Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 17.03.2019 Uruchomiony przez user (administrator) DESKTOP-OUON5L6 (21-03-2019 13:26:37) Uruchomiony z C:\Users\user\Desktop Załadowane profile: user (Dostępne profile: defaultuser0 & user & postgres) Platform: Windows 10 Pro Wersja 1803 17134.590 (X64) Język: Polski (Polska) Domyślna przeglądarka: "C:\Program Files\Slimjet\slimjet.exe" -- "%1" Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Bitsum LLC -> Bitsum LLC) C:\Program Files\Process Lasso\ProcessGovernor.exe (Bitsum LLC -> Bitsum LLC) C:\Program Files\Process Lasso\ProcessLasso.exe (AnVir Software -> AnVir Software) C:\Program Files (x86)\AnVir Task Manager Free\anvirlauncher.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Panda Security S.L -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe (Ivaylo Beltchev -> IvoSoft) [Brak podpisu cyfrowego] C:\Program Files\Classic Shell\ClassicStartMenu.exe (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E_YATISPE.EXE (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (AnVir Software -> AnVir Software) C:\Program Files (x86)\AnVir Task Manager Free\AnVir.exe (AnVir Software -> AnVir Software) C:\Program Files (x86)\AnVir Task Manager Free\anvir64.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [Brak podpisu cyfrowego] HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [153808 2018-12-19] (Panda Security S.L. -> Panda Security, S.L.) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATISPE.EXE [418000 2016-07-14] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKLM\...\Drivers32: [vidc.xvid] => C:\Windows\SysWOW64\xvidvfw.dll [246736 2017-06-22] (Cole Williams Software Limited -> ) HKLM\...\Drivers32: [vidc.x264] => C:\Windows\SysWOW64\x264vfw.dll [3850240 2017-07-30] (x264vfw project) [Brak podpisu cyfrowego] HKLM\...\Drivers32: [vidc.lags] => C:\Windows\SysWOW64\lagarith.dll [230080 2016-09-21] (Cole Williams Software Limited -> ) HKLM\...\Drivers32: [msacm.divxa32] => C:\Windows\SysWOW64\DivXa32.acm [291408 2013-12-17] (Packed With Joy !) [Brak podpisu cyfrowego] GroupPolicy: Ograniczenia - Windows Defender <==== UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 62.179.1.60 62.179.1.61 Tcpip\..\Interfaces\{035d728d-673e-4815-8864-5b8b9b20a91e}: [DhcpNameServer] 8.8.8.8 Tcpip\..\Interfaces\{5c12e41b-726c-4242-b380-9e9cd54b7b71}: [DhcpNameServer] 62.179.1.60 62.179.1.61 HKLM\System\...\Parameters\PersistentRoutes: [104.87.88.177,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [104.89.242.39,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.34.230,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.61.100,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.61.64,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.61.68,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.61.96,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [157.56.77.148,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [157.56.77.149,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [172.230.215.85,255.255.255.255,0.0.0.0,1] PersistentRoutes: Wykryto więcej niż wyliczono: 19 PersistentRoutes. Internet Explorer: ================== BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2018-07-19] (IObit Information Technology -> IObit) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre-10\bin\jp2ssv.dll [2018-03-21] (Oracle America, Inc. -> Oracle Corporation) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [Brak podpisu cyfrowego] Toolbar: HKLM - Brak nazwy - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Brak pliku Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [Brak podpisu cyfrowego] FireFox: ======== FF DefaultProfile: t644avrw.default-1530211272865 FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\t644avrw.default-1530211272865 [2019-03-21] FF Homepage: Mozilla\Firefox\Profiles\t644avrw.default-1530211272865 -> hxxps://www.wp.pl/ FF Plugin: @java.com/DTPlugin,version=13.0.0.0 -> C:\Program Files\Java\jre-10\bin\dtplugin\npDeployJava1.dll [2018-03-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=13.0.0.0 -> C:\Program Files\Java\jre-10\bin\plugin2\npjp2.dll [2018-03-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-03-01] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-10-04] (Google Inc -> Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-10-04] (Google Inc -> Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-03-01] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-1259440541-1541188897-2945871715-1001: @tools.google.com/Google Update;version=3 -> C:\Users\user\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-11] (Google Inc -> Google Inc.) FF Plugin HKU\S-1-5-21-1259440541-1541188897-2945871715-1001: @tools.google.com/Google Update;version=9 -> C:\Users\user\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-11] (Google Inc -> Google Inc.) FF Plugin HKU\S-1-5-21-1259440541-1541188897-2945871715-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-1259440541-1541188897-2945871715-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-1259440541-1541188897-2945871715-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2018-12-16] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-1259440541-1541188897-2945871715-1001: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\user\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2019-02-12] (Google Inc (TEST) -> Epic Privacy Browser) [Brak podpisu cyfrowego] FF Plugin HKU\S-1-5-21-1259440541-1541188897-2945871715-1001: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\user\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2019-02-12] (Google Inc (TEST) -> Epic Privacy Browser) [Brak podpisu cyfrowego] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default [2019-03-21] CHR Extension: (Prezentacje) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-04-25] CHR Extension: (Dokumenty) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-04] CHR Extension: (Dysk Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-04] CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-04] CHR Extension: (Arkusze) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-04-25] CHR Extension: (Dokumenty Google offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-04] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-25] CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-04] CHR Extension: (Chrome Media Router) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-04] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818128 2019-03-01] (Adobe Systems Incorporated -> Adobe Inc.) S3 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2910696 2018-09-10] (Adobe Systems Incorporated -> Adobe Systems, Incorporated) S3 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2704872 2018-09-10] (Adobe Systems Incorporated -> Adobe Systems, Incorporated) S3 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-10-31] (Digital Wave Ltd -> Digital Wave Ltd.) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [145224 2017-03-10] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) S3 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [153360 2018-09-25] (IObit Information Technology -> IObit) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes) R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [109536 2018-12-18] (Panda Security S.L. -> Panda Security, S.L.) S3 Panda VPN Service; C:\Program Files (x86)\Panda Security\Panda Security Protection\Hydra.Sdk.Windows.Service.exe [320848 2017-11-20] (AnchorFree Inc -> ) R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [86104 2016-07-19] (Panda Security S.L -> Panda Security, S.L.) R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [48784 2018-12-19] (Panda Security S.L. -> Panda Security, S.L.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-09-21] (Microsoft Windows Publisher -> Microsoft Corporation) R2 unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [297240 2018-12-20] (Reason Software Company Inc. -> Reason Software Company Inc.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-09-21] (Microsoft Corporation -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-09-21] (Microsoft Corporation -> Microsoft Corporation) S3 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 S3 postgresql-x64-9.5; "C:\Program Files\PostgreSQL\9.5\bin\pg_ctl.exe" runservice -N "postgresql-x64-9.5" -D "C:\Program Files\PostgreSQL\9.5\data" -w ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2017-11-16] (AnchorFree Inc -> The OpenVPN Project) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-06-28] (Martin Malik - REALiX -> REALiX(tm)) R2 inpoutx64; C:\WINDOWS\System32\Drivers\inpoutx64.sys [15008 2017-11-18] (Red Fox UK Limited -> Highresolution Enterprises [www.highrez.co.uk]) R3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys [37184 2018-10-16] (IObit Information Technology -> IObit) R3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys [43392 2018-10-16] (IObit Information Technology -> IObit) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [198512 2019-03-03] (Malwarebytes Corporation -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R1 NNSALPC; C:\WINDOWS\system32\DRIVERS\NNSALPC.sys [111384 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSDNS; C:\WINDOWS\system32\DRIVERS\NNSDNS.sys [104728 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [211736 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [124904 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [130536 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [95472 2018-07-16] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [143848 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPIHSW; C:\WINDOWS\system32\DRIVERS\NNSPIHSW.sys [95208 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [135656 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [344040 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [286184 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [123368 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [285672 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSTLSC; C:\WINDOWS\system32\DRIVERS\NNSTLSC.sys [129512 2018-12-14] (Panda Security S.L. -> Panda Security, S.L.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c1a085cc86772d3f\nvlddmkm.sys [17544792 2018-06-28] (NVIDIA Corporation -> NVIDIA Corporation) R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [198424 2019-01-13] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [160536 2019-01-13] (Panda Security S.L. -> Panda Security, S.L.) R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [214104 2018-12-13] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [147224 2019-01-13] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [159512 2019-01-13] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [128600 2018-12-19] (Panda Security S.L. -> Panda Security, S.L.) U3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [72648 2017-05-22] (Panda Security S.L. -> Panda Security, S.L.) S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2016-06-15] (The OpenVPN Project) [Brak podpisu cyfrowego] R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-12] (Microsoft Windows -> Realtek ) S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (The OpenVPN Project) [Brak podpisu cyfrowego] S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [46040 2017-08-24] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46584 2018-09-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [340008 2018-09-21] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-09-21] (Microsoft Windows -> Microsoft Corporation) R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-10-04] (Zemana Ltd. -> Zemana Ltd.) U4 DiagTrack; Brak ImagePath ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-03-21 13:26 - 2019-03-21 13:27 - 000022579 _____ C:\Users\user\Desktop\FRST.txt 2019-03-21 13:26 - 2019-03-21 13:26 - 002434048 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe 2019-03-21 13:19 - 2019-03-21 13:19 - 000002950 _____ C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_user 2019-03-21 13:19 - 2019-03-21 13:19 - 000001442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk 2019-03-21 13:19 - 2019-03-21 13:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller 2019-03-21 13:18 - 2019-03-21 13:18 - 000000000 ____D C:\Program Files (x86)\IObit 2019-03-21 13:11 - 2019-03-21 13:16 - 000000000 ____D C:\Users\user\Desktop\IObit Uninstaller Pro 8.4.0.8 2019-03-21 12:50 - 2019-03-21 13:26 - 000053053 _____ C:\WINDOWS\ZAM_Guard.krnl.trace 2019-03-21 12:50 - 2017-05-22 06:01 - 000072648 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSKMAD.sys 2019-03-21 09:59 - 2019-03-21 10:23 - 000000000 ____D C:\Users\user\AppData\Roaming\VidCoder 2019-03-21 09:59 - 2019-03-21 09:59 - 000000946 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VidCoder.lnk 2019-03-21 09:59 - 2019-03-21 09:59 - 000000000 ____D C:\Program Files\VidCoder 2019-03-20 14:37 - 2019-03-20 21:12 - 000000000 ____D C:\Users\user\Desktop\DaVinci Resolve - tutoriale 2019-03-20 11:00 - 2019-03-20 11:01 - 045868489 _____ C:\Users\user\Desktop\Photoshop retusz nocnego nieba gwiazd.mp4 2019-03-20 10:56 - 2019-03-20 10:56 - 095362471 _____ C:\Users\user\Desktop\Jak obrabiać zdjęcia gwiazd Obróbka w Adobe Lightroom #1.mp4 2019-03-20 10:01 - 2019-03-20 10:32 - 000000000 ____D C:\Users\user\Desktop\Nowy folder 2019-03-19 19:50 - 2019-03-19 20:27 - 000000000 ____D C:\Program Files (x86)\Apeaksoft Studio 2019-03-19 19:50 - 2019-03-19 19:54 - 000000000 ____D C:\Users\user\Documents\Apeaksoft Studio 2019-03-19 19:50 - 2019-03-19 19:50 - 000000000 ____D C:\Users\user\AppData\Local\Apeaksoft Studio 2019-03-19 12:07 - 2019-03-19 12:07 - 000753616 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-03-18 19:00 - 2019-03-18 19:04 - 000000000 ____D C:\Users\user\AppData\Roaming\Wise Disk Cleaner 2019-03-18 13:05 - 2019-03-18 13:05 - 000002886 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2019-03-18 13:05 - 2019-03-18 13:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2019-03-18 13:05 - 2019-03-18 13:05 - 000000000 ____D C:\Program Files\CCleaner 2019-03-18 10:47 - 2019-03-21 13:26 - 000000000 ____D C:\FRST 2019-03-18 10:29 - 2019-03-18 10:29 - 000000000 ____D C:\Program Files\MPC-HC 2019-03-18 09:54 - 2019-03-18 09:54 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignee769de231b81f8f 2019-03-18 09:53 - 2019-03-18 09:53 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignff6073218b979eb6 2019-03-18 09:53 - 2019-03-18 09:53 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignbf9383dd90ed08e1 2019-03-17 20:00 - 2019-03-17 20:00 - 000001428 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2019-03-14 19:50 - 2019-03-14 19:50 - 000000000 ____D C:\Program Files (x86)\PrivaZer 2019-03-08 14:05 - 2019-03-08 14:05 - 000015685 _____ C:\Users\user\Desktop\Vidéo de l'album Niedziela w Skierniewice - Google Photos.htm 2019-03-08 13:35 - 2019-03-08 13:35 - 000051192 _____ C:\Users\user\Documents\dosłane pit9 Janusz.pdf 2019-03-08 13:34 - 2019-03-08 13:34 - 000073748 _____ C:\Users\user\Documents\dosłane pit7 Janusz.pdf 2019-03-08 13:34 - 2019-03-08 13:34 - 000050967 _____ C:\Users\user\Documents\dosłane pit8 Janusz.pdf 2019-03-08 13:33 - 2019-03-08 13:33 - 000197951 _____ C:\Users\user\Documents\dosłane pit6 Janusz.pdf 2019-03-08 13:33 - 2019-03-08 13:33 - 000118922 _____ C:\Users\user\Documents\dosłane pit5 Janusz.pdf 2019-03-08 13:32 - 2019-03-08 13:32 - 000074026 _____ C:\Users\user\Documents\dosłane pit4 Janusz.pdf 2019-03-08 13:31 - 2019-03-08 13:31 - 000185377 _____ C:\Users\user\Documents\dosłane pit3 Janusz.pdf 2019-03-08 13:31 - 2019-03-08 13:31 - 000111817 _____ C:\Users\user\Documents\dosłane pit2 Janusz.pdf 2019-03-08 13:30 - 2019-03-08 13:30 - 000074204 _____ C:\Users\user\Documents\dosłane pit1 Janusz.pdf 2019-03-08 13:29 - 2019-03-08 13:29 - 000174539 _____ C:\Users\user\Documents\dosłane pit Janusz.pdf 2019-03-08 13:29 - 2019-03-08 13:29 - 000093683 _____ C:\Users\user\Documents\img20190308_13291039.pdf 2019-03-08 13:13 - 2019-03-08 13:13 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign228ac3973208f2e0 2019-03-08 13:12 - 2019-03-08 13:12 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignaf98a0b1ad54735c 2019-03-08 13:12 - 2019-03-08 13:12 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign3ebc74535c4a0443 2019-03-07 19:41 - 2019-03-07 19:41 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign607635d09a2117aa 2019-03-07 19:34 - 2019-03-07 19:34 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignad631978f7a7691c 2019-03-07 19:34 - 2019-03-07 19:34 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign72f193e871540e1b 2019-03-06 11:45 - 2019-03-06 11:45 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsigna9611c9104119c91 2019-03-06 11:41 - 2019-03-06 11:41 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignd1050ea12c25eece 2019-03-06 11:41 - 2019-03-06 11:41 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign5518d1e498e846e1 2019-03-06 11:15 - 2019-03-17 20:00 - 000000000 ___RD C:\Users\user\Creative Cloud Files 2019-03-06 11:04 - 2019-03-06 11:04 - 000001124 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom Classic CC.lnk 2019-03-05 15:36 - 2019-03-05 15:36 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsigne5964bb4f7af3613 2019-03-05 15:34 - 2019-03-05 15:34 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign3f2c35f461491df0 2019-03-05 09:46 - 2019-03-05 09:46 - 000008868 _____ C:\Users\user\Desktop\maya angielski.odt 2019-03-05 09:31 - 2019-03-05 09:31 - 000265643 _____ C:\Users\user\Documents\Janusz inny zakład pracy.pdf 2019-03-05 09:26 - 2019-03-05 09:26 - 000029099 _____ C:\Users\user\Documents\janusz faktura za wczasy rehabilitacyjne.pdf 2019-03-05 09:25 - 2019-03-05 09:25 - 000180471 _____ C:\Users\user\Documents\Janusz pit 1 z innego zakładu.pdf 2019-03-05 09:25 - 2019-03-05 09:25 - 000021474 _____ C:\Users\user\Documents\Janusz zabiegi rehabilitacyjne.pdf 2019-03-05 09:24 - 2019-03-05 09:24 - 000354031 _____ C:\Users\user\Documents\Janusz pit z innego zakładu.pdf 2019-03-04 20:00 - 2019-03-18 19:03 - 000000000 ____D C:\Users\user\AppData\Roaming\XnView 2019-03-04 20:00 - 2019-03-04 20:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView 2019-03-04 20:00 - 2019-03-04 20:00 - 000000000 ____D C:\Program Files (x86)\XnView 2019-03-04 12:57 - 2019-03-04 12:57 - 000221056 _____ C:\Users\user\Documents\img20190304_12575527.pdf 2019-03-04 12:56 - 2019-03-04 12:56 - 000416433 _____ C:\Users\user\Documents\Marzenna pit str5.pdf 2019-03-04 12:55 - 2019-03-04 12:55 - 000224041 _____ C:\Users\user\Documents\Marzenna pit str4.pdf 2019-03-04 12:54 - 2019-03-04 12:54 - 000230593 _____ C:\Users\user\Documents\Marzenna pit str3.pdf 2019-03-04 12:53 - 2019-03-04 12:53 - 000074740 _____ C:\Users\user\Documents\Marzenna pit str2.pdf 2019-03-04 12:52 - 2019-03-04 12:52 - 000042850 _____ C:\Users\user\Documents\Marzenna pit str1.pdf 2019-03-04 12:50 - 2019-03-04 12:50 - 000067569 _____ C:\Users\user\Documents\Janusz pit 6.pdf 2019-03-04 12:48 - 2019-03-04 12:48 - 000067652 _____ C:\Users\user\Documents\Janusz pit 5.pdf 2019-03-04 12:48 - 2019-03-04 12:48 - 000042418 _____ C:\Users\user\Documents\Janusz pit 4.pdf 2019-03-04 12:45 - 2019-03-04 12:45 - 000181653 _____ C:\Users\user\Documents\Janusz pit3.pdf 2019-03-04 12:44 - 2019-03-04 12:44 - 000181850 _____ C:\Users\user\Documents\Janusz pit 2.pdf 2019-03-04 12:43 - 2019-03-04 12:43 - 000354698 _____ C:\Users\user\Documents\Janusz pit 1.pdf 2019-03-04 12:42 - 2019-03-04 12:42 - 000259561 _____ C:\Users\user\Documents\Janusz Todorski pit.pdf 2019-03-03 14:22 - 2019-03-03 14:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-03-03 14:22 - 2019-03-03 14:22 - 000198512 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2019-03-03 14:22 - 2019-03-03 14:22 - 000000000 ____D C:\Program Files\Malwarebytes 2019-03-03 14:22 - 2019-02-01 11:20 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2019-03-03 14:22 - 2019-01-08 15:32 - 000153328 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2019-03-03 14:16 - 2019-03-03 14:16 - 000003366 _____ C:\WINDOWS\System32\Tasks\Anvirlauncher 2019-03-03 14:16 - 2019-03-03 14:16 - 000003220 _____ C:\WINDOWS\System32\Tasks\AnVir Task Manager 2019-03-03 14:15 - 2019-03-03 14:17 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager Free 2019-03-03 14:15 - 2019-03-03 14:15 - 000001190 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\AnVir Task Manager Free.lnk 2019-03-03 14:12 - 2019-03-03 14:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2019-03-03 14:12 - 2019-03-03 14:12 - 000000000 ____D C:\Program Files\7-Zip 2019-02-27 16:00 - 2019-02-27 16:00 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignaa0f8e30f1aefe36 2019-02-27 15:58 - 2019-02-27 15:58 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignbf0f984649b5ac65 2019-02-27 15:47 - 2019-02-27 15:47 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign91017844f67943e7 2019-02-27 15:45 - 2019-02-27 15:45 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsigndf5d356cfe279bef 2019-02-27 13:13 - 2019-02-27 13:13 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsigne2298d64fd9a7a88 2019-02-27 13:09 - 2019-02-27 13:09 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsigncb5a2d2431797098 2019-02-26 16:46 - 2019-02-26 16:46 - 000011063 _____ C:\Users\user\Documents\Bez tytułu 1Nr wizy kanada.odt 2019-02-26 15:04 - 2019-02-26 15:04 - 000022701 _____ C:\Users\user\Documents\img20190226_15045160.pdf 2019-02-23 18:31 - 2019-02-23 18:31 - 000025165 _____ C:\Users\user\Documents\img20190223_18314976.pdf 2019-02-23 18:29 - 2019-02-23 18:29 - 000025064 _____ C:\Users\user\Documents\img20190223_18295354.pdf 2019-02-23 18:27 - 2019-02-23 18:27 - 000025170 _____ C:\Users\user\Documents\img20190223_18274037.pdf 2019-02-20 20:26 - 2019-02-20 20:26 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignceb0ea1924c0257a 2019-02-20 20:26 - 2019-02-20 20:26 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign77da50dd42ff0280 2019-02-20 20:14 - 2019-02-20 20:14 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignd10b3e86d3ef070e 2019-02-20 20:14 - 2019-02-20 20:14 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign18158bac88135974 2019-02-20 19:59 - 2019-02-20 20:00 - 000000000 ____D C:\Program Files\PhotoStitcher 2019-02-20 19:59 - 2019-02-20 19:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStitcher 2019-02-20 13:14 - 2019-02-20 13:14 - 000117926 _____ C:\Users\user\Documents\cv marzenna todorska (3).odtnowy.odt 2019-02-20 13:07 - 2019-02-20 13:07 - 000023575 _____ C:\Users\user\Documents\cv.odt 2019-02-20 12:58 - 2019-02-20 12:58 - 000021985 _____ C:\Users\user\Documents\cv2.odt 2019-02-20 10:34 - 2019-02-20 10:34 - 000015524 _____ C:\Users\user\Documents\fałszerstwo Marka Przeklasy.odt 2019-02-20 08:16 - 2019-02-20 08:16 - 000077208 _____ C:\Users\user\Documents\2 reklamacja PKO BP.odt 2019-02-19 18:17 - 2019-02-19 18:26 - 000000000 ____D C:\Users\user\AppData\Roaming\Stellarium 2019-02-19 18:17 - 2019-02-19 18:17 - 000000000 ____D C:\Users\user\AppData\Local\stellarium 2019-02-19 18:17 - 2019-02-19 18:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellarium 2019-02-19 18:17 - 2019-02-19 18:17 - 000000000 ____D C:\Program Files\Stellarium 2019-02-19 13:09 - 2019-02-19 13:09 - 000000000 ____D C:\Users\user\Documents\MAGIX_MusicEditor 2019-02-19 13:09 - 2019-02-19 13:09 - 000000000 ____D C:\Users\Public\Documents\MAGIX 2019-02-19 13:09 - 2019-02-19 13:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX 2019-02-19 13:08 - 2019-02-19 13:08 - 000000000 ____D C:\Program Files\MAGIX 2019-02-19 13:08 - 2019-02-19 13:08 - 000000000 ____D C:\Program Files\Common Files\MAGIX Services 2019-02-19 13:08 - 2019-02-19 13:08 - 000000000 ____D C:\Program Files (x86)\MAGIX 2019-02-19 12:26 - 2019-02-19 12:26 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsignb0b53c34b1be51e9 2019-02-19 12:24 - 2019-02-19 12:24 - 000000000 ____D C:\Users\user\AppData\Local\Tempzxpsign52da6feae6b66dcd 2019-02-19 11:07 - 2019-02-19 11:07 - 000000000 ____D C:\Users\user\Documents\MAGIX downloads 2019-02-19 10:43 - 2019-02-19 10:53 - 000022641 _____ C:\Users\user\Documents\hosts.txt ==================== Jeden miesiąc (zmodyfikowane) ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2019-03-21 13:22 - 2017-11-18 13:20 - 000000000 ____D C:\Users\user\AppData\Roaming\IObit 2019-03-21 13:11 - 2017-11-17 15:23 - 000000000 ____D C:\Users\user\AppData\Local\ClassicShell 2019-03-21 13:07 - 2017-11-17 17:10 - 000000000 ____D C:\Users\user\AppData\LocalLow\Mozilla 2019-03-21 12:54 - 2018-09-21 12:46 - 001763504 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-03-21 12:54 - 2018-04-12 16:54 - 000782334 _____ C:\WINDOWS\system32\perfh015.dat 2019-03-21 12:54 - 2018-04-12 16:54 - 000151496 _____ C:\WINDOWS\system32\perfc015.dat 2019-03-21 12:54 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF 2019-03-21 12:50 - 2018-09-21 12:43 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-03-21 12:50 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-03-21 12:50 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-03-21 10:59 - 2018-04-11 22:04 - 000262144 _____ C:\WINDOWS\system32\config\BBI 2019-03-21 09:59 - 2017-11-19 19:19 - 000000000 ____D C:\Users\user\AppData\Local\CrashDumps 2019-03-20 19:43 - 2018-09-21 12:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-03-20 11:28 - 2018-03-10 10:31 - 000000000 ____D C:\Program Files\Slimjet 2019-03-20 11:26 - 2018-06-28 19:30 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-03-20 11:26 - 2018-06-28 19:30 - 000000000 ____D C:\Program Files\Mozilla Firefox 2019-03-20 09:50 - 2017-11-18 13:21 - 000000000 ____D C:\Users\user\AppData\LocalLow\IObit 2019-03-20 09:50 - 2017-11-18 13:20 - 000000000 ____D C:\ProgramData\IObit 2019-03-19 20:14 - 2019-02-04 12:58 - 000000000 ____D C:\Users\user\AppData\Roaming\MPC-HC 2019-03-19 18:15 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps 2019-03-18 19:05 - 2018-09-25 08:32 - 000000000 ____D C:\Users\user\Desktop\Janusz 2019-03-18 19:02 - 2018-04-12 00:38 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files 2019-03-18 13:05 - 2018-10-04 19:48 - 000000000 ____D C:\ProgramData\ProductData 2019-03-18 10:30 - 2018-10-07 17:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player Classic Home Cinema 1.8.5 2019-03-17 20:10 - 2017-11-26 11:43 - 000000000 ____D C:\Users\user\AppData\Roaming\qBittorrent 2019-03-17 20:00 - 2018-01-29 13:55 - 000000000 ____D C:\Program Files (x86)\Adobe 2019-03-17 20:00 - 2017-11-19 12:34 - 000000000 ____D C:\Users\user\AppData\Local\Adobe 2019-03-14 19:54 - 2017-12-02 09:57 - 000000000 ____D C:\Users\user\AppData\Local\PrivaZer 2019-03-14 19:50 - 2017-12-02 09:57 - 000001970 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrivaZer.lnk 2019-03-13 21:39 - 2017-11-19 12:58 - 000000000 ____D C:\Program Files (x86)\Google 2019-03-13 21:21 - 2018-12-20 09:55 - 000000000 ____D C:\ProgramData\Unchecky 2019-03-12 17:59 - 2018-12-09 11:14 - 000000000 ____D C:\Program Files\Process Lasso 2019-03-08 14:10 - 2019-01-10 17:02 - 000000000 ____D C:\Users\user\Desktop\zdjęcia rodzinne 2019-03-08 10:55 - 2017-11-19 12:37 - 000000000 ____D C:\Users\user\Documents\Adobe 2019-03-08 10:55 - 2017-11-17 14:04 - 000000000 ____D C:\Users\user\AppData\Roaming\Adobe 2019-03-06 11:37 - 2018-01-29 13:55 - 000000000 ____D C:\ProgramData\Adobe 2019-03-06 11:11 - 2017-11-18 19:30 - 000000000 ____D C:\ProgramData\Package Cache 2019-03-06 11:04 - 2017-11-19 17:53 - 000000000 ____D C:\Program Files\Adobe 2019-03-03 14:36 - 2017-11-18 12:23 - 000000000 ____D C:\Users\user\AppData\Roaming\AIMP 2019-03-03 14:22 - 2018-04-12 00:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-03-03 14:22 - 2017-11-27 13:18 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-03-03 14:16 - 2018-01-08 17:16 - 000000000 ____D C:\Users\user\AppData\Local\AnVir 2019-03-03 14:16 - 2017-11-17 17:36 - 000000000 ____D C:\Program Files (x86)\AnVir Task Manager Free 2019-03-03 14:07 - 2017-11-17 15:02 - 000000000 ____D C:\Program Files\rempl 2019-02-27 15:52 - 2018-09-13 09:25 - 000000000 ____D C:\Program Files\Nikon 2019-02-27 15:52 - 2018-09-13 09:25 - 000000000 ____D C:\Program Files (x86)\Nikon 2019-02-27 15:52 - 2017-11-18 19:30 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2019-02-20 19:42 - 2018-10-25 18:30 - 000001248 _____ C:\Users\user\Desktop\Epson Scan 2.lnk 2019-02-19 13:08 - 2017-11-23 10:41 - 000000000 ____D C:\ProgramData\Magix 2019-02-19 12:17 - 2018-09-19 12:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProShow Producer 2019-02-19 12:17 - 2018-09-19 12:20 - 000000000 ____D C:\ProgramData\Photodex ==================== Pliki w katalogu głównym wybranych folderów ======= 2018-02-20 18:43 - 2018-02-20 18:43 - 000001496 _____ () C:\Users\user\AppData\Local\Adobe Zapisz dla Internetu 13.0 Prefs 2017-11-26 12:08 - 2017-11-26 12:08 - 000140800 _____ () C:\Users\user\AppData\Local\installer.dat 2018-01-24 11:54 - 2018-01-24 11:54 - 000000743 _____ () C:\Users\user\AppData\Local\recently-used.xbel ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\wininit.exe => Plik podpisany cyfrowo C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\WINDOWS\system32\dllhost.exe => Plik podpisany cyfrowo C:\WINDOWS\SysWOW64\dllhost.exe => Plik podpisany cyfrowo C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2018-09-21 12:37 ==================== Koniec FRST.txt ============================