REKLAMA

FRST.txt

Jak odnaleźć źródło wyskakujących reklam w przeglądarce?

Jest FRST i Addition.


Pobierz plik - link do postu

Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 14.01.2018
Uruchomiony przez Bugajski (administrator) BUGAJSKI-KOMP (14-01-2018 18:11:06)
Uruchomiony z C:\Users\Bugajski\Desktop
Załadowane profile: Bugajski (Dostępne profile: Bugajski & Gość)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Język: Polski (Polska)
Internet Explorer Wersja 11 (Domyślna przeglądarka: Opera)
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Opera Software) C:\Program Files\Opera beta\51.0.2830.2\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Rejestr (filtrowane) ===========================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM-x32\...\Run: [SunJavaUpdateSched] = & gt; C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\Run: [CCleaner Monitoring] = & gt; C:\Program Files\CCleaner\CCleaner64.exe [8686296 2016-03-11] (Piriform Ltd)
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\MountPoints2: {4aba5a3e-6c35-11e6-8bea-fbc663278f48} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\MountPoints2: {5015efba-3aa0-11e6-bf09-bf779170fec2} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\MountPoints2: {5f76987e-a3e8-11e5-ad35-8832111d30c8} - F:\setup.exe
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\MountPoints2: {a8564f3d-17a6-11e7-8c8e-a98a4ef4e2ac} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-807507316-616474376-935463795-1000\...\MountPoints2: {ccaf15a3-e3b9-11e6-bdc3-d47f2fbc50a0} - F:\HiSuiteDownLoader.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-06-21]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk - & gt; C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

AutoConfigURL: [S-1-5-21-807507316-616474376-935463795-1000] = & gt; hxxp://web-quick-access.com/wpad.dat?adee6d82bfcd197b5e19cc1c2d12c4de36436174
Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{1D8AE2A3-079A-475E-A708-57CBA21B21FA}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{26DEC2FF-8DA5-4634-B434-DFB45B0E5644}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{35BC49A3-073B-412E-91B8-24954256E7C5}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{379F9595-E108-4083-AE50-5C371DB508FD}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{F04C7441-A1B9-4678-BB51-313748B0C671}: [DhcpNameServer] 192.168.2.1
ManualProxies: 0hxxp://web-quick-access.com/wpad.dat?adee6d82bfcd197b5e19cc1c2d12c4de36436174

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-807507316-616474376-935463795-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\S-1-5-21-807507316-616474376-935463795-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pl-pl/?ocid=iehp
BHO-x32: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-07-07] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-07] (Oracle Corporation)

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files\Microsoft Silverlight\5.1.40620.0\npctrl.dll [2015-06-20] ( Microsoft Corporation)
FF Plugin: @unity3d.com/UnityPlayer64,version=1.0 - & gt; C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin-x32: @adobe.com/ShockwavePlayer - & gt; C:\Windows\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 - & gt; C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 - & gt; C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-07] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files (x86)\Microsoft Silverlight\5.1.40620.0\npctrl.dll [2015-06-19] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - & gt; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - & gt; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-22] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-12-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-12-01] (Google Inc.)
FF Plugin HKU\S-1-5-21-807507316-616474376-935463795-1000: @unity3d.com/UnityPlayer,version=1.0 - & gt; C:\Users\Bugajski\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-807507316-616474376-935463795-1000: ubisoft.com/uplaypc - & gt; C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Brak pliku]

Chrome:
=======
CHR DefaultProfile: ChromeDefaultData2
CHR Profile: C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2 [2018-01-11] & lt; ==== UWAGA
CHR Extension: (Dokumenty) - C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-01]
CHR Extension: (Dysk Google) - C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-12-01]
CHR Extension: (YouTube) - C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-12-01]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-12-01]
CHR Extension: (Gmail) - C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-12-01]
CHR Extension: (Chrome Media Router) - C:\Users\Bugajski\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-01]

Opera:
=======
OPR StartupUrls:
OPR Session Restore: - & gt; [funkcja włączona]
OPR Extension: (uBlock Origin) - C:\Users\Bugajski\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2017-11-13]
StartMenuInternet: (HKLM) Operabeta - C:\Program Files\Opera beta\Launcher.exe

==================== Usługi (filtrowane) ====================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2017-12-23] ()
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1368408 2015-11-30] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-27] (EasyAntiCheat Ltd)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135488 2017-12-22] (SurfRight B.V.)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [Brak podpisu cyfrowego]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2015-07-18] (Microsoft Corporation)
S3 npggsvc; C:\Windows\system32\GameMon.des -service [X]
R2 NVDisplay.ContainerLocalSystem; " C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe " -s NVDisplay.ContainerLocalSystem -f " C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log " -l 3 -d " C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem "

===================== Sterowniki (filtrowane) ======================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

S3 cpuz144; C:\Windows\temp\cpuz144\cpuz144_x64.sys [48984 2017-12-05] (CPUID)
S3 CSRBC; C:\Windows\System32\Drivers\csrbc.sys [38400 2012-08-02] (CSR plc.)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-12-16] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [46392 2015-12-16] (Disc Soft Ltd)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [181304 2016-03-29] (Intel Corporation)
R3 netr28ux; C:\Windows\System32\DRIVERS\netr28ux.sys [2246488 2016-05-12] (MediaTek Inc.)
R3 Serenum; C:\Windows\System32\DRIVERS\nuvserenum.sys [23552 2014-01-12] (Windows (R) Win 7 DDK provider)
R3 Serial; C:\Windows\System32\DRIVERS\nuvserial.sys [86016 2014-01-12] (Nuvoton Technology Corp.)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2015-07-18] (Microsoft Corporation)
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB)

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2018-01-14 18:11 - 2018-01-14 18:11 - 000012703 _____ C:\Users\Bugajski\Desktop\FRST.txt
2018-01-14 18:10 - 2018-01-14 18:10 - 002393088 _____ (Farbar) C:\Users\Bugajski\Desktop\FRST64.exe
2018-01-14 14:33 - 2018-01-14 14:38 - 000000000 ____D C:\Users\Bugajski\AppData\Roaming\trainerv
2018-01-14 12:15 - 2018-01-14 12:15 - 001610112 _____ C:\Users\Bugajski\Desktop\a9aa87-trainerv.rar
2018-01-14 12:15 - 2018-01-14 12:15 - 000000000 ____D C:\Users\Bugajski\Desktop\a9aa87-trainerv
2018-01-13 19:32 - 2018-01-13 19:32 - 000019444 _____ C:\Users\Bugajski\Desktop\[torrenty.to] ESET Smart Security v10 1 219 1 (x86_x64) (KLUCZE TRIAL NA 300 DNI) _ Armaros - PL.torrent
2018-01-08 20:04 - 2018-01-08 20:04 - 000000000 ____D C:\Users\Bugajski\Desktop\BeamNG.drive.v0.11.24.2017
2018-01-08 18:41 - 2018-01-08 20:02 - 3334989669 _____ C:\Users\Bugajski\Desktop\BeamNG.drive.v0.11.24.2017.rar
2018-01-08 18:40 - 2018-01-08 18:40 - 000016518 _____ C:\Users\Bugajski\Desktop\BeamNG.drive.v0.11.24.2017.torrent
2018-01-07 13:15 - 2018-01-07 13:15 - 000993523 _____ C:\Users\Bugajski\Desktop\ScriptHookV_1.0.1290.1.zip
2018-01-05 09:42 - 2018-01-05 09:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grand Theft Auto San Andreas
2018-01-03 19:30 - 2018-01-03 19:30 - 000138281 _____ C:\Users\Bugajski\Desktop\[torrenty.to] Grand Theft Auto_ San Andreas _2005_ - V1 0 1 [1920x1080] [MULTi10-PL] [ISO] [ELAMIGOS] [SyMeTrYcZnY].torrent
2017-12-31 23:33 - 2017-12-31 23:33 - 000000000 ____D C:\Users\Bugajski\AppData\Local\UnrealEngineLauncher
2017-12-31 23:32 - 2017-12-31 23:32 - 000000000 ____D C:\Users\Bugajski\AppData\Local\EpicGamesLauncher
2017-12-27 14:07 - 2017-12-27 14:07 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2017-12-27 14:04 - 2018-01-13 13:26 - 000004154 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1514379859
2017-12-27 14:04 - 2017-12-27 14:04 - 000001297 _____ C:\Users\Bugajski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Przeglądarka Opera.lnk
2017-12-25 10:32 - 2015-11-19 15:07 - 000994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:07 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-12-25 10:32 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-12-23 13:18 - 2017-12-23 13:18 - 000000000 ____D C:\Users\Bugajski\AppData\Local\FortniteGame
2017-12-23 10:15 - 2017-12-27 17:30 - 000000000 ____D C:\Program Files\Epic Games
2017-12-23 09:55 - 2017-12-23 13:18 - 000000000 ____D C:\Users\Bugajski\AppData\Local\UnrealEngine
2017-12-23 09:54 - 2017-12-31 23:33 - 000000000 ____D C:\ProgramData\Epic
2017-12-23 09:54 - 2017-12-23 09:54 - 000001262 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2017-12-23 09:54 - 2017-12-23 09:54 - 000000000 ____D C:\Program Files (x86)\Epic Games
2017-12-22 20:26 - 2017-12-22 20:26 - 000011540 _____ C:\Windows\system32\.crusader
2017-12-22 20:18 - 2017-12-22 20:18 - 000001931 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2017-12-22 20:18 - 2017-12-22 20:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2017-12-22 20:18 - 2017-12-22 20:18 - 000000000 ____D C:\Program Files\HitmanPro
2017-12-20 14:08 - 2017-12-20 14:08 - 000001858 _____ C:\Users\Public\Desktop\YouTubeSongDownloader.lnk
2017-12-20 14:06 - 2017-12-20 14:06 - 068880720 _____ (Abelssoft ) C:\Users\Bugajski\Downloads\YouTube Song Downloader 2018 18.15.exe
2017-12-17 22:00 - 2018-01-13 18:03 - 000001352 _____ C:\Users\Bugajski\Desktop\Roblox Player.lnk
2017-12-17 21:50 - 2018-01-13 18:03 - 000001171 _____ C:\Users\Bugajski\Desktop\Roblox Studio.lnk
2017-12-17 21:50 - 2018-01-13 18:03 - 000000000 ____D C:\Users\Bugajski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2017-12-17 21:49 - 2017-12-17 21:49 - 000822328 _____ (Roblox Corporation) C:\Users\Bugajski\Desktop\RobloxPlayerLauncher.exe
2017-12-15 10:35 - 2017-12-15 10:35 - 000000000 ____D C:\Users\Bugajski\Desktop\bin

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2018-01-14 18:11 - 2017-02-12 19:27 - 000000000 ____D C:\FRST
2018-01-14 11:25 - 2009-07-14 05:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-14 11:25 - 2009-07-14 05:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-14 11:21 - 2017-02-19 22:14 - 000000000 ____D C:\AdwCleaner
2018-01-14 11:18 - 2015-12-10 21:03 - 000000000 ____D C:\ProgramData\NVIDIA
2018-01-14 11:18 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-13 19:45 - 2017-12-05 19:51 - 000000000 ____D C:\Users\Bugajski\AppData\Roaming\qBittorrent
2018-01-13 16:31 - 2016-03-01 09:25 - 000000000 ____D C:\Users\Bugajski\Documents\BeamNG.drive
2018-01-12 20:56 - 2017-02-10 21:56 - 000000000 ____D C:\Users\Bugajski\AppData\Local\CrashDumps
2018-01-11 20:13 - 2017-11-28 17:26 - 000000000 ____D C:\Program Files\Opera beta
2018-01-11 15:30 - 2017-11-28 17:28 - 000003896 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1511886489
2018-01-11 15:28 - 2016-02-01 13:36 - 000000000 ____D C:\Users\Bugajski\Desktop\muzyka
2018-01-09 14:08 - 2015-12-10 20:13 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-01-09 14:08 - 2015-12-10 20:13 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-09 14:08 - 2015-12-10 20:13 - 000004566 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-01-09 14:08 - 2015-12-10 20:13 - 000004412 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-01-09 14:08 - 2015-12-10 20:13 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-01-09 14:08 - 2015-12-10 20:13 - 000000000 ____D C:\Windows\system32\Macromed
2018-01-09 10:56 - 2011-04-12 14:21 - 000739694 _____ C:\Windows\system32\perfh015.dat
2018-01-09 10:56 - 2011-04-12 14:21 - 000155268 _____ C:\Windows\system32\perfc015.dat
2018-01-09 10:56 - 2009-07-14 06:13 - 001668226 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-09 10:56 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-01-08 20:08 - 2015-12-15 19:37 - 000000000 ____D C:\Users\Bugajski\AppData\Local\Microsoft Games
2018-01-08 19:41 - 2016-11-01 17:30 - 000000000 ____D C:\Users\Bugajski\Documents\TrackmaniaTurbo
2018-01-08 19:41 - 2016-11-01 17:30 - 000000000 ____D C:\ProgramData\TrackmaniaTurbo
2018-01-07 13:02 - 2016-11-13 19:35 - 000000000 ____D C:\Users\Bugajski\Documents\American Truck Simulator
2018-01-06 20:50 - 2015-12-12 19:53 - 000000000 ____D C:\Users\Bugajski\AppData\Roaming\.minecraft
2018-01-06 10:10 - 2017-12-01 18:37 - 000002161 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-02 14:16 - 2016-03-22 12:15 - 000000000 ____D C:\Users\Bugajski\Desktop\Gry
2017-12-28 18:28 - 2016-03-27 07:49 - 000007605 _____ C:\Users\Bugajski\AppData\Local\Resmon.ResmonCfg
2017-12-28 18:05 - 2017-05-05 21:18 - 000000000 ____D C:\ProgramData\AVAST Software
2017-12-27 17:29 - 2015-12-10 20:35 - 000000000 ____D C:\Users\Bugajski\AppData\Roaming\uTorrent
2017-12-27 16:04 - 2016-04-07 08:58 - 000000000 ____D C:\Users\Bugajski\AppData\Local\Ubisoft Game Launcher
2017-12-27 14:50 - 2017-12-01 18:33 - 000003480 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-12-27 14:50 - 2017-12-01 18:33 - 000003352 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-12-27 14:50 - 2017-11-28 17:24 - 000003898 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1511886245
2017-12-27 14:50 - 2017-07-27 17:21 - 000003966 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1501172471
2017-12-27 14:50 - 2017-05-02 17:56 - 000003166 _____ C:\Windows\System32\Tasks\{424BDD6D-4BBF-4E06-AAA9-6BD9E8A617E2}
2017-12-27 14:50 - 2017-04-28 10:39 - 000006008 _____ C:\Windows\System32\Tasks\Sataentstazodom Manager
2017-12-27 14:50 - 2016-03-27 07:25 - 000002806 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2017-12-27 14:00 - 2015-12-10 20:36 - 000000839 _____ C:\Users\Bugajski\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2017-12-25 10:37 - 2016-12-13 18:22 - 000000000 ____D C:\Users\Bugajski\Documents\SkidRow
2017-12-24 22:15 - 2016-02-03 15:39 - 000000000 ____D C:\ProgramData\Package Cache
2017-12-24 11:38 - 2009-07-14 06:08 - 000032604 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-12-23 20:08 - 2016-02-13 19:25 - 000000000 ____D C:\Users\Bugajski\Desktop\maksiiu
2017-12-23 09:51 - 2017-11-28 17:23 - 000000000 ____D C:\ProgramData\HitmanPro
2017-12-22 20:18 - 2016-08-19 09:20 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-12-22 20:16 - 2016-11-16 21:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KartingRace
2017-12-22 20:04 - 2017-08-28 20:21 - 000000000 ____D C:\Users\Bugajski\Documents\NFS Most Wanted Backups
2017-12-20 14:08 - 2017-11-20 19:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTubeSongDownloader
2017-12-20 14:08 - 2017-09-16 17:28 - 000000000 ____D C:\Users\Bugajski\Desktop\Różne
2017-12-18 17:23 - 2017-12-09 15:11 - 000000892 _____ C:\Users\Bugajski\Desktop\qBittorrent.lnk
2017-12-17 22:05 - 2016-08-11 08:58 - 000000000 ____D C:\Users\Bugajski\AppData\Local\Roblox
2017-12-17 22:00 - 2016-08-11 08:58 - 000000251 _____ C:\Users\Bugajski\AppData\LocalLow\rbxcsettings.rbx

==================== Pliki w katalogu głównym wybranych folderów =======

2017-10-02 17:56 - 2017-10-02 18:01 - 000000374 _____ () C:\Users\Bugajski\AppData\Roaming\burnaware.ini
2015-12-24 16:05 - 2015-12-24 16:05 - 000000044 _____ () C:\Users\Bugajski\AppData\Roaming\WB.CFG
2017-07-13 21:37 - 2017-07-13 21:37 - 000000000 ___SH () C:\Users\Bugajski\AppData\Local\LumaEmu
2016-10-09 10:22 - 2016-10-09 10:22 - 000000218 _____ () C:\Users\Bugajski\AppData\Local\recently-used.xbel
2016-03-27 07:49 - 2017-12-28 18:28 - 000007605 _____ () C:\Users\Bugajski\AppData\Local\Resmon.ResmonCfg

Niektóre pliki w TEMP:
====================
2006-05-14 19:20 - 2006-05-14 19:20 - 000729088 _____ (Electronic Arts Inc.) C:\Users\Bugajski\AppData\Local\Temp\AutoRun.exe
2017-08-28 20:13 - 2006-05-14 19:20 - 000765952 _____ (Electronic Arts Inc.) C:\Users\Bugajski\AppData\Local\Temp\AutoRunGUI.dll
2017-08-31 15:00 - 2016-10-18 09:18 - 000035968 _____ () C:\Users\Bugajski\AppData\Local\Temp\clearRemnants.exe
2017-04-27 19:01 - 2017-04-27 19:01 - 000000000 _____ () C:\Users\Bugajski\AppData\Local\Temp\EA Sports UFC 2 PC Downloader.exe
2017-07-07 19:57 - 2017-07-07 19:57 - 000739904 _____ (Oracle Corporation) C:\Users\Bugajski\AppData\Local\Temp\jre-8u131-windows-au.exe
2017-05-06 17:35 - 2017-02-03 13:56 - 000069257 _____ () C:\Users\Bugajski\AppData\Local\Temp\Uninstall.exe
2017-03-26 12:59 - 2014-03-21 15:00 - 000147460 _____ (n/a) C:\Users\Bugajski\AppData\Local\Temp\_Uninstall_0.exe

==================== Bamital & volsnap ======================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\system32\winlogon.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\wininit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\explorer.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\services.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\User32.dll = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys = & gt; Plik podpisany cyfrowo

LastRegBack: 2018-01-09 17:19

==================== Koniec FRST.txt ============================