Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 01-10-2017 Uruchomiony przez Marcin (administrator) MARCIN-KOMPUTER (02-10-2017 15:44:41) Uruchomiony z C:\Users\Marcin\Documents\Pobrane Chrome Załadowane profile: Marcin & (Dostępne profile: Marcin & Husky) Platform: Windows 7 Home Premium Service Pack 1 (X64) Język: Polski (Polska) Internet Explorer Wersja 11 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe () C:\Program Files\SecureAge\Everything\Everything.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.SQLEXPRESSEFILM\MSSQL\Binn\sqlservr.exe (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\saappsvc.exe (SecureAge Technology) C:\Program Files\SecureAge\Everything\EverythingServer.exe (SecureAge Technology) C:\Program Files\SecureAge\AntiVirus\sascansvc.exe (SecureAge Technology) C:\Program Files\SecureAge\UniversalAV\UniversalAVService.exe (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\SecureAPlusService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files\SecureAge\Everything\Everything.exe (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\sanotifier.exe (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\SecureAPlus.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE (Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (SecureAge Technology) C:\Program Files\SecureAge\Whitelist\CheckUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11772520 2011-01-04] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2011-02-14] (ELAN Microelectronics Corp.) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9768352 2012-11-30] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5940128 2012-11-30] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-11-30] (Lenovo) HKLM\...\Run: [Everything] => C:\Program Files\SecureAge\Everything\Everything.exe [1441792 2014-08-06] () HKLM\...\Run: [SAAppWhitelistingNotifier] => C:\Program Files\SecureAge\Whitelist\sanotifier.exe [4254184 2017-08-24] (SecureAge Technology) HKLM\...\Run: [SecureAPlus] => C:\Program Files\SecureAge\Whitelist\SecureAPlus.exe [7248912 2017-08-30] (SecureAge Technology) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro) HKLM-x32\...\Run: [PLTSR] => C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe [364400 2010-10-22] (Egis Technology Inc. ) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1534504 2013-01-14] (McAfee, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-12] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [799368 2017-06-05] (Sandboxie Holdings, LLC) HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\MountPoints2: {84cbcb27-f42e-11e6-b9f8-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\MountPoints2: {db59c090-502f-11e6-a050-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [799368 2017-06-05] (Sandboxie Holdings, LLC) HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {84cbcb27-f42e-11e6-b9f8-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {db59c090-502f-11e6-a050-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {84cbcb27-f42e-11e6-b9f8-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {db59c090-502f-11e6-a050-3c970e408dd5} - autorun.exe Lsa: [Notification Packages] scecli EgisPLPwdFilter Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2012-11-30] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy\User: Ograniczenia <==== UWAGA GroupPolicyUsers\S-1-5-21-2413066759-4021284835-616923704-1004\User: Ograniczenia <==== UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 8.8.4.4 213.241.79.37 Tcpip\..\Interfaces\{7F6DFE23-DC54-4E74-B291-43D725A4A130}: [DhcpNameServer] 8.8.4.4 213.241.79.37 213.241.79.38 8.8.8.8 Tcpip\..\Interfaces\{C53A3DB0-E5DD-4F22-A896-292B1DD19F6A}: [DhcpNameServer] 8.8.4.4 213.241.79.37 Internet Explorer: ================== HKU\S-1-5-21-2413066759-4021284835-616923704-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.lenovo.com/ HKU\S-1-5-21-2413066759-4021284835-616923704-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.lenovo.com/ HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-09-28] (Microsoft Corporation) BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.) BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20130221115203.dll [2012-12-26] (McAfee, Inc.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-09-28] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-09-28] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-09-28] (Microsoft Corporation) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\ssv.dll [2017-07-20] (Oracle Corporation) BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20130221115203.dll [2012-12-26] (McAfee, Inc.) BHO-x32: Pomocnik logowania za pomocą identyfikatora Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-09-28] (Microsoft Corporation) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-09-28] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\jp2ssv.dll [2017-07-20] (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2012-12-04] (McAfee, Inc.) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2012-12-04] (McAfee, Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.) Toolbar: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 -> Brak nazwy - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Brak pliku IE Session Restore: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 -> [funkcja włączona] Toolbar: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Brak nazwy - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Brak pliku IE Session Restore: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> [funkcja włączona] DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2012-12-04] (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2012-12-04] (McAfee, Inc.) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-28] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-28] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-28] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-28] (Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2012-12-04] (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2012-12-04] (McAfee, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2012-11-17] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2012-11-17] (McAfee, Inc.) FireFox: ======== FF DefaultProfile: 0wwspgy3.default FF ProfilePath: C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\0wwspgy3.default [2017-10-01] FF NetworkProxy: Mozilla\Firefox\Profiles\0wwspgy3.default -> type", 0 FF Extension: (FoxVox) - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\0wwspgy3.default\Extensions\foxvox@wordit.com [2017-09-27] FF Extension: (One Click Proxy) - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\0wwspgy3.default\Extensions\jid0-zXo3XFGyiDalgkeEO4UYJTUwo2I@jetpack.xpi [2016-07-07] FF Extension: (Adblock Plus) - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\0wwspgy3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-15] FF Extension: (Activity Stream) - C:\Program Files (x86)\Mozilla Firefox\browser\features\activity-stream@mozilla.org.xpi [2017-09-29] [Brak podpisu cyfrowego] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-02-21] [Brak podpisu cyfrowego] FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore FF Extension: (McAfee ScriptScan for Firefox) - C:\Program Files (x86)\Common Files\McAfee\SystemCore [2013-02-21] [Brak podpisu cyfrowego] FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-16] () FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2012-09-12] () FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-16] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1228198.dll [2017-02-27] (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.141.2 -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\dtplugin\npDeployJava1.dll [2017-07-20] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.141.2 -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\plugin2\npjp2.dll [2017-07-20] (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2012-09-12] () FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll [2012-12-04] (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-09-28] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-09-28] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2413066759-4021284835-616923704-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Marcin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Marcin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default [2017-10-02] CHR Extension: (AdBlock) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-09-18] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (Chrome Media Router) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-28] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-02-21] ==================== Usługi (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [956192 2011-02-15] (Broadcom Corporation.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7761608 2017-09-08] (Microsoft Corporation) R2 EgisTec Service Help; C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [327024 2010-10-22] (Egis Technology Inc. ) R2 Everything; C:\Program Files\SecureAge\Everything\Everything.exe [1441792 2014-08-06] () [Brak podpisu cyfrowego] R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [383608 2012-11-16] (McAfee, Inc.) S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241016 2012-12-26] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218320 2012-12-26] (McAfee, Inc.) R2 mfevtp; C:\windows\system32\mfevtps.exe [182312 2012-12-26] (McAfee, Inc.) R2 MSSQL$SQLEXPRESSEFILM; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.SQLEXPRESSEFILM\MSSQL\Binn\sqlservr.exe [199872 2016-06-18] (Microsoft Corporation) R2 saappsvc; C:\Program Files\SecureAge\Whitelist\saappsvc.exe [1045192 2017-08-30] (SecureAge Technology) R2 SAEverythingServer; C:\Program Files\SecureAge\Everything\EverythingServer.exe [214000 2017-03-03] (SecureAge Technology) R2 sascansvc; C:\Program Files\SecureAge\AntiVirus\sascansvc.exe [1112160 2017-04-18] (SecureAge Technology) R2 SAUAVSvc; C:\Program Files\SecureAge\UniversalAV\UniversalAVService.exe [1223912 2017-08-30] (SecureAge Technology) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [198792 2017-06-05] (Sandboxie Holdings, LLC) R2 SecureAPlusService; C:\Program Files\SecureAge\Whitelist\SecureAPlusService.exe [1062720 2017-08-30] (SecureAge Technology) S4 SQLAgent$SQLEXPRESSEFILM; C:\Program Files (x86)\Microsoft SQL Server\MSSQL12.SQLEXPRESSEFILM\MSSQL\Binn\SQLAGENT.EXE [454848 2016-06-18] (Microsoft Corporation) S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [56552 2016-03-22] (Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Sterowniki (filtrowane) ====================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R0 8591C9A5; C:\windows\System32\drivers\8591C9A5.sys [478392 2017-10-01] (Kaspersky Lab ZAO) U5 AppMgmt; C:\windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== UWAGA (Brak ServiceDLL) R3 cfwids; C:\windows\System32\drivers\cfwids.sys [69672 2012-12-26] (McAfee, Inc.) R1 ElRawDisk; C:\windows\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation) S3 HipShieldK; C:\windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-10-02] (Malwarebytes) R3 mfeapfk; C:\windows\System32\drivers\mfeapfk.sys [178840 2012-12-26] (McAfee, Inc.) R3 mfeavfk; C:\windows\System32\drivers\mfeavfk.sys [309400 2012-12-26] (McAfee, Inc.) U3 mfeavfk01; Brak ImagePath R3 mfefirek; C:\windows\System32\drivers\mfefirek.sys [515528 2012-12-26] (McAfee, Inc.) R0 mfehidk; C:\windows\System32\drivers\mfehidk.sys [771096 2012-12-26] (McAfee, Inc.) S3 mferkdet; C:\windows\System32\drivers\mferkdet.sys [106112 2012-12-26] (McAfee, Inc.) R0 mfewfpk; C:\windows\System32\drivers\mfewfpk.sys [339776 2012-12-26] (McAfee, Inc.) R0 SAAppCtl; C:\windows\System32\DRIVERS\saappctl.sys [270760 2017-06-11] (SecureAge Technology) R0 sascan; C:\windows\System32\DRIVERS\sascan.sys [95216 2017-08-13] (SecureAge Technology) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [207496 2017-06-05] (Sandboxie Holdings, LLC) R3 vm331avs; C:\windows\System32\Drivers\vm331avs.sys [228224 2010-10-21] (Vimicro Corporation) R3 vmuvcflt; C:\windows\System32\Drivers\vmuvcflt.sys [8320 2010-08-16] (Vimicro Corporation) U3 BcmSqlStartupSvc; Brak ImagePath U2 CLKMSVC10_3A60B698; Brak ImagePath U2 CLKMSVC10_C3B3B687; Brak ImagePath U2 DriverService; Brak ImagePath U2 IAStorDataMgrSvc; Brak ImagePath U2 iATAgentService; Brak ImagePath U2 idealife Update Service; Brak ImagePath U3 IGRS; Brak ImagePath U2 IviRegMgr; Brak ImagePath U2 nvUpdatusService; Brak ImagePath U2 Oasis2Service; Brak ImagePath U2 PCCarerService; Brak ImagePath U2 ReadyComm.DirectRouter; Brak ImagePath U2 RichVideo; Brak ImagePath U2 RtLedService; Brak ImagePath U2 SeaPort; Brak ImagePath U2 SoftwareService; Brak ImagePath S1 ZAM; \??\C:\windows\System32\drivers\zam64.sys [X] S1 ZAM_Guard; \??\C:\windows\System32\drivers\zamguard64.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc - utworzone pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-10-02 15:34 - 2017-10-02 15:44 - 000000000 ____D C:\FRST 2017-10-02 15:21 - 2017-10-02 15:22 - 000000000 ____D C:\Qoobox 2017-10-02 15:21 - 2017-10-02 15:22 - 000000000 ____D C:\ComboFix 2017-10-02 15:20 - 2017-10-02 15:20 - 000000000 ____D C:\windows\erdnt 2017-10-02 15:13 - 2017-10-02 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2017-10-01 14:34 - 2017-10-01 20:03 - 000000000 ____D C:\KVRT_Data 2017-10-01 14:34 - 2017-10-01 14:34 - 000478392 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\8591C9A5.sys 2017-10-01 14:21 - 2017-10-01 14:21 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\9-lab 2017-10-01 14:20 - 2017-10-02 15:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool 2017-10-01 14:20 - 2017-10-01 14:25 - 000000000 ____D C:\Program Files\9-lab 2017-10-01 14:20 - 2017-10-01 14:20 - 000000000 ____D C:\ProgramData\9-lab 2017-09-29 12:56 - 2017-09-29 12:56 - 000000000 ____H C:\ProgramData\cm-lock 2017-09-28 14:39 - 2017-09-28 14:39 - 000000000 ____D C:\windows\System32\Tasks\Safer-Networking 2017-09-28 14:38 - 2017-09-29 12:55 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2017-09-25 16:01 - 2017-09-25 16:01 - 000000000 _____ C:\Users\Marcin\Desktop\Nowy dokument tekstowy.txt 2017-09-25 10:32 - 2017-09-25 18:56 - 000000000 ____D C:\Users\Marcin\Desktop\SaS 2017-09-25 09:52 - 2017-09-25 09:52 - 000001238 _____ C:\Users\Marcin\Desktop\swieze.txt 2017-09-21 16:46 - 2017-09-21 16:47 - 009809688 _____ (Piriform Ltd) C:\Users\Marcin\Downloads\ccsetup535.exe 2017-09-20 16:20 - 2017-09-20 16:20 - 000350541 _____ C:\Users\Marcin\Downloads\Komunikacja tekstowa a poczucie alienacji w_ród m_odzie_y.pdf 2017-09-18 16:31 - 2017-09-18 16:31 - 000211628 _____ C:\Users\Marcin\Desktop\Pedagogika - studia stacjonarne.pdf 2017-09-18 13:02 - 2017-09-18 13:02 - 000000091 _____ C:\Users\Marcin\Desktop\Ginekomastia - operacja refundowana - Forum KFD.pl.url 2017-09-18 10:10 - 2017-09-25 15:31 - 000000000 ____D C:\Users\Marcin\Desktop\Do wysłania seminarium 2017-09-16 23:26 - 2017-10-02 15:40 - 013159925 _____ C:\windows\system32\Drivers\whitelist2.sa 2017-09-16 23:25 - 2017-09-27 07:18 - 000000000 ____D C:\Program Files\SecureAge 2017-09-16 23:25 - 2017-09-26 21:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SecureAge 2017-09-16 23:08 - 2017-09-16 23:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller 2017-09-16 23:08 - 2017-09-16 23:08 - 000000000 ____D C:\Program Files\VS Revo Group 2017-09-12 21:16 - 2017-09-12 21:16 - 000171722 _____ C:\Users\Marcin\Desktop\CP1100082782 (1).pdf 2017-09-04 22:05 - 2017-09-04 22:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP270 series ==================== Jeden miesiąc - zmodyfikowane pliki i foldery ======== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2017-10-02 15:38 - 2017-06-12 08:32 - 000000000 ____D C:\Users\Marcin\Documents\Pobrane Chrome 2017-10-02 15:27 - 2009-07-14 06:45 - 000021280 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-10-02 15:27 - 2009-07-14 06:45 - 000021280 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-10-02 15:13 - 2017-07-16 18:34 - 000842386 _____ C:\windows\system32\perfh015.dat 2017-10-02 15:13 - 2016-03-16 21:01 - 000192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2017-10-02 15:13 - 2009-07-14 07:13 - 001962876 _____ C:\windows\system32\PerfStringBackup.INI 2017-10-02 15:13 - 2009-07-14 05:20 - 000000000 ____D C:\windows\inf 2017-10-02 15:08 - 2017-07-16 19:18 - 000144173 _____ C:\windows\system32\fastboot.set 2017-10-02 15:05 - 2017-07-16 18:24 - 000000006 ____H C:\windows\Tasks\SA.DAT 2017-10-02 15:03 - 2013-02-18 19:17 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\SoftGrid Client 2017-10-01 14:29 - 2016-12-05 22:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-09-30 16:10 - 2016-11-16 23:38 - 000000000 ____D C:\Users\Husky\AppData\LocalLow\Mozilla 2017-09-29 13:02 - 2017-07-16 18:34 - 000197634 _____ C:\windows\system32\perfc015.dat 2017-09-29 12:07 - 2017-06-04 21:56 - 000011776 ___SH C:\Users\Marcin\Thumbs.db 2017-09-28 16:27 - 2016-05-03 17:20 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-09-28 16:18 - 2012-11-30 21:40 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2017-09-28 14:48 - 2017-02-09 15:35 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy 2017-09-28 14:48 - 2016-05-03 18:25 - 000000138 _____ C:\windows\wininit.ini 2017-09-27 08:40 - 2012-11-30 21:53 - 000002201 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-09-27 07:19 - 2016-11-16 23:22 - 000000000 ____D C:\Users\Husky 2017-09-27 07:19 - 2009-07-14 07:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-09-27 07:19 - 2009-07-14 07:32 - 000000000 ____D C:\Program Files\Windows Defender 2017-09-27 07:19 - 2009-07-14 05:20 - 000000000 __RSD C:\windows\Media 2017-09-27 07:19 - 2009-07-14 05:20 - 000000000 ____D C:\windows\system32\Dism 2017-09-27 07:19 - 2009-07-14 05:20 - 000000000 ____D C:\windows\servicing 2017-09-27 07:19 - 2009-07-14 05:20 - 000000000 ____D C:\windows\Cursors 2017-09-27 07:19 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\System 2017-09-27 07:18 - 2017-07-30 16:08 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2017-09-27 07:18 - 2017-07-25 22:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack 2017-09-27 07:18 - 2017-07-25 19:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-09-27 07:18 - 2017-07-06 18:47 - 000000000 ____D C:\Users\Marcin\Desktop\axa 2017-09-27 07:18 - 2017-06-29 18:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie 2017-09-27 07:18 - 2017-06-20 16:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Narzędzia pakietu Microsoft Office 2016 2017-09-27 07:18 - 2017-03-05 23:49 - 000000000 ____D C:\Users\Marcin\Desktop\ea 2017-09-27 07:18 - 2016-11-16 23:22 - 000000000 ____D C:\Users\Husky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2017-09-27 07:18 - 2016-06-22 21:50 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-09-27 07:18 - 2016-06-22 21:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-09-27 07:18 - 2016-06-22 21:50 - 000000000 ____D C:\Program Files\WinRAR 2017-09-27 07:18 - 2016-06-22 18:52 - 000000000 ____D C:\Program Files\Sandboxie 2017-09-27 07:18 - 2016-05-03 16:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity 5.3.4f1 (64-bit) 2017-09-27 07:18 - 2016-04-13 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-09-27 07:18 - 2016-03-16 21:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2017-09-27 07:18 - 2013-02-18 19:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Polski) 2017-09-27 07:18 - 2013-02-18 19:16 - 000000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client 2017-09-27 07:18 - 2013-02-18 19:12 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2017-09-27 07:18 - 2012-11-30 21:41 - 000000000 ____D C:\ProgramData\Port Locker 2017-09-27 07:18 - 2012-11-30 21:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo 2017-09-27 07:18 - 2012-11-30 21:41 - 000000000 ____D C:\Program Files (x86)\EgisTec Port Locker 2017-09-27 07:18 - 2012-11-30 21:17 - 000000000 ____D C:\Program Files\Elantech 2017-09-27 07:18 - 2012-11-30 21:09 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2017-09-27 07:15 - 2009-07-14 05:20 - 000000000 ____D C:\windows\registration 2017-09-26 21:24 - 2013-02-18 19:12 - 000000000 ____D C:\Users\Marcin 2017-09-22 09:43 - 2017-06-27 16:03 - 000000000 ____D C:\Users\Marcin\Desktop\ricardo 2017-09-20 18:14 - 2017-08-18 15:20 - 000000000 ____D C:\Users\Marcin\Desktop\fff 2017-09-19 20:41 - 2017-06-09 08:39 - 000000000 ___RD C:\Users\Marcin\Desktop\WRS 2017-09-18 17:26 - 2017-01-22 21:18 - 000000000 ____D C:\Users\Marcin\ciechom 2017-09-18 10:33 - 2017-04-23 15:29 - 000000000 ____D C:\Users\Marcin\Desktop\pobrane 2017-09-18 10:32 - 2017-06-27 19:36 - 000000000 ____D C:\Users\Marcin\Desktop\publikacje 2017-09-17 15:34 - 2017-08-31 19:33 - 000000000 ____D C:\Users\Marcin\Desktop\ortezy 2017-09-17 12:54 - 2016-11-16 23:22 - 000000000 ____D C:\Users\Husky\AppData\Local\Google 2017-09-16 22:52 - 2016-12-27 14:27 - 000004412 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater 2017-09-16 22:52 - 2016-08-22 20:00 - 000004566 _____ C:\windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-09-16 22:52 - 2016-06-18 19:17 - 000803328 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2017-09-16 22:52 - 2016-06-18 19:17 - 000144896 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-09-16 22:52 - 2016-06-18 19:17 - 000000000 ____D C:\windows\SysWOW64\Macromed 2017-09-16 22:52 - 2016-06-18 19:17 - 000000000 ____D C:\windows\system32\Macromed 2017-09-16 22:39 - 2016-06-22 18:52 - 000002558 _____ C:\windows\Sandboxie.ini 2017-09-14 12:49 - 2017-07-25 22:41 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\MPC-HC 2017-09-13 20:29 - 2013-02-18 19:14 - 000000000 ____D C:\Users\Marcin\Documents\Bluetooth Exchange Folder 2017-09-12 15:26 - 2013-02-18 19:13 - 000116304 _____ C:\Users\Marcin\AppData\Local\GDIPFONTCACHEV1.DAT 2017-09-10 23:51 - 2017-04-23 15:06 - 000000000 ____D C:\Users\Marcin\Desktop\Zbior wszystkiego 2017-09-06 12:05 - 2009-07-14 05:20 - 000000000 ____D C:\windows\system32\NDF 2017-09-04 22:05 - 2016-03-15 18:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities 2017-09-04 22:05 - 2016-03-15 18:29 - 000000000 ____D C:\Program Files\Canon 2017-09-04 22:05 - 2016-03-15 18:29 - 000000000 ____D C:\Program Files (x86)\Canon ==================== Pliki w katalogu głównym wybranych folderów ======= 2017-08-11 22:04 - 2017-08-11 22:04 - 000007595 _____ () C:\Users\Marcin\AppData\Local\Resmon.ResmonCfg 2017-09-29 12:56 - 2017-09-29 12:56 - 000000000 ____H () C:\ProgramData\cm-lock ==================== Bamital & volsnap ====================== (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) C:\windows\system32\winlogon.exe => Plik podpisany cyfrowo C:\windows\system32\wininit.exe => Plik podpisany cyfrowo C:\windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo C:\windows\explorer.exe => Plik podpisany cyfrowo C:\windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo C:\windows\system32\svchost.exe => Plik podpisany cyfrowo C:\windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo C:\windows\system32\services.exe => Plik podpisany cyfrowo C:\windows\system32\User32.dll => Plik podpisany cyfrowo C:\windows\SysWOW64\User32.dll => Plik podpisany cyfrowo C:\windows\system32\userinit.exe => Plik podpisany cyfrowo C:\windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo C:\windows\system32\rpcss.dll => Plik podpisany cyfrowo C:\windows\system32\dnsapi.dll => Plik podpisany cyfrowo C:\windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo C:\windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo LastRegBack: 2017-09-27 10:22 ==================== Koniec FRST.txt ============================