Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 09-01-2023 Uruchomiony przez Ahmed (administrator) AHMED (MSI MS-7971) (10-01-2023 15:59:57) Uruchomiony z C:\Users\Ahmed\Downloads Załadowane profile: Ahmed Platform: Microsoft Windows 10 Home Wersja 2004 19041.572 (X64) Język: Polski (Polska) Domyślna przeglądarka: Chrome Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe (C:\Program Files\Avid\Avid Link\Avid Link.exe ->) (Avid Technology, Inc. -> Avid Technology, Inc.) C:\Program Files\Avid\Avid Link\AvidAppManHelper.exe (C:\Program Files\Avid\Avid Link\Avid Link.exe ->) (The Qt Company Ltd.) [Brak podpisu cyfrowego] C:\Program Files\Avid\Avid Link\QtWebEngineProcess.exe <7> (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (explorer.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <5> (explorer.exe ->) (Avid Technology, Inc. -> Avid Technology, Inc.) C:\Program Files\Avid\Avid Link\Avid Link.exe (explorer.exe ->) (Focusrite Audio Engineering, Ltd.) [Brak podpisu cyfrowego] C:\Program Files\Focusriteusb\Focusrite Notifier.exe (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <11> (explorer.exe ->) (Lyrha Software Technologies Inc. -> ) C:\Users\Ahmed\AppData\Roaming\SteamServerBrowser\SteamServerBrowser.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <8> (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (explorer.exe ->) (ResolveDevOps Limited -> ResolveDevOps Limited) C:\Users\Ahmed\AppData\Roaming\ProductAuthenticationService\pas.exe (Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\afwServ.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe (services.exe ->) (Avid Technology, Inc. -> Avid Technology, Inc.) C:\Program Files\Avid\Cloud Client Services\Hub.exe (services.exe ->) (Avid Technology, Inc. -> Avid Technology, Inc.) C:\Program Files\Avid\Cloud Client Services\TransportClient.exe (services.exe ->) (Avid Technology, Inc.) [Brak podpisu cyfrowego] C:\Program Files\Avid\Pro Tools\MMERefresh.exe (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) D:\Program Files\Origin\OriginWebHelperService.exe (services.exe ->) (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe (services.exe ->) (Focusrite Audio Engineering Ltd.) [Brak podpisu cyfrowego] D:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe (services.exe ->) (Glarysoft LTD -> Glarysoft Ltd) D:\Glary Utilities 5\GUBootService.exe (services.exe ->) (Glarysoft LTD -> Glarysoft Ltd) D:\Glary Utilities 5\GUPMService.exe (services.exe ->) (Global Media (Thailand) Co., Ltd -> Global Media (Thailand) Co., Ltd) C:\Program Files (x86)\MaskVPN\mask_svc.exe (services.exe ->) (ICEpower a/s -> ICEpower) C:\Windows\System32\ICEsoundService64.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe (services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_fc9ac11e55f51133\RstMwService.exe (services.exe ->) (LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe (services.exe ->) (LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_47917a79b8c7fd22\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (PACE Anti-Piracy, Inc. -> PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe (services.exe ->) (Samsung Electronics CO., LTD. -> ) C:\Windows\SysWOW64\SecUPDUtilSvc.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102832 2021-07-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [Focusrite Notifier] => C:\Program Files\Focusriteusb\Focusrite Notifier.exe [5029376 2020-06-02] (Focusrite Audio Engineering, Ltd.) [Brak podpisu cyfrowego] HKLM\...\Run: [DigidesignMMERefresh] => C:\Program Files\Avid\Pro Tools\MMERefresh.exe [117760 2016-03-25] (Avid Technology, Inc.) [Brak podpisu cyfrowego] HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [215960 2023-01-10] (Avast Software s.r.o. -> AVAST Software) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle America, Inc. -> Oracle Corporation) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Ograniczenia <==== UWAGA HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Ograniczenia <==== UWAGA HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626448 2022-12-14] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\Run: [GUDelayStartup] => D:\Glary Utilities 5\StartupManager.exe [44416 2021-11-15] (Glarysoft LTD -> Glarysoft Ltd) HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\Run: [SteamServerBrowser] => C:\Users\Ahmed\AppData\Roaming\SteamServerBrowser\SteamServerBrowser.exe [289304 2022-01-05] (Lyrha Software Technologies Inc. -> ) HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\Run: [ProductAuthenticationService] => C:\Users\Ahmed\AppData\Roaming\ProductAuthenticationService\pas.exe [1004072 2022-01-05] (ResolveDevOps Limited -> ResolveDevOps Limited) <==== UWAGA HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\Run: [MicrosoftEdgeAutoLaunch_6B3E6219F6F471CE7E4C506DD147F3B3] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3879368 2023-01-05] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\Policies\Explorer\DisallowRun: [1] irsetup.exe HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\MountPoints2: F - "F:\setup.exe" HKU\S-1-5-21-1306247612-828193906-1523655640-1001\...\MountPoints2: L - "L:\AutoRun.exe" --autorun HKLM\...\Windows x64\Print Processors\us015PC: C:\Windows\System32\spool\prtprocs\x64\us015pc.dll [52088 2019-08-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider) HKLM\...\Print\Monitors\us008 Langmon: C:\WINDOWS\system32\us008lm.dll [31256 2019-11-02] (Microsoft Windows Hardware Compatibility Publisher -> ) HKLM\...\Print\Monitors\us015 Langmon: C:\WINDOWS\system32\us015lm.dll [31096 2019-08-26] (Microsoft Windows Hardware Compatibility Publisher -> ) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\108.0.5359.125\Installer\chrmstp.exe [2022-12-16] (Google LLC -> Google LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Link.lnk [2021-02-18] ShortcutTarget: Avid Link.lnk -> C:\Program Files\Avid\Avid Link\Avid Link.exe (Avid Technology, Inc. -> Avid Technology, Inc.) BootExecute: autocheck autochk * HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ============ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {0BB2220E-68F0-4D85-9AB0-D83CA7137AB6} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1306247612-828193906-1523655640-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation) Task: {225839B1-C9EB-4390-9435-144FD338E20B} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {23F39A6E-5670-4945-8D77-FDAC0F6AEC33} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-26] (Google Inc -> Google LLC) Task: {29EC7DAC-7532-448E-A893-B318A10C5934} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {2C4DE01C-F396-4738-B419-5BB51AA025AA} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {4068187E-D8C1-48FA-8CDB-9A04218C13D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-10-26] (Google Inc -> Google LLC) Task: {47AD6C44-F8EE-4540-B780-70C8A02B37DF} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-01] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {571766B3-6DFF-4B60-BB49-D5B2C4D66DC5} - System32\Tasks\Update Manager => C:\Users\Ahmed\AppData\Roaming\Metal.Gear.Solid.V.The.Phantom.Pain-ALI213\Upgrade.exe /upgradeid=f561932c-0bef-41b9-9289-b7d5c099b86b (Brak pliku) Task: {6816747F-1A5B-4FFB-ACC2-3DE0A5F2DA00} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-17] (Microsoft Corporation -> Microsoft Corporation) Task: {6F21B371-F095-4486-8C7C-58EE559B9A35} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144344 2022-12-17] (Microsoft Corporation -> Microsoft Corporation) Task: {740A5C89-221A-46DA-9C1A-61F61E613639} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe [818008 2021-09-15] (Intel Corporation -> Intel(R) Corporation) Task: {7831EE9B-5A77-43C4-99E2-8EF98C42BBA1} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4954008 2023-01-10] (Avast Software s.r.o. -> AVAST Software) Task: {7C29531B-681F-4D8F-BB8E-9A3EAFEA0B0C} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {85D87220-C6BC-4FA3-ABA6-FBAA24A8E84A} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [146816 2022-12-10] (Microsoft Corporation -> Microsoft Corporation) Task: {905F73B1-B533-4867-AC3E-5C2235B069AB} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2311576 2023-01-10] (Avast Software s.r.o. -> Avast Software) Task: {9763A49A-0F4C-4199-896C-61D8F6292BDF} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342080 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {A3758437-F71B-43FD-A085-D18AD7984A21} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [646344 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {AAD60028-623F-4ACC-A9BA-D38EA2506F3E} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [906752 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) Task: {B1AF7A31-9B50-40F2-A936-F120EF709423} - System32\Tasks\Microsoft\Windows\NetFramework\Microsoft .NET Framework => C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe -pool us1.ethermine.org:4444 -pool2 us2.ethermine.org:4444 -wal 0xf6c75E7D9557a97E576308C55b93d82C8a8a05C8.MyRig -proto 3 (Brak pliku) Task: {D3C1DFF6-D6B6-441B-86DD-1063E6D7321B} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-17] (Microsoft Corporation -> Microsoft Corporation) Task: {E0CAA929-9056-4270-BF61-EE8C6B3BD6C5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26308584 2022-12-17] (Microsoft Corporation -> Microsoft Corporation) Task: {E4563441-3F39-4CF1-983C-FF9BA08DBE6A} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189072 2022-12-14] (Microsoft Corporation -> Microsoft Corporation) Task: {F358A968-2253-4FDD-8BE5-74E74600A4B6} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1654272 2022-03-30] (Nvidia Corporation -> NVIDIA Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.) Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{656f287a-4d8e-4de3-b7d1-849ade78ab6f}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{b36dfe1a-a810-4a02-b702-bcaee67d0623}: [DhcpNameServer] 192.168.1.1 Edge: ======= DownloadDir: C:\Users\Ahmed\Downloads Edge DefaultProfile: Default Edge Profile: C:\Users\Ahmed\AppData\Local\Microsoft\Edge\User Data\Default [2023-01-10] Edge DownloadDir: Default -> C:\Users\Ahmed\Downloads Edge Notifications: Default -> hxxps://drive.google.com Edge Extension: (Outlook) - C:\Users\Ahmed\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjhmmnoficofgoiacjaajpkfndojknpb [2020-10-16] Edge Extension: (Adblock Plus - darmowy adblocker) - C:\Users\Ahmed\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2022-12-24] Edge Extension: (Word) - C:\Users\Ahmed\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hikhggiobiflkdfdgdajcfklmcibbopi [2020-10-16] Edge Extension: (Excel) - C:\Users\Ahmed\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\leffmjdabcgaflkikcefahmlgpodjkdm [2020-10-16] Edge Extension: (PowerPoint) - C:\Users\Ahmed\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\opfacbhaojodjaojgocnibmklknchehf [2020-10-16] FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2022-10-13] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2022-10-13] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [Brak podpisu cyfrowego] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR Profile: C:\Users\Ahmed\AppData\Local\Google\Chrome\User Data\Default [2023-01-10] CHR Notifications: Default -> hxxps://aternos.org; hxxps://www.pyszne.pl CHR StartupUrls: Default -> "hxxps://www.google.com/" CHR Extension: (Safe Torrent Scanner) - C:\Users\Ahmed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2022-06-14] CHR Extension: (Dokumenty Google offline) - C:\Users\Ahmed\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-11-22] CHR Extension: (AdBlock — najlepszy bloker reklam) - C:\Users\Ahmed\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-12-20] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Ahmed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29] CHR Profile: C:\Users\Ahmed\AppData\Local\Google\Chrome\User Data\System Profile [2019-10-26] CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8553880 2023-01-10] (Avast Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [597400 2023-01-10] (Avast Software s.r.o. -> AVAST Software) R2 avast! Firewall; C:\Program Files\Avast Software\Avast\afwServ.exe [2038168 2023-01-10] (Avast Software s.r.o. -> AVAST Software) R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [597400 2023-01-10] (Avast Software s.r.o. -> AVAST Software) R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2023-01-10] (Avast Software s.r.o. -> AVAST Software) R2 AvidHubService; C:\Program Files\Avid\Cloud Client Services\Hub.exe [2299208 2017-11-09] (Avid Technology, Inc. -> Avid Technology, Inc.) R2 AvidTransportClient; C:\Program Files\Avid\Cloud Client Services\TransportClient.exe [7067464 2017-11-09] (Avid Technology, Inc. -> Avid Technology, Inc.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12540928 2022-12-17] (Microsoft Corporation -> Microsoft Corporation) R2 DigiRefresh; C:\Program Files\Avid\Pro Tools\MMERefresh.exe [117760 2016-03-25] (Avid Technology, Inc.) [Brak podpisu cyfrowego] S3 digiSPTIService64; C:\Program Files\Avid\Pro Tools\digisptiservice64.exe [197632 2016-03-25] (Avid Technology, Inc.) [Brak podpisu cyfrowego] S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\FileSyncHelper.exe [3478928 2022-12-14] (Microsoft Corporation -> Microsoft Corporation) R2 Focusrite Control Server; D:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe [1554432 2020-06-02] (Focusrite Audio Engineering Ltd.) [Brak podpisu cyfrowego] R2 GUBootService; D:\Glary Utilities 5\GUBootService.exe [873344 2021-11-15] (Glarysoft LTD -> Glarysoft Ltd) R2 GUPMService; D:\Glary Utilities 5\GUPMService.exe [65408 2021-11-15] (Glarysoft LTD -> Glarysoft Ltd) R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.) R2 MaskVPNService; C:\Program Files (x86)\MaskVPN\mask_svc.exe [7493560 2020-08-06] (Global Media (Thailand) Co., Ltd -> Global Media (Thailand) Co., Ltd) S3 MBAMService; D:\Malwarebytes\Anti-Malware\MBAMService.exe [7901368 2021-11-22] (Malwarebytes Inc -> Malwarebytes) S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.238.1114.0002\OneDriveUpdaterService.exe [3845008 2022-12-14] (Microsoft Corporation -> Microsoft Corporation) S3 Origin Client Service; D:\Program Files\Origin\OriginClientService.exe [2579264 2022-11-09] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; D:\Program Files\Origin\OriginWebHelperService.exe [3497800 2022-11-09] (Electronic Arts, Inc. -> Electronic Arts) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2021-05-21] (Even Balance, Inc. -> ) R2 SamsungUPDUtilSvc; C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe [143664 2022-01-23] (Samsung Electronics CO., LTD. -> ) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\NisSrv.exe [3191264 2022-12-02] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe [133592 2022-12-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_47917a79b8c7fd22\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_47917a79b8c7fd22\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem R2 PaceLicenseDServices; "C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe" -u hxxps://activation.paceap.com/InitiateActivation ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [229208 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [391272 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [297832 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [95960 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) S0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [25576 2023-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [39648 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [267888 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [555560 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [105248 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) S0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [80376 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [852000 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [695496 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [212632 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [318456 2023-01-10] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software) S3 atvi-brynhildr; C:\ProgramData\Battle.net_components\brynhildr_odin\brynhildr.sys [2355952 2022-01-15] (Activision Publishing Inc -> Activision Blizzard, Inc.) S3 atvi-randgrid_sr; D:\Program Files\Steam\steamapps\common\Call of Duty HQ\randgrid.sys [2513192 2022-12-19] (Activision Publishing Inc -> Activision Blizzard, Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Brak podpisu cyfrowego] R3 FocusritePCIeSwRoot; C:\WINDOWS\System32\drivers\FocusritePCIeSwRoot.sys [97480 2016-11-16] (Focusrite Audio Engineering Ltd. -> Focusrite Audio Engineering Ltd.) R3 Focusriteusb; C:\WINDOWS\System32\drivers\Focusriteusb.sys [123456 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.) R3 FocusriteusbSwRoot; C:\WINDOWS\System32\drivers\FocusriteusbSwRoot.sys [92568 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.) R3 Focusriteusb_AUDIO; C:\WINDOWS\system32\drivers\FocusriteusbAudio.sys [87912 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.) R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [30720 2021-04-28] (Microsoft Windows Hardware Compatibility Publisher -> Glarysoft Ltd) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2019-11-02] (Martin Malik - REALiX -> REALiX(tm)) R3 iaLPSS2_GPIO2; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_skl.inf_amd64_2a35efc43f1a612e\iaLPSS2_GPIO2_ICL.sys [132872 2020-04-27] (Intel Corporation -> Intel Corporation) R3 iaLPSS2_I2C; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_skl.inf_amd64_363c7132639e12a6\iaLPSS2_I2C_ICL.sys [200456 2020-04-27] (Intel Corporation -> Intel Corporation) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-11-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-11-22] (Malwarebytes Inc -> Malwarebytes) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48552 2022-01-11] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation) S3 OSFMount; D:\Program Files\OSFMount\OSFMount.sys [1299384 2014-02-07] (PassMark Software Pty Ltd -> PassMark Software) S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2014-08-08] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S2 SecDrv; C:\WINDOWS\SysWOW64\drivers\SECDRV.SYS [163644 2021-03-12] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Brak podpisu cyfrowego] S2 SSPORT; C:\WINDOWS\system32\Drivers\SSPORT.sys [19016 2019-05-31] (HP Inc. -> ) R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2018-08-29] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49568 2022-12-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [473376 2022-12-02] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99616 2022-12-02] (Microsoft Windows -> Microsoft Corporation) S3 gencounter; \SystemRoot\System32\drivers\vmgencounter.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2023-01-10 15:59 - 2023-01-10 16:01 - 000031145 _____ C:\Users\Ahmed\Downloads\FRST.txt 2023-01-10 15:59 - 2023-01-10 16:00 - 000000000 ____D C:\FRST 2023-01-10 15:59 - 2023-01-10 15:59 - 000000000 ____D C:\WINDOWS\system32\gf2engine 2023-01-10 15:58 - 2023-01-10 15:58 - 002376704 _____ (Farbar) C:\Users\Ahmed\Downloads\FRST64.exe 2023-01-10 15:13 - 2023-01-10 15:13 - 000002088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premium Security.lnk 2023-01-10 15:13 - 2023-01-10 15:02 - 000273816 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2023-01-10 15:05 - 2023-01-10 15:05 - 000000000 ____D C:\Users\Ahmed\AppData\Roaming\Avast Software 2023-01-10 15:05 - 2023-01-10 15:05 - 000000000 ____D C:\Users\Ahmed\AppData\Local\Avast Software 2023-01-10 15:02 - 2023-01-10 15:13 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update 2023-01-10 15:02 - 2023-01-10 15:02 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software 2023-01-10 15:02 - 2023-01-10 15:02 - 000000000 ____D C:\Program Files\Common Files\Avast Software 2023-01-10 15:00 - 2023-01-10 15:00 - 000000000 ____D C:\Program Files\Avast Software 2023-01-10 14:59 - 2023-01-10 15:03 - 000000000 ____D C:\ProgramData\Avast Software 2023-01-10 14:59 - 2023-01-10 14:59 - 000220784 _____ (AVAST Software) C:\Users\Ahmed\Downloads\avast_free_antivirus_setup_online.exe 2023-01-10 14:51 - 2023-01-10 14:51 - 000000000 ___HD C:\$WINDOWS.~BT 2023-01-10 14:48 - 2023-01-10 14:48 - 000000000 ___HD C:\$WinREAgent 2023-01-08 22:20 - 2023-01-08 22:24 - 000000000 ____D C:\WINDOWS\SecureLib 2023-01-08 22:20 - 2023-01-08 22:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MeldaProduction 2023-01-08 22:19 - 2023-01-08 22:19 - 000000000 ____D C:\Program Files\Common Files\VST3 2023-01-08 22:11 - 2023-01-08 22:21 - 000000000 ____D C:\Users\Ahmed\AppData\Roaming\MeldaProduction 2023-01-08 22:11 - 2023-01-08 22:20 - 000000000 ____D C:\ProgramData\MeldaProduction 2023-01-08 22:03 - 2023-01-08 22:11 - 581038296 _____ C:\Users\Ahmed\Downloads\maudioplugins_16_03_setup.exe 2023-01-08 21:04 - 2023-01-08 21:04 - 002564396 _____ C:\Users\Ahmed\Desktop\Activated_Setup_Use_2023_As_Passw0rd.rar 2023-01-06 18:21 - 2023-01-06 18:21 - 000000022 _____ C:\Users\Ahmed\Downloads\result.zip 2023-01-06 18:12 - 2023-01-06 18:12 - 000430337 ____T C:\Users\Ahmed\Desktop\mso5346.tmp 2023-01-06 17:57 - 2023-01-06 17:57 - 000000000 ____D C:\Users\Ahmed\AppData\LocalLow\NVIDIA 2023-01-06 17:54 - 2023-01-06 17:55 - 000000000 ____D C:\Users\Ahmed\AppData\LocalLow\Adobe 2023-01-06 17:54 - 2023-01-06 17:54 - 000000000 ____D C:\Users\Ahmed\AppData\Roaming\com.adobe.dunamis 2023-01-06 17:54 - 2023-01-06 17:54 - 000000000 ____D C:\Users\Ahmed\AppData\Local\SolidDocuments 2023-01-06 17:54 - 2023-01-06 17:54 - 000000000 ____D C:\Users\Ahmed\.ms-ad 2023-01-06 17:50 - 2023-01-06 18:15 - 000000000 ____D C:\Program Files\Adobe 2023-01-06 17:39 - 2023-01-06 17:55 - 000000000 ____D C:\Users\Ahmed\AppData\Local\Adobe 2023-01-06 17:38 - 2023-01-06 17:55 - 000000000 ____D C:\ProgramData\Adobe 2023-01-06 17:38 - 2023-01-06 17:38 - 031668120 _____ (Adobe Systems Incorporated) C:\Users\Ahmed\Downloads\AdbeRdr950_pl_PL.exe 2023-01-06 14:12 - 2023-01-08 21:08 - 000000000 ____D C:\Users\Ahmed\Desktop\Nowy folder 2022-12-24 20:55 - 2022-12-24 20:55 - 015479340 _____ C:\Users\Ahmed\Desktop\Myszka.wav 2022-12-21 20:58 - 2022-12-21 20:58 - 000000000 ____D C:\Users\Ahmed\AppData\Local\Activision 2022-12-11 14:57 - 2022-12-11 14:57 - 000000000 __SHD C:\found.001 ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2023-01-10 15:47 - 2019-10-26 00:08 - 000000000 ____D C:\Program Files (x86)\Google 2023-01-10 15:40 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-01-10 15:13 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2023-01-10 15:00 - 2022-04-08 13:51 - 000000000 ____D C:\Users\Ahmed\AppData\Roaming\discord 2023-01-10 15:00 - 2022-04-08 13:51 - 000000000 ____D C:\Users\Ahmed\AppData\Local\Discord 2023-01-10 14:52 - 2020-08-24 20:06 - 000000000 ___DC C:\WINDOWS\Panther 2023-01-10 14:49 - 2019-10-25 23:41 - 000000000 ____D C:\ProgramData\NVIDIA 2023-01-09 19:16 - 2019-10-26 07:55 - 000000000 ____D C:\Users\Ahmed\AppData\Local\D3DSCache 2023-01-09 16:59 - 2020-09-01 17:58 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-01-08 22:25 - 2021-02-18 18:12 - 000000000 ____D C:\Users\Public\Pro Tools 2023-01-08 22:25 - 2019-11-03 14:48 - 000000000 ____D C:\Users\Ahmed\AppData\Local\CrashDumps 2023-01-07 15:16 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2023-01-07 15:16 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-01-07 14:21 - 2020-06-06 23:19 - 000002431 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-01-06 18:14 - 2019-10-25 23:51 - 000000000 ____D C:\Users\Ahmed\AppData\Local\Packages 2023-01-06 17:57 - 2019-10-26 00:07 - 000000000 ____D C:\ProgramData\Packages 2023-01-06 17:54 - 2020-09-01 18:01 - 000000000 ____D C:\Users\Ahmed 2023-01-06 17:54 - 2019-10-25 23:51 - 000000000 ____D C:\Users\Ahmed\AppData\Roaming\Adobe 2023-01-06 00:57 - 2020-09-01 18:16 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2023-01-06 00:57 - 2020-09-01 18:16 - 000003442 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2023-01-01 13:38 - 2019-11-12 20:54 - 000000000 ____D C:\Users\Ahmed\AppData\Roaming\Audacity 2022-12-25 19:35 - 2019-05-11 17:20 - 000000565 _____ C:\Users\Ahmed\Desktop\hasło f1.txt 2022-12-19 14:54 - 2019-10-26 07:56 - 000000000 ____D C:\ProgramData\Package Cache 2022-12-19 14:45 - 2019-10-26 23:26 - 000000000 ____D C:\WINDOWS\system32\MRT 2022-12-19 14:41 - 2019-10-26 23:26 - 148633544 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2022-12-18 02:20 - 2020-02-18 15:48 - 000000000 ____D C:\Users\Ahmed\AppData\Roaming\Origin 2022-12-18 02:15 - 2020-02-18 15:48 - 000000000 ____D C:\Users\Ahmed\AppData\Local\Origin 2022-12-17 18:37 - 2022-09-17 20:24 - 000000000 ____D C:\Program Files\Microsoft Office 2022-12-17 18:30 - 2020-02-17 21:52 - 000000000 ____D C:\ProgramData\Origin 2022-12-16 17:53 - 2019-10-26 00:10 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2022-12-14 17:57 - 2022-09-19 13:38 - 000000000 ____D C:\Program Files\Microsoft OneDrive 2022-12-14 17:57 - 2022-09-17 20:47 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task 2022-12-14 17:57 - 2022-09-17 20:47 - 000002176 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-12-14 17:57 - 2021-12-13 12:37 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1306247612-828193906-1523655640-1001 2022-12-11 15:05 - 2020-09-01 18:13 - 001767980 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-12-11 15:05 - 2019-12-07 16:08 - 000784314 _____ C:\WINDOWS\system32\perfh015.dat 2022-12-11 15:05 - 2019-12-07 16:08 - 000152210 _____ C:\WINDOWS\system32\perfc015.dat 2022-12-11 15:05 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 2022-12-11 14:58 - 2020-09-01 18:16 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2022-12-11 14:58 - 2020-09-01 17:58 - 000008192 ___SH C:\DumpStack.log.tmp ==================== Pliki w katalogu głównym wybranych folderów ======== 2021-02-18 15:33 - 2021-02-18 15:35 - 000018544 _____ () C:\Users\Ahmed\AppData\Roaming\Avid_CCS_Service_Stop.log 2020-11-19 16:26 - 2021-03-08 17:32 - 000004608 _____ () C:\Users\Ahmed\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2022-04-08 13:43 - 2022-04-08 13:43 - 000001277 _____ () C:\Users\Ahmed\AppData\Local\Discord — skrót .lnk 2022-07-17 12:17 - 2022-07-17 12:17 - 000000877 _____ () C:\Users\Ahmed\AppData\Local\recently-used.xbel 2021-09-17 15:43 - 2021-09-17 15:43 - 000007597 _____ () C:\Users\Ahmed\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================