Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x86) Wersja: 09-08-2017 Uruchomiony przez HRABIA (10-08-2017 19:48:04) Uruchomiony z C:\Users\HRABIA\Desktop\frst Microsoft Windows 7 Professional N Service Pack 1 (X86) (2016-10-15 14:09:04) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-3805530199-1123286208-3472868733-500 - Administrator - Disabled) Gość (S-1-5-21-3805530199-1123286208-3472868733-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3805530199-1123286208-3472868733-1002 - Limited - Enabled) HRABIA (S-1-5-21-3805530199-1123286208-3472868733-1000 - Administrator - Enabled) => C:\Users\HRABIA ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKU\S-1-5-21-3805530199-1123286208-3472868733-1000\...\uTorrent) (Version: 3.4.9.42606 - BitTorrent Inc.) Adobe Flash Player 26 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated) Adobe Flash Player 26 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated) Adobe Reader XI (11.0.20) - Polish (HKLM\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{77301917-A7CD-8D6D-9204-D819EEFF5C2F}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.) Atheros WLAN Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros) Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 17.5.2303 - AVAST Software) CCleaner (HKLM\...\CCleaner) (Version: 5.22 - Piriform) doPDF (HKLM\...\{4807F96D-2A55-4FD8-9348-4D9CDA6874EE}) (Version: 8.9.950 - Softland) Hidden doPDF 8 (HKLM\...\{6da862f2-c778-4991-ba04-5afd3d7d916c}) (Version: 8.9.950 - Softland) Energy Management (HKLM\...\{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 7.0.3.3 - Lenovo) Hidden Energy Management (HKLM\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 7.0.3.3 - Lenovo) Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden ipla 2.8.7 (HKLM\...\ipla) (Version: 2.8.7 - Cyfrowy Polsat S.A.) K-Lite Codec Pack 11.6.5 Basic (HKLM\...\KLiteCodecPack_is1) (Version: 11.6.5 - ) Lenovo EasyCamera (HKLM\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 13.11.1206.1 - Vimicro) Lenovo pointing device (HKLM\...\Elantech) (Version: 10.4.2.8 - ELAN Microelectronic Corp.) Lenovo Service Bridge (HKU\S-1-5-21-3805530199-1123286208-3472868733-1000\...\dda9ca0b023f4c56) (Version: 1.6.6.0 - Lenovo) Malwarebytes (wersja 3.1.2.1733) (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Microsoft .NET Framework 4.6.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01590 - Microsoft Corporation) Microsoft .NET Framework 4.6.2 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.6.01590 - Microsoft Corporation) Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.8229.2103 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Mozilla Firefox 54.0.1 (x86 pl) (HKLM\...\Mozilla Firefox 54.0.1 (x86 pl)) (Version: 54.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla) novaPDF 8 Printer Driver (HKLM\...\{C1B6DCEE-F31D-41A3-BF18-6F0BE7F28276}) (Version: 8.9.950 - Softland) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8229.2103 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-0000-0000000FF1CE}) (Version: 16.0.8229.2103 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8201.2075 - Microsoft Corporation) Hidden Opera Stable 47.0.2631.39 (HKLM\...\Opera 47.0.2631.39) (Version: 47.0.2631.39 - Opera Software) PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) PowerXpressHybrid (HKLM\...\{097E024D-BE30-4D95-B5F3-B6AE9C1568D4}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Revo Uninstaller 2.0.3 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.3 - VS Revo Group, Ltd.) Screamer Radio (HKU\S-1-5-21-3805530199-1123286208-3472868733-1000\...\Screamer) (Version: 1.0.6167.30805 - Steamcore) Spotify (HKU\S-1-5-21-3805530199-1123286208-3472868733-1000\...\Spotify) (Version: 1.0.59.395.ge6ca9946 - Spotify AB) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) WinRAR 5.31 (32-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-18] (AVAST Software) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-18] (AVAST Software) ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-08] (Alexander Roshal) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-18] (AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes) ContextMenuHandlers3: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-04] () ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll [2012-03-21] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-18] (AVAST Software) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes) ContextMenuHandlers6: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-04] () ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-02-08] (Alexander Roshal) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {006F7832-AE1C-4FD6-839D-C1B826777553} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-07-07] () Task: {25950471-F8B7-4578-800C-6BC99FF64A3D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-07-25] (Microsoft Corporation) Task: {375005EB-57F1-47CC-86C0-B7A7A5C42E43} - System32\Tasks\Opera scheduled Autoupdate 1476546118 => C:\Program Files\Opera\launcher.exe [2017-08-08] (Opera Software) Task: {3CCC4ED9-5ED0-48C8-A772-0AF31ED0EEDD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated) Task: {3EA9F9AC-883C-4136-B6D0-44F634D25C49} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-07-18] (Microsoft Corporation) Task: {43AE996B-0DE6-4107-98D4-A3D27BDE1C65} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd) Task: {4CD9182E-9667-441D-871A-D6D9C6837E2C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-10] (Adobe Systems Incorporated) Task: {632BAF79-25D3-40A4-B289-06DA6D9A5F1C} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_151_pepper.exe [2017-08-10] (Adobe Systems Incorporated) Task: {74CC82B5-8B42-407D-B387-EF12282C9EE9} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-07-18] (Microsoft Corporation) Task: {768B7103-A9D6-454F-B0B6-2014F11130BE} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-18] (AVAST Software) Task: {857A200E-D21F-4101-868B-CD3D70CA3D13} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-07-07] () Task: {86847607-ABFF-4698-9BD2-28ECADEC27FC} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-07-15] (AVAST Software) Task: {8EEC5A40-6AE8-4D86-8A16-2FFE8B4C070B} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-3805530199-1123286208-3472868733-1000 => "C:\Windows\system32\rundll32.exe" dfshim.dll,ShOpenVerbShortcut C:\Users\HRABIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Service Bridge.appref-ms Task: {A8077C2A-6215-44CA-97B2-3B54BEDED2BB} - System32\Tasks\doPDF Update => C:\Program Files\Softland\novaPDF 8\Driver\UpdateApplication.exe [2017-06-06] () Task: {CE19294E-E879-405A-8270-F8A85A7F6966} - System32\Tasks\{80CE5A7B-077E-435F-9F9B-BD54024986A6} => C:\Windows\system32\pcalua.exe -a C:\Users\HRABIA\Downloads\NetFx20SP1_x86.exe -d C:\Users\HRABIA\Downloads Task: {DBE43A75-2359-4336-B508-C139D95F8CCD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-07-25] (Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Skróty & WMI ======================== (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2017-07-18 19:28 - 2017-07-18 19:28 - 000170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-07-18 19:28 - 2017-07-18 19:28 - 000192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-07-18 19:28 - 2017-07-18 19:28 - 000224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-08-10 17:42 - 2017-08-10 17:42 - 005894008 _____ () C:\Program Files\AVAST Software\Avast\defs\17081000\algo.dll 2017-07-18 19:28 - 2017-07-18 19:28 - 000689272 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-07-18 19:28 - 2017-07-18 19:28 - 000231664 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2012-03-21 22:29 - 2012-03-21 22:29 - 000065024 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2017-06-06 20:06 - 2017-06-06 20:06 - 000138672 _____ () C:\Program Files\Softland\novaPDF 8\Server\AgileDotNetRT.dll 2017-08-02 06:27 - 2017-08-02 07:53 - 001720264 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2010-07-04 23:32 - 2010-07-04 23:32 - 000004608 _____ () C:\Program Files\Unlocker\UnlockerHook.dll 2016-10-15 19:19 - 2017-07-07 17:34 - 008931528 _____ () C:\Program Files\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll 2010-07-04 23:32 - 2010-07-04 23:32 - 000010752 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll 2008-12-20 03:20 - 2008-12-20 03:20 - 000051016 _____ () C:\Program Files\Lenovo\Energy Management\HookLib.dll 2012-02-21 13:06 - 2012-02-21 13:06 - 001502208 _____ () C:\Program Files\Lenovo\Energy Management\EMWpfUI.dll 2012-02-21 13:06 - 2012-02-21 13:06 - 000005120 _____ () C:\Program Files\Lenovo\Energy Management\pl-PL\EMWpfUI.resources.dll 2008-12-20 03:20 - 2008-12-20 03:20 - 000063304 _____ () C:\Program Files\Lenovo\Energy Management\kbdhook.dll 2010-07-04 21:51 - 2010-07-04 21:51 - 000017408 _____ () C:\Program Files\Unlocker\UnlockerAssistant.exe 2017-07-18 19:29 - 2017-07-18 19:29 - 001065936 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll 2017-07-17 22:36 - 2017-07-17 22:36 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-07-18 19:28 - 2017-07-18 19:28 - 000292920 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2016-08-26 20:25 - 2016-08-26 20:25 - 000065536 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll 2012-03-21 22:28 - 2012-03-21 22:28 - 000095232 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2011-11-09 09:55 - 2011-11-09 09:55 - 000016384 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2012-03-21 22:09 - 2012-03-21 22:09 - 000369152 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2017-07-18 19:28 - 2017-07-18 19:28 - 000134928 _____ () c:\Program Files\AVAST Software\Avast\vaarclient.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Powiązania plików (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-3805530199-1123286208-3472868733-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\HRABIA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == MSCONFIG\startupreg: Spotify => "C:\Users\HRABIA\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\HRABIA\AppData\Roaming\Spotify\SpotifyWebHelper.exe" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [TCP Query User{9ED1608A-787E-4FA9-B19B-4AC8B214B061}C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe FirewallRules: [UDP Query User{086700E7-4A3B-45D6-9799-F3A746A12B4B}C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe FirewallRules: [{00E8CABE-BD20-41EF-8437-5F856D266461}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{6371C347-7781-42F0-9C9F-94E8B05F87EF}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{2D037941-327F-4AEF-9D67-372F615C055F}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{59907FE6-9239-49D6-AF3A-F57C3F876DA9}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe FirewallRules: [TCP Query User{14B756A5-0F03-40FC-847D-A4F1FBE2C5FF}C:\users\hrabia\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hrabia\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{38A1075F-CC05-48A7-A1AA-EA2CF804B10D}C:\users\hrabia\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hrabia\appdata\roaming\spotify\spotify.exe FirewallRules: [{055EC154-D14C-4B88-B7BD-E80B2EF03279}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{314A4763-122D-4C14-B389-795055F235E1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{918FB668-101A-4C42-B03D-0B2D89BB9225}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe FirewallRules: [{07598469-9120-4245-9396-85A0273EF4DA}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe FirewallRules: [{385D203E-453F-49C8-9595-DB166697E33E}] => (Allow) C:\Program Files\Opera\42.0.2393.137\opera.exe FirewallRules: [TCP Query User{7B22EE80-7FEF-4BE5-9F5C-33ED8FDE4FB1}C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe FirewallRules: [UDP Query User{5B0F08C9-91FE-465A-97AD-78C0E65A8D82}C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\hrabia\appdata\roaming\utorrent\utorrent.exe FirewallRules: [{E8EDC162-903B-4012-AFF1-7CEF5AEB52E6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{D73863DF-D306-40AA-A06E-CC9C9A36529D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{2B701BE9-EC77-4327-8EA5-48918ADC0960}] => (Allow) C:\Program Files\Opera\46.0.2597.57\opera.exe FirewallRules: [{24401C15-879D-4CED-820A-552BBBB66201}] => (Allow) LPort=8501 FirewallRules: [{62B1E097-25D0-4FCD-88F5-7E9B8DB81077}] => (Allow) LPort=8501 FirewallRules: [{B6173FEF-F292-4083-9DBD-EFE74ACCD1EB}] => (Allow) C:\Program Files\Opera\47.0.2631.39\opera.exe ==================== Punkty Przywracania systemu ========================= 26-07-2017 10:55:07 Zaplanowany punkt kontrolny 01-08-2017 22:07:49 doPDF 8 ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= Name: Kontroler Ethernet Description: Kontroler Ethernet Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: USB2.0-CRW Description: USB2.0-CRW Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (08/10/2017 07:08:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/10/2017 05:40:27 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/08/2017 09:25:46 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/07/2017 06:35:10 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/07/2017 04:28:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/07/2017 08:56:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/06/2017 09:28:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/04/2017 04:44:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/04/2017 12:58:31 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/04/2017 09:44:39 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Dziennik System: ============= Error: (08/07/2017 06:39:54 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Microsoft .NET Framework NGEN v4.0.30319_X86. Error: (08/07/2017 06:37:22 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na odpowiedź transakcji z usługi SysMain. Error: (08/07/2017 04:27:51 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 08:57:58 na ‎2017-‎08-‎07 było nieoczekiwane. Error: (08/06/2017 05:29:21 PM) (Source: ACPI) (EventID: 13) (User: ) Description: : Kontroler osadzony nie odpowiedział przed upływem limitu czasu. Może to wskazywać, że wystąpił błąd w sprzęcie lub oprogramowaniu układowym kontrolera osadzonego albo że system BIOS uzyskuje dostęp do kontrolera osadzonego w niepoprawny sposób. Należy skontaktować się z producentem komputera w sprawie uaktualnionego systemu BIOS. W niektórych sytuacjach ten błąd może spowodować niepoprawne funkcjonowanie komputera. Error: (08/06/2017 09:26:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa novaPDF Server niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 60000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (08/06/2017 09:26:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 0 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (08/06/2017 09:26:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Instalator modułów systemu Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (08/06/2017 09:26:18 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Microsoft Office Click-to-Run Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 0 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (08/06/2017 09:26:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Office Software Protection Platform niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (08/06/2017 09:26:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa AMD FUEL Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. ==================== Statystyki pamięci =========================== Procesor: AMD E1-1200 APU with Radeon(tm) HD Graphics Procent pamięci w użyciu: 38% Całkowita pamięć fizyczna: 3577.37 MB Dostępna pamięć fizyczna: 2194.59 MB Całkowita pamięć wirtualna: 7153.06 MB Dostępna pamięć wirtualna: 5675.91 MB ==================== Dyski ================================ Drive c: (Windows) (Fixed) (Total:134.33 GB) (Free:92.06 GB) NTFS ==>[dysk z komponentami startowymi (pozyskano odczytując BCD)] ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 02A1ADF8) Partition 1: (Not Active) - (Size=14.7 GB) - (Type=27) Partition 2: (Active) - (Size=134.3 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ============================