Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 17-10-2016 Uruchomiony przez User (22-10-2016 17:02:22) Uruchomiony z C:\Users\User\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2014-11-15 17:14:24) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-1538902908-1056142196-2300059988-500 - Administrator - Disabled) Gość (S-1-5-21-1538902908-1056142196-2300059988-501 - Limited - Disabled) User (S-1-5-21-1538902908-1056142196-2300059988-1000 - Administrator - Enabled) => C:\Users\User ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189} AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKU\S-1-5-21-1538902908-1056142196-2300059988-1000\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.) 3DMark 11 (HKLM-x32\...\{f9e83b9c-ab7e-4005-8f32-4ea69703a5e4}) (Version: 1.0.132.0 - Futuremark) 3DMark 11 (Version: 1.0.132.0 - Futuremark) Hidden Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.020.20039 - Adobe Systems Incorporated) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated) Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.) Aktualizacja produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{04E205D6-88B1-4652-B162-42DF2C3B1228}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{442ECBCF-94A7-48CC-8CD9-D31FFFD5FA86}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{128A36ED-21BE-4547-9FFE-5B85AEC735DD}) (Version: - Microsoft) AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.) Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.5.4.0 - Auslogics Labs Pty Ltd) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.7.2.45672 - Electronic Arts) Call of Duty - Black Ops III (HKLM-x32\...\Call of Duty - Black Ops III_is1) (Version: - ) Catalyst Control Center Next Localization BR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform) Company of Heroes 2 (HKLM-x32\...\Company of Heroes 2_is1) (Version: Company of Heroes 2 - ) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.0.0.0054 - Disc Soft Ltd) Dying Light (HKLM-x32\...\RHlpbmdMaWdodA==_is1) (Version: 1 - ) Futuremark SystemInfo (HKLM-x32\...\{032DC00A-51D1-4D28-BFB7-1D0E85291E11}) (Version: 4.25.366 - Futuremark) Gameforge Live 2.0.8 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.8 - Gameforge) Ghost Recon Phantoms - EU (HKU\S-1-5-21-1538902908-1056142196-2300059988-1000\...\61e5da2b7c463135) (Version: 1.36.9879.2 - Ubisoft) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.10.1372 - Intel Corporation) Intel(R) Small Business Advantage (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 2.0.31.7101 - Intel(R) Corporation) Intel(R) Smart Connect Technology (HKLM\...\{942B5E6E-E4D4-42FD-8F53-F72BD1994B7C}) (Version: 5.0.10.2850 - Intel Corporation) Intel(R) Update Manager (x32 Version: 1.0.0.36888 - Intel Corporation) Hidden Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) Java(TM) 6 Update 13 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.) K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - ) KONICA MINOLTA PagePro 1300W (HKLM\...\KONICA MINOLTA PagePro 1300W) (Version: - ) LibreOffice 4.3.3.2 (HKLM-x32\...\{87C753BB-81E3-403B-BD87-6293F870B20B}) (Version: 4.3.3.2 - The Document Foundation) Medal of Honor: Pacific Assault™ (HKLM-x32\...\{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}) (Version: 1.2.1.280 - Electronic Arts) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.205.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) Mozilla Firefox 49.0.2 (x86 pl) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 pl)) (Version: 49.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla) MyFreeCodec (HKU\S-1-5-21-1538902908-1056142196-2300059988-1000\...\MyFreeCodec) (Version: - ) Nexon Launcher (HKLM-x32\...\Nexon Nexon Launcher) (Version: 2.0.0 - Nexon) NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 10.2.1.38915 - Electronic Arts, Inc.) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Project CARS (HKLM-x32\...\UHJvamVjdENBUlM=_is1) (Version: 1 - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6959 - Realtek Semiconductor Corp.) S.K.I.L.L. - Special Force 2 (HKLM-x32\...\Special Force 2 Beta_is1) (Version: - ) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14113.3 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.14113.3 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG Moblie USB Driver (HKLM\...\{8F110B6A-60A2-4542-BB19-AD6234E2969D}) (Version: 2.9.5.0916 - SAMSUNG Electronics Co., Ltd. ) Shadow Warrior 2 (HKLM-x32\...\1434021265_is1) (Version: 2.0.0.4 - GOG.com) Shadow Warrior 2 Deluxe Edition (HKLM-x32\...\1735987864_is1) (Version: 2.0.0.1 - GOG.com) Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.018 - MSI) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.0.0 - GOG.com) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) USB Network Joystick (HKLM-x32\...\{2A558A06-A44E-400D-95AD-D9FAA89AFD36}) (Version: V3.70a - ) VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.5 - MSI) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WinRAR 5.11 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {1C46B662-4133-4534-AA16-937386EE4CBC} - System32\Tasks\AdobeAAMUpdater-1.0-User-Komputer-User => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-08-05] (Adobe Systems Incorporated) Task: {288CDC57-51D8-445B-B130-477AEA9AEA46} - System32\Tasks\Driver Booster SkipUAC (User) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {43BF71C1-6C50-47C1-97AE-580356B8E9A9} - System32\Tasks\{B6CAE659-5001-438C-8D0B-DCC5D7BDFD41} => Firefox.exe hxxp://ui.skype.com/ui/0/6.22.81.104/pl/abandoninstall?source=lightinstaller&page=tsMain Task: {5CC86CA8-62D0-4B14-A788-4EB1F95298AC} - System32\Tasks\{4CC226A8-4E0F-4C84-96F5-C3FF85A08F30} => pcalua.exe -a C:\Users\User\Desktop\PP1300WGDIWinx86_1611120PL\PP1300WGDIWinx86_1611120PL\setup.exe -d C:\Users\User\Desktop\PP1300WGDIWinx86_1611120PL\PP1300WGDIWinx86_1611120PL Task: {68DE3ECE-3194-4ACC-B7F5-238E766DC16D} - \Inst_Rep -> Brak pliku <==== UWAGA Task: {6DC76309-9CFF-4809-AB8D-3629E3D8080E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated) Task: {89905991-7006-455E-B604-178858F70B52} - System32\Tasks\Intel(R) Small Business Advantage\Notifier => C:\Program Files\Intel\Intel(R) Small Business Advantage\UI\SBA_Notifier.exe [2013-03-13] (Intel Corporation) Task: {90791DF4-3D58-4F1B-B347-AC2DC8E7BABB} - System32\Tasks\{37C8C52E-7FCA-44D3-A3EF-FF39D742E95A} => pcalua.exe -a C:\Users\User\AppData\Roaming\oursurfing\UninstallManager.exe -c -ptid=smt Task: {95DAE4BD-6F91-4A53-8CE8-CDBB659CDF2A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd) Task: {9A7557AA-837A-4464-B6B4-67D462C32624} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-08-30] (Microsoft Corporation) Task: {BDDDC19F-A158-43EA-9BBF-81658837F8A6} - System32\Tasks\{C2F59612-9445-4AA4-9ACC-ECDB8A2AC0C2} => pcalua.exe -a E:\Setup.exe -d E:\ Task: {ECA6F374-0CD6-44E2-929D-CCD9F6B3C2CD} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-08-30] (Microsoft Corporation) Task: {F316B83E-1658-4007-9647-47A76D9E5ABD} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-09-16] (Advanced Micro Devices, Inc.) Task: {F31A5830-640F-4693-8728-1D2CB567D873} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-12] (Adobe Systems Incorporated) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://mmotraffic.com/catalog/goplay/1000932/MTE3NjYvLy8xMDAwOTMy?click_id=0DyEtA0DyB0E0FtD0C0DtBtD0AtDtDyB2RtBtDtCyDtCtCtBzytCyDtAyCtByCyCzztD ==================== Załadowane moduły (filtrowane) ============== 2014-06-18 18:18 - 2014-06-18 18:18 - 00209712 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe 2014-06-18 18:18 - 2014-06-18 18:18 - 00057648 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll 2014-06-18 18:18 - 2014-06-18 18:18 - 00037168 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll 2014-06-18 18:18 - 2014-06-18 18:18 - 00057648 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTEncryptionCheck.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll 2016-09-13 02:01 - 2016-09-13 02:01 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2014-12-25 16:58 - 2015-07-07 21:00 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2015-11-08 13:38 - 2008-12-10 12:10 - 00796784 _____ () C:\Windows\USB Vibration\7906\USB Gamepad.exe 2016-10-22 16:42 - 2016-10-21 15:24 - 00591360 _____ () C:\Users\User\AppData\Roaming\app.exe 2014-11-15 19:19 - 2013-05-17 01:05 - 01199576 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-10-12 10:00 - 2016-10-12 10:00 - 19635392 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [118] ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== Powiązania plików (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-1538902908-1056142196-2300059988-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 217.113.224.134 - 217.113.224.35 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [{AC574A3F-EAA9-4498-A6DF-6836C79447A8}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{7240E8A0-9A43-48AA-931E-DB22E65EEF48}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{EAB5043A-2DD6-4721-B7B8-36BEB0C89D5A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{4BA62926-F543-4D65-9EDD-244436FFE695}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{B89EFB1A-3C54-4DDA-88FA-E8A5E3FD3A00}D:\gry zainstalowane\company of heroes 2\reliccoh2.exe] => (Allow) D:\gry zainstalowane\company of heroes 2\reliccoh2.exe FirewallRules: [UDP Query User{5BC18374-0BDA-445D-923B-7D890AD8F49A}D:\gry zainstalowane\company of heroes 2\reliccoh2.exe] => (Allow) D:\gry zainstalowane\company of heroes 2\reliccoh2.exe FirewallRules: [TCP Query User{4A927676-4109-4545-9216-F529576BE0BA}D:\gry zainstalowane\dying light\dyinglightgame.exe] => (Allow) D:\gry zainstalowane\dying light\dyinglightgame.exe FirewallRules: [UDP Query User{5E35DF1C-8D1F-484E-9392-504F1D0E6FC9}D:\gry zainstalowane\dying light\dyinglightgame.exe] => (Allow) D:\gry zainstalowane\dying light\dyinglightgame.exe FirewallRules: [TCP Query User{225837D2-98ED-435C-ADC6-38E47CFCF5CC}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{59DCD7B3-184C-4320-ADBD-ACC665EF9BFB}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{5B262E58-52EE-4BA1-8BE4-C79A5D52D042}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{7F2963F9-4310-493E-B88E-5E8938A57432}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{0FBEC219-2E98-42F7-9A73-C05DDC268F38}D:\gry zainstalowane\alien isolation\ai.exe] => (Allow) D:\gry zainstalowane\alien isolation\ai.exe FirewallRules: [UDP Query User{5EC16148-B9A6-45EE-A5E7-96519AC04566}D:\gry zainstalowane\alien isolation\ai.exe] => (Allow) D:\gry zainstalowane\alien isolation\ai.exe FirewallRules: [TCP Query User{5AB138C5-0170-4297-AD37-111A372D368D}D:\gry zainstalowane\far cry 4\bin\farcry4.exe] => (Allow) D:\gry zainstalowane\far cry 4\bin\farcry4.exe FirewallRules: [UDP Query User{E3467364-32E0-4523-99D3-71EE8EA4C632}D:\gry zainstalowane\far cry 4\bin\farcry4.exe] => (Allow) D:\gry zainstalowane\far cry 4\bin\farcry4.exe FirewallRules: [{3C385F46-7331-42F0-803A-764BD1395C61}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\bf4_x86.exe FirewallRules: [{611C5C4A-1A8A-419F-B8D1-213763150E0B}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\bf4_x86.exe FirewallRules: [{36B50738-AC63-4445-A461-D91D20796211}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\bf4.exe FirewallRules: [{2BFDE690-ACD0-4180-8BEE-93045A78E4E9}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\bf4.exe FirewallRules: [{3B468153-320F-466A-B55E-BFD281AA4EBD}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{591B21D2-33B8-4D50-95DF-9A4DDA7DEDCC}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{8378562A-C186-4514-8812-69BA33567CED}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{B0788B54-7383-4BBB-83F4-75C5A2C45877}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{00BDA0E0-38D4-400F-A383-76FB55303E27}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{F51AC4D1-DA76-48FD-81EC-7AAF274713F6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{9B3C20C0-8F5C-4E83-B77F-88B7BF02B0F5}E:\jre\bin\java.exe] => (Block) E:\jre\bin\java.exe FirewallRules: [UDP Query User{86CFB146-4715-4BDC-8D61-B683DA7E459C}E:\jre\bin\java.exe] => (Block) E:\jre\bin\java.exe FirewallRules: [TCP Query User{42CAE22E-7D35-460F-B970-040D0B81316C}D:\gry zainstalowane\call of duty - black ops iii\blackops3.exe] => (Allow) D:\gry zainstalowane\call of duty - black ops iii\blackops3.exe FirewallRules: [UDP Query User{AECCA58A-E4BC-403A-8FE5-AD59B63E2470}D:\gry zainstalowane\call of duty - black ops iii\blackops3.exe] => (Allow) D:\gry zainstalowane\call of duty - black ops iii\blackops3.exe FirewallRules: [TCP Query User{909E4687-13FE-43FD-A220-AFE03E4632D6}C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe] => (Allow) C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe FirewallRules: [UDP Query User{07A38E58-68EA-4D35-8E2F-9FD264A15855}C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe] => (Allow) C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe FirewallRules: [TCP Query User{D5189A83-0720-4064-A6E4-484F33B2B2D8}D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe] => (Block) D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe FirewallRules: [UDP Query User{97D51775-3735-4A3E-B07E-096CB2B579C5}D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe] => (Block) D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe FirewallRules: [{19E4AD0F-EA29-4599-A5CB-95B7ACA1A4F3}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\BF4WebHelper.exe FirewallRules: [{229E8F45-0CFB-429B-BBC1-FE6782E122D9}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\BF4WebHelper.exe FirewallRules: [{A22C34C0-6DE2-42D4-9EDA-F81F3D26307D}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\BF4X86WebHelper.exe FirewallRules: [{2AAB5F8F-D956-4E9E-9FDB-844E150CC12B}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 4\BF4X86WebHelper.exe FirewallRules: [{D52C3B81-8911-4071-8462-99AF064CAE6B}] => (Allow) C:\Program Files (x86)\GameforgeLive\gfl_client.exe FirewallRules: [{0BD0E54A-829A-4FE0-9901-D1DB17B64587}] => (Allow) C:\Program Files (x86)\GameforgeLive\Games\POL_pol\S.K.I.L.L\Binaries\Win32\sf2.exe FirewallRules: [{12EBB7D0-E3B5-4573-AC60-62CE1F3D274D}] => (Allow) C:\Program Files (x86)\GameforgeLive\Games\POL_pol\S.K.I.L.L\Binaries\Win32\sf2.exe FirewallRules: [{C300CFB9-FB7C-4233-9969-3FEEB6CFEFCD}] => (Allow) D:\gry zainstalowane\Battlefield4\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{6E17CB39-47FB-4C36-855E-F86BB45589FA}] => (Allow) D:\gry zainstalowane\Battlefield4\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{935C7BF1-BAD4-49DE-B03B-B25BFB2C1814}] => (Allow) D:\gry zainstalowane\Battlefield4\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{DFCE36A6-12B8-4930-8AB3-623EA0F2EFD4}] => (Allow) D:\gry zainstalowane\Battlefield4\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{9DBAAB70-8A39-4E4C-AD94-BB72BC4D9E86}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 1 Open Beta\bf1.exe FirewallRules: [{B9615AC7-DBD3-458C-94B6-B1E42E171CAE}] => (Allow) D:\gry zainstalowane\Battlefield4\Battlefield 1 Open Beta\bf1.exe FirewallRules: [TCP Query User{2A9EBD32-73E9-4D52-84EA-B78DA7F3A987}C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe] => (Block) C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe FirewallRules: [UDP Query User{DCB6D412-ACE3-4A7E-84E9-EB0C0FE40A42}C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe] => (Block) C:\users\user\appdata\local\apps\2.0\zd844zkt.1b5\pxd39dea.51x\laun...app_2e973cc213891be7_0001.0024_dd24b003d48bfc42\launcher.exe FirewallRules: [TCP Query User{41F339B0-7FDB-4653-8EAA-3FDD0B338C19}D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe] => (Block) D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe FirewallRules: [UDP Query User{364AAA9D-E8F6-410C-A278-01E218CE1067}D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe] => (Block) D:\gry zainstalowane\phantom klient gry\ghost recon phantoms\pdc-live\ghostreconphantoms.exe FirewallRules: [{F9DBECEC-DFE8-4AC7-8A06-7C1E56A2825B}] => (Allow) C:\Nexon\Library\firstassault\appdata\Shipping\GAME.exe FirewallRules: [{45DB591F-6AA8-4618-9087-1E3340EF49CA}] => (Allow) C:\Nexon\Library\firstassault\appdata\Shipping\GAME.exe ==================== Punkty Przywracania systemu ========================= 09-10-2016 20:05:45 Windows Update 12-10-2016 10:46:59 Windows Update 12-10-2016 12:16:32 Windows Update 16-10-2016 10:26:41 Windows Update 19-10-2016 21:24:37 Windows Update 22-10-2016 15:48:53 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 22-10-2016 15:49:17 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 22-10-2016 15:50:00 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 22-10-2016 15:50:52 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 22-10-2016 16:28:10 Removed Wolfenstein ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= Name: wfdrvr_vt_1_10_0_28 Description: wfdrvr_vt_1_10_0_28 Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: wfdrvr_vt_1_10_0_28 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (10/22/2016 04:46:47 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (10/22/2016 04:36:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (10/22/2016 04:07:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: GalaxyClient Helper.exe, wersja: 1.1.18.52, sygnatura czasowa: 0x580773cf Nazwa modułu powodującego błąd: libcef.dll, wersja: 3.2704.1434.0, sygnatura czasowa: 0x57d833c4 Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x000a173d Identyfikator procesu powodującego błąd: 0x11a4 Godzina uruchomienia aplikacji powodującej błąd: 0x01d22c6970a72b0a Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\GalaxyClient\libcef.dll Identyfikator raportu: cd1d871b-9860-11e6-9b96-d43d7ef0cd20 Error: (10/22/2016 03:36:52 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Dziennik System: ============= Error: (10/22/2016 04:46:15 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: wfdrvr_vt_1_10_0_28 Error: (10/22/2016 04:46:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Origin Web Helper Service z powodu następującego błędu: Usługa nie odpowiada na sygnał uruchomienia lub sygnał sterujący w oczekiwanym czasie. Error: (10/22/2016 04:46:14 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Origin Web Helper Service. Error: (10/22/2016 04:45:25 PM) (Source: Service Control Manager) (EventID: 7002) (User: ) Description: Usługa MLPTDR_N zależy od grupy Parallel arbitrator, a nie uruchomiono żadnego członka tej grupy. Error: (10/22/2016 04:35:43 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: wfdrvr_vt_1_10_0_28 Error: (10/22/2016 04:35:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Origin Web Helper Service z powodu następującego błędu: Usługa nie odpowiada na sygnał uruchomienia lub sygnał sterujący w oczekiwanym czasie. Error: (10/22/2016 04:35:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Origin Web Helper Service. Error: (10/22/2016 04:34:50 PM) (Source: Service Control Manager) (EventID: 7002) (User: ) Description: Usługa MLPTDR_N zależy od grupy Parallel arbitrator, a nie uruchomiono żadnego członka tej grupy. Error: (10/22/2016 03:52:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi GalaxyCommunication z powodu następującego błędu: Usługa nie odpowiada na sygnał uruchomienia lub sygnał sterujący w oczekiwanym czasie. Error: (10/22/2016 03:52:41 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą GalaxyCommunication. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i5-4690 CPU @ 3.50GHz Procent pamięci w użyciu: 30% Całkowita pamięć fizyczna: 8120.07 MB Dostępna pamięć fizyczna: 5668.41 MB Całkowita pamięć wirtualna: 16238.33 MB Dostępna pamięć wirtualna: 13568.11 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:200 GB) (Free:17.33 GB) NTFS Drive d: () (Fixed) (Total:731.41 GB) (Free:186.67 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: EE9BC075) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=731.4 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ============================