Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:07-02-2016 Uruchomiony przez Kamila (2016-02-12 14:26:50) Uruchomiony z C:\Users\Kamila\Downloads Windows 8.1 (X64) (2014-01-14 13:48:21) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-2918600208-2786274864-1330061667-500 - Administrator - Disabled) => C:\Users\Administrator Gość (S-1-5-21-2918600208-2786274864-1330061667-501 - Limited - Disabled) Kamila (S-1-5-21-2918600208-2786274864-1330061667-1002 - Administrator - Enabled) => C:\Users\Kamila ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} FW: ESET Personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKU\S-1-5-21-2918600208-2786274864-1330061667-1002\...\uTorrent) (Version: 3.4.6.41698 - BitTorrent Inc.) Aktualizacje NVIDIA 2.10.1.2 (Version: 2.10.1.2 - NVIDIA Corporation) Hidden Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 4.8.1245.73583 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 4.8.1245.73583 - Alcor Micro Corp.) Hidden Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform) Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden DTS Sound (HKLM-x32\...\{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}) (Version: 1.01.2700 - DTS, Inc.) Empress of the Deep - The Darkest Secret (x32 Version: 2.2.0.98 - WildTangent) Hidden ESET Smart Security (HKLM\...\{92172C3C-7BCF-4DA3-8263-6617B13E897F}) (Version: 8.0.319.0 - ESET, spol s r. o.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 48.0.2564.109 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) IDT Audio Driver (HKLM\...\{588A747E-CFF6-46B3-9207-CD754F9473AF}) (Version: 6.10.6491.0 - IDT) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3282 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Island Tribe (x32 Version: 2.2.0.98 - WildTangent) Hidden Island Tribe 5 (HKLM-x32\...\Island Tribe 5_is1) (Version: - Realore Studios) Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-2918600208-2786274864-1330061667-1002\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Preview Redistributable (x64) - 12.0.20617 (HKLM-x32\...\{448652c1-f5f3-4230-98c6-68c10c88b1fb}) (Version: 12.0.20617.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Preview Redistributable (x86) - 12.0.20617 (HKLM-x32\...\{1f407217-9aec-4146-8504-e64ac959c534}) (Version: 12.0.20617.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MPC-HC 1.7.10 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.10 - MPC-HC Team) Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden NVIDIA GeForce Experience 2.10.1.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.1.2 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) NVIDIA Sterownik graficzny 361.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.75 - NVIDIA Corporation) OSC Third Party Libraries (Version: 1.1 - NVIDIA Corporation) Hidden Panel sterowania NVIDIA 361.75 (Version: 361.75 - NVIDIA Corporation) Hidden Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Polski pakiet językowy dla narzędzi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PLK) (Version: 10.0.50903 - Microsoft Corporation) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.300 - Qualcomm Atheros) Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.27599 - Razer Inc.) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.10.1.2 - NVIDIA Corporation) Hidden Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.111 - Skype Technologies S.A.) Spotify (HKLM-x32\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.10.51 - Synaptics Incorporated) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) TOSHIBA Addendum (HKLM-x32\...\{CE0374A6-B204-4336-8293-63FBB1DADBF4}) (Version: 1.00 - TOSHIBA) TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation) TOSHIBA Display Utility (HKLM\...\{84FA4D2D-4273-4C66-BD3D-ADD3FE48DFA2}) (Version: 1.1.5.0 - Toshiba Corporation) TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation) TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.1.0001.6403 - Toshiba Corporation) TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.10 - TOSHIBA) TOSHIBA Password Utility (HKLM-x32\...\InstallShield_{78931270-BC9E-441A-A52B-73ECD4ACFAB5}) (Version: 3.00.344 - Toshiba Corporation) TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.9.09.6400 - Toshiba Corporation) TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.1.02.55065006 - Toshiba Corporation) TOSHIBA Service Station (HKLM\...\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation) TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0030 - Toshiba Corporation) TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.1.2.32001 - Toshiba Corporation) Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.0 - Toshiba Europe GmbH) TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102 - Toshiba Corporation) Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0415-1000-0000000FF1CE}_Office15.PROPLUS_{67847964-08E2-4A8F-B09D-B08D5CE69250}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3114502) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6F47687A-78E9-41B1-8587-ED0CC2677A2A}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3114502) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6F47687A-78E9-41B1-8587-ED0CC2677A2A}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3114502) 64-Bit Edition (HKLM\...\{90150000-012B-0415-1000-0000000FF1CE}_Office15.PROPLUS_{6F47687A-78E9-41B1-8587-ED0CC2677A2A}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent) WildTangent Games App (Toshiba Games) (x32 Version: 4.0.11.13 - WildTangent) Hidden WinRAR 5.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {18EAE7DF-3952-4779-A7DA-D71DEBC754C9} - System32\Tasks\{0AA53485-0133-4E4A-979E-3CD209160B69} => Chrome.exe hxxp://ui.skype.com/ui/0/6.14.0.104/pl/abandoninstall?page=tsProgressBar Task: {21AC6E0E-A866-4FF7-B88A-704D0E4A5CAF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {3B99B664-04E8-4038-BDA7-454A3C106113} - System32\Tasks\GoogleUpdateTaskMachineUA1d040c2d7a4a2d9 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {46AFAB49-6D85-48B1-B09D-081C4998D512} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {4899893D-A5EE-4A0E-ADDD-AF26D3C0B189} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {5ABBDE83-BEB7-4E3A-9474-8F2DCA9A3CC0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd) Task: {69170A1F-2663-4048-AE4F-C91E54EF96A2} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-07-19] (Toshiba Europe GmbH) Task: {6F7BB697-DEAE-4678-8134-6C41BCC1A426} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {88CDAD42-1DF5-45D7-947E-78C38CA55586} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation) Task: {C25CF56A-132A-4B10-9B29-47A0E8A6C6F4} - System32\Tasks\GoogleUpdateTaskMachineCore1d00063450f4e8c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {DAC7B487-65D3-45A4-996E-D93A32C49F11} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2013-08-28] (TODO: ) Task: {E0183097-EE63-4699-9704-692E7995D89E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-14] (Microsoft Corporation) Task: {EAAF2611-F513-43FF-9E93-74B955F74F83} - System32\Tasks\GoogleUpdateTaskMachineUA1d00063459dcb20 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {ECCBA67B-9279-4F2C-ADD0-C74AD0871E85} - System32\Tasks\GoogleUpdateTaskMachineUA1cf8df32ab91385 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {FFF86B3D-239F-4E94-87BD-65FFE7EF5F22} - System32\Tasks\{316B9AB9-4E60-44F2-A45E-51C18535A945} => Chrome.exe hxxp://ui.skype.com/ui/0/7.18.0.111/pl/abandoninstall?source=lightinstaller&page=tsBing (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d00063450f4e8c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf8df32ab91385.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d00063459dcb20.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d040c2d7a4a2d9.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2013-11-23 01:09 - 2016-01-23 02:04 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-06-11 06:44 - 2015-06-11 06:44 - 00022528 _____ () C:\WINDOWS\System32\sst6clm.dll 2016-01-23 15:23 - 2016-01-20 08:36 - 00292920 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2012-07-19 03:38 - 2012-07-19 03:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll 2013-09-19 18:33 - 2013-08-12 18:52 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2016-01-23 15:23 - 2016-01-20 08:36 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2013-11-23 01:02 - 2013-09-04 01:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 26065408 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\libcef.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00739840 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\libGLESv2.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00293040 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\ortp.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00909312 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\platforms\qwindows.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00130048 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\libEGL.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00020992 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\imageformats\qgif.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00021504 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\imageformats\qico.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00205312 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\imageformats\qjpeg.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00225792 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\imageformats\qmng.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00015872 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\imageformats\qsvg.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00312832 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\imageformats\qtiff.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00010240 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\qml\QtQuick.2\qtquick2plugin.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00054272 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\qml\QtQuick\Layouts\qquicklayoutsplugin.dll 2016-01-28 20:16 - 2016-01-28 20:16 - 00010240 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6734\qml\QtQml\Models.2\modelsplugin.dll 2016-01-11 10:36 - 2016-01-11 10:36 - 00932032 _____ () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\Users\Kamila:gs5sys AlternateDataStreams: C:\ProgramData\desktop.ini:gs5sys AlternateDataStreams: C:\Users\Kamila\Cookies:gs5sys AlternateDataStreams: C:\Users\Kamila\Dane aplikacji:gs5sys AlternateDataStreams: C:\Users\Kamila\Szablony:gs5sys AlternateDataStreams: C:\Users\Kamila\Ustawienia lokalne:gs5sys AlternateDataStreams: C:\Users\Kamila\Desktop\desktop.ini:gs5sys AlternateDataStreams: C:\Users\Kamila\AppData\Local:gs5sys AlternateDataStreams: C:\Users\Kamila\AppData\Roaming:gs5sys AlternateDataStreams: C:\Users\Kamila\AppData\Local\Dane aplikacji:gs5sys AlternateDataStreams: C:\Users\Kamila\AppData\Local\Historia:gs5sys AlternateDataStreams: C:\Users\Kamila\Documents\desktop.ini:gs5sys AlternateDataStreams: C:\Users\Public\Documents\desktop.ini:gs5sys ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-2918600208-2786274864-1330061667-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Kamila\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\image_0002.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) MSCONFIG\Services: dts_apo_service => 2 MSCONFIG\Services: GamesAppIntegrationService => 2 MSCONFIG\Services: GamesAppService => 3 MSCONFIG\Services: GFNEXSrv => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: Razer Game Scanner Service => 2 HKLM\...\StartupApproved\Run: => "TecoResident" HKLM\...\StartupApproved\Run: => "TSSSrv" HKLM\...\StartupApproved\Run: => "TosWaitSrv" HKLM\...\StartupApproved\Run: => "MouseDriver" HKLM\...\StartupApproved\Run32: => "Anti-phishing Domain Advisor" HKLM\...\StartupApproved\Run32: => "1.TPUReg" HKLM\...\StartupApproved\Run32: => "AmIcoSinglun64" HKLM\...\StartupApproved\Run32: => "TSVU" HKLM\...\StartupApproved\Run32: => "Razer Synapse" HKU\S-1-5-21-2918600208-2786274864-1330061667-1002\...\StartupApproved\StartupFolder: => "Wysyłanie do programu OneNote.lnk" HKU\S-1-5-21-2918600208-2786274864-1330061667-1002\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{4DB0514A-BCD3-4301-AAEA-107C2D63B399}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe FirewallRules: [{9E2B8E66-DA75-47D5-8F43-CD949972E95B}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe FirewallRules: [{525BB892-8E10-49CA-8CEC-F59CAF8394BC}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe FirewallRules: [{28C68800-6C90-4C16-BF60-E7513E6E13D9}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe FirewallRules: [{06245B98-12BE-4D02-A618-72CC5A21BD1A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{64310F9A-E7AF-4B7A-9096-CB54F5357E0E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{408DFC6F-7DDC-400A-A633-F907EBDEAFFE}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{4C46AF90-BF93-4420-833F-7CF7098B79CA}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{672FC495-AC2C-4FB9-BFC2-7023DB17853C}] => (Allow) C:\Users\Kamila\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{99A95C2F-0B9C-47E4-AA6A-04302B9F9B8F}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{35E1EC1D-3DF2-4718-9C12-AE2C43DA7521}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{648BF28A-C857-4DC6-B58B-1FF06279B41D}] => (Allow) C:\Users\Kamila\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{D7AABC2E-2960-48A9-A53C-E14031676353}] => (Allow) C:\Users\Kamila\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{88F30302-0341-4E1F-8DFB-35F975346E80}] => (Allow) C:\Users\Kamila\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{5A12828E-539F-48AA-B3D4-6B1F9621EA6F}] => (Allow) C:\Users\Kamila\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{49D10E02-6CD4-40ED-8B68-879662666DC5}] => (Allow) C:\Users\Kamila\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{525C6F45-9D9E-4500-953E-8A320E30D7B6}] => (Allow) C:\Users\Kamila\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{48230DC3-4263-4AEC-87F1-B8BF7E14B1E0}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{CBBBA833-7663-4E2A-9CBA-F5FA9EE59A22}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{EA56ED74-806E-49E0-8C7A-2DFD2D0DB878}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{4AC5B6AE-FD59-4652-A73D-F2D24AB4C2DB}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{D16A787E-7989-4A25-A043-69DB23459156}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{AA4D2456-E5A9-4F56-BE2C-BBF20DA71D9D}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{CFC5C2D4-863F-475C-A769-2AB766958A14}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{3572D4C3-99C3-44DA-95FD-E2A5FB4A23D3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{1298772D-2232-4864-9D90-06ABC23743F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{9B60B628-CDC1-45D1-BD52-17B7E249075A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{CBFBC8A0-B946-4BD9-A1BD-E63F493F162B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{E62B88BF-B186-4872-927F-D26358E7A3D8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Punkty Przywracania systemu ========================= UWAGA: Przywracanie systemu jest wyłączone ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (02/12/2016 02:20:04 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: ZARZĄDZANIE NT) Description: There was an error with the Windows Location Provider database Error: (02/12/2016 02:13:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: gffmdgger.exe, wersja: 2.1.19357.0, sygnatura czasowa: 0x52e7ea83 Nazwa modułu powodującego błąd: gffmdgger.exe, wersja: 2.1.19357.0, sygnatura czasowa: 0x52e7ea83 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000011aa Identyfikator procesu powodującego błąd: 0x16fc Godzina uruchomienia aplikacji powodującej błąd: 0xgffmdgger.exe0 Ścieżka aplikacji powodującej błąd: gffmdgger.exe1 Ścieżka modułu powodującego błąd: gffmdgger.exe2 Identyfikator raportu: gffmdgger.exe3 Pełna nazwa pakietu powodującego błąd: gffmdgger.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: gffmdgger.exe5 Error: (02/12/2016 02:12:22 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: gmer.exe, wersja: 2.1.19357.0, sygnatura czasowa: 0x52e7ea83 Nazwa modułu powodującego błąd: gmer.exe, wersja: 2.1.19357.0, sygnatura czasowa: 0x52e7ea83 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000011aa Identyfikator procesu powodującego błąd: 0xcd8 Godzina uruchomienia aplikacji powodującej błąd: 0xgmer.exe0 Ścieżka aplikacji powodującej błąd: gmer.exe1 Ścieżka modułu powodującego błąd: gmer.exe2 Identyfikator raportu: gmer.exe3 Pełna nazwa pakietu powodującego błąd: gmer.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: gmer.exe5 Error: (02/12/2016 12:02:50 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (02/11/2016 11:35:06 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (02/10/2016 11:06:42 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program LiveComm.exe w wersji 17.5.9600.20911 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 21c8 Godzina rozpoczęcia: 01d1644e9680c6f9 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe Identyfikator raportu: 8edf9fe6-d042-11e5-85ce-645a04aaa639 Pełna nazwa pakietu powodującego błąd: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe Identyfikator aplikacji względem pakietu powodującego błąd: ppleae38af2e007f4358a809ac99a64a67c1 Error: (02/10/2016 12:15:00 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (02/09/2016 01:39:42 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (02/08/2016 01:11:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: taskhost.exe, wersja: 6.3.9600.17415, sygnatura czasowa: 0x545040f5 Nazwa modułu powodującego błąd: DfpCommon.dll, wersja: 6.3.9600.17415, sygnatura czasowa: 0x545048ba Kod wyjątku: 0xc00000fd Przesunięcie błędu: 0x0000000000051bd7 Identyfikator procesu powodującego błąd: 0xfc Godzina uruchomienia aplikacji powodującej błąd: 0xtaskhost.exe0 Ścieżka aplikacji powodującej błąd: taskhost.exe1 Ścieżka modułu powodującego błąd: taskhost.exe2 Identyfikator raportu: taskhost.exe3 Pełna nazwa pakietu powodującego błąd: taskhost.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: taskhost.exe5 Error: (02/08/2016 01:04:25 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Dziennik System: ============= Error: (02/12/2016 11:52:38 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 1:24:58 AM na ‎2/‎12/‎2016 było nieoczekiwane. Error: (02/11/2016 11:24:57 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 1:06:30 AM na ‎2/‎11/‎2016 było nieoczekiwane. Error: (02/10/2016 12:04:49 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 1:23:46 AM na ‎2/‎10/‎2016 było nieoczekiwane. Error: (02/09/2016 03:26:49 PM) (Source: Schannel) (EventID: 4119) (User: ZARZĄDZANIE NT) Description: Odebrano alert krytyczny ze zdalnego punktu końcowego. Kod alertu krytycznego zdefiniowany przez protokół TLS to 20. Error: (02/09/2016 03:23:46 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 2:49:34 PM na ‎2/‎9/‎2016 było nieoczekiwane. Error: (02/09/2016 01:29:34 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 12:15:03 AM na ‎2/‎9/‎2016 było nieoczekiwane. Error: (02/08/2016 10:55:04 AM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x0000005a (0x0000000000000001, 0x0000000000000001, 0x0000000000000000, 0x0000000000000000)C:\WINDOWS\MEMORY.DMP020816-17125-01 Error: (02/08/2016 10:55:03 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 12:51:22 AM na ‎2/‎8/‎2016 było nieoczekiwane. Error: (02/07/2016 12:51:21 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 12:40:51 AM na ‎2/‎7/‎2016 było nieoczekiwane. Error: (02/06/2016 04:40:50 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 12:29:37 AM na ‎2/‎6/‎2016 było nieoczekiwane. CodeIntegrity: =================================== Date: 2015-11-09 14:41:30.834 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 23:36:04.342 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:44:08.411 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:44:08.162 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:44:07.911 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:44:07.554 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:44:07.311 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:44:07.063 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:43:58.714 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-16 17:43:55.899 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz Procent pamięci w użyciu: 56% Całkowita pamięć fizyczna: 3971.27 MB Dostępna pamięć fizyczna: 1735.02 MB Całkowita pamięć wirtualna: 8067.27 MB Dostępna pamięć wirtualna: 5919.46 MB ==================== Dyski ================================ Drive c: (TI31216600A) (Fixed) (Total:344.23 GB) (Free:295.78 GB) NTFS Drive d: (Suny) (Fixed) (Total:343.13 GB) (Free:204.74 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 00000000) Partition: GPT. ==================== Koniec Addition.txt ============================