Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 21.07.2018 Uruchomiony przez user (24-07-2018 09:36:54) Uruchomiony z C:\Users\user\Desktop\FRST Windows 10 Home Wersja 1803 17134.167 (X64) (2018-05-22 11:27:33) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-3244572619-1344660955-1707226054-500 - Administrator - Disabled) defaultuser0 (S-1-5-21-3244572619-1344660955-1707226054-1000 - Limited - Enabled) => C:\Users\defaultuser0 Gość (S-1-5-21-3244572619-1344660955-1707226054-501 - Limited - Disabled) Konto domyślne (S-1-5-21-3244572619-1344660955-1707226054-503 - Limited - Disabled) user (S-1-5-21-3244572619-1344660955-1707226054-1001 - Administrator - Enabled) => C:\Users\user WDAGUtilityAccount (S-1-5-21-3244572619-1344660955-1707226054-504 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 18.011.20055 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 30.0.0.107 - Adobe Systems Incorporated) Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.134 - Adobe Systems Incorporated) Adobe Flash Player 30 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 30.0.0.134 - Adobe Systems Incorporated) Aktualizacje NVIDIA 31.2.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.2.0.0 - NVIDIA Corporation) Hidden Armored Warfare MyCom (HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\Armored Warfare MyCom) (Version: 1.170 - My.com B.V.) Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.5.2342 - AVAST Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 5.44 - Piriform) Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 67.0.3396.99 - Comodo) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.6.0.0283 - Disc Soft Ltd) Dishonored - Game of the Year Edition (HKLM-x32\...\Dishonored - Game of the Year Edition_is1) (Version: - ) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 398.36 - NVIDIA Corporation) Hidden Driver Booster 5 (HKLM-x32\...\Driver Booster_is1) (Version: 5.4.0 - IObit) EaseUS Partition Master 12.8 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS) EaseUS Todo Backup Free 10.6 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 10.6 - CHENGDU YIWO Tech Development Co., Ltd) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Far Cry 3 Complete Collection wersja 1.05 (HKLM-x32\...\{831C540A-FBC9-4511-A7A8-67BC3FACF7F5}_is1) (Version: 1.05 - UBISoft) GameCenter My.Com (HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\GameCenter) (Version: 4.1432 - My.Com B.V.) GameSessions Data Delivery x86 (HKLM-x32\...\{9AA2C827-8AF8-40C5-B500-5A6DB3233D71}) (Version: 1.28.488.0 - Tangentix Ltd) GameSessions Runtime x86 (HKLM-x32\...\{79DD8AE4-FAA0-44DB-A42F-F09252B5B99A}) (Version: 1.28.488.0 - Tangentix Ltd) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Malwarebytes (wersja 3.5.1.2522) (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts) Microsoft OneDrive (HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{56F27690-F6EA-3356-980A-02BA379506EE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25017 (HKLM-x32\...\{d6f233bd-3f8c-43f6-878b-07bd0568d595}) (Version: 14.10.25017.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{cb7c3049-21de-415b-bd85-b65c14e547df}) (Version: 14.10.25017.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Mozilla Firefox 61.0.1 (x64 pl) (HKLM\...\Mozilla Firefox 61.0.1 (x64 pl)) (Version: 61.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 61.0 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) NVIDIA GeForce Experience 3.14.0.139 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.14.0.139 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) NVIDIA Sterownik 3D Vision 398.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 398.36 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation) NVIDIA Sterownik graficzny 398.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 398.36 - NVIDIA Corporation) NVIDIA Sterownik kontrolera 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 10.5.21.179 - Electronic Arts, Inc.) Panel sterowania NVIDIA 398.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 398.36 - NVIDIA Corporation) Hidden qBittorrent 4.1.1 (HKLM-x32\...\qBittorrent) (Version: 4.1.1 - The qBittorrent project) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8395 - Realtek Semiconductor Corp.) Screenpresso (HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\Screenpresso) (Version: 1.7.2.0 - Learnpulse) Sniper Elite 4 (HKLM\...\Sniper Elite 4_is1) (Version: 1.0 - ) Sophos Anti-Rootkit 1.5.4 (HKLM-x32\...\Sophos-AntiRootkit) (Version: 1.5.4 - Sophos Plc) Speedtest by Ookla (HKLM\...\{9CC33E6C-8EF8-4CE3-A874-D5B18966A73F}) (Version: 1.0.14.001 - Ookla) StarCraft (HKLM-x32\...\StarCraft) (Version: - Blizzard Entertainment) StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) The Evil Within 2 (HKLM-x32\...\The Evil Within 2_is1) (Version: - ) Uplay (HKLM-x32\...\Uplay) (Version: 44.0 - Ubisoft) WinRAR 5.50 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH) World of Tanks (HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-06-23] (AVAST Software) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-06-23] (AVAST Software) ContextMenuHandlers1: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-09-04] (CHENGDU YIWO Tech Development Co.,Ltd) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-09-13] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-09-13] (Alexander Roshal) ContextMenuHandlers2-x32: [a-squared Free Shell Extension] -> {A155339D-CCCD-4714-85EB-3754B804C9DF} => c:\program files (x86)\a-squared free\a2freecontmenu.dll [2008-04-11] (Emsi Software GmbH) ContextMenuHandlers2-x32: [a-squared Free Shell Extension x64] -> {85D26561-0241-4BE2-A8DF-8F921A0EF948} => c:\program files (x86)\a-squared free\a2freecontmenu64.dll [2008-04-11] (Emsi Software GmbH) ContextMenuHandlers2-x32: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-09-04] (CHENGDU YIWO Tech Development Co.,Ltd) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-06-23] (AVAST Software) ContextMenuHandlers3-x32: [a-squared Free Shell Extension] -> {A155339D-CCCD-4714-85EB-3754B804C9DF} => c:\program files (x86)\a-squared free\a2freecontmenu.dll [2008-04-11] (Emsi Software GmbH) ContextMenuHandlers3-x32: [a-squared Free Shell Extension x64] -> {85D26561-0241-4BE2-A8DF-8F921A0EF948} => c:\program files (x86)\a-squared free\a2freecontmenu64.dll [2008-04-11] (Emsi Software GmbH) ContextMenuHandlers3-x32: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers4: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-09-04] (CHENGDU YIWO Tech Development Co.,Ltd) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-06-24] (NVIDIA Corporation) ContextMenuHandlers6-x32: [a-squared Free Shell Extension] -> {A155339D-CCCD-4714-85EB-3754B804C9DF} => c:\program files (x86)\a-squared free\a2freecontmenu.dll [2008-04-11] (Emsi Software GmbH) ContextMenuHandlers6-x32: [a-squared Free Shell Extension x64] -> {85D26561-0241-4BE2-A8DF-8F921A0EF948} => c:\program files (x86)\a-squared free\a2freecontmenu64.dll [2008-04-11] (Emsi Software GmbH) ContextMenuHandlers6-x32: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-06-23] (AVAST Software) ContextMenuHandlers6-x32: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers6-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-09-13] (Alexander Roshal) ContextMenuHandlers6-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-09-13] (Alexander Roshal) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {09248172-BA29-450A-8F4A-5E217DD2A21B} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-06-12] (AVAST Software) Task: {174102CF-EA11-4453-A331-B0428CBE882B} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-06-24] (NVIDIA Corporation) Task: {1D8C27C2-BFCC-4A4A-9B66-2EC869971CD8} - System32\Tasks\S-1-5-21-3244572619-1344660955-1707226054-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-12] (Microsoft Corporation) Task: {2E996137-D991-486B-A89B-AF72DB1F8B9C} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\5.4.0\Scheduler.exe [2018-04-28] (IObit) Task: {448475AD-918F-4477-8D04-C835C963D141} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-06-24] (NVIDIA Corporation) Task: {48A034D7-56D3-48D6-B06F-E9747CF1ACCA} - System32\Tasks\{C9210D93-324F-8502-E6D9-D3D6660BF30B} => C:\Program Files\Opera\Launcher.exe Task: {4A17D0EA-EAF4-4617-9C1B-2D3C5F41B8E8} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-06-24] (NVIDIA Corporation) Task: {4AD47DA3-18C9-434C-AA3E-ADCCA2BEB34B} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-06-24] (NVIDIA Corporation) Task: {4F0D5D47-5054-4E50-BFE2-BA0A26684FFD} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-06-23] (AVAST Software) Task: {5B4019C2-A800-4136-9023-44707983FC24} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-06-24] (NVIDIA Corporation) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] () Task: {78A39C3C-D99A-4627-9303-E143DB8ED8E3} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-06-24] (NVIDIA Corporation) Task: {7EF3E424-E4AE-4881-939C-CB19213907F0} - System32\Tasks\Driver Booster SkipUAC (user) => C:\Program Files (x86)\IObit\Driver Booster\5.4.0\DriverBooster.exe [2018-05-09] (IObit) Task: {902CE84A-BDCB-4328-A017-47A4E5A1FE8F} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-06-24] (NVIDIA Corporation) Task: {A0784DAA-45C3-433C-A00F-35051F546818} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe Task: {A26CE17F-E929-4752-8874-FE5B2CB59694} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-06-24] (NVIDIA Corporation) Task: {ADC6CAD8-5C06-476B-9212-FE6B6315CE74} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_134_Plugin.exe [2018-07-23] (Adobe Systems Incorporated) Task: {B1430CD0-AC2B-4E8A-ACFD-0D57748DEC40} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_134_pepper.exe [2018-07-11] (Adobe Systems Incorporated) Task: {BB22A72F-D67F-4585-A04E-ECE085D96912} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-06-24] (NVIDIA Corporation) Task: {D7595DD2-B1B0-4EC6-95CD-D676B21DB2E5} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-06-24] (Piriform Ltd) Task: {DAE9CA87-6039-40C8-8B64-E96FF6D46DDF} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-07-23] (Adobe Systems Incorporated) Task: {E0B63B5C-8C66-45F1-BDAF-AB87BF588388} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-06-24] (Piriform Ltd) Task: {F51730D2-A4BB-4803-80DF-52C718D74F79} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated) Task: {F6186D05-593A-4189-B511-BC36EAFE8AED} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-06-24] (NVIDIA Corporation) Task: {FCA2F855-2769-47E1-B787-2482AEC741AE} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-06-24] (NVIDIA Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Skróty & WMI ======================== (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\395fbb84ca74fb25\Comodo Dragon.lnk -> C:\Program Files (x86)\Comodo\Dragon\dragon.exe (Comodo) -> --profile-directory=Default ==================== Załadowane moduły (filtrowane) ============== 2018-07-09 19:00 - 2018-06-24 19:27 - 001314752 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-12-07 17:07 - 2017-08-30 13:29 - 000260752 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe 2018-04-12 01:34 - 2018-04-12 01:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2018-07-10 19:21 - 2018-07-06 08:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-12-07 17:07 - 2017-02-21 18:19 - 000083136 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CodeLog.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000019648 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CompressFile.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000090816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBGetRemoteNetInfo.dll 2017-12-07 17:07 - 2016-03-07 19:08 - 001291264 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll 2017-12-07 17:07 - 2004-10-05 04:08 - 000055808 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000024768 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CmcTbProxy.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000188608 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCPipeCenter.dll 2017-12-07 17:07 - 2017-08-30 13:25 - 000183440 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCAdapt.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000163520 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCAdapt_RTTO.dll 2017-12-07 17:07 - 2017-08-30 13:27 - 000055952 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBInfo.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000018112 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCNetTokenProxy.dll 2017-12-07 17:07 - 2017-08-30 13:25 - 000061072 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActivationOnline.dll 2017-12-07 17:07 - 2017-09-04 18:39 - 000699024 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EuActiveOnline.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000487568 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EULicenseDLL.DLL 2017-12-07 17:07 - 2017-08-30 13:26 - 000021648 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\fsclog.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000085648 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\logsys.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000032912 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DiskSearchImg.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000070800 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\MountImg.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000160400 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ImgFile.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000296592 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DsImgFile.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000078528 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FatLib.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000305808 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSUtil.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000026304 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CallbackOperator.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000210112 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSLib.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000074432 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckImg.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000142016 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\vhdvmdk.dll 2017-12-07 17:07 - 2017-09-11 15:28 - 000085136 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\BootDriver.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000844944 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ExImage.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000195776 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBackupSize.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000414400 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidImage.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000162448 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumDisk.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000029376 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DeviceAdapter.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000114368 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FileStorage.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000026816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\GetDriverInfo.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000022720 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CorrectMbr.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000034448 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumTapeDevice.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000054464 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbTapeBrowse.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000066240 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\RegLib.dll 2017-12-07 17:07 - 2017-08-30 13:25 - 000026768 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AccountManager.dll 2017-12-07 17:07 - 2017-08-30 13:26 - 000072848 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NasOperator.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000221376 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBrowser.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000079040 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CloudOperator.dll 2017-12-07 17:07 - 2017-08-30 13:25 - 000021648 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActiveOnline.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000138432 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\VMConfig.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000021696 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidDeviceManager.dll 2017-12-07 17:07 - 2017-08-30 13:27 - 000074896 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SqlExBrowser.dll 2017-12-07 17:07 - 2017-08-30 13:27 - 000585872 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SqlSMOCPlusPlus.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000045248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbDataSwap.dll 2017-12-07 17:07 - 2017-08-30 13:25 - 000367760 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DeviceManager.dll 2017-12-07 17:07 - 2017-08-30 13:25 - 000141456 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Device.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000149184 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Partition.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000052416 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FileSystemAnalyser.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000064192 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FATFileSystemAnalyser.dll 2017-12-07 17:07 - 2016-12-06 03:43 - 000091840 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Common.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000058560 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSFileSystemAnalyser.dll 2017-12-07 17:07 - 2016-12-06 03:44 - 000210112 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SmartBackup.dll 2018-03-07 08:15 - 2018-03-07 08:15 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2018-06-23 20:59 - 2018-06-23 20:59 - 000483544 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2018-06-23 20:59 - 2018-06-23 20:59 - 000282840 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2018-07-09 19:00 - 2018-06-24 19:27 - 001032640 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-06-17 16:52 - 2017-10-16 10:14 - 000442144 _____ () C:\Program Files (x86)\IObit\Driver Booster\5.4.0\madExcept_.bpl 2018-06-17 16:52 - 2017-10-16 10:14 - 000210720 _____ () C:\Program Files (x86)\IObit\Driver Booster\5.4.0\madBasic_.bpl 2018-06-17 16:52 - 2017-10-16 10:14 - 000059680 _____ () C:\Program Files (x86)\IObit\Driver Booster\5.4.0\madDisAsm_.bpl ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\Users\Public\AppData:CSM [480] ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Powiązania plików (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2017-11-16 14:26 - 2018-01-17 11:21 - 000000826 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img1.jpg DNS Servers: 37.8.214.2 - 31.11.202.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run32: => "WidgetPodatnikInfo" HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\StartupApproved\Run: => "World of Tanks" HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\StartupApproved\Run: => "Screenpresso" HKU\S-1-5-21-3244572619-1344660955-1707226054-1001\...\StartupApproved\Run: => "GameCenter" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [UDP Query User{F2A6935D-0C2E-44AA-859D-9F42FD62837B}E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe] => (Allow) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe FirewallRules: [TCP Query User{6DB48D7B-3709-48B0-A56F-7F258270C329}E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe] => (Allow) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe FirewallRules: [UDP Query User{D960422F-FE37-45BD-B98A-61A2B37DAB03}C:\users\user\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\user\appdata\local\gamecenter\gamecenter.exe FirewallRules: [TCP Query User{99CDF838-AAAA-400D-9565-389CCA019A53}C:\users\user\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\user\appdata\local\gamecenter\gamecenter.exe FirewallRules: [UDP Query User{D7EF2FDE-58B2-450E-8234-143A2BCBA0E2}C:\users\user\appdata\local\mycomgames\gamecenter.exe] => (Allow) C:\users\user\appdata\local\mycomgames\gamecenter.exe FirewallRules: [TCP Query User{B22D6FAF-3D15-4649-83DC-9256ACD619FB}C:\users\user\appdata\local\mycomgames\gamecenter.exe] => (Allow) C:\users\user\appdata\local\mycomgames\gamecenter.exe FirewallRules: [{ED5D0E80-1343-46C9-AB0F-818C283A02E8}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{1461706C-C44A-4596-AD8E-DB162E06F48C}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [UDP Query User{CD00FB46-0595-48FC-B80E-E500C1C9E95A}C:\users\user\appdata\local\mycomgames\gamecenter.exe] => (Allow) C:\users\user\appdata\local\mycomgames\gamecenter.exe FirewallRules: [TCP Query User{171F9ED1-F186-46F6-965B-BDAC0EEC40C1}C:\users\user\appdata\local\mycomgames\gamecenter.exe] => (Allow) C:\users\user\appdata\local\mycomgames\gamecenter.exe FirewallRules: [UDP Query User{22E25A0D-3234-44A0-BC6B-53F08DCDCD30}E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe] => (Block) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe FirewallRules: [TCP Query User{9FE1FECB-2064-4DA1-B88D-6501F7A830DD}E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe] => (Block) E:\mygames\armored warfare mycom\bin64\armoredwarfare.exe FirewallRules: [{F4815C1D-AA26-4A5C-809C-A31F7259D57C}] => (Allow) E:\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{EF973312-852E-4791-8974-2CA90F7F683B}] => (Allow) E:\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{0D9D3196-0E26-4E48-85F9-9BEB220BA60B}] => (Allow) E:\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [{D3C3C891-9A12-4E29-9583-EB09D5B527C3}] => (Allow) E:\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [{D1E3570D-7892-46B9-9474-99C94453DF95}] => (Allow) E:\SteamLibrary\steamapps\common\HOMEFRONT\Binaries\HOMEFRONT.exe FirewallRules: [{976F6506-D05B-4976-A1EA-5A35F6056DB7}] => (Allow) E:\SteamLibrary\steamapps\common\HOMEFRONT\Binaries\HOMEFRONT.exe FirewallRules: [{BE317C2F-E9A2-4640-BBA2-F0028F79F8DA}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{9809C44F-AB6A-42A2-B3F9-80DC2C64DEC0}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{4B724AF4-CB83-4B09-BA07-7AEB649619F2}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{216E1A81-7799-4920-A7C3-EE55DFFEDC73}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{47A70609-66B0-4D46-AEA6-2A60382D869C}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{818CAB4F-4923-4EC0-8CC9-C8FF9F377D8B}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{862FF561-03AC-4490-928C-37D32751DEB5}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe FirewallRules: [{D61A38AE-30FA-4776-BB68-D89C19CF73BA}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe FirewallRules: [{FB89CF7D-6104-4AAC-BB30-95E803BC3F04}] => (Allow) LPort=8733 FirewallRules: [{1ABDCF8B-6061-48B9-91C9-67D7B720EE93}] => (Allow) C:\Program Files (x86)\Tangentix\DDRuntime\GSLauncher.exe FirewallRules: [UDP Query User{B62DE07C-D0DB-4984-953D-0E8F2AF3D2A0}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{90C87A47-C8A1-47E5-B954-5F88E9300078}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe FirewallRules: [{3C2CEF42-AC07-4DAF-90AE-F10305A3AC13}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{E78428D7-7BFF-4394-AECA-695279B4082D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{D6292961-B208-444A-80BE-2D3EBEE5DF3D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{E6AE494C-453E-4A0C-95EC-78230267571F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{6FB963CE-567F-4235-A057-7FBE1327B330}] => (Allow) d:\Games\World_of_Tanks\worldoftanks.exe FirewallRules: [{24A198E6-85AA-40A3-A1F1-52BDAE238D2B}] => (Allow) d:\Games\World_of_Tanks\worldoftanks.exe FirewallRules: [{B7ACDCE4-3AEE-4645-8E01-90FE49E679A4}] => (Allow) d:\Games\World_of_Tanks\WoTLauncher.exe FirewallRules: [{26F19723-E9E1-4B09-B867-215EAD3B5DA9}] => (Allow) d:\Games\World_of_Tanks\WoTLauncher.exe FirewallRules: [{CBFEB30F-3C8D-499D-BD2B-9D066B47859A}] => (Allow) E:\SteamLibrary\steamapps\common\Team Fortress 2\hl2.exe FirewallRules: [{B1B363A2-C7A9-4FE9-84FB-8BA5E0B3340F}] => (Allow) E:\SteamLibrary\steamapps\common\Team Fortress 2\hl2.exe FirewallRules: [{A47B93C6-0A20-4561-9E6D-A967571EFBE7}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.4.0\DriverBooster.exe FirewallRules: [{FD8350B7-0723-4D82-B739-E32C8F12A6AD}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.4.0\DriverBooster.exe FirewallRules: [{60E07013-FCA7-426E-A2D8-44F107E36BD9}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.4.0\DBDownloader.exe FirewallRules: [{F0769D86-CB77-4162-B0B7-4B950CBD1454}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.4.0\DBDownloader.exe FirewallRules: [{3BC8CBB9-2AF8-40AD-8920-DCD6D06481A0}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.4.0\AutoUpdate.exe FirewallRules: [{9E3DC33B-4F9E-463D-B6E8-18948D5C41B5}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.4.0\AutoUpdate.exe FirewallRules: [{D68DB8CD-FF1A-4BCD-9587-24BFD695393D}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe FirewallRules: [{0EA6ACE4-7A7F-4509-9AED-CEB8782612C9}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe FirewallRules: [TCP Query User{BAB46406-789D-4637-88D0-ED259201F2E8}C:\users\user\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\user\appdata\local\gamecenter\gamecenter.exe FirewallRules: [UDP Query User{E3D72FC7-2AAE-44A3-B515-9E83C5153C8D}C:\users\user\appdata\local\gamecenter\gamecenter.exe] => (Allow) C:\users\user\appdata\local\gamecenter\gamecenter.exe FirewallRules: [TCP Query User{3937D118-BF7E-4CD3-8BA4-61C0E0CE34B3}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{18CE4816-A646-4626-91B9-47AD83B687C2}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe FirewallRules: [{CA79FEA4-04DB-4E36-95C7-340FD76EACBE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{907F1870-5266-498B-A23C-6998C519A22B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{912E835B-CAF9-42BB-AB03-F05F59B42579}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{76440BC3-23B2-45C3-BB0C-8DBD9182A20B}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [TCP Query User{8BEA4FFC-606C-4076-8908-434EA82717F5}D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3.exe] => (Block) D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3.exe FirewallRules: [UDP Query User{5B52F48D-B15C-462B-BBCE-DF77DB5E1806}D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3.exe] => (Block) D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3.exe FirewallRules: [TCP Query User{793ECD5E-5F6B-4CFD-8F33-E4AB57D1AAE4}D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3_d3d11.exe] => (Block) D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3_d3d11.exe FirewallRules: [UDP Query User{967E0919-2F28-4DDC-B60B-BD6AF449333D}D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3_d3d11.exe] => (Block) D:\program files (x86)\far cry 3 complete collection\far cry 3\bin\farcry3_d3d11.exe FirewallRules: [TCP Query User{C4A415EB-38CF-4980-AC98-E3E48222E51B}D:\program files (x86)\bethesda softworks\dishonored - game of the year edition\binaries\win32\dishonored.exe] => (Block) D:\program files (x86)\bethesda softworks\dishonored - game of the year edition\binaries\win32\dishonored.exe FirewallRules: [UDP Query User{1C52725B-148C-4104-BCDF-43F05E029253}D:\program files (x86)\bethesda softworks\dishonored - game of the year edition\binaries\win32\dishonored.exe] => (Block) D:\program files (x86)\bethesda softworks\dishonored - game of the year edition\binaries\win32\dishonored.exe FirewallRules: [{A66D9C95-F01F-472E-9C68-3F5000E76B0F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{208F5088-2A37-4746-AD5B-6A684D09E2EF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{A431A0FF-2F0F-439C-9E7C-C555DC78766A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{4CC96089-AF8D-4808-8D9E-D971F7E65AAC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{6C28500C-4A4B-4BEB-BEFB-73C2472DF0CE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{975C779B-60F0-4F8C-B3E5-F97AA79BE049}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{F400A1F1-54B3-4383-9A43-6CB4858DB1BB}] => (Allow) E:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe FirewallRules: [{9E7D3449-C1B3-46DF-B8F1-B6551DB1E2BE}] => (Allow) E:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe FirewallRules: [{BC158778-B667-4ABC-91D9-D1CE04C97EA2}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe FirewallRules: [{B7FBD13E-5D96-46FE-8BED-5E6636D347C6}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe FirewallRules: [{94BE069D-F5A0-45EB-A502-B1632525076D}] => (Allow) C:\Users\user\AppData\Local\NET.Framework SDK\msiexec64.exe FirewallRules: [{05E0425A-45BF-4592-95E6-F4F09531DD87}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe FirewallRules: [{E782BD2F-F425-46BE-A5E6-49C7C11B27DF}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{A8A66DB6-3F18-4A56-B87A-F37E6011E86C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{4949EB66-23E3-4D53-A693-D841BA9883AB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{A77B7C2A-F86F-4E04-A778-6D375F92FFB4}] => (Allow) C:\Users\user\AppData\Local\NET.Framework SDK\msiexec64.exe FirewallRules: [{ABBDD00F-BC4A-4EFE-A3B5-99DE4A71CAEE}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe FirewallRules: [{7EF501D9-E341-49DD-9ED6-7B1F2A881FDF}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{7AC3C910-7739-4AC5-AF76-60834AB6E8DB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{976521F3-C247-4E14-A6CB-10993C42BBFA}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{80770149-5009-40CD-AAD1-7E84875E1AE8}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{B12630E0-C1CA-4204-A409-1B7AFD9959E7}] => (Allow) C:\Users\user\AppData\Local\NET.Framework SDK\msiexec64.exe FirewallRules: [{40232E2B-0DC0-4F7A-ABF2-99B3AA83BE77}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe FirewallRules: [{924A977E-B0A3-4E27-99F6-0396439B704A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{9D3ED3A7-9C45-42C7-B1CB-533D8EC0427E}] => (Allow) C:\Users\user\AppData\Local\NET.Framework SDK\msiexec64.exe FirewallRules: [{AF209C51-348C-439A-B471-C6DACC8842A8}] => (Allow) C:\WINDOWS\SysWOW64\rundll32.exe FirewallRules: [{0FDBE953-728C-4582-8995-361B267649F3}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{819C2EE4-3AB2-424E-87DD-E8B45F566A90}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe FirewallRules: [{95783195-6F82-459D-812D-A67E6FE5BBF0}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe ==================== Punkty Przywracania systemu ========================= 09-07-2018 23:34:38 Zaplanowany punkt kontrolny 11-07-2018 01:45:55 Installed Dual-Core Optimizer. 19-07-2018 05:26:45 Zaplanowany punkt kontrolny ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (07/24/2018 09:10:27 AM) (Source: Microsoft-Windows-WMI) (EventID: 5601) (User: ZARZĄDZANIE NT) Description: Usługa Instrumentacja zarządzania Windows nie może załadować plików repozytorium z katalogu %windir%\system32\wbem\repository. Może to być spowodowane uszkodzeniem plików repozytorium, ustawieniami zabezpieczeń tego katalogu, brakiem miejsca na dysku lub innymi problemami dotyczącymi zasobów systemowych, na przykład brakiem pamięci. Jeśli ten błąd występuje przy każdym ponownym rozruchu komputera, może być konieczne wykonanie następujących czynności przez administratora tego komputera: zatrzymanie usługi WMI, sprawdzenie ustawień zabezpieczeń tego folderu i zawartych w nim plików oraz uruchomienie narzędzia WMIDiag w celu zweryfikowania kondycji Instrumentacji zarządzania Windows. Error: (07/23/2018 04:38:44 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: taskmgr.exe, wersja: 10.0.17134.1, sygnatura czasowa: 0xe3592b68 Nazwa modułu powodującego błąd: DUser.dll, wersja: 10.0.17134.1, sygnatura czasowa: 0xf3bed37b Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000000000000b68d Identyfikator procesu powodującego błąd: 0x9d0 Godzina uruchomienia aplikacji powodującej błąd: 0x01d4222e446d8be2 Ścieżka aplikacji powodującej błąd: C:\WINDOWS\system32\taskmgr.exe Ścieżka modułu powodującego błąd: C:\WINDOWS\system32\DUser.dll Identyfikator raportu: 40352e85-2f00-4129-a6dc-38e720acd660 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (07/23/2018 04:29:02 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja: 61.0.1.6759, sygnatura czasowa: 0x5b3c2adf Nazwa modułu powodującego błąd: NPSWF64_30_0_0_134.dll, wersja: 30.0.0.134, sygnatura czasowa: 0x5b317b67 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000ae542d Identyfikator procesu powodującego błąd: 0x1908 Godzina uruchomienia aplikacji powodującej błąd: 0x01d4222cd318de75 Ścieżka aplikacji powodującej błąd: C:\Program Files\Mozilla Firefox\plugin-container.exe Ścieżka modułu powodującego błąd: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_30_0_0_134.dll Identyfikator raportu: 9c1af955-a654-4ec8-8070-6bf7373a0fea Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (07/23/2018 04:00:31 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja: 61.0.1.6759, sygnatura czasowa: 0x5b3c2adf Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000005a683ff8744 Identyfikator procesu powodującego błąd: 0x910 Godzina uruchomienia aplikacji powodującej błąd: 0x01d42228e06e9e08 Ścieżka aplikacji powodującej błąd: C:\Program Files\Mozilla Firefox\plugin-container.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: 56a3f208-a189-4796-be26-3f8277d7b467 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (07/21/2018 12:00:02 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: DESKTOP-1HJVOJ0) Description: httphttp-2147467263 Error: (07/21/2018 11:54:17 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury QueryFullProcessImageNameW. hr = 0x80070006, Nieprawidłowe dojście. . Operacja: Wykonywanie operacji asynchronicznej Kontekst: Stan bieżący: DoSnapshotSet Error: (07/21/2018 07:13:39 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury QueryFullProcessImageNameW. hr = 0x80070006, Nieprawidłowe dojście. . Operacja: Wykonywanie operacji asynchronicznej Kontekst: Stan bieżący: DoSnapshotSet Error: (07/21/2018 12:19:16 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: EasyTune.exe, wersja: 7.2.0.42, sygnatura czasowa: 0x574eae16 Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 10.0.17134.165, sygnatura czasowa: 0xfa43f4b2 Kod wyjątku: 0xe0434352 Przesunięcie błędu: 0x0010ddc2 Identyfikator procesu powodującego błąd: 0xce4 Godzina uruchomienia aplikacji powodującej błąd: 0x01d42077ac93ddb4 Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\GIGABYTE\EasyTune\EasyTune.exe Ścieżka modułu powodującego błąd: C:\WINDOWS\System32\KERNELBASE.dll Identyfikator raportu: 796d852d-5cd7-4f1f-9d6e-3db759da2247 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Dziennik System: ============= Error: (07/24/2018 09:10:27 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa NVIDIA Telemetry Container zakończyła działanie; wystąpił następujący błąd: Plik wykonywalny polecenia rodzajowego zwrócił wynik wskazujący błąd. Error: (07/24/2018 09:10:27 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Centrum zabezpieczeń zakończyła działanie; wystąpił następujący błąd: Usługa uwierzytelniania jest nieznana. Error: (07/24/2018 09:10:12 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Automatyczna aktualizacja strefy czasowej z powodu następującego błędu: Potok został zakończony. Error: (07/24/2018 09:10:09 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Windows Audio zakończyła działanie; wystąpił następujący błąd: Trwa proces zamykania systemu. Error: (07/24/2018 09:10:09 AM) (Source: DCOM) (EventID: 10010) (User: ZARZĄDZANIE NT) Description: Serwer Windows.Internal.StateRepository.ApplicationExtension nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (07/24/2018 09:10:03 AM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Usługa aswbIDSAgent nie została poprawnie zamknięta po odebraniu kodu sterującego przed zamknięciem. Error: (07/24/2018 09:09:06 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 22:24:16 na ‎23.‎07.‎2018 było nieoczekiwane. Error: (07/23/2018 10:24:16 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 21:43:02 na ‎23.‎07.‎2018 było nieoczekiwane. CodeIntegrity: =================================== Date: 2018-07-24 09:09:02.654 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_485c1c3102021986\nvlddmkm.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-07-23 04:42:03.041 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_485c1c3102021986\nvlddmkm.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Statystyki pamięci =========================== Procesor: AMD Athlon(tm) II X4 640 Processor Procent pamięci w użyciu: 20% Całkowita pamięć fizyczna: 8189.55 MB Dostępna pamięć fizyczna: 6471.74 MB Całkowita pamięć wirtualna: 9469.55 MB Dostępna pamięć wirtualna: 7509.98 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:149.16 GB) (Free:102.64 GB) NTFS Drive d: () (Fixed) (Total:390.8 GB) (Free:29.09 GB) NTFS Drive e: () (Fixed) (Total:390.71 GB) (Free:36.44 GB) NTFS Drive f: (tom615) (Fixed) (Total:74.53 GB) (Free:43.64 GB) NTFS ==>[system z komponentami startowymi (pozyskano odczytując dysk)] \\?\Volume{8e778e77-0000-0000-0000-804a25000000}\ () (Fixed) (Total:0.83 GB) (Free:0.45 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 74.5 GB) (Disk ID: 88D7A686) Partition 1: (Active) - (Size=74.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 8E778E77) Partition 1: (Not Active) - (Size=149.2 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=855 MB) - (Type=27) Partition 3: (Not Active) - (Size=390.8 GB) - (Type=07 NTFS) Partition 4: (Active) - (Size=390.7 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ============================