Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:27-04-2016 Uruchomiony przez Paulina (2016-04-27 19:01:18) Uruchomiony z C:\Users\Paulina\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2011-10-15 14:27:19) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-459723227-2305396002-3096522437-500 - Administrator - Disabled) Gość (S-1-5-21-459723227-2305396002-3096522437-501 - Limited - Enabled) Paulina (S-1-5-21-459723227-2305396002-3096522437-1000 - Administrator - Enabled) => C:\Users\Paulina UpdatusUser (S-1-5-21-459723227-2305396002-3096522437-1008 - Limited - Enabled) => C:\Users\UpdatusUser.Finalka ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: COMODO Antivirus (Enabled - Up to date) {D0CC7563-ABD2-DEBE-138E-FDD553335AF2} AS: Comodo Defense+ (Enabled - Up to date) {6BAD9487-8DE8-D130-293E-C6A728B4104F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: COMODO Firewall (Enabled) {E8F7F446-E1BD-DFE6-38D1-54E0ADE01D89} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKLM-x32\...\uTorrent) (Version: 3.1.3 - ) Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2904.00 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.5.2904.00 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3004 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.1130.2010 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3502 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version: 15.4.5722.2 - Microsoft Corporation) ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (HKLM-x32\...\{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}) (Version: 15.4.5722.2 - Microsoft Corporation) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.) Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.9.0.465 - Adobe Systems Incorporated) Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Illustrator CC 2014 (HKLM-x32\...\{2B4B4082-8043-4646-8334-B0A29E641211}) (Version: 18.1.1 - Adobe Systems Incorporated) Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated) Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Reader 9.5.5 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated) Aktualizacje NVIDIA 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation) Anki (HKLM-x32\...\Anki) (Version: - ) Anti-Twin (Installation 10/30/2013) (HKLM-x32\...\Anti-Twin 2013-01-06 23.10.06) (Version: - Joerg Rosenthal, Germany) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Aptana Studio (HKU\S-1-5-21-459723227-2305396002-3096522437-1000\...\Aptana Studio 3.6.0) (Version: 3.6.0 - Appcelerator) Aptana Studio (HKU\S-1-5-21-459723227-2305396002-3096522437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Aptana Studio 3.6.0) (Version: 3.6.0 - Appcelerator) Aptana Studio (x32 Version: 3.6.0 - Appcelerator) Hidden AQQ (HKLM-x32\...\AQQ) (Version: 3.0.0.50 - Creative Team S.A.) Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft) Asystent menedżera zawartości dla PlayStation(R) (HKLM-x32\...\{32C46540-7693-49E1-A81E-121B09C8303B}) (Version: 3.00.7187.47 - Sony Computer Entertainment Inc.) Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team) AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - ) Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden Broadcom Card Reader Driver Installer (HKLM\...\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.6.1.2 - Broadcom Corporation) Broadcom NetLink Controller (HKLM\...\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.4.1 - Broadcom Corporation) CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.6.5931 - CDBurnerXP) ChomikBox (HKLM-x32\...\{C7B52FAF-58D8-438C-B810-F78C3C927504}) (Version: 2.0.8.0 - Chomikuj.pl) clear.fi (HKLM-x32\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 1.0.1422.00 - CyberLink Corp.) clear.fi (x32 Version: 1.0.1422.00 - CyberLink Corp.) Hidden clear.fi (x32 Version: 9.0.7418 - CyberLink Corp.) Hidden clear.fi Client (HKLM-x32\...\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.00.3008 - Acer Incorporated) COMODO GeekBuddy (HKLM-x32\...\COMODO GeekBuddy) (Version: 3.3.217083.59 - COMODO) COMODO Internet Security (HKLM\...\{4EAB2511-0135-48CA-A47B-CE1E6836793A}) (Version: 5.8.16726.2131 - COMODO Security Solutions Inc.) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Control ActiveX del Windows Live Mesh per a connexions remotes (HKLM-x32\...\{76C064E2-BB99-4453-8FDA-42BC01AD0734}) (Version: 15.4.5722.2 - Microsoft Corporation) Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E}) (Version: 15.4.5722.2 - Microsoft Corporation) Controle ActiveX do Windows Live Mesh para Conexões Remotas (HKLM-x32\...\{39B3184E-0BFB-40FA-ADDC-E7E2D535CDA9}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DeepSkyStacker (HKLM-x32\...\{18435829-4E75-4CD1-9796-A62DBBAE2ED7}) (Version: 3.2.0 - ) Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.4 - Dolby Laboratories Inc) Dropbox (HKLM-x32\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.27.33 - Dropbox, Inc.) Hidden English Translator XT (HKLM-x32\...\InstallShield_{6F89200D-9C19-42F7-A056-640C9D4C158C}) (Version: 4.00.0000 - Techland) English Translator XT (x32 Version: 4.00.0000 - Techland) Hidden FBReader for Windows (HKLM-x32\...\FBReader for Windows) (Version: - ) FileZilla Client 3.15.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.15.0.2 - Tim Kosse) Flip Words 2 (HKLM-x32\...\Flip Words 2_is1) (Version: - ) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Git version 1.8.4-preview20130916 (HKLM-x32\...\Git_is1) (Version: 1.8.4-preview20130916 - The Git Development Community) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.) Google Photos Backup (HKU\S-1-5-21-459723227-2305396002-3096522437-1000\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.) Google Photos Backup (HKU\S-1-5-21-459723227-2305396002-3096522437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) HP Deskjet 2050 J510 series Badanie ulepszeń produktu (HKLM\...\{878D7EAE-7B73-484B-AC39-FFCF5760D672}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Deskjet 2050 J510 series Podstawowe oprogramowanie urządzenia (HKLM\...\{1497F824-EBC0-4277-B40D-1A0D6892C0D5}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Deskjet 2050 J510 series Pomoc (HKLM-x32\...\{7A3DF2E2-CF13-44FB-A93E-F71D5381DB3F}) (Version: 140.0.61.61 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife) HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Acer Incorporated) Inkscape 0.91 (HKLM\...\{81922150-317E-4BB0-A31D-FF1C14F707C5}) (Version: 0.91 - inkscape.org) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation) Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Kadu 0.12.3 (HKLM-x32\...\Kadu) (Version: 0.12.3 - Kadu Team) Kits Configuration Installer (x32 Version: 8.100.25984 - Microsoft) Hidden Kontrola Windows Live Mesh ActiveX za daljinske veze (HKLM-x32\...\{19CBDE24-2761-49A5-816B-D2BA65D0CA8D}) (Version: 15.4.5722.2 - Microsoft Corporation) Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version: 15.4.5722.2 - Microsoft Corporation) LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Launch Manager (HKLM-x32\...\LManager) (Version: 5.1.4 - Acer Inc.) Light Image Resizer 4.0.4.3 (HKLM-x32\...\{EBE030DD-D404-4D92-85E9-8C3624820808}_is1) (Version: 4.0.4.3 - ObviousIdea) MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{4820118E-F7B6-4D70-9B38-6B8C3EB85BC1}) (Version: 7.0.1.27 - MAGIX Software GmbH) MAGIX Speed burnR (MSI) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden Malwarebytes Anti-Malware wersja 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MediaEspresso (x32 Version: 1.0.1418_35759 - CyberLink Corp.) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Polski (HKLM-x32\...\{90140011-0066-0415-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Moduł Szybka instalacja pakietu Microsoft Office 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Moduł Szybka instalacja pakietu Microsoft Office 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Movavi Video Converter 16 (HKLM-x32\...\Movavi Video Converter 16) (Version: 16.0.2 - Movavi) Mozilla Firefox 46.0 (x86 pl) (HKLM-x32\...\Mozilla Firefox 46.0 (x86 pl)) (Version: 46.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.0.5955 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MyFreeCodec (HKU\S-1-5-21-459723227-2305396002-3096522437-1000\...\MyFreeCodec) (Version: - ) MyFreeCodec (HKU\S-1-5-21-459723227-2305396002-3096522437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MyFreeCodec) (Version: - ) MyWinLocker (Version: 4.0.14.11 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.11 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.11 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.11 - Egis Technology Inc.) Hidden NapiProjekt 2.0.0 (build 2028) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Neverwinter (HKLM-x32\...\Neverwinter) (Version: - Cryptic Studios) newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.) newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden Node.js (HKLM-x32\...\{2D41A012-35EE-4724-AE8E-E592EDD9F89D}) (Version: 0.10.13 - Joyent, Inc. and other Node contributors) Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden NVIDIA Oprogramowanie systemu PhysX 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA Sterownik graficzny 310.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 310.70 - NVIDIA Corporation) Odlotowa farma 3: Epoka lodowcowa (HKLM-x32\...\Odlotowa farma 3: Epoka lodowcowa) (Version: - Alawar Entertainment Inc.) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenOffice.org 3.4.1 (HKLM-x32\...\{18192D3F-5537-4560-AD89-D695F72AF91D}) (Version: 3.41.9593 - Apache Software Foundation) Origin (HKLM-x32\...\Origin) (Version: 9.4.11.2806 - Electronic Arts, Inc.) osu! (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284C}) (Version: 0.0.0.0 - peppy) Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation) Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation) Panel sterowania NVIDIA 310.70 (Version: 310.70 - NVIDIA Corporation) Hidden Paragon Partition Manager™ 14 Free (HKLM\...\{47E5588F-C3A0-11DE-9857-005056C00008}) (Version: 90.00.0003 - Paragon Software) PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r4600) (Version: - ) Pd-0.43.4-extended (HKLM-x32\...\pd_is1) (Version: - puredata.info) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden PhoTransEdit Desktop (HKLM-x32\...\{4D905890-5435-49D8-B33B-37243F35ADAB}) (Version: 1.7.0 - ) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podatnik.info PIT pro 2015 wersja 2.2.12.0 (HKLM-x32\...\{B239B43B-3E99-40B0-80BF-1B1BCA868D4E}_is1) (Version: 2.2.12.0 - Podatnik.info Sp. z o.o.) Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 5.5 - Power Software Ltd) PrivDog (HKLM-x32\...\PrivDog) (Version: 1.8.0.15 - privdog.com) PSP Video 9 6 (HKLM-x32\...\PSP Video 9) (Version: 6 - Red Kawa) Puzzle Quest (HKLM-x32\...\PuzzleQuest_is1) (Version: - ) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6329 - Realtek Semiconductor Corp.) RPG Maker VX (HKLM-x32\...\RPG Maker VX_is1) (Version: 1.02 - Enterbrain) RPG MAKER VX Ace RTP (HKLM-x32\...\RPGVXAce_RTP_is1) (Version: 1.00 - Enterbrain) RPG Maker VX RTP (HKLM-x32\...\RPG Maker VX RTP_is1) (Version: 1.02 - Enterbrain) RPG Tsukuru XP (HKLM-x32\...\RPG Tsukuru XP) (Version: - ) Samplitude 11 (HKLM-x32\...\{AE0009FD-8F50-4565-835D-4432BD18D792}) (Version: 11.0.1.0 - MAGIX AG) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.34.0 - SAMSUNG Electronics Co., Ltd.) SDK Debuggers (x32 Version: 8.100.26837 - Microsoft Corporation) Hidden Shredder (Version: 2.0.8.7 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.7 - Egis Technology Inc.) Hidden Skype™ 7.12 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.12.101 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.6.0 - Synaptics Incorporated) Tablet Wacom (HKLM-x32\...\Wacom Tablet Driver) (Version: - Wacom Technology Corp.) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) The Sims 2: Ultimate Collection (HKLM-x32\...\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts) Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft) Urruneko konexioetarako Windows Live Mesh ActiveX kontrola (HKLM-x32\...\{7BA6DF02-B094-45D7-A3C9-BE3684253922}) (Version: 15.4.5722.2 - Microsoft Corporation) Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation) Vector Magic (HKLM-x32\...\Vector Magic) (Version: 1.15 - Vector Magic, Inc.) VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN) Wakan 1.67 (HKLM-x32\...\Wakan) (Version: 1.67 - Filip Kabrt) WebTablet IE Plugin (HKLM-x32\...\Wacom WebTabletPlugin for IE) (Version: 1.1.0.4 - Wacom Technology Corp.) WebTablet Netscape Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Netscape) (Version: 1.1.0.3 - Wacom Technology Corp.) Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (HKLM-x32\...\{09B7C7EB-3140-4B5E-842F-9C79A7137139}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Meshin etäyhteyksien ActiveX-komponentti (HKLM-x32\...\{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Software Development Kit for Windows 8.1 (HKLM-x32\...\{dfe9c941-2d53-42eb-8631-05ab80216136}) (Version: 8.100.26837 - Microsoft Corporation) WinRAR 4.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) Wyprawa na Północ (HKLM-x32\...\Wyprawa na Północ) (Version: - ) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ตัวควบคุม ActiveX ใน Windows Live Mesh สำหรับการเชื่อมต่อระยะไกล (ไทย) (HKLM-x32\...\{A2EDAEEB-C981-46D5-8163-CF8F5F640EEE}) (Version: 15.4.5722.2 - Microsoft Corporation) 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-459723227-2305396002-3096522437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Paulina\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-459723227-2305396002-3096522437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{ca586c80-7c84-4b88-8537-726724df6929}\InprocServer32 -> C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll () CustomCLSID: HKU\S-1-5-21-459723227-2305396002-3096522437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Paulina\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-459723227-2305396002-3096522437-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Paulina\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-459723227-2305396002-3096522437-1000_Classes\CLSID\{ca586c80-7c84-4b88-8537-726724df6929}\InprocServer32 -> C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll () CustomCLSID: HKU\S-1-5-21-459723227-2305396002-3096522437-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Paulina\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {042D2E22-936D-4394-96B2-C633F81FD1BB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-459723227-2305396002-3096522437-1000UA => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {0665AB90-E2CC-4CF7-915A-D56F5A9FCE50} - System32\Tasks\{2BE58350-A6EF-4003-86B8-FCACFFC9DB30} => C:\Program Files (x86)\Launch Manager\LManager.exe [2011-03-14] (Dritek System Inc.) Task: {078C7C59-C9D5-4569-8DAF-11AE786705F3} - System32\Tasks\{21447546-E78E-44CF-B6BE-1FB3F95BF903} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {0985298D-60CC-47C5-9B9F-365109071DB8} - System32\Tasks\AdobeAAMUpdater-1.0-Finalka-Paulina => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19] (Adobe Systems Incorporated) Task: {0B521909-C81A-41EE-8A31-D5DEC7130018} - System32\Tasks\{CFB76DF4-5D54-417E-AB39-F9991735051F} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {0DC04486-5324-4778-B93C-F85D67D3817E} - System32\Tasks\{D006A6DC-42C1-4CB2-BC55-B1FB17CB732E} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {0FAAC0D2-D8A4-427F-A572-6B4398F01255} - System32\Tasks\{8955AFB1-CEED-44F3-B1C9-07BF7F24B003} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {0FE97E06-BB8B-4382-8C4F-D0B387BC1EF4} - System32\Tasks\{36811E10-F2A8-463F-8F42-A3BC2507BEF0} => C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe [2010-04-07] (Adobe Systems, Incorporated) Task: {116B50C0-D7E3-46B9-9130-B9E700E42C1A} - System32\Tasks\{59B2622A-2399-40BF-A55E-30DE4C9CE930} => C:\Users\Paulina\Desktop\Fsecure_T10206167836976275T_.exe [2016-03-31] (Facebook Inc.) Task: {13698ABA-0AB3-404E-8596-D190987E2DF2} - System32\Tasks\{EA865393-4D28-4340-BCED-2F8AAD5EA383} => C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe [2010-04-07] (Adobe Systems, Incorporated) Task: {18A08366-D4CD-4356-98FC-274985938358} - System32\Tasks\{2B47557F-9327-49BD-B494-AB577FC3455B} => pcalua.exe -a "C:\Users\Paulina\Desktop\Rpg Tsukuru XP PL [www.rpgmaker.pl].exe" -d C:\Users\Paulina\Desktop Task: {1987D296-0D1B-4E78-B7A7-280B1DFE10B5} - System32\Tasks\{F1E24C5F-E32B-4DA4-A0EF-546C67BE0E25} => pcalua.exe -a "C:\Program Files (x86)\Enterbrain\RPGVX\unins000.exe" -d "C:\Program Files (x86)\Enterbrain\RPGVX" -c "C:\Program Files (x86)\Enterbrain\RPGVX\RPGVX.exe" Task: {221C904B-5132-405A-B8B4-3E3D5B536D0A} - System32\Tasks\{C4B94166-CD55-4093-8B93-211F42A06368} => C:\Users\Paulina\Desktop\Dokumenty\Hopkins_PL.exe Task: {22D886A3-946D-4347-881C-5BBB7D7ADA9F} - System32\Tasks\{69457CA1-42DF-4410-BC1D-68EE21D8D951} => C:\Program Files (x86)\RPG Maker\RPGVX\RPGVX.exe Task: {2384F90D-5438-4ABB-9C1C-5BADDBDE00EE} - System32\Tasks\{47331DCF-CB88-43B0-AFC1-382248C7735C} => C:\Users\Paulina\Desktop\vlc-1.1.11-win32.exe Task: {2BBF33D7-FA0C-4F18-8596-088ED96FAD69} - System32\Tasks\{79B5F4A4-0C78-4ECB-BE1D-87CBBC34E638} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.wrp.exe Task: {30F99D52-63BD-4D63-9A47-AFDE5F8EB520} - System32\Tasks\{C3445296-D258-43E4-9B97-011E81BDE1CE} => C:\Users\Paulina\Desktop\ESET_T10206160369869602T_.exe Task: {34154BE5-D943-4908-AE98-E0D062E3A5EA} - System32\Tasks\{D4866BEC-C75A-483F-93B7-9EFC458B1841} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.wrp.exe Task: {3420B73B-3878-4659-AA51-2AD52FD9E27E} - System32\Tasks\{755829AF-9092-40CC-B535-06A539496972} => C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe [2010-04-07] (Adobe Systems, Incorporated) Task: {348C8430-37B6-4BF5-AA17-1BDB3DCA175C} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-09] (COMODO) Task: {34BFB6A8-EF19-4141-84AB-3184A4259A46} - System32\Tasks\{94411E27-CA0A-46C9-A7BD-E69BC2CBD218} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {36FAD45A-2D5A-4CBB-8C0E-A275D038688E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-27] (Piriform Ltd) Task: {3909BC89-151D-4D66-A5EB-715476A0C5F6} - System32\Tasks\{3649895A-BAD6-4F14-8ECC-CBBC8DB0C48D} => C:\Program Files (x86)\RPG Tsukuru XP\RPGXP.exe [2006-06-23] () Task: {3BA005E3-19EC-4D64-8A35-F8098E4E579F} - System32\Tasks\{80460103-7B14-412B-9740-F159A0324012} => C:\Program Files (x86)\Rayman Legends\Rayman Legends.exe Task: {3CF123A3-3927-4442-8E55-3E83443DC425} - System32\Tasks\{16A9CB63-41B2-441F-BA8E-B6AEEAE484BE} => pcalua.exe -a G:\setupSNK.exe -d G:\ Task: {4166A514-F152-4100-B07E-74C665AEE436} - System32\Tasks\{BBB1953D-E4F7-48F8-A275-7FC29B076E15} => pcalua.exe -a "C:\Users\Paulina\Desktop\ゲーム\Farm Frenzy 3 Ice Age.exe" -d C:\Users\Paulina\Desktop\ゲーム Task: {45CB9B10-FCFE-4DF9-B23C-7B836655B10B} - System32\Tasks\{9A556524-31CE-4542-9484-DBD3D93C1EB3} => F:\Farm Frenzy 3 Ice Age.exe Task: {50BBCC0B-089F-4988-A539-F35DA3FD8646} - System32\Tasks\{8051222E-B970-40AC-B3C1-BE20A8FF271A} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {554AC6EB-BF70-4E6C-A460-77E337FAD7A2} - System32\Tasks\{1EC7AA6B-405D-4E85-98AF-A4F13BAF45AA} => pcalua.exe -a "C:\Program Files (x86)\RPG Maker\RPGVX\Uninstall.exe" Task: {5579BF1D-909D-4792-A320-38D696C3716A} - System32\Tasks\{BBCDF76A-89D0-4E30-876D-FCEA8F162EAB} => C:\Users\Paulina\Desktop\ゲーム\Farm Frenzy 3 Ice Age.exe Task: {55CFCAC9-2F8C-4E4B-8588-D357F3EB35D6} - System32\Tasks\{3FEAB998-4E96-4BB1-9B71-C44CE1878BFE} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.59.116/pl/abandoninstall?page=tsPlugin Task: {576E3B39-260A-4EA4-A943-EAC517670CF1} - System32\Tasks\{7958FAB3-4EAE-4F6A-80C6-7B467399544C} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {58A26395-A630-4E32-B75B-B12232D77D75} - System32\Tasks\{764A42A2-BE65-4469-9E01-B28311C8EDBD} => pcalua.exe -a C:\Users\Paulina\Desktop\TL-WN422G_v2_100611\Setup.exe -d C:\Users\Paulina\Desktop\TL-WN422G_v2_100611 Task: {59C54569-2A58-48E9-A233-9F4CAD07F1BF} - System32\Tasks\{233030A9-C20F-48C2-8AFD-3B63A7C9EFEE} => pcalua.exe -a "C:\Users\Paulina\Desktop\Torrenty\The Sims 3 - Razor1911 Final MAXSPEED\Final Version Patch\Sims3_1.0.632.00002_from_1.0.631.00002.exe" -d "C:\Users\Paulina\Desktop\Torrenty\The Sims 3 - Razor1911 Final MAXSPEED\Final Version Patch" Task: {5C64D23A-3F3D-436F-BCEE-F164DFE6B859} - System32\Tasks\{4784D493-04CC-41A4-A4B4-8A5420CFC2B9} => pcalua.exe -a C:\Users\Paulina\Desktop\idraw3.exe -d C:\Users\Paulina\Desktop Task: {5CBE522C-A3FE-4FFB-A29C-3A6BE0C01E8F} - System32\Tasks\{52643C03-ED46-46C5-AC9F-3397BA750103} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\SubEdit-Player\subedit.exe" Task: {5CD05ADA-B75C-4DB8-80C6-2D155365308D} - System32\Tasks\clear.fi => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe [2011-02-22] (Acer Incorporated) Task: {5F957720-545E-4D5B-9F21-5E208C78D50F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated) Task: {67604F2B-D290-46A9-AA01-1B27F9193A34} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-06-03] (Dropbox, Inc.) Task: {6B779EC0-9BED-481B-98DE-1CE07798770D} - System32\Tasks\{2AC97837-3683-4AF0-918D-82D1E16B3FE3} => D:\bydgoszcz.exe Task: {6B9690A4-8374-4AC2-BB68-6C253650FBFF} - System32\Tasks\{5D88CFAD-70C3-4BB0-9754-E45873DEBCCB} => C:\Program Files (x86)\PhoTransEdit\PhoTransEdit.exe [2014-01-06] (PhoTransEdit) Task: {6EED874C-0D75-4072-AA2C-11DF751C0207} - System32\Tasks\{1EA42C37-85E9-4A89-BA73-322E53B3DA0E} => C:\Program Files (x86)\Rayman Legends\Rayman Legends.exe Task: {6FB6B1F9-E376-441F-B4B1-A34C07BA6368} - System32\Tasks\{DA89BB60-ED48-4ADF-B704-2853069FC933} => C:\Program Files (x86)\SubEdit-Player\subedit.exe Task: {7541E79D-2F6C-4EE1-98F4-A8B42EF4BBD8} - System32\Tasks\{4D67114D-3CA1-4A69-87FB-42C6D8637CC2} => pcalua.exe -a C:\Users\Paulina\Desktop\ESOv504_Installer\install.exe -d C:\Users\Paulina\Desktop\ESOv504_Installer Task: {7BB455A6-CF6D-41AB-AB63-791D1869BD4F} - System32\Tasks\{3179179F-C5E4-4E63-A4F0-14E43F80FC07} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {7C8EB4FC-09DE-464A-8ECE-53F57B6CBBB5} - System32\Tasks\{1E63C641-73D5-4367-91C1-25F6DD95B88B} => E:\Install.exe Task: {7CDE962A-0354-4AD1-963F-1F3BEAE3D71D} - System32\Tasks\{E43B8503-8195-454C-A9B0-D23EE0AD8EA2} => C:\Users\Paulina\Desktop\ゲーム\Farm Frenzy 3 Ice Age.exe Task: {7D7FB77E-02A6-4263-AC39-E323879A1CB7} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-09] (COMODO) Task: {8F3C61E7-C61A-4710-B923-8CBB71669094} - System32\Tasks\{2DBEB5CC-E93E-4B05-A655-A78BA6EC4B61} => Firefox.exe hxxp://ui.skype.com/ui/0/6.1.59.129/pl/abandoninstall?page=tsProgressBar Task: {93C08F02-796B-4799-A7BD-13A6D25CBD15} - System32\Tasks\clear.fiAgent => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe [2011-02-22] (CyberLink Corp.) Task: {9A6256BB-C2F2-4C4A-B204-AF577A5E5533} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe Task: {A191FD6A-8B32-4899-82AD-CD2E9EBBA00D} - System32\Tasks\{8D4CC582-D755-4E36-A29D-F1F8203D839C} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {A260339B-CF15-48D8-B51C-C58DD07CFBA4} - \Program aktualizacji online firmy Adobe. -> Brak pliku <==== UWAGA Task: {AB98C04C-39AB-4422-83E9-925492F32EB3} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-03-24] (Oracle Corporation) Task: {AC06E716-9289-4581-B6AA-80B5D2928F3F} - System32\Tasks\{50634131-9604-4FB1-B53C-0B8C38CC5D5C} => D:\TL-WN422G\Setup.exe Task: {AC22B48C-BFE3-42CF-97F9-881ECEB43C8C} - System32\Tasks\{F5AB60AE-E83B-4E59-8E20-68FF5B3F000B} => pcalua.exe -a C:\Users\Paulina\Desktop\ゲーム\RPG_Maker_VX_102_ENU_SSG\RPGMakerVX102\RPGMakerVX1.02\RPGVX\Setup.exe -d C:\Users\Paulina\Desktop\ゲーム\RPG_Maker_VX_102_ENU_SSG\RPGMakerVX102\RPGMakerVX1.02\RPGVX Task: {AEC8C04E-0FD1-4371-B701-42C98F45D4E1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-459723227-2305396002-3096522437-1000Core => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {B430EBE6-9833-439B-98C8-BF1DB021A3B2} - System32\Tasks\{2FED6C61-86BE-404A-BA2B-1CF337B67C84} => C:\Users\Paulina\Desktop\FileZilla_3.5.2_win32-setup.exe Task: {B6BEAFA5-45F2-4FB1-AA8B-5D0F23464A30} - System32\Tasks\{AF5C1400-8209-4B67-BF5F-8E558936E32C} => C:\Program Files (x86)\Rayman Legends\Rayman Legends.exe Task: {B9CBE868-2824-4144-9FE5-CE8EFF7F0376} - System32\Tasks\{1BEF5AE8-8492-4200-87D3-2F5D242F0614} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {BA1FC216-897E-4106-870F-E1366DC24A82} - System32\Tasks\{9F5A4829-D93E-4A68-9D1F-A1F69A0CF375} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-09-28] (Skype Technologies S.A.) Task: {BB2517AE-F2C3-4135-A941-E90C7F977B30} - System32\Tasks\DMREngine => C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe [2011-02-22] (CyberLink) Task: {BCA51376-2769-40E7-9E8E-94D0E228F183} - System32\Tasks\{6F16EB2A-BCF4-4AF7-814B-83B021B277AD} => C:\Program Files (x86)\pd\bin\pd.exe [2013-01-24] () Task: {BD858601-AEB9-4A64-9142-50FB1604B31A} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-06-03] (Dropbox, Inc.) Task: {BFADE472-A05A-4F58-BBD4-F888B01C64C6} - System32\Tasks\{8731443C-FBE0-4AC2-9872-16E73E4712C8} => C:\Users\Paulina\Desktop\ゲーム\pcsx2-0.9.8-r4600-setup.exe Task: {C0D82BE4-A161-479A-B6CB-900B3C3C0017} - System32\Tasks\{95DEA943-4642-41E6-ACD0-4E2DBA54CDF3} => C:\Program Files (x86)\SubEdit-Player\subedit.exe Task: {C1137A84-FEBA-4884-9D7B-C2DF2B2562D3} - System32\Tasks\{333C4E30-3B94-4635-8592-97D788DF658B} => C:\Users\Paulina\Desktop\Yu-Gi-Oh Power Of Chaos\Joey\joey_pc.exe Task: {C34361F1-DE36-4DBC-8CD7-1D8F507CDCCD} - System32\Tasks\{7028C3D3-AB09-4D20-867B-55E398BE0728} => C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe [2010-04-07] (Adobe Systems, Incorporated) Task: {C6A0BB28-CE62-4392-80F1-DE1E203AFD16} - System32\Tasks\{F4BFEC9F-006B-41F5-9EF0-00235584A191} => pcalua.exe -a C:\Users\Paulina\Desktop\subedit+codecpack_b4072_install.exe -d "C:\Program Files (x86)\Mozilla Firefox" Task: {C82001EC-8CAF-4BB6-A383-7B5F64728CF3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-30] (Google Inc.) Task: {CF880B2E-4816-4237-8192-58D35C1638AB} - System32\Tasks\{9D7680A9-AE85-4F89-AD37-A67A4D29707A} => F:\Farm Frenzy 3 Ice Age.exe Task: {D1FA1A4B-2946-4E4B-98EA-04CE98FE4487} - System32\Tasks\{50B8069E-6D1E-492D-A6CD-9F0EDA9417B7} => C:\Program Files (x86)\Red Kawa\Video Converter App\VideoConverterApp.exe [2010-09-03] (Red Kawa) Task: {D30CE33B-02AB-49EC-B668-ED2113B77A8D} - System32\Tasks\{D70A3725-D370-4EED-87DA-464DD4D222B9} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {D4330DB5-5AA4-4E41-8D0F-286C214EAB38} - System32\Tasks\{72480995-DFC4-4441-A249-5F1DD7C5E348} => C:\Users\Paulina\Desktop\ゲーム\RPG Maker VX PL 1 02\RPG Maker VX PL 1_02.exe Task: {D52EABCB-5156-4C70-B458-DBA20E5008E3} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-04-09] (COMODO) Task: {D8553732-94D7-453E-916A-99BEE9A350B7} - System32\Tasks\{98BEAE6D-7795-4A25-9FE5-257A96B6C0F0} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {DAFFBB06-01DF-4343-8108-F800753CC0B9} - System32\Tasks\{CDA21F6B-A336-4CB9-94EE-15E3E5D0A31C} => C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe [2010-04-07] (Adobe Systems, Incorporated) Task: {DDD64219-71B9-4690-ACF8-E40276198E25} - System32\Tasks\{F98E6C57-78BB-442F-892B-3145B0BA1A2F} => C:\Users\Paulina\Desktop\ゲーム\ccsetup313.exe Task: {DE6E8A48-A013-46F6-8B4F-61FC79CB648D} - System32\Tasks\{BE4F5C06-0E84-4E53-B25B-CF0BCFA443C6} => C:\Users\Paulina\Desktop\Torrenty\Flip.Words.2.v1.1.WinALL.Incl.Keygen-ECLiPSE\FlipWords2Setup.exe Task: {E1900E6C-8C6A-49F9-9AD8-B57BFE6A83CE} - System32\Tasks\HPCustParticipation HP Deskjet 2050 J510 series => C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.) Task: {E3FA81CA-A5FF-4CBD-B168-3B0920BE489C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-30] (Google Inc.) Task: {E3FECE4F-D8D2-42E9-AF3A-65D694F0AD67} - System32\Tasks\{DFBC0383-27D0-41A6-ACB0-F44AF6C9E0AB} => C:\Program Files (x86)\Rayman Legends\Rayman Legends.exe Task: {E7F72071-E1CB-477C-B1E9-97C1EA52922C} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-09] (COMODO) Task: {E903A3CF-3A26-46E3-8C7D-6DBBB307CB5B} - System32\Tasks\{86B13E70-B4A6-40F2-A5AE-74767856B154} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {ECD74386-5829-42A2-8361-B57CCC29B398} - System32\Tasks\Program aktualizacji online firmy HP => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2010-06-09] (Hewlett-Packard) Task: {F1C4DC55-A1CA-4C47-8D4D-317F5E153652} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-04-09] (COMODO) Task: {F21E96CB-2074-4175-B032-49179F123C25} - System32\Tasks\{D95C4053-FF2F-4995-B11F-191B214C0340} => C:\Program Files (x86)\RPG Maker\RPGVX\RPGVX.exe Task: {F32ADE3E-028C-477C-A355-202C4B602072} - System32\Tasks\{A0BBA1C5-C883-4AA4-B9AF-7CA38954CB14} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {F4C891FA-E730-4B6A-8051-F6EE31A1BAB4} - System32\Tasks\{B73A6A68-2526-48B2-B33A-076371879C5B} => pcalua.exe -a C:\Users\Paulina\Desktop\ICeQ_5.14.exe -d "C:\Program Files (x86)\Mozilla Firefox" Task: {F901DAD6-1933-4E40-BFCF-C6E2ED4BDD5F} - System32\Tasks\{1AE92FFB-EA69-4725-9B99-BFA74DCE00E3} => C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe [2010-04-07] (Adobe Systems, Incorporated) Task: {F9C5329D-E3A2-4244-9F83-8A502FCA191C} - System32\Tasks\{6FC68189-F4FF-4B79-A479-70D9B25064D7} => C:\Program Files (x86)\Games\Farm Frenzy 3 Ice Age\FarmFrenzy3_Arctica.exe Task: {FD8C7860-3A28-4401-B18A-C2E95FFD2F5A} - System32\Tasks\{94055504-659E-4C88-B259-F1A336EC557D} => C:\Users\Paulina\Desktop\vlc-1.1.11-win32.exe Task: {FEF50CEF-760A-47BD-9B3A-EECD680A4CE6} - System32\Tasks\{ED393930-C601-4770-BD0B-B1AD3CBFA1A5} => pcalua.exe -a C:\Users\Paulina\Desktop\IsoBurner-Setup.exe -d C:\Users\Paulina\Desktop (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-459723227-2305396002-3096522437-1000Core.job => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-459723227-2305396002-3096522437-1000UA.job => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Node.js\Node.js command prompt.lnk -> C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) -> /k "C:\Program Files (x86)\nodejs\nodevars.bat" ==================== Załadowane moduły (filtrowane) ============== 2012-12-18 21:59 - 2013-08-30 00:43 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-12-19 16:57 - 2014-12-19 16:57 - 01039008 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-02-10 21:45 - 2016-02-10 21:45 - 00052912 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2015-02-11 20:17 - 2015-02-11 20:17 - 00718377 _____ () C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll 2009-01-22 01:45 - 2009-01-22 01:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll 2015-01-21 04:06 - 2015-01-21 04:06 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll 2014-12-19 16:57 - 2014-12-19 16:57 - 05979808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2010-02-28 02:33 - 2010-02-28 02:33 - 00077664 _____ () C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe 2011-11-23 12:27 - 2011-11-23 12:27 - 00493880 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\CRF\export.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 00358712 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\EventMonitor\export.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 02687800 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\GuiListener\export.dll 2011-05-26 05:43 - 2011-11-23 12:27 - 00020280 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLANG.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 01131320 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\CLPS_RES.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 00500024 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\RemoteDesktop\export.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 02185016 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\Socket\export.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 05714232 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\Socket\Adaptor.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 00048952 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\RemoteDesktop\ShHook.dll 2011-11-23 12:27 - 2011-11-23 12:27 - 00146232 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\EventMonitor\EventMonitor.dll 2011-10-07 19:46 - 2016-03-16 12:25 - 00073912 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav 2011-02-15 20:37 - 2011-02-15 20:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2011-02-15 20:36 - 2011-02-15 20:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2014-10-31 14:56 - 2014-10-31 14:56 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\ba8588c3319d63350220ec2ac3eb2c36\IsdiInterop.ni.dll 2011-04-06 12:30 - 2010-09-14 03:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2016-02-10 21:45 - 2016-02-10 21:45 - 00048816 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2016-04-11 21:33 - 2016-04-06 12:04 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\libglesv2.dll 2016-04-11 21:33 - 2016-04-06 12:04 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\libegl.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aepdu.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidcertstorecheck.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidpolicyconverter.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appidsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\audiodg.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\blackbox.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DCompiler_43.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\d3dx11_43.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\D3DX9_43.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dciman32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\drmmgrtn.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\drmv2clt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\fontsub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwcollector.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwcollectorres.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieetwproxystub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iernonce.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\iesetup.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lpk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mferror.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mshtmlmedia.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msmmsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msnetobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MsRdpWebAccess.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msscp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\MsSpellCheckingFacility.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispco6432702.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvdispgenco6432702.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\NvFBC64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvhdagenco6420103.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvhdap64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\NvIFR64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvoglshim64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\nvvsvc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\OpenCL.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcadm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcaevts.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\pcalua.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\pcawrk.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\perftrack.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\powertracker.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdpendp_winip.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\RdpGroupPolicyExtension.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdpudd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rrinstaller.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\setbcdlocale.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbGDCoInstaller.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\ubpm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Wacom_Tablet.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wdi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winload.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winresume.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wksprt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wksprtPS.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\X3DAudio1_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAPOFX1_5.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\XAudio2_7.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\xinput1_3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\appidapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\blackbox.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptsp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_43.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_43.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_43.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\dciman32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\drmmgrtn.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\drmv2clt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxtmsft.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\fontsub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\ieetwproxystub.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iernonce.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\iesetup.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieui.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ieUnatt.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\lpk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mferror.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtml.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MshtmlDac.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mshtmlmedia.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msnetobj.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msrating.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\MsRdpWebAccess.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msscp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\msxml3r.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\NvFBC.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\NvIFR.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\nvoglshim32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\OpenCL.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rdpendp_winip.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rdvidcrl.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\rrinstaller.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\ubpm.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wdi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wksprtPS.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmdrmsdk.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID [64] AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_7.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_5.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_7.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\SysWOW64\xinput1_3.dll:$CmdTcID [130] AlternateDataStreams: C:\Windows\system32\Drivers\appid.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mountmgr.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\nvhda64v.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\PEAuth.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\rdpvideominiport.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\TsUsbFlt.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\TsUsbGD.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\wacommousefilter.sys:$CmdTcID [64] AlternateDataStreams: C:\Windows\system32\Drivers\wacomvhid.sys:$CmdTcID [64] AlternateDataStreams: C:\ProgramData\Temp:2430E4FC [286] AlternateDataStreams: C:\ProgramData\Temp:4D066AD2 [143] AlternateDataStreams: C:\ProgramData\Temp:5925E400 [286] AlternateDataStreams: C:\ProgramData\Temp:5D458568 [272] AlternateDataStreams: C:\ProgramData\Temp:798A3728 [119] AlternateDataStreams: C:\ProgramData\Temp:8173A019 [131] AlternateDataStreams: C:\ProgramData\Temp:9B750A13 [151] AlternateDataStreams: C:\ProgramData\Temp:C46995DA [129] AlternateDataStreams: C:\ProgramData\Temp:E79EFDA4 [308] AlternateDataStreams: C:\Users\Paulina\Desktop\1(1).jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\10-11_Poczta1507_PE.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\10-11_Poczta1508_PE.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\10532727_756690891057127_7149393593755045070_o(1).jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\11297438_919945611376822_1944946491_o.jpg:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\11297438_919945611376822_1944946491_o.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\12318058_959452297435190_183770743_o.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\12633227_1175132575832459_1421689361_o.jpg:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\12633227_1175132575832459_1421689361_o.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\ankieta.doc:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\ankieta.doc:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Aruś(1).jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Aruś2.jpg:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\Aruś2.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Blaszka.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\data(1).xml:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\data(1).xml:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\data.csv:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\dolnyslask_tekstowa.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Foczuś.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Fsecure_T10206167836976275T_.exe:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\Fsecure_T10206167836976275T_.exe:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\grafik marzec 2016.doc:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\grafik marzec 2016.doc:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\index.php:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\J.S. Bach - St. Matthew Passion, BWV 244 _ Aria_ Erbarme dich, mein Gott.mp3:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\J.S. Bach - St. Matthew Passion, BWV 244 _ Aria_ Erbarme dich, mein Gott.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Joy Division - Atmosphere.mp3:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\Joy Division - Atmosphere.mp3:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\K.pdf:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\K.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Kamayu.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Merlin.gif:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\O-księżnice-Zosi-i-rycerzu-Witaminku(1).doc:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\O-księżnice-Zosi-i-rycerzu-Witaminku(1).doc:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\O-księżnice-Zosi-i-rycerzu-Witaminku.doc:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Parrots.mp4:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\podanie o przesunięcie terminu praktyki.docx:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\podanie o przesunięcie terminu praktyki.docx:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\pro612-5_int.exe:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\RDX 2 GRUPY 13.04.16_po zmianie_DOBRY.xls:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\RDX 2 GRUPY 13.04.16_po zmianie_DOBRY.xls:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Regulamin programu Wirtualnych Adopcji 2011.11.13.docx:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\Regulamin programu Wirtualnych Adopcji 2011.11.13.docx:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Scenariusz wydarzenia animacyjnego.docx:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\Scenariusz wydarzenia animacyjnego.docx:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Scenariusz.odt:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\schubert_spektakl.mp4:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\schubert_spektakl.mp4:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Smoki.png:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\spf-hasla.txt:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\spf-hasla.txt:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Streszczenie.docx:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\Streszczenie.docx:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\url.htm:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\usunięte PW odbiorcze.xml:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\usunięte PW.xml:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\usunięte PW.xml:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Warsztaty.jpg:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Średniowiecze-prezntacja.doc:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Desktop\Średniowiecze-prezntacja.doc:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Desktop\Środowiska.pdf:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Downloads\FileZilla_3.15.0.2_win64-setup.exe:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Downloads\FileZilla_3.16.0_win64-setup.exe:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Downloads\FRST.exe:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Downloads\FRST.exe:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Downloads\FRST64.exe:$CmdTcID [64] AlternateDataStreams: C:\Users\Paulina\Downloads\FRST64.exe:$CmdZnID [26] AlternateDataStreams: C:\Users\Paulina\Downloads\qq.jpg:$CmdZnID [26] ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CLPSLS => ""="Service" ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-459723227-2305396002-3096522437-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-459723227-2305396002-3096522437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-459723227-2305396002-3096522437-1007\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg HKU\S-1-5-21-459723227-2305396002-3096522437-1007-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg HKU\S-1-5-21-459723227-2305396002-3096522437-1008\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg HKU\S-1-5-21-459723227-2305396002-3096522437-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja wyłączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: AthBtTray => "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" MSCONFIG\startupreg: AtherosBtStack => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" MSCONFIG\startupreg: COMODO => C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: EgisTecPMMUpdate => "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" MSCONFIG\startupreg: EgisUpdate => "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d MSCONFIG\startupreg: Google Photos Backup => "C:\Users\Paulina\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe" /autostart MSCONFIG\startupreg: Google Update => "C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: PrivDogService => "C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedadssvc.exe" MSCONFIG\startupreg: SuiteTray => "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [{6E7F0282-320B-4A28-912C-2063B3B942AC}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{AD8A6F6E-A646-42D5-A2FD-61A6F9CF7DD1}] => (Allow) LPort=2869 FirewallRules: [{A0BE558E-616C-4229-BB74-4F7BC3821DF3}] => (Allow) LPort=1900 FirewallRules: [{2B9CF7D8-C987-42D6-A0BD-6954CA361EAA}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [{8F2663D2-2CE5-4657-BF11-94ED01837260}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe FirewallRules: [{EFC6064B-3BC5-445E-8C9C-4827B6F0A243}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe FirewallRules: [{446BA307-0E4C-4025-8FA8-1F9CF892585B}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\CLML\CLMLSvc.exe FirewallRules: [{90859512-3E24-4007-B1E6-C1767830BBF6}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe FirewallRules: [{A03C3CC2-FD33-4882-BAD5-38E171ABC545}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe FirewallRules: [{E3B5D22D-2A86-43D3-AA06-3EBDF06772D5}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe FirewallRules: [{36896768-FB18-4CB1-90E2-77E0750690B4}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe FirewallRules: [{B4683F29-62BF-4533-9C52-D6AF4FE78757}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe FirewallRules: [{DFB5CD99-3D6C-4AD1-897F-4DBD535B37CE}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{90EBED47-3BC4-442D-8180-A77779C3EDD8}] => (Allow) C:\Program Files\Gry\Assassin's Creed\AssassinsCreed_Dx9.exe FirewallRules: [{332FDC2A-7553-4248-9839-036CB306627B}] => (Allow) C:\Program Files\Gry\Assassin's Creed\AssassinsCreed_Dx9.exe FirewallRules: [{61E8138A-F750-4B3B-B109-9ACA444607DE}] => (Allow) C:\Program Files\Gry\Assassin's Creed\AssassinsCreed_Dx10.exe FirewallRules: [{4B984013-2D11-475F-93B1-F1C99D1F3C71}] => (Allow) C:\Program Files\Gry\Assassin's Creed\AssassinsCreed_Dx10.exe FirewallRules: [{B24014B9-CE22-4EDC-88E1-EE7C96AEEEDD}] => (Allow) C:\Program Files\Gry\Assassin's Creed\AssassinsCreed_Launcher.exe FirewallRules: [{2EDE0361-8547-4061-B432-1D552BFA0B28}] => (Allow) C:\Program Files\Gry\Assassin's Creed\AssassinsCreed_Launcher.exe FirewallRules: [{8C3DC4F1-ECEC-4551-9B21-948632B6A4CD}] => (Allow) C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe FirewallRules: [{D7081D15-E00B-4C2A-AF60-FE02A0AF98BB}] => (Allow) C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe FirewallRules: [{CD7B5114-5405-49EF-B0DE-C419912E6FB2}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{EE913914-DD26-4712-BBCB-9AE29A0ECF8E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{293B16E0-5D5D-4662-AC1E-E1B7E18796BF}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{34397618-BE31-423A-9856-E2CB47953B7B}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{4F9501BB-47FD-4CA5-9DB2-3054F47FF0EE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{FFC1EB72-40EB-4B11-A0C9-9B48564CA69A}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 2 Ultimate Collection\Fun with Pets\SP9\TSBin\Sims2EP9.exe FirewallRules: [{B06BE2E7-0720-4445-8204-32A469865358}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 2 Ultimate Collection\Fun with Pets\SP9\TSBin\Sims2EP9.exe FirewallRules: [{D1724586-2587-481E-A6AF-2A22AC54EC32}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{D28E07E0-B3FE-4821-9AA5-8C38AA2329FA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{BE5A5818-7C7B-4923-BBF5-4E0181846B9B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{ACABB1B9-36C7-4CB2-A644-03EEE358D592}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6DC90BDB-9A09-46F1-8DDD-1C52910C6B89}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{8E4018F3-5682-4005-917E-F609CC9C01E7}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Punkty Przywracania systemu ========================= 27-04-2016 14:53:30 Installed Inkscape 0.91 ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (04/27/2016 06:02:20 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program 14F6.tmp w wersji 0.0.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 192c Godzina rozpoczęcia: 01d1a09a39045645 Godzina zakończenia: 246 Ścieżka aplikacji: C:\Windows\Temp\14F6.tmp Identyfikator raportu: Error: (04/27/2016 02:52:33 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program msiexec.exe w wersji 5.0.7601.17514 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 1c58 Godzina rozpoczęcia: 01d1a08390501386 Godzina zakończenia: 18 Ścieżka aplikacji: C:\Windows\System32\msiexec.exe Identyfikator raportu: d4bc12db-0c76-11e6-9c42-b870f4898fd9 Error: (04/27/2016 03:15:06 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla "assemblyIdentity1". Błąd w pliku manifestu lub w pliku zasad "assemblyIdentity2" w wierszu assemblyIdentity3. Wartość "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" atrybutu "version" elementu "assemblyIdentity" jest nieprawidłowa. Error: (04/27/2016 03:09:32 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla "assemblyIdentity1". Błąd w pliku manifestu lub w pliku zasad "assemblyIdentity2" w wierszu assemblyIdentity3. Wartość "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" atrybutu "version" elementu "assemblyIdentity" jest nieprawidłowa. Error: (04/27/2016 01:15:35 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla "assemblyIdentity1". Błąd w pliku manifestu lub w pliku zasad "assemblyIdentity2" w wierszu assemblyIdentity3. Wartość "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" atrybutu "version" elementu "assemblyIdentity" jest nieprawidłowa. Error: (04/27/2016 12:39:29 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla "assemblyIdentity1". Błąd w pliku manifestu lub w pliku zasad "assemblyIdentity2" w wierszu assemblyIdentity3. Wartość "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" atrybutu "version" elementu "assemblyIdentity" jest nieprawidłowa. Error: (04/26/2016 11:32:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja: 45.0.2.5941, sygnatura czasowa: 0x57071d64 Nazwa modułu powodującego błąd: mozglue.dll, wersja: 45.0.2.5941, sygnatura czasowa: 0x57070ebc Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x0000ec22 Identyfikator procesu powodującego błąd: 0x24c0 Godzina uruchomienia aplikacji powodującej błąd: 0xplugin-container.exe0 Ścieżka aplikacji powodującej błąd: plugin-container.exe1 Ścieżka modułu powodującego błąd: plugin-container.exe2 Identyfikator raportu: plugin-container.exe3 Error: (04/26/2016 10:48:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja: 45.0.2.5941, sygnatura czasowa: 0x57071d64 Nazwa modułu powodującego błąd: mozglue.dll, wersja: 45.0.2.5941, sygnatura czasowa: 0x57070ebc Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x0000ec22 Identyfikator procesu powodującego błąd: 0x21ec Godzina uruchomienia aplikacji powodującej błąd: 0xplugin-container.exe0 Ścieżka aplikacji powodującej błąd: plugin-container.exe1 Ścieżka modułu powodującego błąd: plugin-container.exe2 Identyfikator raportu: plugin-container.exe3 Error: (04/26/2016 10:48:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: firefox.exe, wersja: 45.0.2.5941, sygnatura czasowa: 0x57070ec1 Nazwa modułu powodującego błąd: guard32.dll, wersja: 8.2.0.5005, sygnatura czasowa: 0x5704e805 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00028647 Identyfikator procesu powodującego błąd: 0x9d0 Godzina uruchomienia aplikacji powodującej błąd: 0xfirefox.exe0 Ścieżka aplikacji powodującej błąd: firefox.exe1 Ścieżka modułu powodującego błąd: firefox.exe2 Identyfikator raportu: firefox.exe3 Error: (04/26/2016 10:48:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: firefox.exe, wersja: 45.0.2.5941, sygnatura czasowa: 0x57070ec1 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000 Identyfikator procesu powodującego błąd: 0x9d0 Godzina uruchomienia aplikacji powodującej błąd: 0xfirefox.exe0 Ścieżka aplikacji powodującej błąd: firefox.exe1 Ścieżka modułu powodującego błąd: firefox.exe2 Identyfikator raportu: firefox.exe3 Dziennik System: ============= Error: (04/23/2016 09:50:02 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error: (04/23/2016 09:41:19 PM) (Source: Disk) (EventID: 15) (User: ) Description: Urządzenie \Device\Harddisk1\DR11 nie jest jeszcze przygotowane do dostępu. Error: (04/21/2016 09:16:08 PM) (Source: Disk) (EventID: 15) (User: ) Description: Urządzenie \Device\Harddisk1\DR10 nie jest jeszcze przygotowane do dostępu. Error: (04/16/2016 12:39:31 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error: (04/14/2016 04:26:33 PM) (Source: Disk) (EventID: 15) (User: ) Description: Urządzenie \Device\Harddisk1\DR1 nie jest jeszcze przygotowane do dostępu. Error: (04/11/2016 09:01:40 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {96D1EED3-701E-4FE5-B996-A543A8465897} Error: (04/10/2016 11:10:14 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na odpowiedź transakcji z usługi LanmanServer. Error: (04/04/2016 10:34:56 PM) (Source: Disk) (EventID: 15) (User: ) Description: Urządzenie \Device\Harddisk2\DR8 nie jest jeszcze przygotowane do dostępu. Error: (04/04/2016 10:34:56 PM) (Source: Disk) (EventID: 15) (User: ) Description: Urządzenie \Device\Harddisk2\DR8 nie jest jeszcze przygotowane do dostępu. Error: (04/04/2016 10:25:48 PM) (Source: bScsiSDa) (EventID: 9) (User: ) Description: Urządzenie \Device\Scsi\bScsiSDa1 nie odpowiedziało w ramach ustalonego limitu czasu. CodeIntegrity: =================================== Date: 2012-08-30 13:04:56.456 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\nvoptimusmft.dll because the set of per-page image hashes could not be found on the system. Date: 2012-08-30 13:04:22.899 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\nvoptimusmft.dll because the set of per-page image hashes could not be found on the system. Date: 2012-08-30 13:03:59.255 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\nvoptimusmft.dll because the set of per-page image hashes could not be found on the system. Date: 2012-08-30 13:02:40.870 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\nvoptimusmft.dll because the set of per-page image hashes could not be found on the system. Date: 2012-08-30 13:01:43.153 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\nvoptimusmft.dll because the set of per-page image hashes could not be found on the system. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz Procent pamięci w użyciu: 54% Całkowita pamięć fizyczna: 5995.86 MB Dostępna pamięć fizyczna: 2730.55 MB Całkowita pamięć wirtualna: 11989.91 MB Dostępna pamięć wirtualna: 7412.2 MB ==================== Dyski ================================ Drive c: (Acer) (Fixed) (Total:338.32 GB) (Free:20.54 GB) NTFS Drive h: (NIKON D3200) (Removable) (Total:29.5 GB) (Free:7.69 GB) FAT32 ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 9A50FAAD) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=338.3 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=112.3 GB) - (Type=05) ======================================================== Disk: 1 (Size: 29.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== Koniec Addition.txt ============================