Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 22-01-2020 01 Uruchomiony przez Dorota (administrator) DESKTOP-P7FFKII (LENOVO 20217) (23-01-2020 10:23:00) Uruchomiony z C:\Users\Dorota\Desktop Załadowane profile: Dorota (Dostępne profile: Dorota & DefaultAppPool) Platform: Windows 10 Home Wersja 1809 17763.973 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) () [Brak podpisu cyfrowego] C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe (Intel Corporation -> ) C:\Windows\System32\igfxTray.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_18.1910.1283.0_x64__8wekyb3d8bbwe\LocalBridge.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19101.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor Corp -> Realtek semiconductor) C:\Windows\RTFTrack.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5062384 2015-08-30] (Realtek Semiconductor Corp -> Realtek semiconductor) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [183088 2019-12-14] (ESET, spol. s r.o. -> ESET) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13886208 2015-05-21] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) HKU\S-1-5-21-1752920659-2708304617-1936187302-1001\...\MountPoints2: {67f3478d-72c6-11e9-bc2c-681729f1135e} - "D:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-1752920659-2708304617-1936187302-1001\...\MountPoints2: {85fc9b2f-9951-11e9-bc2f-681729f1135e} - "D:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-1752920659-2708304617-1936187302-1001\...\MountPoints2: {85fc9bbf-9951-11e9-bc2f-681729f1135e} - "D:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-1752920659-2708304617-1936187302-1001\...\MountPoints2: {85fc9bc8-9951-11e9-bc2f-681729f1135e} - "D:\HTC_Sync_Manager_PC.exe" ==================== Zaplanowane zadania (filtrowane) ============ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{1bada3aa-e9cd-42d1-a55a-be4cebc0ed8c}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{8fd3c95a-fcf8-45df-984b-9c88f08a43a9}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== FireFox: ======== FF DefaultProfile: tnocsasa.default FF ProfilePath: C:\Users\Dorota\AppData\Roaming\Mozilla\Firefox\Profiles\tnocsasa.default [2020-01-23] FF Notifications: Mozilla\Firefox\Profiles\tnocsasa.default -> hxxps://pilot.wp.pl FF Extension: (uBlock Origin) - C:\Users\Dorota\AppData\Roaming\Mozilla\Firefox\Profiles\tnocsasa.default\Extensions\uBlock0@raymondhill.net.xpi [2019-11-25] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-01-23] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2245488 2019-12-14] (ESET, spol. s r.o. -> ESET) R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2245488 2019-12-14] (ESET, spol. s r.o. -> ESET) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [353768 2018-11-15] (Intel Corporation -> Intel Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [Brak podpisu cyfrowego] S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\NisSrv.exe [2433136 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MsMpEng.exe [109896 2019-06-05] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [149944 2019-11-09] (ESET, spol. s r.o. -> ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [103264 2019-11-09] (ESET, spol. s r.o. -> ESET) S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15800 2019-06-17] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET) R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [189512 2019-11-09] (ESET, spol. s r.o. -> ESET) R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [50712 2019-11-09] (ESET, spol. s r.o. -> ESET) R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [79744 2019-12-14] (ESET, spol. s r.o. -> ESET) R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [116696 2019-12-14] (ESET, spol. s r.o. -> ESET) S3 htcnprot; C:\Windows\system32\DRIVERS\htcnprot.sys [36928 2013-10-17] (HTC Corp. -> Windows (R) Win 7 DDK provider) R3 L1C; C:\Windows\System32\drivers\L1C63x64.sys [121344 2018-09-15] (Microsoft Windows -> Qualcomm Atheros Co., Ltd.) R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3343872 2018-09-15] (Microsoft Windows -> Intel Corporation) R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_c76e6fcd108a9f7d\nvlddmkm.sys [20736440 2019-03-15] (NVIDIA Corporation -> NVIDIA Corporation) R0 nvpciflt; C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_c76e6fcd108a9f7d\nvpciflt.sys [57224 2019-03-15] (NVIDIA Corporation -> NVIDIA Corporation) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3069680 2015-08-30] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [24576 2018-09-15] (Microsoft Windows -> Microsoft Corporation) S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [47496 2019-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [337632 2019-06-05] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [53984 2019-06-05] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) =================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-01-23 10:23 - 2020-01-23 10:24 - 000010201 _____ C:\Users\Dorota\Desktop\FRST.txt 2020-01-23 10:22 - 2020-01-23 10:23 - 000000000 ____D C:\FRST 2020-01-23 10:22 - 2020-01-23 10:22 - 000001044 _____ C:\Users\Dorota\Desktop\Nowy dokument tekstowy (2).txt 2020-01-23 09:42 - 2020-01-23 09:42 - 008905728 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 007922688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 005436696 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 002469440 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 002323896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 001200920 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000673792 _____ (Microsoft Corporation) C:\Windows\system32\wiaaut.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000651776 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiaaut.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000410616 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000350416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000322048 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000228864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000189440 _____ (Microsoft Corporation) C:\Windows\system32\sti_ci.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000145920 _____ (Microsoft Corporation) C:\Windows\system32\wiadss.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000119808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiadss.dll 2020-01-23 09:42 - 2020-01-23 09:42 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\wiarpc.dll 2020-01-23 09:41 - 2020-01-23 09:42 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 009668408 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 007645392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 006543736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 004588544 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 003637248 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2020-01-23 09:41 - 2020-01-23 09:41 - 002707968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys 2020-01-23 09:41 - 2020-01-23 09:41 - 002419712 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2020-01-23 09:41 - 2020-01-23 09:41 - 002149160 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001936520 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001721144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001708544 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001701888 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001677088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001670800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001665712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001258296 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 001084416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 001050624 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 001049400 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 000949248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000930816 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000878080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 000839680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\MdmDiagnostics.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000677144 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe 2020-01-23 09:41 - 2020-01-23 09:41 - 000541264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000405304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys 2020-01-23 09:41 - 2020-01-23 09:41 - 000378368 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000326144 _____ (Microsoft Corporation) C:\Windows\system32\DiagnosticLogCSP.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\ConhostV1.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000289792 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000154976 _____ (Microsoft Corporation) C:\Windows\system32\dmcmnutils.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 000145920 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\cryptcatsvc.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000122568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmcmnutils.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\enterpriseresourcemanager.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000083456 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe 2020-01-23 09:41 - 2020-01-23 09:41 - 000073728 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\enterpriseresourcemanager.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin 2020-01-23 09:41 - 2020-01-23 09:41 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin 2020-01-23 09:01 - 2020-01-23 09:03 - 000000000 ____D C:\AdwCleaner 2020-01-23 09:00 - 2020-01-23 09:01 - 008237744 _____ (Malwarebytes) C:\Users\Dorota\Desktop\adwcleaner_8.0.1.exe 2020-01-23 08:58 - 2020-01-23 08:58 - 002580480 _____ (Farbar) C:\Users\Dorota\Desktop\FRST64.exe 2020-01-23 08:51 - 2020-01-23 08:51 - 000000080 ___SH C:\bootTel.dat 2020-01-23 08:37 - 2020-01-23 08:38 - 000000000 ____D C:\Users\Dorota\Desktop\CrystalDiskInfo8_4_0 2020-01-23 00:38 - 2020-01-23 08:52 - 000000000 ____D C:\Program Files\Mozilla Firefox 2020-01-07 12:19 - 2020-01-10 18:27 - 000000000 ____D C:\rots 2020-01-07 11:59 - 2020-01-07 12:19 - 000000000 ____D C:\Users\Dorota\Desktop\rots 2019-12-30 11:41 - 2019-12-30 11:41 - 000000000 ____D C:\Users\Dorota\AppData\Local\mbam 2019-12-30 11:40 - 2019-12-30 11:40 - 000000000 ____D C:\Users\Dorota\AppData\Local\mbamtray 2019-12-30 11:36 - 2019-12-30 11:36 - 000000000 ____D C:\Users\Dorota\AppData\Roaming\Obsidium 2019-12-30 09:33 - 2019-12-30 09:33 - 000000000 ____D C:\Users\Dorota\AppData\Roaming\WinRAR 2019-12-30 09:33 - 2019-12-30 09:33 - 000000000 ____D C:\Users\Dorota\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2019-12-30 09:33 - 2019-12-30 09:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2019-12-30 09:33 - 2019-12-30 09:33 - 000000000 ____D C:\Program Files\WinRAR 2019-12-29 09:33 - 2019-12-29 09:33 - 000606208 _____ C:\Users\Dorota\Downloads\wykaz_ogierow.xls 2019-12-29 09:31 - 2019-12-29 09:33 - 000606208 _____ C:\Users\Dorota\Desktop\wykaz_ogierow.xls ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2020-01-23 10:10 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-01-23 10:06 - 2019-06-20 06:56 - 000000000 ____D C:\Program Files\UNP 2020-01-23 10:04 - 2019-03-20 15:52 - 002052070 _____ C:\Windows\system32\PerfStringBackup.INI 2020-01-23 10:04 - 2018-09-15 17:43 - 000890152 _____ C:\Windows\system32\perfh015.dat 2020-01-23 10:04 - 2018-09-15 17:43 - 000198852 _____ C:\Windows\system32\perfc015.dat 2020-01-23 10:04 - 2018-09-15 08:31 - 000000000 ____D C:\Windows\INF 2020-01-23 10:00 - 2019-03-20 16:06 - 000000000 ____D C:\Users\Dorota\AppData\LocalLow\Mozilla 2020-01-23 09:59 - 2019-03-20 17:00 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2020-01-23 09:59 - 2019-03-20 17:00 - 000000000 __SHD C:\Users\Dorota\IntelGraphicsProfiles 2020-01-23 09:58 - 2019-03-20 17:02 - 000000000 ____D C:\ProgramData\NVIDIA 2020-01-23 09:56 - 2019-03-20 15:47 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-01-23 09:56 - 2019-03-20 15:46 - 000258560 _____ C:\Windows\system32\FNTCACHE.DAT 2020-01-23 09:55 - 2018-09-15 07:09 - 000524288 _____ C:\Windows\system32\config\BBI 2020-01-23 09:54 - 2018-09-15 08:33 - 000000000 ___SD C:\Windows\system32\UNP 2020-01-23 09:54 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\ShellExperiences 2020-01-23 09:54 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\bcastdvr 2020-01-23 09:52 - 2019-03-20 16:57 - 000000000 ____D C:\Windows\system32\MRT 2020-01-23 09:48 - 2019-03-20 16:57 - 120202352 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-01-23 09:47 - 2018-09-15 08:23 - 000000000 ____D C:\Windows\CbsTemp 2020-01-23 08:52 - 2019-03-20 16:06 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-01-23 08:13 - 2019-03-20 16:11 - 000000000 ____D C:\Users\Dorota\AppData\Local\D3DSCache 2020-01-23 08:11 - 2019-06-23 21:51 - 000000000 ____D C:\Users\Dorota\AppData\Local\CrashDumps 2020-01-23 07:46 - 2019-03-20 16:06 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2020-01-23 06:58 - 2019-03-20 15:46 - 000000000 ____D C:\Windows\system32\SleepStudy 2020-01-21 03:32 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\AppReadiness 2020-01-16 05:08 - 2018-09-15 07:09 - 000000000 ____D C:\Windows\servicing 2020-01-07 18:09 - 2019-07-03 16:18 - 000000000 ____D C:\Users\Dorota\AppData\Roaming\zaap 2020-01-07 18:09 - 2019-07-03 16:18 - 000000000 ____D C:\Users\Dorota\AppData\Roaming\Ankama Launcher 2020-01-05 13:51 - 2019-06-17 21:50 - 000000008 _____ C:\Users\Dorota\AppData\Roaming\DofusAppId0_1 2020-01-05 13:17 - 2019-06-17 21:50 - 000000113 _____ C:\Users\Dorota\AppData\Roaming\D2Info0 2020-01-04 10:08 - 2019-03-20 16:01 - 000000000 ____D C:\Users\Dorota\AppData\Local\Packages 2020-01-03 17:19 - 2019-06-20 17:04 - 000000008 _____ C:\Users\Dorota\AppData\Roaming\DofusAppId0_2 2020-01-02 19:49 - 2019-06-22 22:12 - 000000008 _____ C:\Users\Dorota\AppData\Roaming\DofusAppId0_3 2019-12-30 15:02 - 2019-06-17 21:50 - 000000000 ____D C:\Users\Dorota\AppData\Roaming\Dofus ==================== Pliki w katalogu głównym wybranych folderów ======== 2019-06-17 21:50 - 2020-01-05 13:17 - 000000113 _____ () C:\Users\Dorota\AppData\Roaming\D2Info0 2019-06-17 21:50 - 2020-01-05 13:51 - 000000008 _____ () C:\Users\Dorota\AppData\Roaming\DofusAppId0_1 2019-06-20 17:04 - 2020-01-03 17:19 - 000000008 _____ () C:\Users\Dorota\AppData\Roaming\DofusAppId0_2 2019-06-22 22:12 - 2020-01-02 19:49 - 000000008 _____ () C:\Users\Dorota\AppData\Roaming\DofusAppId0_3 ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================