Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja: 30-06-2020 Uruchomiony przez adam (administrator) DOM (GBT___ AWRDACPI) (30-06-2020 22:22:36) Uruchomiony z C:\Documents and Settings\adam\Pulpit\FRST Załadowane profile: adam Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) Język: Polski Internet Explorer Wersja 8 (Domyślna przeglądarka: Chrome) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (CyberLink -> ) [Brak podpisu cyfrowego] C:\Program Files\CyberLink\Shared Files\RichVideo.exe (France Télécom R&D) [Brak podpisu cyfrowego] C:\PROGRA~1\NEOSTR~1\TaskBarIcon.exe (France Telecom) [Brak podpisu cyfrowego] C:\WINDOWS\system32\FTRTSVC.exe (Google Inc -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe <4> (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Windows Component Publisher -> Microsoft Corporation) C:\WINDOWS\system32\alg.exe (Microsoft Windows Component Publisher -> Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe (Microsoft Windows Component Publisher -> Microsoft Corporation) C:\WINDOWS\system32\wdfmgr.exe (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe (Nero AG) [Brak podpisu cyfrowego] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG) [Brak podpisu cyfrowego] C:\Program Files\Ahead\InCD\InCDsrv.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner.exe (Sony DADC Austria AG.) [Brak podpisu cyfrowego] C:\WINDOWS\system32\UAService7.exe (Windows (R) Codename Longhorn DDK provider) [Brak podpisu cyfrowego] C:\Program Files\UPHClean\uphclean.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [WOOWATCH] => C:\Program Files\neostrada tp\Watch.exe [20480 2004-08-23] (France Télécom R&D) [Brak podpisu cyfrowego] HKLM\...\Run: [WOOTASKBARICON] => C:\Program Files\neostrada tp\GestMAJ.exe [32768 2004-10-14] (France Télécom R&D) [Brak podpisu cyfrowego] HKLM\...\Run: [SkyTel] => C:\WINDOWS\SkyTel.EXE [2879488 2006-05-16] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16207872 2006-05-18] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) HKLM\...\Run: [InCD] => C:\Program Files\Ahead\InCD\InCD.exe [1397760 2006-03-14] (Nero AG) [Brak podpisu cyfrowego] HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) HKLM\...\Run: [IMJPMIG8.1] => C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [208952 2004-08-03] (Microsoft Windows Publisher -> Microsoft Corporation) HKLM\...\Run: [IMEKRMIG6.1] => C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE [44032 2001-08-17] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\...\Run: [MSPY2002] => C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [59392 2002-08-28] (Microsoft Windows Publisher -> ) HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2002-08-28] (Microsoft Windows Publisher -> Microsoft Corporation) HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2002-08-28] (Microsoft Windows Publisher -> Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) [Brak podpisu cyfrowego] HKLM\...\Run: [ISUSPM Startup] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) [Brak podpisu cyfrowego] HKLM\...\Run: [UserFaultCheck] => %systemroot%\system32\dumprep 0 -u HKLM\...\Run: [NvCplDaemon] => C:\WINDOWS\system32\NvCpl.dll [15236544 2016-07-11] (NVIDIA Corporation -> NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] => C:\WINDOWS\system32\NvMCTray.dll [383544 2016-07-11] (NVIDIA Corporation -> NVIDIA Corporation) HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2591888 2016-07-11] (NVIDIA Corporation -> ) HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-06-14] (NVIDIA Corporation -> NVIDIA Corporation) HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKU\S-1-5-21-796845957-790525478-839522115-1003\...\Run: [PowerBar] => *********ţ**lĄ@*lĄ@*Dţ***ł7~*********ţ**&ł7~lĄ@*lĄ@***** ţ******°˙**Ź*9~0ł7~˙˙˙˙&ł7~Đx7~xţ***ţ**ŕx7~******** ****ţ**Ěţ**sä*|xţ**0***********Q*ntAł7~****************Ôď**Ď***\*******lĄ@*lĄ@*Ěţ**zw7~**** (dane wartości zawierają 59 znaków więcej). HKU\S-1-5-21-796845957-790525478-839522115-1003\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [17085056 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) HKLM\...\Windows NT x86\Print Processors\MS_XPS: C:\Windows\System32\spool\prtprocs\W32X86\filterpipelineprintproc.dll [89088 2008-07-06] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\...\Windows NT x86\Print Processors\winprint: localspl.dll HKLM\...\Print\Monitors\BJ Language Monitor: C:\WINDOWS\system32\cnbjmon.dll [49152 2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\...\Print\Monitors\PJL Language Monitor: C:\WINDOWS\system32\pjlmon.dll [15360 2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\Software\...\AppCompatFlags\Custom\MSIEXEC.EXE: [{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb] -> Microsoft Windows Application Compatibility Database HKLM\Software\...\AppCompatFlags\Custom\Nexcel.exe: [{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb] -> Microsoft Windows Application Compatibility Database HKLM\Software\...\AppCompatFlags\Custom\picture.exe: [{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb] -> Microsoft Windows Application Compatibility Database HKLM\Software\...\AppCompatFlags\Custom\xdict.exe: [{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb] -> Microsoft Windows Application Compatibility Database HKLM\Software\...\AppCompatFlags\InstalledSDB\{deb7008b-681e-4a4a-8aae-cc833e8216ce}: [DatabasePath] -> C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb [2003-06-13] HKLM\Software\Microsoft\Active Setup\Installed Components: [<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] -> C:\WINDOWS\system32\ieudinit.exe [2009-03-08] (Microsoft Windows -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] -> C:\WINDOWS\inf\unregmp2.exe [2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] -> C:\WINDOWS\system32\shmgrate.exe [2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}] -> HKLM\Software\Microsoft\Active Setup\Installed Components: [{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] -> HKLM\Software\Microsoft\Active Setup\Installed Components: [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] -> C:\Program Files\Outlook Express\setup50.exe [2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] -> C:\WINDOWS\system32\advpack.dll [2009-03-08] (Microsoft Windows -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{5945c046-1e7d-11d1-bc44-00c04fd912be}] -> C:\WINDOWS\system32\advpack.dll [2009-03-08] (Microsoft Windows -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] -> C:\WINDOWS\system32\advpack.dll [2009-03-08] (Microsoft Windows -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{7790769C-0471-11d2-AF11-00C04FA35D02}] -> C:\Program Files\Outlook Express\setup50.exe [2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe [2020-06-23] (Google Inc -> Google Inc.) HKLM\Software\...\Winlogon\GPExtensions: [{C631DF4C-088F-4156-B058-4375F0853CD8}] -> C:\WINDOWS\System32\cscui.dll [2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) Lsa: [Notification Packages] scecli scecli BootExecute: autocheck autochk * sdnclean.exe ==================== Zaplanowane zadania============================= (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job => C:\WINDOWS\system32\xp_eos.exe Task: C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job => C:\WINDOWS\system32\xp_eos.exe Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{A00985A6-C4E5-4B33-9C0B-E8893DC1C497}.job => C:\WINDOWS\system32\msfeedssync.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\..\Interfaces\{8A01679A-A278-43F5-830D-C3EB43FE678D}: [NameServer] 8.8.8.8,8.8.4.4 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-796845957-790525478-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pl-pl/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-796845957-790525478-839522115-1003 -> ${searchCLSID} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr=megaupi7s&q={searchTerms} SearchScopes: HKU\S-1-5-21-796845957-790525478-839522115-1003 -> {A3BF85EB-1C0E-4DCC-918E-9B9AFF42D76A} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr=megaupi7s&q={searchTerms} Toolbar: HKLM - Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-07-07] (Microsoft Corporation MSN -> Microsoft Corporation) Toolbar: HKU\S-1-5-21-796845957-790525478-839522115-1003 -> Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-07-07] (Microsoft Corporation MSN -> Microsoft Corporation) DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {31435657-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} DPF: {68282C51-9459-467B-95BF-3C0E89627E55} hxxp://www.mks.com.pl/skaner/SkanerOnline.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll [2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll [2007-01-19] (Microsoft Corporation -> Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll [2007-01-19] (Microsoft Corporation -> Microsoft Corporation) FireFox: ======== FF DefaultProfile: h387udkw.default FF DefaultProfile: pb37smz4.default FF ProfilePath: C:\Documents and Settings\adam\Dane aplikacji\org.wicknix\Arctic Fox\Profiles\h387udkw.default [2020-06-21] FF ProfilePath: C:\Documents and Settings\adam\Dane aplikacji\Mypal\Profiles\pb37smz4.default [2020-06-30] FF Extension: (Adblock Latitude) - C:\Documents and Settings\adam\Dane aplikacji\Mypal\Profiles\pb37smz4.default\Extensions\adblocklatitude@addons.palemoon.org.xpi [2020-06-14] [Przestarzałe] [Brak podpisu cyfrowego] FF Extension: (uBlock Origin) - C:\Documents and Settings\adam\Dane aplikacji\Mypal\Profiles\pb37smz4.default\Extensions\uBlock0@raymondhill.net.xpi [2020-06-23] [Przestarzałe] [Brak podpisu cyfrowego] FF ProfilePath: C:\Documents and Settings\adam\Dane aplikacji\Mozilla\Firefox\Profiles\9m1fkhk6.default-1567556013484 [2020-06-30] FF Extension: (Hotfix for Firefox bug 1548973 (armagaddon 2.0) mitigation) - C:\Documents and Settings\adam\Dane aplikacji\Mozilla\Firefox\Profiles\9m1fkhk6.default-1567556013484\features\{9768d2d2-5748-4597-95a4-653e01d86868}\hotfix-bug-1548973@mozilla.org.xpi [2019-09-04] [Przestarzałe] FF ProfilePath: C:\Documents and Settings\adam\Dane aplikacji\Moonchild Productions\Pale Moon\Profiles\xi221gzv.default [2020-06-30] FF Homepage: C:\Documents and Settings\adam\Dane aplikacji\Moonchild Productions\Pale Moon\Profiles\xi221gzv.default -> hxxps://palemoon.start.me/ FF Extension: (Adblock Latitude) - C:\Documents and Settings\adam\Dane aplikacji\Moonchild Productions\Pale Moon\Profiles\xi221gzv.default\Extensions\adblocklatitude@addons.palemoon.org.xpi [2018-11-25] [Przestarzałe] [Brak podpisu cyfrowego] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: (Brak nazwy) - C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-12-25] [Brak podpisu cyfrowego] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: (Microsoft .NET Framework Assistant) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-21] [Przestarzałe] [Brak podpisu cyfrowego] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_32_0_0_344.dll [2020-03-20] (Adobe Inc. -> ) [Brak podpisu cyfrowego] FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [Brak pliku] FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [Brak pliku] FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-04-27] (RealNetworks, Inc. -> RealNetworks, Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems, Incorporated -> Adobe Systems Inc.) FF Plugin: yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1 -> C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll [2007-03-10] (Yahoo! Inc. -> Yahoo! Inc.) Chrome: ======= CHR Profile: C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default [2020-06-30] CHR Extension: (Slides) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-06-23] CHR Extension: (Docs) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-06-23] CHR Extension: (Google Drive) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-06-23] CHR Extension: (YouTube) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-06-23] CHR Extension: (Sheets) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-06-23] CHR Extension: (Google Docs Offline) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-06-23] CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-06-23] CHR Extension: (Gmail) - C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-06-23] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 FTRTSVC; C:\WINDOWS\System32\FTRTSVC.exe [40960 2004-08-23] (France Telecom) [Brak podpisu cyfrowego] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Brak podpisu cyfrowego] R2 InCDsrv; C:\Program Files\Ahead\InCD\InCDsrv.exe [871424 2005-07-08] (Nero AG) [Brak podpisu cyfrowego] R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4753104 2018-05-09] (Malwarebytes Corporation -> Malwarebytes) S3 MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [53337 2005-01-26] (Sony Corporation) [Brak podpisu cyfrowego] R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation -> NVIDIA Corporation) S3 PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [53337 2005-01-26] (Sony Corporation) [Brak podpisu cyfrowego] S3 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [66872 2020-05-11] (Even Balance, Inc. -> ) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [171040 2007-01-08] (CyberLink -> ) [Brak podpisu cyfrowego] S3 SPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [69718 2005-01-26] (Sony Corporation) [Brak podpisu cyfrowego] S3 SwPrv; C:\WINDOWS\System32\dllhost.exe /Processid:{E77DF6D1-0608-4071-B8C0-029D384224ED} [5120 2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) R2 UPHClean; C:\Program Files\UPHClean\uphclean.exe [399872 2010-09-13] (Windows (R) Codename Longhorn DDK provider) [Brak podpisu cyfrowego] R2 UserAccess7; C:\WINDOWS\system32\UAService7.exe [135168 2017-02-25] (Sony DADC Austria AG.) [Brak podpisu cyfrowego] ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 ac97intc; C:\WINDOWS\System32\drivers\ac97intc.sys [96256 2001-08-17] (Microsoft Windows Component Publisher -> Intel Corporation) S3 alcan5wn; C:\WINDOWS\System32\DRIVERS\alcan5wn.sys [53600 2003-12-08] (Microsoft Windows Hardware Compatibility Publisher -> THOMSON) S3 alcaudsl; C:\WINDOWS\System32\DRIVERS\alcaudsl.sys [70688 2003-12-08] (Microsoft Windows Hardware Compatibility Publisher -> THOMSON) R2 Aspi32; C:\Windows\System32\Drivers\Aspi32.sys [25244 1999-09-10] (Adaptec) [Brak podpisu cyfrowego] R3 b57w2k; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [126720 2004-12-06] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom Corporation) S3 dtproscsibus; C:\WINDOWS\System32\DRIVERS\dtproscsibus.sys [25104 2015-04-26] (Disc Soft Ltd -> Disc Soft Ltd) R2 EIO; C:\WINDOWS\system32\drivers\EIO.sys [11264 2005-10-19] (ASUSTeK Computer Inc.) [Brak podpisu cyfrowego] S3 ET5Drv; C:\WINDOWS\System32\Drivers\ET5Drv.sys [186584 2004-09-21] (Microsoft Corporation) [Brak podpisu cyfrowego] R1 FsVga; C:\WINDOWS\System32\DRIVERS\fsvga.sys [12288 2001-10-26] (Microsoft Windows Component Publisher -> Microsoft Corporation) S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [25280 2007-11-12] (LogMeIn, Inc. -> LogMeIn, Inc.) R3 HDAudBus; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Microsoft Windows Component Publisher -> Windows (R) Server 2003 DDK provider) R4 InCDfs; C:\Windows\System32\Drivers\InCDfs.sys [99584 2005-07-08] (Nero AG) [Brak podpisu cyfrowego] R1 InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [29696 2005-07-08] (Nero AG) [Brak podpisu cyfrowego] U1 InCDrec; C:\Windows\System32\Drivers\InCDrec.sys [8704 2005-07-08] (Nero AG) [Brak podpisu cyfrowego] R1 incdrm; C:\Windows\System32\Drivers\incdrm.sys [28672 2006-03-14] (Nero AG) [Brak podpisu cyfrowego] R3 IntcAzAudAddService; C:\WINDOWS\System32\drivers\RtkHDAud.sys [4275712 2006-05-16] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) R0 iteraid; C:\WINDOWS\System32\DRIVERS\iteraid.sys [25067 2004-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Integrated Technology Express, Inc.) R1 kbfilter; C:\Windows\System32\Drivers\kbfilter.sys [11776 2003-03-27] (WayTech Development, Inc.) [Brak podpisu cyfrowego] S3 keycrypt; C:\WINDOWS\System32\DRIVERS\KeyCrypt32.sys [142344 2016-08-11] (Zemana Ltd. -> Zemana Ltd.) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [220896 2020-06-30] (Malwarebytes Corporation -> Malwarebytes) R1 moufiltr; C:\Windows\System32\Drivers\moufiltr.sys [8448 2004-10-11] (Windows (R) 2000 DDK provider) [Brak podpisu cyfrowego] R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [145608 2016-07-11] (NVIDIA Corporation -> NVIDIA Corporation) S3 PCANDIS5; C:\WINDOWS\system32\PCANDIS5.SYS [16128 2003-08-04] (Printing Communications Assoc., Inc. (PCAUSA)) [Brak podpisu cyfrowego] R3 Ptilink; C:\WINDOWS\System32\DRIVERS\ptilink.sys [17792 2001-08-17] (Microsoft Windows Component Publisher -> Parallel Technologies, Inc.) U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Windows Component Publisher -> Microsoft Corporation) R2 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [20480 2008-04-13] (Microsoft Windows Component Publisher -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) S3 SER120; C:\WINDOWS\System32\DRIVERS\SER120.sys [32910 2005-03-22] (USB Com port.) [Brak podpisu cyfrowego] R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [721904 2009-08-18] () [Brak podpisu cyfrowego] [Plik w użyciu] S3 Video3D; C:\WINDOWS\System32\Drivers\Video3D32.sys [16000 2005-09-27] () [Brak podpisu cyfrowego] S3 cpuz140; \??\C:\DOCUME~1\adam\USTAWI~1\Temp\cpuz140\cpuz140_x32.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) =================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) Error(1) reading file: "C:\Documents and Settings\adam\Pulpit\Deadpool Team-Up 891 (2010) Minutemen-XxxX.cbr " 2020-06-30 22:02 - 2020-06-30 22:22 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\FRST 2020-06-30 21:47 - 2020-06-30 21:47 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\txt z pulp 2020-06-27 15:57 - 2020-06-27 15:57 - 000081772 _____ C:\Documents and Settings\adam\Pulpit\37q31-justpasteit.pdf 2020-06-23 16:31 - 2020-06-30 21:03 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\solounique 2020-06-23 15:46 - 2020-06-23 16:23 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\DDU 2020-06-23 15:41 - 2020-06-23 15:43 - 219985952 _____ (NVIDIA Corporation) C:\Documents and Settings\adam\Pulpit\368.81-desktop-winxp-32bit-international.exe 2020-06-23 13:08 - 2020-06-30 22:16 - 000000878 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2020-06-23 13:08 - 2020-06-30 22:13 - 000000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2020-06-23 13:07 - 2020-06-23 13:07 - 000001826 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome.lnk 2020-06-23 13:07 - 2020-06-23 13:07 - 000001820 _____ C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk 2020-06-23 04:23 - 2020-06-30 21:03 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\NAH 2020-06-23 01:58 - 2020-06-23 02:25 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\Note 2020-06-23 00:58 - 2020-06-23 00:58 - 000222648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5536E6C8.sys 2020-06-23 00:57 - 2020-06-23 00:57 - 000222648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\257673EE.sys 2020-06-23 00:55 - 2020-06-23 00:55 - 000222648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\4171B79C.sys 2020-06-23 00:27 - 2020-06-23 00:27 - 000222648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2461D3FE.sys 2020-06-22 23:45 - 2020-06-22 23:45 - 000150816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2020-06-21 13:05 - 2020-06-30 21:03 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\KMCavisandsigs 2020-06-21 11:22 - 2020-06-21 11:22 - 000000000 ____D C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\org.wicknix 2020-06-21 11:22 - 2020-06-21 11:22 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\Arktyczny Lis 2020-06-21 11:22 - 2020-06-21 11:22 - 000000000 ____D C:\Documents and Settings\adam\Dane aplikacji\org.wicknix 2020-06-21 00:21 - 2020-06-21 00:21 - 000000766 _____ C:\Documents and Settings\All Users\Pulpit\System Ninja.lnk 2020-06-21 00:21 - 2020-06-21 00:21 - 000000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\System Ninja 2020-06-21 00:20 - 2020-06-30 22:10 - 000000000 ____D C:\Program Files\System Ninja 2020-06-20 16:07 - 2020-06-20 16:07 - 000000683 _____ C:\Documents and Settings\All Users\Pulpit\CCleaner.lnk 2020-06-20 16:07 - 2020-06-20 16:07 - 000000000 ____D C:\Program Files\CCleaner 2020-06-20 16:07 - 2020-06-20 16:07 - 000000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\CCleaner 2020-06-20 15:53 - 2020-06-21 13:34 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\Ninja 2020-06-20 15:10 - 2020-06-30 22:17 - 000220896 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2020-06-20 15:10 - 2020-06-20 15:10 - 000001716 _____ C:\Documents and Settings\All Users\Pulpit\Malwarebytes.lnk 2020-06-20 15:10 - 2020-06-20 15:10 - 000000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes 2020-06-20 15:10 - 2018-04-26 05:36 - 000128736 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae.sys 2020-06-20 15:09 - 2020-06-20 15:09 - 000000000 ____D C:\Program Files\Malwarebytes 2020-06-18 15:05 - 2020-06-30 21:47 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\akcjapulpit 2020-06-18 08:08 - 2020-06-20 12:23 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\Reinstalka Chrome 2020-06-15 17:29 - 2020-06-15 17:29 - 000000683 _____ C:\Documents and Settings\adam\Pulpit\Skrót do uphclean.exe.lnk 2020-06-15 17:27 - 2020-06-15 17:27 - 000000000 ____D C:\Program Files\UPHClean 2020-06-14 03:40 - 2020-06-14 03:42 - 000000000 ____D C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Mypal 2020-06-14 03:40 - 2020-06-14 03:40 - 000000000 ____D C:\Documents and Settings\adam\Dane aplikacji\Mypal 2020-06-14 03:39 - 2020-06-14 03:39 - 000000645 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Mypal.lnk 2020-06-14 03:39 - 2020-06-14 03:39 - 000000639 _____ C:\Documents and Settings\All Users\Pulpit\Mypal.lnk 2020-06-14 03:39 - 2020-06-14 03:39 - 000000000 ____D C:\Program Files\Mypal 2020-06-14 03:31 - 2020-06-14 03:31 - 000144643 _____ C:\Documents and Settings\adam\Pulpit\bookmarks.html 2020-06-12 19:41 - 2020-06-14 22:48 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\copy 2020-06-11 09:56 - 2020-06-11 09:56 - 000222648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\1341795B.sys 2020-06-11 09:45 - 2020-06-11 09:45 - 000222648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\42227ED5.sys 2020-06-11 09:43 - 2020-06-11 09:43 - 000222648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\7355628C.sys 2020-06-11 04:00 - 2020-06-17 09:51 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\NeoSet 2020-06-06 18:21 - 2020-06-06 18:22 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\Cyberlore Stuff 2020-06-06 03:25 - 2020-06-30 22:24 - 000000000 ____D C:\FRST 2020-06-06 00:17 - 2020-06-06 00:17 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\VOLUME 2 2020-06-04 16:21 - 2020-06-04 16:22 - 042711440 _____ C:\Documents and Settings\adam\Pulpit\Wolverine Special 102.5 (1996) (Digital) (Shadowcat-Empire).cbz 2020-06-02 15:07 - 2020-06-30 21:03 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\desktopgarbage 2020-05-31 00:29 - 2020-05-31 00:29 - 000000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\ClamAV ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-06-30 22:27 - 2006-11-02 19:30 - 000000000 ____D C:\Documents and Settings\adam\Ustawienia lokalne\Temp 2020-06-30 22:24 - 2016-06-28 19:19 - 000032424 _____ C:\WINDOWS\SchedLgU.Txt 2020-06-30 22:24 - 2015-02-19 13:10 - 000000460 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{A00985A6-C4E5-4B33-9C0B-E8893DC1C497}.job 2020-06-30 22:21 - 2006-11-02 19:30 - 000000000 ____D C:\Documents and Settings\adam\Pulpit 2020-06-30 22:20 - 2019-06-01 10:49 - 000015832 _____ C:\WINDOWS\system32\nvAppTimestamps 2020-06-30 22:16 - 2015-02-19 13:06 - 000000220 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2020-06-30 22:16 - 2006-12-30 17:24 - 000000000 ____D C:\Program Files\neostrada tp 2020-06-30 22:16 - 2006-11-02 19:27 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-06-30 22:16 - 2001-07-22 00:17 - 000012984 _____ C:\WINDOWS\system32\wpa.dbl 2020-06-30 22:14 - 2006-11-02 19:30 - 000000292 ___SH C:\Documents and Settings\adam\ntuser.ini 2020-06-30 22:13 - 2006-11-02 19:30 - 000000000 __SHD C:\Documents and Settings\adam\Ustawienia lokalne\Historia 2020-06-30 22:10 - 2015-02-19 13:00 - 000065536 _____ C:\WINDOWS\system32\config\Internet.evt 2020-06-30 22:10 - 2013-09-03 19:53 - 000065536 _____ C:\WINDOWS\system32\config\TuneUp.evt 2020-06-30 22:10 - 2010-08-20 14:31 - 000065536 _____ C:\WINDOWS\system32\config\AMPingLo.evt 2020-06-30 22:09 - 2006-11-02 19:30 - 000000000 ____D C:\Documents and Settings\adam 2020-06-30 22:07 - 2018-11-11 21:58 - 000000000 ____D C:\Documents and Settings\adam\Dane aplikacji\MPC-HC 2020-06-30 21:47 - 2006-11-02 19:30 - 000000000 ___RD C:\Documents and Settings\adam\Moje dokumenty 2020-06-30 21:03 - 2020-05-18 06:05 - 000000000 ____D C:\Program Files\Defraggler 2020-06-30 21:03 - 2020-05-11 00:09 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\tuq 2020-06-30 21:03 - 2020-04-18 14:05 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\cak 2020-06-30 21:03 - 2020-01-20 03:43 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\pvk2 2020-06-30 21:03 - 2019-02-24 01:40 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\Vqz 2020-06-30 21:03 - 2018-01-04 04:26 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\New Downloads 2020-06-30 21:03 - 2015-03-06 00:21 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\Pobrane 2020-06-30 21:03 - 2006-11-02 19:30 - 000000000 ___RD C:\Documents and Settings\adam\Moje dokumenty\Moje obrazy 2020-06-30 19:54 - 2018-08-04 13:30 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\Wolverine 001-020 (1988-1990) (Digital) 2020-06-30 17:18 - 2018-01-04 03:19 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\reg back 2020-06-30 13:13 - 2006-11-02 19:30 - 000000000 ___HD C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji 2020-06-26 17:42 - 2015-09-24 21:11 - 001047100 _____ C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-796845957-790525478-839522115-1003-0.dat 2020-06-26 17:42 - 2015-03-21 02:58 - 000218854 _____ C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat 2020-06-23 17:02 - 2007-08-03 05:31 - 000001984 _____ C:\WINDOWS\system32\d3d9caps.dat 2020-06-23 13:07 - 2007-01-14 02:27 - 000000000 ____D C:\Program Files\Google 2020-06-23 13:07 - 2007-01-14 02:27 - 000000000 ____D C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Google 2020-06-23 13:07 - 2006-11-02 19:03 - 000000000 ____D C:\Documents and Settings\All Users\Pulpit 2020-06-23 13:07 - 2006-11-02 19:03 - 000000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy 2020-06-23 00:59 - 2017-05-23 19:49 - 000000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes' Anti-Malware (portable) 2020-06-21 14:20 - 2016-11-08 07:46 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\lelkav2 2020-06-21 12:49 - 2015-03-05 03:43 - 000000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Java 2020-06-21 12:47 - 2020-05-20 15:22 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\Franc and others 2020-06-21 12:47 - 2020-05-18 03:07 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\angiev 2020-06-21 12:47 - 2020-05-11 01:52 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\apaczs 2020-06-21 12:47 - 2020-05-04 02:51 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\most harley stuff 2020-06-21 12:47 - 2020-04-19 00:41 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\kat bry 2020-06-21 12:47 - 2020-04-16 13:30 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\fbwczor 2020-06-21 12:47 - 2020-04-16 12:23 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\wolverinecards 2020-06-21 12:47 - 2020-04-04 02:39 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\katr 2020-06-21 12:47 - 2020-03-31 21:26 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\xyj 2020-06-21 12:47 - 2020-03-20 15:14 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\nowosci 2020-06-21 12:47 - 2020-03-15 13:59 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\mij 2020-06-21 12:47 - 2019-11-02 22:09 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\olivka 2020-06-21 12:47 - 2019-08-20 21:30 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\oa 2020-06-21 12:47 - 2019-07-27 03:16 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\curuxa 2020-06-21 12:47 - 2019-07-23 17:56 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\dziejkaz 2020-06-21 12:47 - 2019-04-22 17:26 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\jad 2020-06-21 12:47 - 2018-12-16 23:20 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\Eqz 2020-06-21 12:47 - 2018-11-26 13:29 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\sylkov 2020-06-21 12:47 - 2018-11-13 02:32 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\klin 2020-06-21 12:47 - 2018-07-29 02:18 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\JSpr2 2020-06-21 12:47 - 2017-09-09 15:59 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\ki 2020-06-21 12:47 - 2017-08-21 23:31 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\natq 2020-06-21 12:47 - 2017-07-12 05:08 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\glazura 2020-06-21 12:47 - 2017-03-03 22:04 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\werq 2020-06-21 12:47 - 2017-03-02 22:19 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\asiarc 2020-06-21 12:47 - 2017-02-22 20:30 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\maxf 2020-06-21 12:47 - 2017-02-13 20:37 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\K@P0 2020-06-21 12:47 - 2017-02-12 00:15 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\missalexis luty 17 2020-06-21 12:47 - 2017-01-01 20:54 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\imm 2020-06-21 12:47 - 2016-09-19 02:27 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\KG 2020-06-21 12:47 - 2016-08-30 14:09 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\83joanna89 2020-06-21 12:47 - 2016-08-20 18:28 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\ec2 2020-06-21 12:47 - 2016-08-02 01:55 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\Wolverine Respect 2020-06-21 12:47 - 2016-03-18 20:36 - 000000000 ____D C:\Program Files\porządek 2020-06-21 12:47 - 2015-08-03 19:12 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\JJ 2020-06-21 12:47 - 2015-06-29 02:07 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\mix czerw 2020-06-21 12:47 - 2015-05-13 21:39 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\mix2 2020-06-21 12:47 - 2015-03-29 01:13 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\Monika M 2020-06-21 12:47 - 2006-11-15 22:34 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\Rózne 2020-06-21 12:35 - 2009-08-29 14:29 - 000000000 ____D C:\Program Files\Java 2020-06-21 11:22 - 2006-11-02 19:30 - 000000000 ___HD C:\Documents and Settings\adam\Dane aplikacji 2020-06-20 15:47 - 2020-05-18 03:53 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\PIRIFORM 2020-06-20 15:09 - 2019-02-01 22:39 - 000000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes 2020-06-18 15:04 - 2020-03-12 14:22 - 000000000 ____D C:\Documents and Settings\adam\Pulpit\new2 2020-06-18 08:18 - 2019-08-23 00:45 - 000000000 ____D C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Adblock Plus for IE 2020-06-14 22:34 - 2006-11-02 19:57 - 000000000 RSHDC C:\WINDOWS\system32\dllcache 2020-06-09 23:26 - 2006-11-04 23:52 - 000000116 _____ C:\WINDOWS\NeroDigital.ini 2020-06-08 15:00 - 2015-02-19 13:06 - 000000214 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job 2020-06-07 16:37 - 2006-11-02 19:30 - 000000000 ___HD C:\Documents and Settings\NetworkService\Ustawienia lokalne\Historia 2020-06-06 15:47 - 2007-04-11 18:50 - 000000008 __RSH C:\Documents and Settings\All Users\ntuser.pol 2020-06-06 15:47 - 2006-11-02 19:02 - 000000000 ____D C:\Documents and Settings\All Users 2020-06-06 15:36 - 2006-11-02 19:35 - 000000000 ___SD C:\Documents and Settings\Administrator\Ustawienia lokalne\Historia 2020-06-06 15:36 - 2006-11-02 19:30 - 000000000 ___HD C:\Documents and Settings\LocalService\Ustawienia lokalne\Historia 2020-06-06 15:36 - 2006-11-02 19:03 - 000000000 __SHD C:\Documents and Settings\Default User\Ustawienia lokalne\Historia 2020-06-06 15:35 - 2007-04-11 18:49 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2020-06-04 03:11 - 2007-06-27 21:34 - 000000000 ____D C:\Documents and Settings\adam\Moje dokumenty\Soul Reaver 2 2020-06-02 20:54 - 2020-05-29 22:08 - 000000000 ____D C:\Program Files\SecureAge 2020-06-02 16:11 - 2006-11-02 19:57 - 000000000 ____D C:\WINDOWS\security 2020-06-02 16:05 - 2019-09-18 19:53 - 000000000 ____D C:\Documents and Settings\adam\Dane aplikacji\Everything 2020-05-31 00:29 - 2006-11-02 19:03 - 000000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji ==================== Pliki w katalogu głównym wybranych folderów ======== 2006-11-04 20:08 - 2004-10-01 16:00 - 000040960 _____ () C:\Program Files\Uninstall_CDS.exe 2019-09-08 17:16 - 2019-09-08 17:16 - 000000036 _____ () C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\housecall.guid.cache 2013-10-21 20:41 - 2019-07-27 19:07 - 000000101 _____ () C:\Documents and Settings\adam\Ustawienia lokalne\Dane aplikacji\Images.fl 2013-09-25 04:39 - 2013-09-25 04:39 - 000050439 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1380076721.bdinstall.bin 2013-09-25 04:52 - 2013-09-25 04:52 - 000030778 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1380077398.bdinstall.bin 2013-09-25 04:55 - 2013-09-25 04:55 - 000030040 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1380077584.bdinstall.bin 2013-09-29 17:12 - 2013-09-29 17:12 - 000056105 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1380467504.bdinstall.bin 2013-10-02 12:03 - 2013-10-02 12:03 - 000055860 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1380707873.bdinstall.bin 2013-10-05 16:49 - 2013-10-05 16:49 - 000055976 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1380984522.bdinstall.bin 2013-11-18 14:06 - 2013-11-18 14:06 - 000055332 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1384776315.bdinstall.bin 2013-11-21 19:34 - 2013-11-21 19:34 - 000054258 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385055214.bdinstall.bin 2013-11-24 15:46 - 2013-11-24 15:46 - 000054257 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385300770.bdinstall.bin 2013-11-24 16:17 - 2013-11-24 16:17 - 000054102 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385302597.bdinstall.bin 2013-11-24 16:47 - 2013-11-24 16:47 - 000054124 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385304424.bdinstall.bin 2013-11-24 17:18 - 2013-11-24 17:18 - 000053945 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385306269.bdinstall.bin 2013-11-24 17:48 - 2013-11-24 17:48 - 000053944 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385308105.bdinstall.bin 2013-11-24 18:19 - 2013-11-24 18:19 - 000053942 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385309933.bdinstall.bin 2013-11-24 18:50 - 2013-11-24 18:50 - 000053945 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385311786.bdinstall.bin 2013-11-24 19:33 - 2013-11-24 19:33 - 000032383 _____ () C:\Documents and Settings\All Users\Dane aplikacji\1385314042.bdinstall.bin 2007-11-04 15:07 - 2007-11-10 05:12 - 000003155 _____ () C:\Documents and Settings\All Users\Dane aplikacji\QTSBandwidthCache ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================