
- Kod: Zaznacz wszystko
Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:27-01-2016
Uruchomiony przez Marek (administrator) DESKTOP-UEMC19E (31-01-2016 13:36:10)
Uruchomiony z C:\Users\Marek\Downloads
Załadowane profile: Marek (Dostępne profile: Marek)
Platform: Windows 10 Home (X64) Język: Polski (Polska)
Internet Explorer Wersja 11 (Domyślna przeglądarka: Chrome)
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Procesy (filtrowane) =================
(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Rejestr (filtrowane) ===========================
(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-24] (NVIDIA Corporation)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.2.2.524\ASUSWSLoader.exe [63272 2015-05-31] ()
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [24952456 2015-12-08] (Dropbox, Inc.)
HKU\S-1-5-21-1851731846-1835135236-2760378971-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.2.2.524\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.2.2.524\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.2.2.524\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\avast! SecureLine.lnk [2015-09-06]
ShortcutTarget: avast! SecureLine.lnk -> C:\Program Files\AVAST Software\SecureLine\SecureLine.exe (AVAST Software)
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
==================== Internet (filtrowane) ====================
(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)
AutoConfigURL: [S-1-5-21-1851731846-1835135236-2760378971-1001] => hxxp://unblockservice.com/wpad.dat?81476734a7ef86573985a181444c5edc5168835
Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{aad0867b-d52d-4833-9d0d-cfc0e6ebc0e4}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{c4fb7100-49f2-42f0-92f6-84c2e6a9ec57}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1851731846-1835135236-2760378971-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki
HKU\S-1-5-21-1851731846-1835135236-2760378971-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus15.msn.com/?pc=ASTE
SearchScopes: HKU\S-1-5-21-1851731846-1835135236-2760378971-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1851731846-1835135236-2760378971-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-04-30] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-12-29] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-12-29] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-12-29] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-12-29] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2016-01-08] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2016-01-08] (McAfee, Inc.)
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-01-08] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2016-01-08] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-28] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-15] ()
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2015-12-29]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2016-01-29] [Brak podpisu cyfrowego]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki
CHR StartupUrls: Default -> "hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki"
CHR Profile: C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentacje Google) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-28]
CHR Extension: (Dokumenty Google) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-28]
CHR Extension: (Dysk Google) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-28]
CHR Extension: (YouTube) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-28]
CHR Extension: (Google Search) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-28]
CHR Extension: (Discovery App) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\daihhikmdckadnpcegaochhkllcpbbmk [2015-12-28] [UpdateUrl: hxxp://cdn.ratediscoverymarket.com/update] <==== UWAGA
CHR Extension: (Arkusze Google) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-28]
CHR Extension: (SiteAdvisor) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-12-28]
CHR Extension: (Dokumenty Google offline) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-28]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-28]
CHR Extension: (Gmail) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-28]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-01-28]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-01-28]
==================== Usługi (filtrowane) ========================
(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
S2 0283251453395508mcinstcleanup; C:\Windows\TEMP\028325~1.EXE [918056 2015-11-27] (McAfee, Inc.)
S2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.2.2.524\AsusWSWinService.exe [71168 2015-05-31] (ASUS Cloud Corporation) [Brak podpisu cyfrowego]
S2 ASUSGiftBoxDekstop; C:\Program Files (x86)\ASUS\ASUS GIFTBOX Desktop\ASUSGIFTBOXDesktop.exe [315704 2015-07-20] (ASUS)
S2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [323152 2015-07-29] (Windows (R) Win 7 DDK provider)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-12-07] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-12-07] (Dropbox, Inc.)
S2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1385640 2015-08-04] (Intel Corporation)
S2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-14] (WildTangent)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
S2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359856 2015-07-30] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Brak podpisu cyfrowego]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Brak podpisu cyfrowego]
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation)
S2 Kingsoft_WPS_UpdateService; C:\Program Files (x86)\Kingsoft\WPS Office\9.1.0.4947\wtoolex\wpsupdatesvr.exe [133480 2015-08-15] (Zhuhai Kingsoft Office Software Co.,Ltd)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [158952 2015-12-29] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [863448 2016-01-08] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [338208 2015-03-19] (McAfee, Inc.)
R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe [1694152 2015-12-02] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [681680 2016-01-08] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [234192 2015-11-18] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [380896 2016-01-04] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [275368 2015-11-18] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [453520 2016-01-03] (McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [902112 2015-12-14] (Intel Security, Inc.)
S2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [445240 2015-04-29] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S2 Pyifnaqb; "C:\Users\Marek\AppData\Roaming\KulvFuj\Ieioi.exe" -cms [X]
===================== Sterowniki (filtrowane) ==========================
(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4317808 2015-07-14] (Qualcomm Atheros Communications, Inc.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [100776 2015-06-30] (ASUS Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [79248 2015-11-25] (McAfee, Inc.)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [43512 2015-08-04] (Intel Corporation)
R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [41976 2015-08-04] (Intel Corporation)
R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [251384 2015-08-04] (Intel Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc.)
R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [88256 2015-06-26] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [419624 2015-11-25] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [351144 2015-11-25] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [83096 2015-11-25] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [496368 2015-11-25] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [846080 2015-11-25] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [539496 2015-11-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [109480 2015-11-20] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [37448 2015-12-29] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [245096 2015-11-25] (McAfee, Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [887552 2015-07-15] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410880 2015-12-07] (Realsil Semiconductor Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U0 msahci; system32\drivers\msahci.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (filtrowane) ===================
(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
==================== Jeden miesiąc - utworzone pliki i foldery ========
(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
2016-01-31 13:36 - 2016-01-31 13:37 - 00021080 _____ C:\Users\Marek\Downloads\FRST.txt
2016-01-31 13:35 - 2016-01-31 13:36 - 00000000 ____D C:\FRST
2016-01-31 13:35 - 2016-01-31 13:35 - 02370560 _____ (Farbar) C:\Users\Marek\Downloads\FRST64.exe
2016-01-31 13:34 - 2016-01-31 13:34 - 01721856 _____ (Farbar) C:\Users\Marek\Downloads\FRST.exe
2016-01-31 12:48 - 2016-01-31 12:48 - 00016148 _____ C:\Windows\system32\DESKTOP-UEMC19E_Marek_HistoryPrediction.bin
2016-01-31 12:29 - 2016-01-31 13:09 - 00004020 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
2016-01-31 12:29 - 2016-01-31 12:29 - 00004208 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse
2016-01-31 12:25 - 2016-01-31 12:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2016-01-30 23:00 - 2016-01-31 01:30 - 00000000 ____D C:\Users\Marek\AppData\Roaming\TS3Client
2016-01-30 23:00 - 2016-01-30 23:00 - 00001010 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-01-30 23:00 - 2016-01-30 23:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2016-01-30 23:00 - 2016-01-30 23:00 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2016-01-30 22:59 - 2016-01-30 22:59 - 31017664 _____ (TeamSpeak Systems GmbH) C:\Users\Marek\Downloads\TeamSpeak3-Client-win64-3.0.18.2.exe
2016-01-30 22:56 - 2016-01-31 01:32 - 08388608 _____ C:\Users\Marek\Downloads\TeamSpeak-46554-dp.vhdx
2016-01-29 17:49 - 2016-01-29 17:49 - 00000000 ____D C:\Windows\system32\doai
2016-01-29 17:40 - 2016-01-29 17:55 - 01507840 _____ C:\Users\Marek\Desktop\adwcleaner_5.031.exe
2016-01-28 20:22 - 2016-01-28 20:22 - 00000000 ____D C:\Users\Public\Documents\ASUS_Hipost
2016-01-28 18:45 - 2016-01-28 18:46 - 05497564 _____ C:\Users\Marek\Downloads\Magda Femme - Nowator - Jestem na tak 2015 (1).ogg
2016-01-28 18:45 - 2016-01-28 18:45 - 03754524 _____ C:\Users\Marek\Downloads\Sulin - Miedzy Mna A Toba.ogg
2016-01-28 18:38 - 2016-01-28 18:40 - 00000000 ____D C:\Users\Marek\AppData\Local\Tempfolder
2016-01-28 18:37 - 2016-01-28 18:37 - 00003420 _____ C:\Windows\System32\Tasks\Fuoral
2016-01-28 18:37 - 2016-01-28 18:37 - 00000000 ____D C:\Users\Marek\AppData\LocalLow\Company
2016-01-28 18:37 - 2016-01-28 18:37 - 00000000 ____D C:\uninst
2016-01-28 18:37 - 2016-01-28 18:37 - 00000000 _____ C:\Windows\SysWOW64\Number of results
2016-01-28 18:22 - 2016-01-28 18:23 - 05497564 _____ C:\Users\Marek\Downloads\Magda Femme - Nowator - Jestem na tak 2015.ogg
2016-01-28 18:06 - 2016-01-28 18:05 - 00000967 _____ C:\Windows\system32\Drivers\etc\hp.bak
2016-01-28 18:05 - 2016-01-29 16:19 - 00000000 ____D C:\ProgramData\4f596ec3-77fb-4fc3-82cb-691c42c71d77
2016-01-28 18:01 - 2016-01-28 18:01 - 03833856 _____ C:\Users\Marek\Downloads\K2_-_1_Moment_ft_Buka_mp3.pm.mp3.iso
2016-01-26 14:00 - 2016-01-26 14:00 - 00000000 ____D C:\ProgramData\Intel Security
2016-01-26 13:59 - 2016-01-26 13:59 - 00000000 ____D C:\Program Files\Common Files\Intel Security
2016-01-23 14:21 - 2016-01-31 12:24 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture
2016-01-22 22:03 - 2016-01-22 22:03 - 00003628 _____ C:\Windows\System32\Tasks\ASUS Smart Gesture Launcher
2016-01-22 22:02 - 2016-01-22 22:02 - 00056952 _____ C:\Windows\system32\ASGCoInstaller_x64.dll
2016-01-22 22:02 - 2016-01-22 22:02 - 00000000 ____D C:\ProgramData\SetupTPDriver
2016-01-20 19:21 - 2016-01-20 19:22 - 00000062 _____ C:\Users\Marek\Downloads\listen.pls
2016-01-17 18:58 - 2016-01-17 18:58 - 00123407 _____ C:\Users\Marek\Downloads\FAKTURA-P-11430474-16010670590573-00053857.pdf
2016-01-16 12:09 - 2016-01-16 12:09 - 00000000 ____D C:\Users\Marek\AppData\LocalLow\Temp
2016-01-15 00:14 - 2016-01-15 00:14 - 00031596 _____ C:\Users\Marek\Downloads\oferta.pdf
2016-01-13 10:22 - 2016-01-05 04:07 - 02463704 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-01-13 10:22 - 2016-01-05 04:07 - 00377592 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2016-01-13 10:22 - 2016-01-05 04:06 - 08022368 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-01-13 10:22 - 2016-01-05 04:06 - 01991120 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2016-01-13 10:22 - 2016-01-05 04:06 - 01270104 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2016-01-13 10:22 - 2016-01-05 04:06 - 01063504 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2016-01-13 10:22 - 2016-01-05 04:06 - 00119800 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2016-01-13 10:22 - 2016-01-05 04:04 - 02824248 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 02641928 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2016-01-13 10:22 - 2016-01-05 04:04 - 01591848 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 01150816 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00862056 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00787720 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-01-13 10:22 - 2016-01-05 04:04 - 00784136 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00779928 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00772448 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00751992 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2016-01-13 10:22 - 2016-01-05 04:04 - 00667856 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00250520 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2016-01-13 10:22 - 2016-01-05 04:04 - 00249464 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2016-01-13 10:22 - 2016-01-05 04:04 - 00243248 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00233992 _____ (Microsoft Corporation) C:\Windows\system32\mftranscode.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00115704 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2016-01-13 10:22 - 2016-01-05 04:04 - 00090912 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2016-01-13 10:22 - 2016-01-05 04:04 - 00083704 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2016-01-13 10:22 - 2016-01-05 03:59 - 00781976 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-01-13 10:22 - 2016-01-05 03:52 - 00441696 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-01-13 10:22 - 2016-01-05 03:50 - 01817064 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2016-01-13 10:22 - 2016-01-05 03:50 - 01083072 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-01-13 10:22 - 2016-01-05 03:50 - 00723648 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-01-13 10:22 - 2016-01-05 03:50 - 00345080 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2016-01-13 10:22 - 2016-01-05 03:50 - 00251544 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2016-01-13 10:22 - 2016-01-05 03:50 - 00205072 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2016-01-13 10:22 - 2016-01-05 03:31 - 01365576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-01-13 10:22 - 2016-01-05 03:30 - 02459096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2016-01-13 10:22 - 2016-01-05 03:30 - 02162064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2016-01-13 10:22 - 2016-01-05 03:30 - 02152744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2016-01-13 10:22 - 2016-01-05 03:30 - 01106872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2016-01-13 10:22 - 2016-01-05 03:30 - 00882208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2016-01-13 10:22 - 2016-01-05 03:30 - 00368776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2016-01-13 10:22 - 2016-01-05 03:30 - 00232896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2016-01-13 10:22 - 2016-01-05 03:30 - 00100712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2016-01-13 10:22 - 2016-01-05 03:29 - 00208688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 02445128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 00714808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 00696192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
2016-01-13 10:22 - 2016-01-05 03:28 - 00695752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2016-01-13 10:22 - 2016-01-05 03:28 - 00645144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 00635312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 00497896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 00277400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
2016-01-13 10:22 - 2016-01-05 03:28 - 00116728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 00107952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
2016-01-13 10:22 - 2016-01-05 03:28 - 00082096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
2016-01-13 10:22 - 2016-01-05 03:28 - 00072808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
2016-01-13 10:22 - 2016-01-05 03:21 - 00658528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2016-01-13 10:22 - 2016-01-05 03:18 - 21873152 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-01-13 10:22 - 2016-01-05 03:15 - 24592896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-01-13 10:22 - 2016-01-05 03:15 - 00931328 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2016-01-13 10:22 - 2016-01-05 03:15 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2016-01-13 10:22 - 2016-01-05 03:15 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\usermgrcli.dll
2016-01-13 10:22 - 2016-01-05 03:10 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\mfh264enc.dll
2016-01-13 10:22 - 2016-01-05 03:10 - 00305776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2016-01-13 10:22 - 2016-01-05 03:10 - 00278424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
2016-01-13 10:22 - 2016-01-05 03:10 - 00188032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
2016-01-13 10:22 - 2016-01-05 03:09 - 01234944 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2016-01-13 10:22 - 2016-01-05 03:09 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-01-13 10:22 - 2016-01-05 03:02 - 01672192 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-01-13 10:22 - 2016-01-05 03:02 - 00678912 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-01-13 10:22 - 2016-01-05 03:02 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-01-13 10:22 - 2016-01-05 03:01 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-01-13 10:22 - 2016-01-05 03:00 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-01-13 10:22 - 2016-01-05 03:00 - 00771072 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-01-13 10:22 - 2016-01-05 02:59 - 00572928 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-01-13 10:22 - 2016-01-05 02:57 - 00712704 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2016-01-13 10:22 - 2016-01-05 02:57 - 00578560 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2016-01-13 10:22 - 2016-01-05 02:57 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-01-13 10:22 - 2016-01-05 02:56 - 07523840 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-01-13 10:22 - 2016-01-05 02:51 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2016-01-13 10:22 - 2016-01-05 02:51 - 01009664 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-01-13 10:22 - 2016-01-05 02:51 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2016-01-13 10:22 - 2016-01-05 02:51 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2016-01-13 10:22 - 2016-01-05 02:51 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2016-01-13 10:22 - 2016-01-05 02:44 - 00159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2016-01-13 10:22 - 2016-01-05 02:44 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usermgrcli.dll
2016-01-13 10:22 - 2016-01-05 02:43 - 19324928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-01-13 10:22 - 2016-01-05 02:42 - 00871936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2016-01-13 10:22 - 2016-01-05 02:38 - 00556032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfh264enc.dll
2016-01-13 10:22 - 2016-01-05 02:32 - 01541632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-01-13 10:22 - 2016-01-05 02:32 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2016-01-13 10:22 - 2016-01-05 02:31 - 00563200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-01-13 10:22 - 2016-01-05 02:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2016-01-13 10:22 - 2016-01-05 02:30 - 18802176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-01-13 10:22 - 2016-01-05 02:29 - 00650240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-01-13 10:22 - 2016-01-05 02:29 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-01-13 10:22 - 2016-01-05 02:26 - 00373760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-01-13 10:22 - 2016-01-05 02:24 - 05454848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-01-13 10:22 - 2016-01-05 02:20 - 00890880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2016-01-13 10:22 - 2016-01-05 02:19 - 01070080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2016-01-13 10:22 - 2016-01-05 02:19 - 00747008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
2016-01-13 10:22 - 2016-01-05 02:19 - 00409088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
2016-01-13 10:22 - 2016-01-05 02:19 - 00404992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
2016-01-12 23:08 - 2016-01-12 23:08 - 00212341 _____ C:\Users\Marek\Downloads\O10_Faktura_indywidualna_000-046-4543-6261_16_01_F001_Z.pdf
2016-01-08 07:53 - 2016-01-03 02:40 - 00826872 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-08 07:53 - 2016-01-03 02:40 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-08 07:37 - 2016-01-31 13:16 - 00000000 ____D C:\AdwCleaner
2016-01-08 07:36 - 2016-01-08 07:36 - 01749504 _____ C:\Users\Marek\Downloads\adwcleaner_5.028 (1).exe
2016-01-08 07:35 - 2016-01-08 07:35 - 01749504 _____ C:\Users\Marek\Downloads\adwcleaner_5.028.exe
2016-01-08 06:51 - 2016-01-08 06:51 - 00772016 _____ (Reimage®) C:\Users\Marek\Downloads\ReimageRepair.exe
2016-01-04 17:06 - 2016-01-04 17:06 - 00003342 _____ C:\Windows\System32\Tasks\{48229BA5-8CDB-4029-BC94-C7AF498B95C8}
==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========
(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
2016-01-31 13:16 - 2015-12-28 10:56 - 00000000 ____D C:\Users\Marek\AppData\Roaming\WarThunder
2016-01-31 13:10 - 2015-08-15 06:30 - 00000424 _____ C:\Windows\Tasks\WpsNotifyTask_Administrator.job
2016-01-31 13:08 - 2015-12-07 16:02 - 00001182 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2016-01-31 13:07 - 2015-08-15 06:30 - 00000424 _____ C:\Windows\Tasks\WpsUpdateTask_Administrator.job
2016-01-31 12:48 - 2015-12-28 08:38 - 00000000 ____D C:\Program Files (x86)\Steam
2016-01-31 12:44 - 2015-12-28 12:39 - 00001078 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-31 12:44 - 2015-12-28 12:39 - 00001074 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-31 12:39 - 2015-08-15 15:03 - 00000000 ____D C:\Windows\Panther
2016-01-31 12:37 - 2015-10-30 20:56 - 00000000 ___HD C:\$WINDOWS.~BT
2016-01-31 12:26 - 2015-12-29 10:58 - 00004226 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{019FE7E6-6A75-4769-8864-DF83FD7FA7CC}
2016-01-31 12:26 - 2015-09-06 17:26 - 00003544 _____ C:\Windows\System32\Tasks\ASUS Live Update1
2016-01-31 12:26 - 2015-09-06 17:26 - 00003534 _____ C:\Windows\System32\Tasks\ASUS Live Update2
2016-01-31 12:25 - 2015-12-07 16:04 - 00000000 ___RD C:\Users\Marek\Dropbox
2016-01-31 12:25 - 2015-12-07 16:01 - 00000000 ____D C:\Users\Marek\AppData\Local\Dropbox
2016-01-31 12:24 - 2015-12-07 15:43 - 00000165 _____ C:\Users\Marek\AppData\Roaming\sp_data.sys
2016-01-31 12:23 - 2015-12-07 16:02 - 00001178 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2016-01-30 23:02 - 2015-08-15 14:20 - 00815198 _____ C:\Windows\system32\perfh015.dat
2016-01-30 23:02 - 2015-08-15 14:20 - 00156680 _____ C:\Windows\system32\perfc015.dat
2016-01-30 23:02 - 2015-08-15 06:21 - 01836100 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-30 23:02 - 2015-07-10 12:02 - 00000000 ____D C:\Windows\INF
2016-01-30 20:23 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\AppReadiness
2016-01-30 20:17 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2016-01-29 17:52 - 2015-12-07 15:43 - 00000000 __SHD C:\Users\Marek\IntelGraphicsProfiles
2016-01-29 17:52 - 2015-12-07 15:38 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-01-29 17:50 - 2015-07-10 13:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-29 17:49 - 2015-07-10 10:05 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-01-29 17:20 - 2015-07-10 10:05 - 00032768 ___SH C:\Windows\system32\config\ELAM
2016-01-29 15:52 - 2015-12-28 12:41 - 00002280 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-29 15:52 - 2015-12-28 12:41 - 00002268 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-28 19:01 - 2015-09-06 17:49 - 00001542 _____ C:\Users\Public\Desktop\WPS Office.lnk
2016-01-28 19:00 - 2015-09-06 17:31 - 00000000 ____D C:\ProgramData\McAfee
2016-01-28 18:37 - 2015-09-06 16:29 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-01-28 18:36 - 2015-12-13 09:45 - 00122160 _____ (DEVGURU Co., LTD.(http://www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2016-01-28 18:35 - 2015-12-13 09:49 - 00214832 _____ (DEVGURU Co., LTD.(http://www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2016-01-26 14:02 - 2015-09-06 17:31 - 00000000 ____D C:\Program Files\Common Files\McAfee
2016-01-26 14:01 - 2015-07-10 12:04 - 00000000 ___HD C:\Windows\ELAMBKUP
2016-01-26 14:00 - 2015-12-10 20:40 - 00000000 ____D C:\Windows\System32\Tasks\McAfee
2016-01-22 22:03 - 2015-09-06 17:26 - 00000000 ____D C:\Program Files\DIFX
2016-01-22 22:03 - 2015-08-15 06:29 - 00000000 ____D C:\Program Files (x86)\ASUS
2016-01-21 17:58 - 2015-09-06 17:31 - 00000000 ____D C:\Program Files (x86)\McAfee
2016-01-15 23:17 - 2015-07-10 11:55 - 00000000 ____D C:\Windows\CbsTemp
2016-01-15 23:16 - 2015-12-10 21:11 - 00000000 ____D C:\Windows\system32\MRT
2016-01-15 23:13 - 2015-12-10 21:10 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-01-13 23:24 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\LiveKernelReports
2016-01-08 18:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\rescache
2016-01-08 18:01 - 2015-08-15 14:19 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2016-01-08 18:01 - 2015-07-10 17:30 - 00000000 ____D C:\Program Files\Windows Journal
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\SysWOW64\winrm
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\SysWOW64\WCN
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\system32\winrm
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\system32\WCN
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\system32\slmgr
2016-01-08 18:01 - 2015-07-10 17:26 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ___SD C:\Windows\SysWOW64\F12
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ___SD C:\Windows\system32\F12
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ___SD C:\Windows\system32\DiagSvcs
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ___RD C:\Windows\MiracastView
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ___RD C:\Windows\DevicesFlow
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\SysWOW64\oobe
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\SysWOW64\MUI
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\SysWOW64\Com
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\oobe
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\MUI
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\migwiz
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\Com
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\IME
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\Help
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Windows Defender
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\System
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-01-08 18:01 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-01-08 18:01 - 2015-07-10 10:05 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-01-08 18:01 - 2015-07-10 10:05 - 00000000 ____D C:\Windows\system32\Sysprep
2016-01-08 18:01 - 2015-07-10 10:05 - 00000000 ____D C:\Windows\system32\Dism
2016-01-08 18:01 - 2015-07-10 10:05 - 00000000 ____D C:\Windows\servicing
2016-01-08 06:52 - 2015-12-07 15:43 - 00000000 ____D C:\Users\Marek\AppData\Local\Packages
2016-01-06 20:46 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\SysWOW64\en-GB
2016-01-06 20:46 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\en-GB
2016-01-04 18:06 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\NDF
2016-01-04 15:53 - 2015-12-28 12:39 - 00000000 ____D C:\Users\Marek\AppData\Local\Google
==================== Pliki w katalogu głównym wybranych folderów =======
2015-12-07 15:43 - 2016-01-31 12:24 - 0000165 _____ () C:\Users\Marek\AppData\Roaming\sp_data.sys
2015-09-06 17:14 - 2015-09-06 17:14 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Niektóre pliki w TEMP:
====================
C:\Users\Marek\AppData\Local\Temp\5jUZ4YL1jA.exe
C:\Users\Marek\AppData\Local\Temp\e1ktzb6ryW.exe
C:\Users\Marek\AppData\Local\Temp\ICReinstall_installer_Steam_sciagnij.exe
C:\Users\Marek\AppData\Local\Temp\oprun12252.exe
C:\Users\Marek\AppData\Local\Temp\oprun12732.exe
C:\Users\Marek\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Marek\AppData\Local\Temp\setup_758.exe
C:\Users\Marek\AppData\Local\Temp\sqlite3.dll
C:\Users\Marek\AppData\Local\Temp\UX5SrOKACv.exe
==================== Bamital & volsnap =================
(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)
C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
C:\Windows\explorer.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
C:\Windows\system32\services.exe => Plik podpisany cyfrowo
C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll
[2015-07-10 12:00] - [2015-07-10 12:00] - 0534064 ____A (Microsoft Corporation) 06E38EF031143B41A713E5301D90E62B
C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo
LastRegBack: 2016-01-22 18:51
==================== Koniec FRST.txt ============================