REKLAMA

FRST.txt

Windows7 - Nie wczytują się strony na nowym koncie użytkownika

Logi w załączniku. Tylko uprzedzam, że nie będę na ślepo wykonywać żadnych skryptów, bo mam mocno spersonalizowany system i nie chciałabym, żeby mi pousuwał zmiany, które sama wprowadziłam np. w rejestrze. Muszę wiedzieć co i dlaczego usuwam Odnośnie masy dodatków do Firefoxa, to są dodatki zainstalowane głównie w Cyberfoxie, którego prawie nie używam, ale czasami potrzebuję i nie zamierzam ich usuwać :P Na najnowszym lisku mam ich bardzo mało. Problem natomiast występuje na świeżo zainstalowanych przeglądarkach, na nowym koncie użytkownika. Z tym, że Google Chrome już usunęłam, został tylko Vivaldi i Kinza. Nie wiem też, co robi tam ten Trend Micro Internet Security, bo miałam go dawno temu, a teraz przeszukałam dysk, rejestr oraz zaplanowane zadania i nigdzie nie znalazłam po nim żadnych plików. Nie mam pojęcia skąd FRST to wygrzebał :/ Zapora Comodo jest obecnie wyłączona, bo chwilowo używam wersji próbnej Malwarebytes Pro. Jest też druga zapora, którą kiedyś zainstalowałam i jakoś tak została, ale też jest wyłączona. Inne tego typu programy są używane wyłącznie do skanowania raz na jakiś czas i normalnie nie są uruchomione. Windows Update jest wyłączony celowo i tak ma pozostać :P


Pobierz plik - link do postu

Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 10.10.2018
Uruchomiony przez x (administrator) TOSHIBA (10-10-2018 21:52:13)
Uruchomiony z D:\Inne\FRST
Załadowane profile: x & Test (Dostępne profile: x & Test & Administrator & Gość & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Język: Polski (Polska)
Internet Explorer Wersja 11 (Domyślna przeglądarka: " C:\Program Files\Slimjet\slimjet.exe " -- " %1 " )
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(Duality Software) C:\Program Files\DS Clock\dsetime.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Duality Software) C:\Program Files\DS Clock\dsclock.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

==================== Rejestr (filtrowane) ===========================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\...\Run: [SynTPEnh] = & gt; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [NoDesktop] 0
HKLM\...\Policies\Explorer: [NoLogOff] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoSetTaskBar] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Run: [DS Clock] = & gt; C:\Program Files\DS Clock\DSClock.exe [1349960 2011-10-10] (Duality Software)
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Run: [DAEMON Tools Lite] = & gt; C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Run: [Vivaldi Update Notifier] = & gt; C:\Users\Test\AppData\Local\Vivaldi\Application\update_notifier.exe [1679432 2018-10-02] (Vivaldi Technologies AS)
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoCDBurning] 1
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [DisallowCpl] 1
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoLogOff] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoSetTaskBar] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-868905537-1386466793-4044497068-1006\...\Run: [Sidebar] = & gt; %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-868905537-1386466793-4044497068-1006\...\Run: [Vivaldi Update Notifier] = & gt; C:\Users\Test\AppData\Local\Vivaldi\Application\update_notifier.exe [1679432 2018-10-02] (Vivaldi Technologies AS)
HKU\S-1-5-18\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoStartMenuSubFolders] 0
Startup: C:\Users\x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KeNotify.lnk [2016-03-16]
ShortcutTarget: KeNotify.lnk - & gt; C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
Startup: C:\Users\x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainlendar.vbs [2018-06-21] ()
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia & lt; ==== UWAGA

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{9AA5ED54-C078-44DE-8A9F-1263BB7C2AFA}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{EECA5EBF-7748-4E61-8C22-4B8395972549}: [NameServer] 156.154.70.25,156.154.71.25

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-868905537-1386466793-4044497068-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
SearchScopes: HKLM - & gt; DefaultScope {C6073918-0D2D-451C-9E17-378B8AA6FB33} URL = hxxp://www.bing.com/search?q={searchTerms} & form=TSHMDF & pc=MATM & src=IE-SearchBox
SearchScopes: HKLM - & gt; {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - & gt; {C6073918-0D2D-451C-9E17-378B8AA6FB33} URL = hxxp://www.bing.com/search?q={searchTerms} & form=TSHMDF & pc=MATM & src=IE-SearchBox
SearchScopes: HKLM-x32 - & gt; DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKLM-x32 - & gt; {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - & gt; {ED4573EC-F7F5-4605-A14E-BD493EB68CF6} URL = hxxp://www.bing.com/search?q={searchTerms} & form=TSHMDF & pc=MATM & src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; DefaultScope {8104DE94-5A24-4911-9334-88389B9B1AB2} URL = hxxp://www.google.com/search?hl=pl & q={searchTerms}
SearchScopes: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; {0558F61F-229C-4530-9EF3-FF7AFB3F580E} URL =
SearchScopes: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; {8104DE94-5A24-4911-9334-88389B9B1AB2} URL = hxxp://www.google.com/search?hl=pl & q={searchTerms}
SearchScopes: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; {C6073918-0D2D-451C-9E17-378B8AA6FB33} URL =
SearchScopes: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; {CF70D0AC-80AF-4AF7-A008-F0BE06443B5B} URL = hxxp://www.bing.com/search?FORM=UP74DF & PC=UP74 & dt=022813 & q={searchTerms} & src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; {D7E7914F-76E4-4F5A-9658-3AFD6B4BAE72} URL = hxxp://megaslownik.pl/slownik.php?phrase={searchTerms} & lang=it
SearchScopes: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; {E14F7381-5DB9-4AD0-BCAD-8666ADF1990A} URL = hxxp://www.allegro.pl/search.php?sg=0 & string={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll [2018-01-28] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - & gt; {9030D464-4C02-4ABF-8ECC-5164760863C6} - & gt; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-28] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-01-28] (Oracle Corporation)
BHO-x32: Pomocnik logowania za pomocą identyfikatora Windows Live - & gt; {9030D464-4C02-4ABF-8ECC-5164760863C6} - & gt; C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-28] (Oracle Corporation)
IE Session Restore: HKU\S-1-5-21-868905537-1386466793-4044497068-1000 - & gt; [funkcja włączona]

FireFox:
========
FF DefaultProfile: i9xanolt.default-1525990595989
FF DefaultProfile: 5ry4ukwl.default
FF ProfilePath: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989 [2018-10-10]
FF Homepage: Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989 - & gt; about:home
FF NetworkProxy: Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989 - & gt; type " , 0
FF Session Restore: Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989 - & gt; [funkcja włączona]
FF Extension: (MuteLinks) - C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\Extensions\@mutelinks.xpi [2018-05-13]
FF Extension: (F.B Purity - Cleans up Facebook (WX)) - C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\Extensions\fbpElectroWebExt@fbpurity.com.xpi [2018-09-29]
FF Extension: (uBlock Origin) - C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\Extensions\uBlock0@raymondhill.net.xpi [2018-09-24]
FF Extension: (Page Translate) - C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\Extensions\{087ef4e1-4286-4be6-9aa3-8d6c420ee1db}.xpi [2018-10-07]
FF Extension: (Export Tabs URLs) - C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\Extensions\{17165bd9-9b71-4323-99a5-3d4ce49f3d75}.xpi [2018-07-12]
FF Extension: (Telemetry coverage) - C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\features\{978d6ca6-b933-4823-b71a-eef1c9361a0d}\telemetry-coverage-bug1487578@mozilla.org.xpi [2018-10-10] [Przestarzałe]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\searchplugins\bing-images.xml [2014-02-12]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\searchplugins\deviantart.xml [2012-07-26]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\searchplugins\filmweb.xml [2012-07-19]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\searchplugins\google-default.xml [2012-11-25]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\searchplugins\google-images.xml [2012-07-19]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\searchplugins\yandeximages.xml [2015-11-22]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\i9xanolt.default-1525990595989\searchplugins\zumipl.xml [2012-09-08]
FF ProfilePath: C:\Users\x\AppData\Roaming\Mozilla\Firefox\Profiles\161jxq5x.Test [2018-10-10]
FF ProfilePath: C:\Users\x\AppData\Roaming\Flickr\Flickr Uploadr\Profiles\qjnfvbc4.default [2017-06-23]
FF ProfilePath: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default [2018-10-10]
FF Homepage: Comodo\IceDragon\Profiles\5ry4ukwl.default - & gt; about:newtab
FF Session Restore: Comodo\IceDragon\Profiles\5ry4ukwl.default - & gt; [funkcja włączona]
FF Extension: (Comodo Online Security) - C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\Extensions\cos@comodo.com.xpi [2018-07-20]
FF Extension: (Https Enforcement) - C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\Extensions\https@comodo.com.xpi [2018-07-20]
FF Extension: (Polski Language Pack) - C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\Extensions\langpack-pl@firefox.mozilla.org.xpi [2018-10-04]
FF Extension: (Polski słownik poprawnej pisowni) - C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\Extensions\pl@dictionaries.addons.mozilla.org [2018-02-13] [Przestarzałe]
FF Extension: (uBlock Origin) - C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\Extensions\uBlock0@raymondhill.net.xpi [2018-09-30]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\searchplugins\bing-images.xml [2014-02-12]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\searchplugins\deviantart.xml [2012-07-26]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\searchplugins\filmweb.xml [2012-07-19]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\searchplugins\google-default.xml [2012-11-25]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\searchplugins\google-images.xml [2012-07-19]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\searchplugins\yandeximages.xml [2015-11-22]
FF SearchPlugin: C:\Users\x\AppData\Roaming\Comodo\IceDragon\Profiles\5ry4ukwl.default\searchplugins\zumipl.xml [2012-09-08]
FF ProfilePath: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx [2018-10-10]
FF Session Restore: 8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx - & gt; [funkcja włączona]
FF Extension: (MuteLinks) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\@mutelinks.xpi [2017-12-29] [Przestarzałe]
FF Extension: (Tiny url) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\@tinyurl.xpi [2017-10-19] [Przestarzałe]
FF Extension: (bug489729(Disable detach and tear off tab)) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\bug489729@alice0775 [2018-01-02] [Przestarzałe]
FF Extension: (Classic Theme Restorer) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2016-11-02] [Przestarzałe]
FF Extension: (Classic Toolbar Buttons) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2016-11-02] [Przestarzałe]
FF Extension: (DblClicker) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\dblclicker@byo.co.il.xpi [2017-12-29] [Przestarzałe]
FF Extension: (Facebook - No Ads in News Feed) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\facebook_no_ads_in_news_feed-0.0.8-an+fx-windows.xpi [2017-07-02]
FF Extension: (F.B Purity - Cleans up Facebook (WX)) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\fbpElectroWebExt@fbpurity.com.xpi [2018-02-22]
FF Extension: (FloatNotes) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\floatnotes@felix-kling.de.xpi [2016-05-22] [Przestarzałe]
FF Extension: (Gmail Watcher) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\gmailwatcher@sonthakit.xpi [2016-02-01] [Przestarzałe]
FF Extension: (Hide Caption Titlebar Plus ⁴) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\hidecaptionplus-dp@dummy.addons.mozilla.org.xpi [2017-12-29] [Przestarzałe]
FF Extension: (GlobalFindBar) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\jid0-GlobalFindBar@jetpack.xpi [2016-05-09] [Przestarzałe]
FF Extension: (Hide Unwanted Results of Google Search) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\jid0-TpZJ4wPImlT1zIqfw58bD9vOeWQ@jetpack.xpi [2016-01-03] [Przestarzałe]
FF Extension: (Google search link fix) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi [2018-01-13]
FF Extension: (Disable HTML5 Fullscreen Alert) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\jid1-Duz06d3mQhPItw@jetpack.xpi [2016-01-03] [Przestarzałe]
FF Extension: (Flash Control) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\jid1-sNL73VCI4UB0Fw@jetpack.xpi [2016-02-24] [Przestarzałe]
FF Extension: (Keybinder) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\keybinder@fail.cl.xpi [2017-05-15] [Przestarzałe]
FF Extension: (New Tab from Location Bar) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\newtabfromlocationbar@piro.sakura.ne.jp.xpi [2016-12-09] [Przestarzałe]
FF Extension: (Personas Plus) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\personas@christopher.beard.xpi [2017-10-16] [Przestarzałe]
FF Extension: (Polski słownik poprawnej pisowni) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\pl@dictionaries.addons.mozilla.org [2018-01-02] [Przestarzałe]
FF Extension: (S3.Google Translator) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\s3google@translator.xpi [2017-12-29] [Przestarzałe]
FF Extension: (Saved Password Editor) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\savedpasswordeditor@daniel.dawson.xpi [2017-12-29] [Przestarzałe]
FF Extension: (Bezpieczne logowanie) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\secureLogin@blueimp.net.xpi [2017-04-12] [Przestarzałe]
FF Extension: (Site Searcher) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\site-search@erlendorf.xpi [2017-12-29] [Przestarzałe]
FF Extension: (Thumbnail Zoom Plus) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\thumbnailZoom@dadler.github.com.xpi [2017-06-09] [Przestarzałe]
FF Extension: (uBlock Origin) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\uBlock0@raymondhill.net.xpi [2018-03-09]
FF Extension: (ZButton+: Undo Close Tab) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\undoCloseTab@zbutton.ru.xpi [2018-03-09]
FF Extension: (Vertical Toolbar) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\verticaltoolbar@xuldev.org.xpi [2017-12-29] [Przestarzałe]
FF Extension: (Screengrab (fix version)) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi [2017-10-08] [Przestarzałe]
FF Extension: (Flagfox) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2017-12-29] [Przestarzałe]
FF Extension: (Stylish) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2017-11-01] [Przestarzałe]
FF Extension: (PinImage) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{4c2ec070-b8d6-11e1-afa6-0800200c9a66}.xpi [2017-04-06] [Przestarzałe]
FF Extension: (ScrapBook) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}.xpi [2017-01-03] [Przestarzałe]
FF Extension: (Google Shortcuts) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2016-05-09] [Przestarzałe]
FF Extension: (Re-Pagination) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{6072cb90-a0bd-11da-a746-0800200c9a66}.xpi [2016-09-17] [Przestarzałe]
FF Extension: (YouTube High Definition) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2018-01-13]
FF Extension: (Session Exporter) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{943b5589-7808-4a70-acdc-7b6ee21e7cce}.xpi [2017-07-01] [Przestarzałe]
FF Extension: (View Image Resurrected) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{aad28606-44f7-4681-a654-684b78783f51}.xpi [2018-03-17]
FF Extension: (BBCodeXtra) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{af79f858-4b25-4ca4-822b-b5db1be628fc}.xpi [2016-12-09] [Przestarzałe]
FF Extension: (Flash and Video Download) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}.xpi [2018-03-09]
FF Extension: (Navigational Sounds) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{d84a846d-f7cb-4187-a408-b171020e8940}.xpi [2017-08-26] [Przestarzałe]
FF Extension: (User Agent Switcher) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2016-05-09] [Przestarzałe]
FF Extension: (Menu Editor) - C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\Extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi [2014-02-04] [Przestarzałe] [Brak podpisu cyfrowego]
FF Extension: (CyberCTR) - C:\Program Files\Cyberfox\browser\features\CTR@8pecxstudios.com.xpi [2017-12-08] [Przestarzałe] [Brak podpisu cyfrowego]
FF SearchPlugin: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\searchplugins\bing-images.xml [2014-02-12]
FF SearchPlugin: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\searchplugins\deviantart.xml [2012-07-26]
FF SearchPlugin: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\searchplugins\filmweb.xml [2012-07-19]
FF SearchPlugin: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\searchplugins\google-default.xml [2012-11-25]
FF SearchPlugin: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\searchplugins\google-images.xml [2012-07-19]
FF SearchPlugin: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\searchplugins\yandeximages.xml [2015-11-22]
FF SearchPlugin: C:\Users\x\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\rdsqc6wc.xxx\searchplugins\zumipl.xml [2012-09-08]
FF Plugin: @adobe.com/FlashPlayer - & gt; C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-09] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - & gt; C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2016-09-13] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.161.2 - & gt; C:\Program Files\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.161.2 - & gt; C:\Program Files\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-28] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.1 - & gt; C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - & gt; C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-09] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 - & gt; C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 - & gt; C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - & gt; C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL [2011-04-05] (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=15.0.2.72 - & gt; C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2012-04-03] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.448 - & gt; C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll [2009-10-09] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.2.72 - & gt; C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll [2012-04-03] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=15.0.2.72 - & gt; C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll [2012-04-03] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - & gt; C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2009-10-09] (RealNetworks, Inc.)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 - & gt; C:\Program Files (x86)\TabletPlugins\npwacom.dll [2011-04-20] (Wacom, Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.0.0.1 - & gt; C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-31] (Wacom)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 - & gt; C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-31] (Wacom)
FF Plugin-x32: wacom.com/WacomTabletPlugin - & gt; C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-31] (Wacom)
FF Plugin HKU\S-1-5-21-868905537-1386466793-4044497068-1000: wacom.com/WacomTabletPlugin - & gt; C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-31] (Wacom)
StartMenuInternet: Firefox-78E4F6AE264C139E - C:\Program Files\Mozilla Firefox 60\firefox.exe

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - & lt; Brak Path/update_url & gt;

==================== Usługi (filtrowane) ====================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

S3 ABBYY.Licensing.FineReader.ScreenshotReader.9.0; C:\Program Files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe [759048 2009-05-15] (ABBYY)
S4 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [Brak podpisu cyfrowego]
S4 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [11395096 2018-03-13] (COMODO)
S4 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2876096 2018-03-13] (COMODO)
R2 DSClockSyncTime; C:\Program Files\DS Clock\dsetime.exe [62264 2009-11-19] (Duality Software)
S3 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [39616 2016-06-03] (CHENGDU YIWO Tech Development Co., Ltd)
S4 firewallsvce; C:\Program Files\Evorim\Free Firewall\firewallsvc.exe [582000 2018-01-30] ()
S4 IceDragonUpdater; C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe [2648848 2018-08-06] (Comodo Inc.)
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation)
S4 ListaryService; C:\Program Files\Listary\ListaryService.exe [257776 2014-09-25] ()
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
S4 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2016-09-08] (CyberLink)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH)
S4 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [658600 2017-07-06] (WiseCleaner.com)

===================== Sterowniki (filtrowane) ======================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R3 CLMirrorDriver; C:\Windows\System32\DRIVERS\CLMirrorDriver.sys [21264 2018-02-07] (CyberLink)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [34280 2018-02-01] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [846624 2018-02-01] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [59096 2018-02-01] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-01-28] (Disc Soft Ltd)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [152184 2018-04-26] (Malwarebytes)
R0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [60968 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd) [Brak podpisu cyfrowego]
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [48168 2015-12-10] () [Brak podpisu cyfrowego]
R1 EUDSKACS; C:\Windows\system32\drivers\eudskacs.sys [18472 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd) [Brak podpisu cyfrowego]
R1 EUFDDISK; C:\Windows\system32\drivers\EuFdDisk.sys [192552 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd) [Brak podpisu cyfrowego]
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [123544 2018-02-01] (COMODO)
R1 isedrv; C:\Windows\system32\drivers\isedrv.sys [50856 2017-08-08] (COMODO)
R0 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [190696 2018-10-10] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [112864 2018-10-10] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [44768 2018-10-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-10-10] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [94328 2018-10-10] (Malwarebytes)
U5 nvtfg; C:\Windows\system32\drivers\nvtfg.sys [14456 2018-09-26] (NoVirusThanks Company Srl)
S3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation)
S3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation)
S3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation)
S3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2014-01-28] (Duplex Secure Ltd.)
R3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [33864 2017-10-26] (wisecleaner.com)
S3 WiseRegNotify; C:\Windows\WiseRegNotify.sys [51272 2018-01-22] (WiseCleaner.com)
U3 ash2gtom; C:\Windows\System32\Drivers\ash2gtom.sys [0 ] (Advanced Micro Devices) & lt; ==== UWAGA (zerobajtowy plik/folder)

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2018-10-10 19:26 - 2018-10-10 19:26 - 000002222 _____ C:\Users\Test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kinza.lnk
2018-10-10 19:26 - 2018-10-10 19:26 - 000002185 _____ C:\Users\Test\Desktop\Kinza.lnk
2018-10-10 19:26 - 2018-10-10 19:26 - 000000000 ____D C:\Users\x\AppData\Local\Kinza
2018-10-10 19:26 - 2018-10-10 19:26 - 000000000 ____D C:\Users\Test\AppData\Local\Kinza
2018-10-10 19:25 - 2018-10-10 19:26 - 050642928 _____ (Dayz株式会社) C:\Users\Test\Downloads\kinza_x64_4.9.1.exe
2018-10-10 17:20 - 2018-10-10 17:20 - 000010153 _____ C:\Users\x\AppData\Local\recently-used.xbel
2018-10-10 15:36 - 2018-10-10 15:36 - 000001428 _____ C:\Users\Test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-10-10 13:46 - 2018-10-10 13:46 - 000000000 _____ C:\Windows\system32\ipconfig
2018-10-10 13:35 - 2018-10-10 13:49 - 000005002 _____ C:\Users\Test\Desktop\ip.txt
2018-10-10 13:13 - 2018-10-10 13:46 - 000000079 _____ C:\Users\Test\Desktop\adres.txt
2018-10-10 12:54 - 2018-10-10 16:56 - 000044768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-10-10 12:53 - 2018-10-10 17:07 - 000094328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-10-10 12:53 - 2018-10-10 16:56 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-10-10 12:53 - 2018-10-10 16:56 - 000112864 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-10-10 12:53 - 2018-10-10 12:53 - 000190696 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-10-10 12:47 - 2018-10-10 12:47 - 000000000 ____D C:\Users\Test\AppData\Roaming\Adobe
2018-10-10 03:50 - 2018-10-10 03:50 - 052268888 _____ (Cerious Software Inc. ) C:\Users\x\Desktop\thmpls10sp1.exe
2018-10-10 03:35 - 2018-10-10 03:35 - 000380253 _____ C:\Users\x\Desktop\Broda-Script.zip
2018-10-10 03:35 - 2018-10-10 03:35 - 000158063 _____ C:\Users\x\Desktop\EmelyneScript.zip
2018-10-10 00:12 - 2018-10-10 00:12 - 000000000 ____D C:\Users\x\AppData\Local\Vivaldi
2018-10-10 00:02 - 2018-10-10 00:02 - 000002262 _____ C:\Users\Test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivaldi.lnk
2018-10-10 00:01 - 2018-10-10 00:02 - 000000000 ____D C:\Users\Test\AppData\Local\Vivaldi
2018-10-10 00:00 - 2018-10-10 00:01 - 054367816 _____ (Vivaldi Technologies AS) C:\Users\Test\Downloads\Vivaldi.2.0.1309.37.x64.exe
2018-10-09 23:58 - 2018-10-10 13:31 - 000000000 ____D C:\Users\Test\AppData\LocalLow\Comodo
2018-10-09 23:58 - 2018-10-09 23:58 - 000000000 ____D C:\Users\Test\AppData\Roaming\Comodo
2018-10-09 23:58 - 2018-10-09 23:58 - 000000000 ____D C:\Users\Test\AppData\Local\Comodo
2018-10-09 23:56 - 2018-10-09 23:56 - 000000119 _____ C:\Users\Test\Desktop\wiaraprzyrodzona.wordpress.com.url
2018-10-09 23:54 - 2018-10-09 23:55 - 000000000 ____D C:\Users\Test\AppData\Local\Google
2018-10-09 23:50 - 2018-10-10 19:26 - 000000000 ____D C:\Users\Test\AppData\LocalLow\Mozilla
2018-10-09 23:50 - 2018-10-10 19:23 - 000000000 ____D C:\Users\Test\AppData\Local\Mozilla
2018-10-09 23:50 - 2018-10-09 23:51 - 000000000 ____D C:\Users\Test\AppData\Roaming\Mozilla
2018-10-09 23:49 - 2018-10-09 23:49 - 000000020 ___SH C:\Users\Test\ntuser.ini
2018-10-09 23:49 - 2018-10-09 23:49 - 000000000 ____D C:\Users\Test\AppData\Local\VirtualStore
2018-10-09 23:49 - 2018-10-09 23:49 - 000000000 ____D C:\Users\Test
2018-10-09 23:49 - 2018-01-30 01:50 - 000001006 _____ C:\Users\Test\Desktop\Free Firewall.lnk
2018-10-09 23:49 - 2016-06-26 00:00 - 000000000 ____D C:\Users\Test\AppData\Roaming\Macromedia
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Ustawienia lokalne
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Szablony
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Moje dokumenty
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Menu Start
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Documents\Moje wideo
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Documents\Moje obrazy
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Documents\Moja muzyka
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\Dane aplikacji
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\AppData\Local\Historia
2018-10-09 23:49 - 2013-08-03 07:40 - 000000000 __SHD C:\Users\Test\AppData\Local\Dane aplikacji
2018-10-09 23:49 - 2009-07-14 20:09 - 000000000 ____D C:\Users\Test\AppData\Roaming\Media Center Programs
2018-10-09 00:48 - 2018-10-09 00:49 - 000993650 _____ C:\Users\x\Desktop\test.tif
2018-10-07 22:10 - 2018-10-07 22:11 - 030113178 _____ C:\Users\x\Desktop\Sokiliny-Floral-Set.zip
2018-10-07 09:30 - 2018-10-07 09:30 - 000000010 _____ C:\Users\x\Desktop\ociekacz.txt
2018-10-04 15:29 - 2018-10-04 15:36 - 317924677 _____ C:\Users\x\Desktop\Rustic-Watercolor-Set-Kate-Rina.zip
2018-09-27 02:08 - 2018-09-27 02:09 - 391689406 _____ C:\Users\x\Desktop\rejestr.reg
2018-09-26 22:33 - 2018-09-26 22:33 - 000014456 _____ (NoVirusThanks Company Srl) C:\Windows\system32\Drivers\nvtfg.sys
2018-09-26 17:44 - 2018-09-26 17:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-09-25 18:56 - 2018-09-25 18:57 - 000000000 ____D C:\Users\x\Desktop\PorterhausFamily
2018-09-24 00:38 - 2018-09-24 02:40 - 006574929 _____ C:\Users\x\Desktop\5bvD2ls.xcf
2018-09-18 11:09 - 2018-09-18 11:10 - 000000020 _____ C:\Users\x\Desktop\nr przesyłki.txt
2018-09-13 07:17 - 2018-09-13 07:17 - 000008406 _____ C:\Users\x\Desktop\ZróbSobieKrem.html
2018-09-11 02:34 - 2018-09-11 02:34 - 001511229 _____ C:\Users\x\Desktop\Joyful-Script-Get-Studio.zip

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2018-10-10 21:52 - 2018-03-09 08:21 - 000000000 ___RD C:\FRST
2018-10-10 21:49 - 2017-06-24 18:15 - 000000000 ____D C:\Windows\Panther
2018-10-10 21:48 - 2015-12-24 17:54 - 000000000 ____D C:\Users\x\AppData\Local\FileSearchy
2018-10-10 21:31 - 2014-05-30 23:41 - 000000000 ____D C:\Program Files (x86)\Google
2018-10-10 20:56 - 2017-08-11 21:29 - 000000000 ____D C:\Users\x\AppData\LocalLow\Mozilla
2018-10-10 20:11 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2018-10-10 17:43 - 2014-05-01 23:25 - 000000000 ___RD C:\Users\x\.gimp-2.8
2018-10-10 17:03 - 2009-07-14 06:45 - 000019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-10-10 17:03 - 2009-07-14 06:45 - 000019248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-10-10 16:58 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\inetsrv
2018-10-10 16:56 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-10-10 00:15 - 2011-06-09 05:14 - 000000000 ___RD C:\Users\x\.rainlendar2
2018-10-09 23:58 - 2014-05-30 23:41 - 000000000 ____D C:\Users\x\AppData\Local\Google
2018-10-09 02:10 - 2018-05-17 06:54 - 000000000 ____D C:\Users\x\AppData\Roaming\gmic
2018-10-08 06:46 - 2012-02-26 22:18 - 000000000 ____D C:\Windows\Minidump
2018-10-07 17:32 - 2018-01-09 15:15 - 000000000 ____D C:\Users\x\Inkscape autosave
2018-10-06 14:01 - 2018-04-05 13:39 - 000000000 ____D C:\Users\x\AppData\LocalLow\Comodo
2018-10-05 17:41 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-10-04 21:46 - 2018-05-17 02:25 - 000000000 ____D C:\Users\x\AppData\Local\babl-0.1
2018-10-04 16:59 - 2014-01-15 04:03 - 000000000 ____D C:\Users\x\AppData\Local\CrashDumps
2018-10-04 16:50 - 2018-05-11 00:00 - 000000000 ____D C:\Program Files\Mozilla Firefox 60
2018-10-01 06:19 - 2018-02-12 04:46 - 000000000 ____D C:\Windows\System32\Tasks\COMODO
2018-09-30 06:56 - 2018-02-13 11:18 - 000001141 _____ C:\Users\Public\Desktop\Comodo IceDragon.lnk
2018-09-27 02:22 - 2014-07-14 13:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bezpieczeństwo
2018-09-27 02:13 - 2009-07-14 19:55 - 000812644 _____ C:\Windows\system32\perfh015.dat
2018-09-27 02:13 - 2009-07-14 19:55 - 000186760 _____ C:\Windows\system32\perfc015.dat
2018-09-27 02:13 - 2009-07-14 07:13 - 001862664 _____ C:\Windows\system32\PerfStringBackup.INI
2018-09-26 18:41 - 2016-11-12 23:13 - 000000000 ___RD C:\EEK
2018-09-26 17:37 - 2011-01-27 15:09 - 000001912 _____ C:\Windows\epplauncher.mif
2018-09-26 05:04 - 2016-03-25 06:16 - 000000000 ____D C:\Users\x\AppData\Roaming\Wise Care 365
2018-09-26 04:38 - 2013-05-01 02:11 - 000000000 ____D C:\Users\x\AppData\Roaming\Notepad++
2018-09-24 02:10 - 2013-07-14 14:50 - 000000000 ____D C:\Users\x\AppData\Local\gtk-2.0

==================== Pliki w katalogu głównym wybranych folderów =======

2011-01-27 22:17 - 2007-01-17 20:21 - 000302592 _____ (ZbyloSoft) C:\Program Files\Cinema.exe
2014-03-14 22:25 - 2010-11-22 00:16 - 001123840 _____ (Karol Winnicki) C:\Program Files (x86)\BESTplayer.exe
2014-07-08 20:42 - 2012-11-06 11:22 - 000081920 _____ (Microsoft) C:\Program Files (x86)\Carapace.exe
2011-07-02 06:52 - 2008-04-13 15:42 - 000102912 _____ (Microsoft Corporation) C:\Program Files (x86)\clipbrd.exe
2014-10-18 10:45 - 2016-05-21 01:54 - 000000164 _____ () C:\Users\x\AppData\Roaming\.cmyktool_errorlog
2017-03-05 01:21 - 2017-03-05 01:22 - 000000031 _____ () C:\Users\x\AppData\Roaming\fd4_sys.d
2017-06-17 12:01 - 2017-06-25 02:25 - 000016303 _____ () C:\Users\x\AppData\Roaming\FlickrSync.Config.betmari.XML
2014-02-04 06:19 - 2018-05-18 13:24 - 000000312 _____ () C:\Users\x\AppData\Roaming\FotoSketcher.ini
2012-04-19 22:46 - 2012-04-19 22:48 - 000000553 _____ () C:\Users\x\AppData\Roaming\FreeDesktopClock.ini
2016-03-16 03:21 - 2016-03-16 03:21 - 000000010 _____ () C:\Users\x\AppData\Local\.C3F2FH85-G3D2-2F02-D5CH-7D3D8C553E56
2016-03-17 02:18 - 2016-05-29 10:45 - 000000010 _____ () C:\Users\x\AppData\Local\.DG212F11-EC8C-210D-DE1E-D9584D18D740
2016-01-05 00:10 - 2018-05-18 07:17 - 000001062 _____ () C:\Users\x\AppData\Local\43d15e80ee0ca18448ed415b876369ed
2016-10-17 03:13 - 2016-10-17 03:13 - 000000063 _____ () C:\Users\x\AppData\Local\emaildefaults
2018-01-28 15:27 - 2018-01-28 15:27 - 000000036 _____ () C:\Users\x\AppData\Local\housecall.guid.cache
2017-06-22 21:18 - 2017-06-22 21:18 - 000000412 _____ () C:\Users\x\AppData\Local\karboncalligraphyrc
2017-03-14 18:23 - 2017-03-14 18:25 - 000015043 _____ () C:\Users\x\AppData\Local\kritacrash.log
2018-02-10 09:21 - 2018-02-10 09:21 - 000000039 _____ () C:\Users\x\AppData\Local\kritadisplayrc
2016-10-17 03:12 - 2018-02-10 09:21 - 000027130 _____ () C:\Users\x\AppData\Local\kritarc
2018-10-10 17:20 - 2018-10-10 17:20 - 000010153 _____ () C:\Users\x\AppData\Local\recently-used.xbel
2011-09-03 19:43 - 2018-04-17 00:51 - 000007628 _____ () C:\Users\x\AppData\Local\Resmon.ResmonCfg
2017-11-05 10:27 - 2017-11-07 08:22 - 000000010 _____ () C:\Users\x\AppData\Local\sponge.last.runtime.cache

==================== Bamital & volsnap ======================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\system32\winlogon.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\wininit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\explorer.exe
[2011-04-27 09:04] - [2011-02-25 08:19] - 002388992 _____ (Microsoft Corporation) 71C68D11D223321EB7AD382C2FC3A2D6

C:\Windows\SysWOW64\explorer.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\services.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\User32.dll = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe = & gt; Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll = & gt; Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll = & gt; Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys = & gt; Plik podpisany cyfrowo

LastRegBack: 2018-10-05 20:35

==================== Koniec FRST.txt ============================