09-27 16:52 - 2015-10-12 12:05 - 00102136 _____ (Riverbed Technology, Inc.) C:\WINDOWS\system32\Packet.dll
2016-09-27 16:52 - 2015-10-12 12:05 - 00053299 _____ C:\WINDOWS\system32\pthreadVC.dll
2016-09-27 16:52 - 2015-10-12 12:05 - 00036600 _____ (Riverbed Technology, Inc.) C:\WINDOWS\system32\Drivers\npf.sys
2016-09-27 15:55 - 2016-09-28 16:58 - 00065536 _____ C:\WINDOWS\system32\config\Kaspersk.evt
2016-09-27 15:44 - 2016-09-27 15:46 - 00000000 ___HD C:\kleaner.tmp
2016-09-27 09:25 - 2016-09-27 09:25 - 00000000 ____D C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\CEF
2016-09-26 13:08 - 2016-09-26 13:08 - 00921280 _____ (Microsoft Corporation) C:\WINDOWS\ucrtbase.dll
2016-09-26 11:24 - 2016-09-26 11:23 - 00090112 _____ C:\WINDOWS\Minidump\Mini092616-01.dmp
2016-09-24 09:38 - 2016-09-29 10:13 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-09-22 16:57 - 2016-09-22 16:57 - 00052736 _____ C:\Documents and Settings\admin\Pulpit\LISTA OBECNOSCI APS PL.xls
2016-09-21 09:02 - 2016-09-21 07:57 - 00000139 _____ C:\Documents and Settings\admin\Pulpit\Przypisania danych i odwołania- skoroszyt, arkusz, obszar, komórka - CONT-EVO - Wizualizacja i analiza danych na mapie w Excel, aplikacje, szkolenia.url
2016-09-19 13:33 - 2016-09-19 13:33 - 00000000 ____D C:\Documents and Settings\admin\Moje dokumenty\Pobrane AssecoWAPRO
2016-09-19 13:26 - 2016-09-21 16:22 - 00000000 ____D C:\Documents and Settings\admin\Pulpit\wfmag 8_00
2016-09-19 09:40 - 2016-09-19 09:40 - 14496125 _____ C:\Documents and Settings\admin\Pulpit\Archiwum_WAPRO_20160919_0940.zip
2016-09-14 14:11 - 2016-09-14 14:12 - 00008724 _____ C:\WINDOWS\ModemLog_ZTE Mobile Connect Modem Device.txt
2016-09-14 09:46 - 2016-09-14 10:46 - 06502080 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2016-09-01 16:46 - 2016-09-01 16:46 - 00000000 ____D C:\Program Files\Web Connection

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-09-30 09:15 - 2015-06-12 13:52 - 00000000 ____D C:\Documents and Settings\admin\Ustawienia lokalne\Temp
2016-09-30 09:15 - 2015-06-12 13:52 - 00000000 ____D C:\Documents and Settings\admin\Pulpit
2016-09-30 09:01 - 2016-08-16 09:19 - 00000000 ____D C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\HTC MediaHub
2016-09-30 09:00 - 2016-07-16 11:38 - 00000266 _____ C:\WINDOWS\Tasks\AutoKMS.job
2016-09-30 09:00 - 2016-05-23 10:38 - 00001032 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-30 09:00 - 2015-06-15 10:30 - 00000316 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-09-30 09:00 - 2015-06-12 13:53 - 00000222 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job
2016-09-30 09:00 - 2015-06-12 13:50 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-30 09:00 - 2008-04-15 13:00 - 00002300 _____ C:\WINDOWS\system32\wpa.dbl
2016-09-29 17:00 - 2015-06-12 13:52 - 00000188 ___SH C:\Documents and Settings\admin\ntuser.ini
2016-09-29 17:00 - 2015-06-12 13:50 - 00032536 _____ C:\WINDOWS\SchedLgU.Txt
2016-09-29 16:55 - 2016-05-23 10:38 - 00001036 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-29 16:46 - 2016-05-20 14:13 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-29 14:44 - 2015-06-12 15:03 - 00000000 ___HD C:\WINDOWS\inf
2016-09-29 14:42 - 2016-06-28 14:31 - 00080184 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudbus.sys
2016-09-29 14:42 - 2015-06-12 15:36 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups
2016-09-29 14:40 - 2015-06-12 13:52 - 00000000 ___HD C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji
2016-09-29 14:39 - 2015-06-12 15:12 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit
2016-09-29 14:39 - 2015-06-12 15:12 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy
2016-09-29 14:39 - 2015-06-12 13:52 - 00000000 __RHD C:\Documents and Settings\admin\Dane aplikacji
2016-09-29 11:45 - 2015-07-13 16:59 - 00000000 ____D C:\Program Files\Sony Mobile
2016-09-29 08:58 - 2015-06-12 15:09 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji
2016-09-28 16:58 - 2015-07-10 11:41 - 00065536 _____ C:\WINDOWS\system32\config\OAlerts.evt
2016-09-28 16:58 - 2015-06-24 17:01 - 03939535 _____ C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-1614895754-2049760794-1801674531-1005-0.dat
2016-09-28 16:58 - 2015-06-24 17:01 - 00290646 _____ C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat
2016-09-28 16:58 - 2015-06-12 13:52 - 00000000 ____D C:\Documents and Settings\admin
2016-09-28 15:22 - 2015-06-12 15:09 - 01328685 _____ C:\WINDOWS\setuplog.txt
2016-09-28 15:15 - 2016-05-24 15:18 - 00000393 _____ C:\Documents and Settings\admin\Pulpit\Skrót do volume(sda4) na Samba Server (192.168.1.1).lnk
2016-09-28 15:12 - 2016-07-16 11:38 - 00000000 ____D C:\WINDOWS\AutoKMS
2016-09-28 15:12 - 2015-06-12 15:03 - 00000000 ____D C:\WINDOWS\Help
2016-09-28 14:51 - 2015-06-12 13:52 - 00000000 ___RD C:\Documents and Settings\admin\Menu Start\Programy
2016-09-28 14:50 - 2016-04-12 10:27 - 00000000 ____D C:\Program Files\Windows Loader
2016-09-28 12:58 - 2016-04-06 20:22 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-09-28 12:40 - 2016-05-02 15:49 - 00000000 ____D C:\Documents and Settings\admin\Dane aplikacji\uTorrent
2016-09-28 12:38 - 2015-06-12 15:09 - 00000000 ____D C:\Documents and Settings\All Users
2016-09-28 12:09 - 2015-06-24 13:11 - 00002574 _____ C:\Documents and Settings\admin\Menu Start\µTorrent.lnk
2016-09-28 10:53 - 2016-04-06 21:09 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-09-27 16:52 - 2015-06-12 13:52 - 00000000 ___RD C:\Documents and Settings\admin\Moje dokumenty
2016-09-27 15:52 - 2015-06-12 15:09 - 00000000 ___HD C:\Documents and Settings\Default User
2016-09-27 15:48 - 2015-06-15 10:24 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software
2016-09-26 11:24 - 2015-08-24 16:46 - 00000000 ____D C:\WINDOWS\Minidump
2016-09-23 16:55 - 2016-04-07 20:51 - 00000000 ____D C:\Documents and Settings\admin\TMOP2BackUp_Z
2016-09-23 16:55 - 2015-06-12 15:12 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
2016-09-23 11:52 - 2015-06-12 13:53 - 00000000 ___RD C:\Documents and Settings\admin\Moje dokumenty\Moja muzyka
2016-09-22 16:48 - 2016-07-16 09:43 - 00000000 ____D C:\Documents and Settings\admin\Pulpit\wald
2016-09-21 16:16 - 2016-04-07 21:47 - 00000000 ____D C:\Documents and Settings\admin\Pulpit\telefony i modemy
2016-09-21 16:08 - 2016-07-14 13:34 - 00000000 ____D C:\Documents and Settings\admin\Pulpit\dok
2016-09-21 16:08 - 2016-05-02 15:50 - 00002574 _____ C:\Documents and Settings\admin\Pulpit\µTorrent.lnk
2016-09-21 15:18 - 2015-08-13 11:48 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\DatacardService
2016-09-21 11:30 - 2015-06-26 13:26 - 02521448 _____ C:\AutoMapaSetupLog.txt
2016-09-20 15:47 - 2016-06-02 12:47 - 00000000 ____D C:\Documents and Settings\admin\Moje dokumenty\Pliki programu Outlook
2016-09-19 13:20 - 2015-06-12 16:57 - 00000000 ____D C:\Documents and Settings\admin\Dane aplikacji\Free Download Manager
2016-09-16 12:57 - 2016-06-07 16:40 - 00000000 ____D C:\Documents and Settings\admin\.android
2016-09-16 12:57 - 2015-08-26 10:22 - 00000000 ____D C:\Program Files\DIFX
2016-09-14 14:21 - 2015-07-28 14:11 - 00003742 _____ C:\WINDOWS\ModemLog_ZTE Proprietary USB Modem #2.txt
2016-09-14 10:46 - 2015-06-12 13:40 - 00796352 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-09-14 10:46 - 2015-06-12 13:40 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-09-14 10:46 - 2015-06-12 13:40 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-09-08 15:00 - 2015-06-12 13:53 - 00000216 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job

==================== Pliki w katalogu głównym wybranych folderów =======

2015-07-28 10:58 - 2015-07-28 10:58 - 0002528 _____ () C:\Documents and Settings\admin\Dane aplikacji\$_hpcst$.hpc
2016-02-03 13:04 - 2016-08-25 14:21 - 0003584 _____ () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-04-07 20:34 - 2016-04-07 20:34 - 0000218 _____ () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\recently-used.xbel
2015-06-19 14:20 - 2015-06-19 14:20 - 0000057 _____ () C:\Documents and Settings\All Users\Dane aplikacji\Ament.ini
2016-02-11 15:58 - 2016-04-21 11:53 - 0009816 _____ () C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log

Pliki do przeniesienia lub usunięcia:
====================
C:\Documents and Settings\admin\Del1C5B.bat
C:\Documents and Settings\Default User\Del1C5B.bat


Niektóre pliki w TEMP:
====================
C:\Documents and Settings\admin\Ustawienia lokalne\Temp\DataCard_Setup.exe
C:\Documents and Settings\admin\Ustawienia lokalne\Temp\MiFiInstaller_0.exe
C:\Documents and Settings\admin\Ustawienia lokalne\Temp\NEventMessages.dll
C:\Documents and Settings\admin\Ustawienia lokalne\Temp\NOSEventMessages.dll
C:\Documents and Settings\admin\Ustawienia lokalne\Temp\removedirectory.exe
C:\Documents and Settings\admin\Ustawienia lokalne\Temp\ResetDevice.exe
C:\Documents and Settings\admin\Ustawienia lokalne\Temp\StopService.exe


==================== Bamital & volsnap ======================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\WINDOWS\explorer.exe = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\winlogon.exe = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\svchost.exe = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\services.exe = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\User32.dll = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\userinit.exe = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\rpcss.dll = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\dnsapi.dll = & gt; Plik podpisany cyfrowo
C:\WINDOWS\system32\Drivers\volsnap.sys = & gt; Plik podpisany cyfrowo

==================== Koniec FRST.txt ============================