Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017 Ran by damia (18-03-2017 17:12:50) Running from C:\Users\damia\Desktop Windows 10 Pro Version 1607 (X64) (2016-09-21 01:48:59) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1922636286-9306992-3665695711-500 - Administrator - Enabled) => C:\Users\Administrator damia (S-1-5-21-1922636286-9306992-3665695711-1001 - Administrator - Enabled) => C:\Users\damia DefaultAccount (S-1-5-21-1922636286-9306992-3665695711-503 - Limited - Disabled) Guest (S-1-5-21-1922636286-9306992-3665695711-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\uTorrent) (Version: 3.4.9.43295 - BitTorrent Inc.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated) AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden Airytec Switch Off (HKLM\...\Airytec Switch Off) (Version: 3.5.1 - Airytec) Aktualizacja produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{04E205D6-88B1-4652-B162-42DF2C3B1228}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{442ECBCF-94A7-48CC-8CD9-D31FFFD5FA86}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{128A36ED-21BE-4547-9FFE-5B85AEC735DD}) (Version: - Microsoft) Aktualizacje NVIDIA 2.11.3.5 (Version: 2.11.3.5 - NVIDIA Corporation) Hidden ALLPlayer V6.X (HKLM-x32\...\ALLPlayer_is1) (Version: - ALLPlayer Group, Ltd.) BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden Centrum obsługi urządzeń z systemem Windows Mobile (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Copy (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.3.0.0156 - Disc Soft Ltd) Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden DJ_AIO_NS_LP_DocCD (x32 Version: 90.0.222.000 - Hewlett-Packard) Hidden DJ_AIO_ProductContext (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden DJ_AIO_Software (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden DJ_AIO_Software_min (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden e-pity 8.0.14 za rok 2016 (HKLM-x32\...\{80D8170E-5590-218-B9ED-E24E4C99A11D}_is1) (Version: 8.0.14 - e-file sp. z o.o. sp.k.) EVEREST Ultimate Edition v5.50 (HKLM-x32\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.) F2100 (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden F2100_Help (x32 Version: 90.0.222.000 - Hewlett-Packard) Hidden Fraps (HKLM-x32\...\Fraps) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Deskjet All-In-One Software (HKLM\...\{2CB8566A-8EA6-417A-BAB1-1B10A88C79BB}) (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) LG Mobile Driver (HKLM-x32\...\{3F490D0E-3131-438C-BCF9-7549CB88DF41}) (Version: 4.0.4 - LG Electronics) LG One Click Root (HKLM-x32\...\{5085AFF1-777B-4052-85D1-59140D26DB28}) (Version: 1.3.0.0 - avicohh software) LinuxLive USB Creator (HKLM-x32\...\LinuxLive USB Creator) (Version: 2.9 - Thibaut Lauziere) MarketResearch (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50905.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 52.0 (x64 pl) (HKLM\...\Mozilla Firefox 52.0 (x64 pl)) (Version: 52.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.0.6270 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden NetWorx 5.5.5 (HKLM\...\NetWorx_is1) (Version: - Softperfect) Nokia Connectivity Cable Driver (HKLM-x32\...\{D4BF151C-70A8-4CE2-906F-4173A575BAD9}) (Version: 7.1.182.0 - Nokia) Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia) Nokia PC Suite (x32 Version: 7.1.180.94 - Nokia) Hidden NVIDIA GeForce Experience 2.11.3.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.3.5 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) NVIDIA Sterownik 3D Vision 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.53 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA Sterownik graficzny 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.53 - NVIDIA Corporation) NVIDIA Sterownik kontrolera 3D Vision 364.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation) OCCT 4.4.1 (HKLM-x32\...\OCCT) (Version: 4.4.1 - Ocbase.com) Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.) Pakiet sterowników systemu Windows - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia) Pakiet sterowników systemu Windows - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia) Panel sterowania NVIDIA 376.53 (Version: 376.53 - NVIDIA Corporation) Hidden Phoenix Service Software 2012.24.000.48366 (HKLM-x32\...\Phoenix Service Software 2012.24.000.48366_is1) (Version: - Seidea.com) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) Realterm 2.0.0.70_SignedWrapper (HKLM-x32\...\Realterm) (Version: 2.0.0.70_SignedWrapper - Broadcast Equipment) Rise of the Tomb Raider (HKLM-x32\...\{45F08513-973A-4C18-93FD-8E12B1908390}_is1) (Version: - Square Enix) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.0 - Rockstar Games) Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.11.3.5 - NVIDIA Corporation) Hidden SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden Sony Mobile Emma (HKLM-x32\...\Emma) (Version: 2.15.14.201510090937 - Sony Mobile Communications Inc.) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Stardock Start10 (HKLM\...\Start10_is1) (Version: 1.0 - Stardock Software, Inc.) Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden UltraStar Deluxe (HKLM-x32\...\UltraStar Deluxe) (Version: 1.1 - USDX Team) UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden WinAVR 20100110 (remove only) (HKLM-x32\...\WinAVR-20100110) (Version: 20100110 - ) WinRAR 5.21 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) X-Mouse Button Control 2.10.2 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.10.2 - Highresolution Enterprises) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {07715638-B366-4A96-BC7E-92F4EA535667} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-29] (Google Inc.) Task: {15D05637-2F93-40B3-B39D-315BB654AA3F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-14] (Adobe Systems Incorporated) Task: {17AB1F21-A5A2-4078-9A55-569E050388E5} - System32\Tasks\v4-0-30319\ngen => Rundll32.exe "C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll",eHeZcuQLD Task: {1BE7791A-80B6-4AD3-BCB0-668C3C78ADEE} - System32\Tasks\{1903351C-55ED-438A-8661-64A4289AC210} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -c -runfromtemp -l0x0409 -removeonly Task: {323BB2AD-D680-45C5-A445-C91DF7938EEB} - System32\Tasks\v4 => Rundll32.exe "C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll",eHeZcuQLD Task: {3E2D6A0F-9B89-44E8-B7C1-029AB44634FB} - System32\Tasks\7368e7341e2044H34 => Rundll32.exe "C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll",eHeZcuQLD <==== ATTENTION Task: {6D04B0E3-C893-47DC-9BBE-6B6DEEB03A7A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-29] (Google Inc.) Task: {7F1C774A-E1F5-4222-8A83-283FD2C72CBA} - System32\Tasks\ielowutil => Rundll32.exe "C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll",eHeZcuQLD Task: {A0551398-D6AD-4913-B200-2D0AB703ACD5} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-03-14] (Microsoft Corporation) Task: {CB064887-771A-4406-8F00-20116A636182} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {DA7896D3-833F-4041-83F7-71E1E0B4F6BB} - System32\Tasks\QForlLgs0EYm => qforllgs0eym.exe Task: {F4F4A3E4-1AB0-41CB-AA9D-74E5D9245640} - System32\Tasks\ielowutil-exe => Rundll32.exe "C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll",eHeZcuQLD Task: {F50D2B54-2AC8-438E-ADF0-B792AFFD8D48} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2016-05-29] () Task: {FC35E804-4A6F-476F-A80E-181C44C17C19} - System32\Tasks\v4-0-30319\mscorsvw => Rundll32.exe "C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll",eHeZcuQLD Task: {FDB06B8F-D88D-4CA6-9D10-B91200B34BED} - System32\Tasks\v4-0 => Rundll32.exe "C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll",eHeZcuQLD (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> %SNP% ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> %SNF% ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-03-14 19:20 - 2017-03-04 08:19 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2017-03-13 23:43 - 2014-03-22 19:35 - 03139072 _____ () C:\ProgramData\7368e7341e2044H34\7368e7341e2044H34.dll 2016-09-21 02:41 - 2016-12-29 13:44 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-03-25 23:01 - 2016-05-02 06:54 - 00369208 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll 2016-01-26 19:40 - 2016-05-02 06:55 - 00289848 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2016-03-25 23:01 - 2016-05-02 06:55 - 03613240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll 2016-04-16 15:00 - 2016-05-02 06:54 - 01148984 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll 2016-04-16 15:00 - 2016-05-02 06:55 - 02667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll 2016-04-16 15:00 - 2016-05-02 06:55 - 01990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll 2016-04-16 15:00 - 2016-05-02 06:55 - 01842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll 2016-01-26 23:34 - 2016-05-02 06:55 - 00208952 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll 2016-04-16 15:00 - 2016-05-02 06:54 - 00921656 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll 2016-04-16 15:00 - 2016-05-02 06:54 - 00035896 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll 2017-03-14 19:20 - 2017-03-04 08:19 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-09-21 02:51 - 2016-09-21 02:51 - 00959168 _____ () C:\Users\damia\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64\ClientTelemetry.dll 2016-07-10 21:19 - 2016-09-19 11:09 - 00813056 _____ () C:\Program Files\NetWorx\sqlite.dll 2017-03-14 01:23 - 2017-03-14 01:23 - 04031440 _____ () C:\Users\damia\Desktop\adwcleaner_6.044.exe 2017-03-18 17:07 - 2017-03-18 17:07 - 00249344 _____ () C:\WINDOWS\TEMP\g8657.tmp.exe 2016-01-26 19:40 - 2016-05-02 07:02 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 12:04 - 2015-07-10 12:02 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1922636286-9306992-3665695711-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\damia\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img2.jpg DNS Servers: 82.163.142.8 - 95.211.158.136 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk" HKLM\...\StartupApproved\Run: => "Windows Mobile Device Center" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\StartupApproved\Run: => "ALLUpdate" HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\StartupApproved\Run: => "AlcoholAutomount" HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\StartupApproved\Run: => "XperiaCompanionAgent" HKU\S-1-5-21-1922636286-9306992-3665695711-1001\...\StartupApproved\Run: => "YfnPack" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{20189693-0B7F-467B-B701-20797D549FDA}] => (Allow) C:\Program Files\NetWorx\networx.exe FirewallRules: [{6DCEDC78-6D18-4685-A635-D518C922FCA0}] => (Allow) C:\Users\damia\Downloads\Windows 10 Activators\KMSpico.10.0.102040 Beta\KMSELDI.exe FirewallRules: [{E3AAF4C6-9B0C-4A3F-A00B-5BFCFF56E800}] => (Allow) C:\Users\damia\Downloads\Windows 10 Activators\KMSpico.10.0.102040 Beta\KMSELDI.exe FirewallRules: [{DC0016F2-B3EE-4087-B7BD-DE2BC4B961B7}] => (Allow) LPort=1688 FirewallRules: [UDP Query User{8261906D-2C14-4740-BAA9-68F2828734F8}C:\program files (x86)\nokia\phoenix\phoenix.exe] => (Allow) C:\program files (x86)\nokia\phoenix\phoenix.exe FirewallRules: [TCP Query User{B1FC14A8-59D2-4E87-A36C-E29F1B509742}C:\program files (x86)\nokia\phoenix\phoenix.exe] => (Allow) C:\program files (x86)\nokia\phoenix\phoenix.exe FirewallRules: [UDP Query User{15A19CCC-82E8-4668-91CB-8440BA36F77D}C:\program files (x86)\common files\nokia\fuse\fuseservice.exe] => (Allow) C:\program files (x86)\common files\nokia\fuse\fuseservice.exe FirewallRules: [TCP Query User{6F26994F-5460-4FC6-99FE-929343B139A7}C:\program files (x86)\common files\nokia\fuse\fuseservice.exe] => (Allow) C:\program files (x86)\common files\nokia\fuse\fuseservice.exe FirewallRules: [{24B035FE-6E16-45B5-B12B-E4C31F416562}] => (Allow) D:\Program Files (x86)\Sony Mobile\Emma\Emma.exe FirewallRules: [{49EE1154-2391-41EE-997A-3D44FF660B3D}] => (Allow) D:\Program Files (x86)\Sony Mobile\Emma\Emma.exe FirewallRules: [{41F34783-C2A8-4112-B98E-12069F53FF17}] => (Allow) LPort=26675 FirewallRules: [{1F468046-AE7A-4966-B030-6F8E65552ABE}] => (Allow) %systemroot%\WindowsMobile\wmdHost.exe FirewallRules: [{3B1EBA13-9A6A-4B0E-8492-DA38D489124E}] => (Allow) %systemroot%\WindowsMobile\wmdHost.exe FirewallRules: [{3FC3E89D-6177-4FFE-A946-168824BD5856}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{552AACFC-40AB-4E00-BB97-F510B6483A6E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [UDP Query User{E3FF3716-8281-4CBD-99BF-4F6048CCC7EB}D:\program files (x86)\ubisoft\farcry 3\bin\farcry3.exe] => (Block) D:\program files (x86)\ubisoft\farcry 3\bin\farcry3.exe FirewallRules: [TCP Query User{1202558D-02E0-4DE9-8601-E7FA7CAE2FDC}D:\program files (x86)\ubisoft\farcry 3\bin\farcry3.exe] => (Block) D:\program files (x86)\ubisoft\farcry 3\bin\farcry3.exe FirewallRules: [{ECA8BB84-9F68-4BB8-BD04-20C1C9D4ADA0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0E344CCA-ADBF-435E-B5D0-B26290119AC6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{5DEAD514-180F-46DC-8CA9-02E9FEB0F854}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{835DE142-A80A-46DF-B2DA-5D8ABDD9DF00}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{F8F7CF59-CF50-4F1F-9AC2-6CCBEF216184}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{7F473C0E-9153-46DE-8309-D39C1C41C32E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{441AE02E-D42E-41CB-9020-8E20BBA9110D}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{8BF067B7-1263-44ED-9927-5788C0EBA8A2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{A46FD199-9C1C-43AE-BB69-EF4727300C91}] => (Allow) C:\Users\damia\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{0FC22365-8D09-4A20-ACDC-E373768BE717}] => (Allow) C:\Users\damia\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{8CEAC3A3-2DF6-4936-9CDD-11FC2D7486E3}] => (Allow) C:\Users\damia\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{5EE56627-4C86-4AB1-8D3D-AC5554F6CAA9}] => (Allow) C:\Users\damia\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{56C98287-7218-48C6-915A-2822AF378EC8}] => (Allow) C:\Users\damia\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{DAF2FA0B-B2E3-4434-8A85-B43B6F4D2004}] => (Allow) C:\Users\damia\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{09C9D5E2-7CB6-4E7C-8EFA-4993528CA570}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe FirewallRules: [UDP Query User{5CE48716-98FF-4A60-B7E2-2E71601C7AF5}C:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\program files\rockstar games\grand theft auto v\gta5.exe FirewallRules: [{1EEB2AC3-288F-4961-8073-A525B74816AE}] => (Allow) C:\Users\damia\AppData\Local\Temp\nsj654F.tmp\Installer-10067444.exe FirewallRules: [{AD81C098-F161-48A0-84B1-5E44D21CAE36}] => (Allow) C:\Users\damia\AppData\Local\Temp\nsj654F.tmp\Installer-10067444.exe FirewallRules: [TCP Query User{C245A967-1582-4BB0-B78C-4A076C790FC5}C:\program files (x86)\origin games\fifa 16 demo\fifa16_demo.exe] => (Allow) C:\program files (x86)\origin games\fifa 16 demo\fifa16_demo.exe FirewallRules: [UDP Query User{5496D1FD-67E5-49A2-AFB5-22ED4CD2C056}C:\program files (x86)\origin games\fifa 16 demo\fifa16_demo.exe] => (Allow) C:\program files (x86)\origin games\fifa 16 demo\fifa16_demo.exe FirewallRules: [TCP Query User{3AA5CE4C-7C9A-4297-84AA-3A34D6999A09}D:\program files (x86)\red barrels\outlast\binaries\win64\olgame.exe] => (Allow) D:\program files (x86)\red barrels\outlast\binaries\win64\olgame.exe FirewallRules: [UDP Query User{9875E3F7-1FF3-4F0B-B6D7-86C2968121C4}D:\program files (x86)\red barrels\outlast\binaries\win64\olgame.exe] => (Allow) D:\program files (x86)\red barrels\outlast\binaries\win64\olgame.exe FirewallRules: [TCP Query User{FB9E09CD-09BD-4A94-96CC-16FD1EEBD95B}D:\program files (x86)\far cry 4\bin\farcry4.exe] => (Allow) D:\program files (x86)\far cry 4\bin\farcry4.exe FirewallRules: [UDP Query User{66A6DF6D-B105-46C3-A074-B1616879D8A3}D:\program files (x86)\far cry 4\bin\farcry4.exe] => (Allow) D:\program files (x86)\far cry 4\bin\farcry4.exe FirewallRules: [{400F4EDB-F6B6-43A7-ADBA-7F8B0C7E5291}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{11FC01C0-A740-4666-AF0E-EE0392502C97}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{73B74A8E-38A4-4EA6-88D8-F6516531ADED}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{3D14CD88-48A9-4E56-95AA-D4B2B9E80F6F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{07680B50-778A-43A9-ADBB-5D42C4446FB5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{51ABD00A-2490-44B2-B9CE-F78F45725713}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{CF1BA2A4-D493-45C4-ADE1-55A13C24CD84}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{65750E50-1C84-44FE-A7A6-01187CBC1D75}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{7C3D8621-A2B6-4207-A82C-F79657BB8B74}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe FirewallRules: [{17B80585-BB99-4A52-A6B6-9A8EDA8F605D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{E1DCACEE-9EDC-4051-8559-A7DBEC3BEA5F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{06DB6660-FC0A-48D4-9F13-7E1B45679C8A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{01027D4B-389B-4A8D-9971-A211BD1A5CFD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{AE8BA21B-EF52-4E68-A5CE-895A95308A49}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{7AE05883-43E5-42E7-9225-A10DEA5A0811}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{8CA57D11-A324-4548-A6B0-F425F1958A4C}] => (Allow) C:\WINDOWS\AutoKMS\AutoKMS.exe FirewallRules: [{0ED99DEA-CA12-4BD9-A141-D8E1F3315FEA}] => (Allow) C:\WINDOWS\AutoKMS\AutoKMS.exe FirewallRules: [{0445E808-415E-4704-9267-AB9B61D77EEA}] => (Allow) C:\Program Files\NetWorx\networx.exe FirewallRules: [{7264566C-1D82-4BE8-ABA6-E9D445F87BF1}] => (Allow) C:\Program Files\Eltima Software\Flexihub\flexihub64.exe FirewallRules: [{BD8868DB-87C4-49EA-8F00-EB54E5115AF4}] => (Allow) C:\Program Files\Eltima Software\Flexihub\flexihub-gui.exe FirewallRules: [{2840A569-C0EB-4E11-ADEA-3C91B2A0BFF5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{DBA37370-16A2-4205-BC09-74788E8E4895}] => (Allow) C:\Users\damia\Downloads\Windows 10 Activators\Microsoft Toolkit 2.5.3\Microsoft Toolkit.exe FirewallRules: [{F26DB80F-2E11-4FFB-BCA6-20D77DE956CB}] => (Allow) C:\Users\damia\Downloads\Windows 10 Activators\Microsoft Toolkit 2.5.3\Microsoft Toolkit.exe FirewallRules: [{22A56D5A-A56F-4214-A7D3-227764D5EDE3}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [{47820670-8C3E-45EA-8E08-6F7EF47E6615}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{623F011F-DB70-45FD-8322-635CFF889B1D}] => (Allow) C:\Windows\System32\rundll32.exe ==================== Restore Points ========================= 18-03-2017 16:58:33 przywracanie ==================== Faulty Device Manager Devices ============= Name: Urządzenie wejściowe PCI Description: Urządzenie wejściowe PCI Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/18/2017 05:13:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5691JFE) Description: Aktywacja aplikacji Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (03/18/2017 05:12:21 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5691JFE) Description: Aktywacja aplikacji Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (03/18/2017 05:12:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: ShellExperienceHost.exe, wersja: 10.0.14393.447, sygnatura czasowa: 0x5819bf85 Nazwa modułu powodującego błąd: ShellExperienceHost.exe, wersja: 10.0.14393.447, sygnatura czasowa: 0x5819bf85 Kod wyjątku: 0xc000027b Przesunięcie błędu: 0x0000000000022e27 Identyfikator procesu powodującego błąd: 0x1184 Godzina uruchomienia aplikacji powodującej błąd: 0x01d2a0026bc113bd Ścieżka aplikacji powodującej błąd: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Ścieżka modułu powodującego błąd: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Identyfikator raportu: c6778d81-1110-4ebe-849b-f0e0485922a1 Pełna nazwa pakietu powodującego błąd: Microsoft.Windows.ShellExperienceHost_10.0.14393.953_neutral_neutral_cw5n1h2txyewy Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (03/18/2017 05:11:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program FRST64.exe w wersji 15.3.2017.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w oknie Zabezpieczenia i konserwacja w Panelu sterowania. Identyfikator procesu: 6ac Godzina rozpoczęcia: 01d2a0025717d6f3 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Users\damia\Desktop\FRST64.exe Identyfikator raportu: 9b12d7ac-0bf5-11e7-9cae-bc5ff454ed9b Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (03/18/2017 05:11:52 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5691JFE) Description: Aktywacja aplikacji Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (03/18/2017 05:11:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: ShellExperienceHost.exe, wersja: 10.0.14393.447, sygnatura czasowa: 0x5819bf85 Nazwa modułu powodującego błąd: ShellExperienceHost.exe, wersja: 10.0.14393.447, sygnatura czasowa: 0x5819bf85 Kod wyjątku: 0xc000027b Przesunięcie błędu: 0x0000000000022e27 Identyfikator procesu powodującego błąd: 0x1338 Godzina uruchomienia aplikacji powodującej błąd: 0x01d2a0025a81464d Ścieżka aplikacji powodującej błąd: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Ścieżka modułu powodującego błąd: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Identyfikator raportu: 192375e2-d5f4-4ffb-831b-5a6fb1b988e2 Pełna nazwa pakietu powodującego błąd: Microsoft.Windows.ShellExperienceHost_10.0.14393.953_neutral_neutral_cw5n1h2txyewy Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (03/18/2017 05:11:23 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program FRST64.exe w wersji 15.3.2017.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w oknie Zabezpieczenia i konserwacja w Panelu sterowania. Identyfikator procesu: 270 Godzina rozpoczęcia: 01d2a0022ab90947 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Users\damia\Desktop\FRST64.exe Identyfikator raportu: 8678d21e-0bf5-11e7-9cae-bc5ff454ed9b Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (03/18/2017 05:11:17 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5691JFE) Description: Aktywacja aplikacji Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (03/18/2017 05:11:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: ShellExperienceHost.exe, wersja: 10.0.14393.447, sygnatura czasowa: 0x5819bf85 Nazwa modułu powodującego błąd: ShellExperienceHost.exe, wersja: 10.0.14393.447, sygnatura czasowa: 0x5819bf85 Kod wyjątku: 0xc000027b Przesunięcie błędu: 0x0000000000022e27 Identyfikator procesu powodującego błąd: 0x340 Godzina uruchomienia aplikacji powodującej błąd: 0x01d2a00245a98e06 Ścieżka aplikacji powodującej błąd: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Ścieżka modułu powodującego błąd: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Identyfikator raportu: 3aa8fac5-d1dd-4be7-9cde-45c8560df8d3 Pełna nazwa pakietu powodującego błąd: Microsoft.Windows.ShellExperienceHost_10.0.14393.953_neutral_neutral_cw5n1h2txyewy Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (03/18/2017 05:10:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-5691JFE) Description: Aktywacja aplikacji Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App nie powiodła się. Błąd: -2144927141. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. System errors: ============= Error: (03/18/2017 05:13:00 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:12:21 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer App nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:11:52 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer App nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:11:17 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer App nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:10:00 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:09:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:09:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:09:14 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer App nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:09:00 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (03/18/2017 05:08:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5691JFE) Description: Serwer Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider nie zarejestrował się w modelu DCOM w wymaganym czasie. CodeIntegrity: =================================== Date: 2017-03-16 18:59:53.550 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-03-14 20:58:02.081 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-03-12 03:33:59.206 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-02-25 02:48:55.135 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-02-18 16:29:47.477 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-29 02:08:56.550 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-29 02:08:56.549 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-29 02:08:56.544 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-29 02:08:41.006 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-29 02:08:41.005 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume9\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: AMD Phenom(tm) II X4 965 Processor Percentage of memory in use: 14% Total physical RAM: 10213.79 MB Available physical RAM: 8721.72 MB Total Virtual: 11813.79 MB Available Virtual: 10391.04 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.24 GB) (Free:4.28 GB) NTFS Drive d: () (Fixed) (Total:766.51 GB) (Free:2.07 GB) NTFS Drive f: () (Fixed) (Total:149.9 GB) (Free:0.91 GB) NTFS Drive g: (Zastrzeżone przez system) (Fixed) (Total:0.1 GB) (Free:0.05 GB) NTFS ==>[system with boot components (obtained from drive)] Drive k: (MYLINUXLIVE) (Removable) (Total:3.73 GB) (Free:2.52 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A29DF9C6) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=149.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=766.5 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=15 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 111.8 GB) (Disk ID: 19179A0A) Partition: GPT. ======================================================== Disk: 2 (Size: 3.7 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================