Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja:27-01-2016
Uruchomiony przez Administrator (administrator) MAREK-A4431E758 (28-01-2016 22:28:13)
Uruchomiony z E:\DOKUMENTY\pobrane
Załadowane profile: Administrator (Dostępne profile: Administrator)
Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) Język: Polski
Internet Explorer Wersja 7 (Domyślna przeglądarka: FF)
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-f...utorial-how-to-use-farbar-recovery-scan-tool/
==================== Procesy (filtrowane) =================
(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\Av\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe
() C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Atheros) C:\WINDOWS\system32\acs.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
() C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe
() C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WJATH\AthServer.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Glarysoft Ltd) C:\Program Files\Glary Utilities 5\Integrator.exe
(Glarysoft Ltd) C:\Program Files\Glary Utilities 5\MemfilesService.exe
(Opera Software) C:\Program Files\Opera\34.0.2036.50\opera.exe
(Opera Software) C:\Program Files\Opera\34.0.2036.50\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\34.0.2036.50\opera.exe
(Opera Software) C:\Program Files\Opera\34.0.2036.50\opera.exe
(Opera Software) C:\Program Files\Opera\34.0.2036.50\opera.exe
(Opera Software) C:\Program Files\Opera\34.0.2036.50\opera.exe
(Opera Software) C:\Program Files\Opera\34.0.2036.50\opera.exe
(Glarysoft Ltd) C:\Program Files\Glary Utilities 5\DiskCleaner.exe
==================== Rejestr (filtrowane) ===========================
(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [18750976 2009-10-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\Av\avgui.exe [3874216 2016-01-08] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Dropbox] => C:\Program Files\Dropbox\Client\Dropbox.exe [24952456 2015-12-08] (Dropbox, Inc.)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [179624 2016-01-12] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-10-05] (Malwarebytes)
HKU\S-1-5-19\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-20\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32
HKU\S-1-5-21-776561741-1409082233-1801674531-500\...\Run: [GUDelayStartup] => C:\Program Files\Glary Utilities 5\StartupManager.exe [36776 2016-01-18] (Glarysoft Ltd)
HKU\S-1-5-21-776561741-1409082233-1801674531-500\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
HKU\S-1-5-21-776561741-1409082233-1801674531-500\...\MountPoints2: {3c4644f8-7a68-11e5-896e-4061865f33ac} - G:\Autorun.exe
HKU\S-1-5-21-776561741-1409082233-1801674531-500\...\MountPoints2: {9b18b92e-29a9-11e5-8523-806d6172696f} - G:\DVDSetup.exe
HKU\S-1-5-18\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32
Lsa: [Authentication Packages] msv1_0 nwprovau
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\TP-LINK Wireless Configuration Utility.lnk [2015-11-15]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
BootExecute: autocheck autochk /p \??\C:autocheck autochk * C:\PROGRA~1\AVG\Av\avgrsx.exe /sync /restart
==================== Internet (filtrowane) ====================
(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)
Hosts: Nie znaleziono pliku Hosts w domyślnym katalogu
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{4A89F512-B0AE-4937-B9A8-BBDFEAE7774A}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{758C20B2-CB46-4695-B997-D2D3DA245CEB}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-26] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\yj29p0rg.default
FF SelectedSearchEngine: webssearches
FF Homepage: hxxp://www.google.com/
FF Session Restore: -> [funkcja włączona]
FF Plugin:
@Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40620.0\npctrl.dll [2015-06-19] ( Microsoft Corporation)
FF Plugin:
@Microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2007-11-07] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default
==================== Usługi (filtrowane) ========================
(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
R2 acs; C:\WINDOWS\system32\acs.exe [499796 2014-05-23] (Atheros) [Brak podpisu cyfrowego]
S3 AvgAMPS; C:\Program Files\AVG\Av\avgamps.exe [627544 2016-01-08] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [3906568 2016-01-08] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [865704 2016-01-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [583936 2016-01-08] (AVG Technologies CZ, s.r.o.)
S2 dbupdate; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-21] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-21] (Dropbox, Inc.)
S3 idsvc; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [864256 2007-10-11] (Microsoft Corporation) [Brak podpisu cyfrowego]
S3 jswpsapi; C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WPS\jswpsapi.exe [360529 2014-05-23] (wireless) [Brak podpisu cyfrowego]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S4 NetTcpPortSharing; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [122880 2007-10-11] (Microsoft Corporation) [Brak podpisu cyfrowego]
S3 npggsvc; C:\WINDOWS\system32\GameMon.des [3611808 2015-07-22] (INCA Internet Co., Ltd.)
R2 nvsvc; C:\WINDOWS\system32\nvsvc32.exe [168004 2009-07-08] (NVIDIA Corporation) [Brak podpisu cyfrowego]
R2 NWCWorkstation; C:\WINDOWS\System32\nwwks.dll [65536 2008-04-14] (Microsoft Corporation)
R2 NwSapAgent; C:\WINDOWS\System32\ipxsap.dll [66560 2001-10-26] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [1164688 2015-12-16] ()
===================== Sterowniki (filtrowane) ==========================
(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative)
R1 AmdPPM; C:\WINDOWS\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices)
R3 AR9271; C:\WINDOWS\System32\DRIVERS\athuw.sys [1763584 2014-05-23] (Atheros Communications, Inc.)
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [149936 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [245168 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [231344 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [31664 2015-11-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [229296 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [308656 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [194992 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [37296 2015-12-04] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [231856 2015-10-08] (AVG Technologies CZ, s.r.o.)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [242240 2015-10-24] (DT Soft Ltd)
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [17472 2015-07-14] (Glarysoft Ltd)
R3 JSWSCIMD; C:\WINDOWS\System32\DRIVERS\jswscimd.sys [57440 2014-05-23] (Atheros Communications, Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [170200 2016-01-28] (Malwarebytes)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [66688 2009-07-01] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [164896 2009-06-30] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13824 2009-07-01] (NVIDIA Corporation)
R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation)
R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2001-08-17] (Microsoft Corporation)
R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2001-08-17] (Microsoft Corporation)
R3 NWRDR; C:\WINDOWS\System32\DRIVERS\nwrdr.sys [163584 2008-04-13] (Microsoft Corporation)
U0 rmadsjgy; C:\WINDOWS\System32\drivers\yjmpqs.sys [52440 2016-01-28] (Malwarebytes)
S3 SG762_XP; C:\WINDOWS\System32\DRIVERS\WlanBZXP.sys [402432 2006-01-19] (ZyDAS Technology Corporation)
R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361344 2008-05-08] (Microsoft Corporation) [Brak podpisu cyfrowego]
R3 WSIMD; C:\WINDOWS\System32\DRIVERS\wsimd.sys [58208 2014-05-23] (Atheros Communications, Inc.) [Brak podpisu cyfrowego]
S4 IntelIde; Brak ImagePath
S3 MSICDSetup; \??\F:\CDriver.sys [X]
U1 WS2IFSL; Brak ImagePath
==================== NetSvcs (filtrowane) ===================
(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)
==================== Jeden miesiąc - utworzone pliki i foldery ========
(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
2016-01-28 22:28 - 2016-01-28 22:28 - 00000000 ____D C:\FRST
2016-01-28 21:42 - 2016-01-28 21:42 - 00052440 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\yjmpqs.sys
2016-01-28 21:06 - 2016-01-28 21:07 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-01-28 21:05 - 2016-01-28 21:05 - 00000777 _____ C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk
2016-01-28 21:05 - 2016-01-28 21:05 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-01-28 21:05 - 2016-01-28 21:05 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware
2016-01-28 21:05 - 2016-01-28 21:05 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
2016-01-28 21:05 - 2015-10-05 09:50 - 00121560 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-01-28 21:05 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-01-28 20:45 - 2016-01-28 21:21 - 00000000 ____D C:\AdwCleaner
2016-01-28 19:37 - 2016-01-28 19:37 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\Soft-4-Free.com
2016-01-28 18:45 - 2016-01-28 20:51 - 00000472 _____ C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1454003135.job
2016-01-28 18:45 - 2016-01-28 18:45 - 00000675 _____ C:\Documents and Settings\All Users\Pulpit\Opera.lnk
2016-01-28 18:45 - 2016-01-28 18:45 - 00000675 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Opera.lnk
2016-01-28 11:11 - 2016-01-28 11:11 - 00000000 __SHD C:\found.000
2016-01-26 11:01 - 2016-01-26 11:01 - 00115388 _____ C:\Documents and Settings\Administrator\Moje dokumenty\[torrenty.pl] Agenci T A R C Z Y - Marvel's Agents of S H I E L D [s1e1-22] [480p] [WEB-DL] [XviD-Ralf DeiX] [Lektor PL] [676kowal].torrent
2016-01-20 19:20 - 2016-01-20 19:21 - 08545075 _____ C:\Documents and Settings\Administrator\Moje dokumenty\matmapoferiachpp.pdf
2016-01-20 16:45 - 2016-01-19 20:20 - 22604032 _____ C:\Documents and Settings\Administrator\Moje dokumenty\1.DEM
2016-01-20 16:45 - 2016-01-19 19:53 - 20563576 _____ C:\Documents and Settings\Administrator\Moje dokumenty\2.dem
2016-01-20 16:45 - 2016-01-19 19:26 - 21530407 _____ C:\Documents and Settings\Administrator\Moje dokumenty\3.dem
2016-01-20 16:45 - 2016-01-19 19:00 - 22354649 _____ C:\Documents and Settings\Administrator\Moje dokumenty\4.dem
2016-01-20 07:44 - 2016-01-20 07:44 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\mot
2016-01-19 21:37 - 2016-01-19 21:38 - 22364160 _____ C:\Documents and Settings\Administrator\Moje dokumenty\dedust2-1601191834-de_dust2.tar.gz
2016-01-19 21:37 - 2016-01-19 21:37 - 22609920 _____ C:\Documents and Settings\Administrator\Moje dokumenty\dedust2-1601191953-de_dust2.tar.gz
2016-01-19 21:37 - 2016-01-19 21:37 - 21534720 _____ C:\Documents and Settings\Administrator\Moje dokumenty\dedust2-1601191900-de_dust2.tar.gz
2016-01-19 21:37 - 2016-01-19 21:37 - 20572160 _____ C:\Documents and Settings\Administrator\Moje dokumenty\dedust2-1601191926-de_dust2.tar.gz
2016-01-17 17:33 - 2016-01-27 22:12 - 00000000 ____D C:\Documents and Settings\Administrator\Menu Start\Programy\MOS v1.50
2016-01-17 17:12 - 2016-01-27 22:12 - 00000000 ____D C:\Documents and Settings\Administrator\Menu Start\Programy\MOS v1.4
2016-01-17 15:48 - 2016-01-17 16:43 - 228349212 _____ () C:\Documents and Settings\Administrator\Moje dokumenty\TATW_3.2_Patch.exe
2016-01-17 15:19 - 2008-04-16 11:15 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\m2_tw_kingdoms_pl_patch_105
2016-01-17 15:10 - 2016-01-17 15:10 - 00000681 _____ C:\Documents and Settings\Administrator\Pulpit\Medieval II Total War.lnk
2016-01-17 15:07 - 2016-01-17 15:07 - 00000000 ____D C:\Documents and Settings\Administrator\Menu Start\Programy\Sega
2016-01-17 14:36 - 2016-01-17 14:39 - 109991641 _____ C:\Documents and Settings\Administrator\Moje dokumenty\medieval_2_total_war_kingdoms_pl_patch_105.zip
2016-01-17 00:25 - 2016-01-15 00:19 - 03624790 _____ C:\Documents and Settings\Administrator\Pulpit\Jacek Piekara - Ja Inkwizytor - Kościany Galeon (Tom wg chronologii wydarzeń 06).MOBI
2016-01-15 14:47 - 2016-01-15 14:47 - 00303506 _____ C:\Documents and Settings\Administrator\Moje dokumenty\e12.zip
2016-01-14 18:14 - 2016-01-14 18:14 - 00021538 _____ C:\Documents and Settings\Administrator\Moje dokumenty\ŁatwiejszyStartPiterAIpodstawka.rar
2016-01-14 18:09 - 2016-01-14 18:09 - 00050573 _____ C:\Documents and Settings\Administrator\Moje dokumenty\PiterAIpodst.3.3.rar
2016-01-14 14:52 - 2016-01-14 14:52 - 00000000 ____D C:\Program Files\Speccy
2016-01-14 14:52 - 2016-01-14 14:52 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Speccy
2016-01-14 14:50 - 2016-01-28 21:50 - 00000432 _____ C:\WINDOWS\Tasks\At1.job
2016-01-13 15:56 - 2016-01-13 15:56 - 01814528 _____ C:\Documents and Settings\Administrator\Moje dokumenty\hydroksykwasy.ppt
2016-01-10 22:15 - 2016-01-10 22:16 - 30192139 _____ C:\Documents and Settings\Administrator\Moje dokumenty\nagrania_angielski_PR.zip
2016-01-10 22:15 - 2016-01-10 22:16 - 19236045 _____ C:\Documents and Settings\Administrator\Moje dokumenty\nagrania_angielski_PP.zip
2016-01-07 14:05 - 2016-01-07 14:05 - 00000000 ____D C:\WINDOWS\CSC
2016-01-01 20:33 - 2016-01-17 18:50 - 00000876 _____ C:\Documents and Settings\Administrator\Pulpit\Third Age - Total War.lnk
2016-01-01 20:33 - 2016-01-01 20:33 - 00000000 ____D C:\Documents and Settings\Administrator\Menu Start\Programy\Third Age - Total War 3.0 (Part 2of2)
2016-01-01 20:25 - 2016-01-01 20:25 - 00000000 ____D C:\Documents and Settings\Administrator\Menu Start\Programy\Third Age - Total War 3.0 (Part 1of2)
2016-01-01 19:44 - 2016-01-01 19:44 - 00107888 _____ (Sony DADC Austria AG.) C:\WINDOWS\system32\CmdLineExt.dll
2015-12-29 00:35 - 2015-12-29 00:35 - 00341491 _____ C:\Documents and Settings\Administrator\Moje dokumenty\Nowy_Dokument_programu_Microsoft_Office_Word.pdf
==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========
(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)
2016-01-28 22:28 - 2015-07-14 15:04 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp
2016-01-28 21:42 - 2015-07-14 15:04 - 00000000 ___RD C:\Documents and Settings\Administrator\Moje dokumenty
2016-01-28 21:42 - 2015-07-14 15:04 - 00000000 ___HD C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji
2016-01-28 21:42 - 2015-07-13 23:25 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji
2016-01-28 21:36 - 2015-09-21 15:31 - 00001154 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-01-28 21:20 - 2015-07-19 12:11 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-01-28 21:12 - 2015-07-14 16:01 - 00000761 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Glary Utilities 5.lnk
2016-01-28 21:12 - 2015-07-14 16:01 - 00000755 _____ C:\Documents and Settings\All Users\Pulpit\Glary Utilities 5.lnk
2016-01-28 21:12 - 2015-07-14 16:00 - 00000334 _____ C:\WINDOWS\Tasks\GlaryInitialize 5.job
2016-01-28 21:12 - 2015-07-14 16:00 - 00000000 ____D C:\Program Files\Glary Utilities 5
2016-01-28 21:12 - 2015-07-14 15:04 - 00000000 ___HD C:\Documents and Settings\Administrator\Szablony
2016-01-28 21:05 - 2015-07-13 23:26 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy
2016-01-28 21:05 - 2015-07-13 23:26 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit
2016-01-28 20:52 - 2015-09-21 16:10 - 00000000 ___RD C:\Documents and Settings\Administrator\Moje dokumenty\Dropbox
2016-01-28 20:52 - 2015-09-21 15:30 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Dropbox
2016-01-28 20:51 - 2015-09-23 07:57 - 00000442 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-01-28 20:51 - 2015-07-13 21:51 - 00032348 _____ C:\WINDOWS\SchedLgU.Txt
2016-01-28 20:51 - 2009-07-08 09:58 - 00236798 _____ C:\WINDOWS\system32\NvApps.xml
2016-01-28 20:50 - 2015-09-21 15:31 - 00001150 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-01-28 20:50 - 2015-07-13 21:51 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-28 20:49 - 2015-11-15 09:57 - 00524288 _____ C:\WINDOWS\system32\config\ACS.evt
2016-01-28 20:49 - 2015-07-14 15:20 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\MFAData
2016-01-28 20:49 - 2015-07-14 15:05 - 00000188 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2016-01-28 20:48 - 2015-07-14 15:05 - 00000761 _____ C:\Documents and Settings\Administrator\Menu Start\Programy\Internet Explorer.lnk
2016-01-28 20:48 - 2015-07-14 15:04 - 00000000 __RHD C:\Documents and Settings\Administrator\Dane aplikacji
2016-01-28 20:48 - 2015-07-14 15:04 - 00000000 ___RD C:\Documents and Settings\Administrator\Menu Start\Programy
2016-01-28 18:45 - 2015-07-14 15:21 - 00000000 ____D C:\Program Files\Opera
2016-01-28 18:43 - 2015-07-24 18:12 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Pobrane
2016-01-28 11:20 - 2015-07-14 15:04 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit
2016-01-27 19:25 - 2015-07-13 23:26 - 01262776 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-27 19:25 - 2001-10-26 16:15 - 00558796 _____ C:\WINDOWS\system32\perfh015.dat
2016-01-27 19:25 - 2001-10-26 16:15 - 00105734 _____ C:\WINDOWS\system32\perfc015.dat
2016-01-27 15:04 - 2001-07-21 22:17 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-01-26 19:03 - 2015-12-07 21:55 - 00000000 ____D C:\Program Files\Counter-Strike 1.6 NonSteam
2016-01-26 15:17 - 2015-07-20 05:04 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent
2016-01-25 12:15 - 2015-07-14 15:04 - 00000000 ____D C:\Documents and Settings\Administrator
2016-01-23 23:35 - 2015-07-14 16:01 - 00000992 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-21 22:54 - 2015-08-31 22:15 - 00013824 _____ C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-01-21 19:37 - 2015-11-29 02:24 - 00000000 ____D C:\Documents and Settings\Administrator\.gimp-2.8
2016-01-21 16:12 - 2015-07-14 15:33 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\AVG
2016-01-21 16:12 - 2015-07-13 23:22 - 00000000 ___HD C:\WINDOWS\inf
2016-01-18 16:25 - 2015-11-16 17:26 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\Nowy folder
2016-01-17 15:17 - 2015-07-13 21:42 - 00000000 ____D C:\WINDOWS\system32\DirectX
2016-01-17 15:16 - 2015-11-06 13:42 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\SEGA
2016-01-17 15:12 - 2015-07-14 15:07 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-01-17 14:49 - 2015-12-12 19:57 - 00000000 ____D C:\Program Files\Sega
2016-01-16 02:41 - 2015-07-22 20:59 - 00000000 ____D C:\Program Files\Steam
2016-01-13 23:56 - 2015-08-31 23:35 - 00000811 _____ C:\Documents and Settings\Administrator\Pulpit\Daum Potplayer.lnk
2016-01-07 14:08 - 2015-11-15 09:58 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-01-06 11:06 - 2015-11-22 12:47 - 00000617 _____ C:\Documents and Settings\All Users\Pulpit\AVG.lnk
2016-01-06 11:06 - 2015-11-22 12:47 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\AVG Zen
2016-01-04 16:40 - 2015-09-06 21:00 - 00000000 ____D C:\WINDOWS\Minidump
2016-01-01 19:41 - 2015-07-19 12:11 - 00000730 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk
2016-01-01 19:41 - 2015-07-19 12:11 - 00000724 _____ C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk
==================== Pliki w katalogu głównym wybranych folderów =======
2015-08-31 22:15 - 2016-01-21 22:54 - 0013824 _____ () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-29 01:17 - 2015-11-29 01:17 - 0004846 _____ () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\recently-used.xbel
2015-09-21 15:35 - 2015-09-21 15:41 - 0000166 _____ () C:\Documents and Settings\All Users\Dane aplikacji\Microsoft.SqlServer.Compact.351.32.bc
Pliki do przeniesienia lub usunięcia:
====================
C:\Windows\Tasks\At1.job
==================== Bamital & volsnap =================
(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)
C:\WINDOWS\explorer.exe => Plik podpisany cyfrowo
C:\WINDOWS\system32\winlogon.exe => Plik podpisany cyfrowo
C:\WINDOWS\system32\svchost.exe => Plik podpisany cyfrowo
C:\WINDOWS\system32\services.exe => Plik podpisany cyfrowo
C:\WINDOWS\system32\User32.dll => Plik podpisany cyfrowo
C:\WINDOWS\system32\userinit.exe => Plik podpisany cyfrowo
C:\WINDOWS\system32\rpcss.dll => Plik podpisany cyfrowo
C:\WINDOWS\system32\dnsapi.dll => Plik podpisany cyfrowo
C:\WINDOWS\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo
==================== Koniec FRST.txt ============================