Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by Czarny at 2015-03-18 19:30:33 Running from C:\Users\Czarny\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Disabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Disabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1849503456-2863148246-254835565-1001\...\uTorrent) (Version: 3.4.2.36615 - BitTorrent Inc.) 50Coupoonss (HKLM-x32\...\{CF987D06-1DCF-7B36-5B43-13BC8699C44C}) (Version: - "") <==== ATTENTION Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) AllSAvueR (HKLM-x32\...\{F5853CDF-2C63-6D1D-B286-CBB1CD5DFD62}) (Version: - "") <==== ATTENTION AMD Catalyst Install Manager (HKLM\...\{3FAEEEBE-48F4-84C1-2B49-96AE73E67E3E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) avast! Premier (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Blipshot one click screenshots (HKLM-x32\...\{F6C44C71-2CFE-8176-3A4D-CBD0DCE5AEFA}) (Version: - "") <==== ATTENTION CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform) Counter Strike 1.6 (HKU\S-1-5-21-1849503456-2863148246-254835565-1001\...\Counter Strike 1.6) (Version: 02.00.00.00 - Valkiria) Counter-Strike 1.6 [p48] build 4554 (HKLM-x32\...\Counter-Strike 1.6) (Version: [p48] build 4554 - CSSetti.pl) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) DownSeave (HKLM-x32\...\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version: - "") <==== ATTENTION FormatFactory 3.6.0.0 (HKLM-x32\...\FormatFactory) (Version: 3.6.0.0 - Format Factory) Google Chrome Canary (HKU\S-1-5-21-1849503456-2863148246-254835565-1001\...\Google Chrome SxS) (Version: 41.0.2241.0 - Google Inc.) GureeaTSaVe4U (HKLM-x32\...\{45606A90-3363-3A3B-1C15-C40E77F4DAA0}) (Version: - "") <==== ATTENTION Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Huawei E5372 (HKLM-x32\...\Huawei E5372) (Version: 1.12.01.69 - Huawei Technologies Co.,Ltd) HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden JoniaCoupon (HKLM-x32\...\{51417852-174C-88D4-34A0-D0FE7858BE47}) (Version: - "") <==== ATTENTION Justin Bieber (HKLM-x32\...\{F1422DAA-0829-09A1-7536-73936CAB8FFA}) (Version: - "") <==== ATTENTION League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Microsoft .NET Framework 4.5.1 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 36.0.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 36.0.1 (x86 pl)) (Version: 36.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MpcStar 5.4 (HKLM-x32\...\MpcStar) (Version: 5.4 - www.mpcstar.com) Multimedia keyboard driver (HKLM-x32\...\{4F896DE0-EF26-11D5-BBEC-00D0B740900A}) (Version: - ) NetoCOupon (HKLM-x32\...\{317D8BB4-16C3-CFBD-3777-AED69667DA46}) (Version: - "") <==== ATTENTION NoMore Ads (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - NoMore Ads) <==== ATTENTION OpenOffice 4.1.1 (HKLM-x32\...\{B5373BA3-BAD7-4EAC-A9D2-B66B41B82C57}) (Version: 4.11.9775 - Apache Software Foundation) Opera Stable 24.0.1558.64 (HKLM-x32\...\Opera 24.0.1558.64) (Version: 24.0.1558.64 - Opera Software ASA) PLAY ONLINE (HKLM-x32\...\PLAY ONLINE) (Version: 21.005.11.14.264 - Huawei Technologies Co.,Ltd) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6959 - Realtek Semiconductor Corp.) RobboSaver (HKLM-x32\...\{BE360B8B-0F10-CA89-FC84-A5EAB71A6AF8}) (Version: - "") <==== ATTENTION ShoapDrropu (HKLM-x32\...\{B6D700D3-3D0D-FEEB-D675-2CE78F9EC5D6}) (Version: - "") <==== ATTENTION Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.) Sleeping Dogs Gold Repack (HKLM-x32\...\Sleeping Dogs Gold Repack) (Version: - ) SSaveLots (HKLM-x32\...\{35E13884-BAC3-5F4A-799B-05F882E0BD9F}) (Version: - "") <==== ATTENTION Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) Total War: ROME II - Emperor Edition (HKLM-x32\...\Steam App 214950) (Version: - Creative Assembly) Turntable fm Extended (HKLM-x32\...\{7223EDAC-E091-B3C1-BD91-B66CE557800F}) (Version: - "") <==== ATTENTION WinRAR 5.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1849503456-2863148246-254835565-1001_Classes\CLSID\{1BEAC3E3-B852-44F4-B468-8906C062422E}\localserver32 -> C:\Users\Czarny\AppData\Local\Google\Chrome SxS\Application\41.0.2241.0\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-1849503456-2863148246-254835565-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Czarny\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1849503456-2863148246-254835565-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Czarny\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.) ==================== Restore Points ========================= 10-03-2015 19:31:22 Windows Update 11-03-2015 03:00:43 Windows Update 14-03-2015 13:14:16 Windows Defender Checkpoint 14-03-2015 13:31:03 Usunięte Internet Manager 14-03-2015 13:37:43 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 17-03-2015 18:43:57 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {08BB2BEB-4B14-460A-9551-930AA3A4F2D9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-10-04] (AVAST Software) Task: {3752C7EF-3868-45C5-9908-1960B21A09CC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated) Task: {3CE9772D-0A5E-4680-AB98-DD597212F1E9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1849503456-2863148246-254835565-1001Core => C:\Users\Czarny\AppData\Local\Google\Update\GoogleUpdate.exe [2014-08-04] (Google Inc.) Task: {A3C885DC-A091-4328-BEAB-659856B115F3} - System32\Tasks\{3E90300D-1DA5-41CC-96F5-45D9BA40D2E0} => c:\program files (x86)\opera\launcher.exe [2014-09-25] (Opera Software) Task: {A4915791-269F-4F0F-9EAF-E9A3389F93E0} - System32\Tasks\Opera scheduled Autoupdate 1406354775 => C:\Program Files (x86)\Opera\launcher.exe [2014-09-25] (Opera Software) Task: {B5491CBE-FDC6-44C0-AC70-827E02105D50} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd) Task: {BC59204E-7A14-47F8-AB1C-A572D2D6E456} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1849503456-2863148246-254835565-1001UA => C:\Users\Czarny\AppData\Local\Google\Update\GoogleUpdate.exe [2014-08-04] (Google Inc.) Task: {D698A49E-655D-4747-8721-29A6EF4E6D28} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-CZARNY-PC => C:\Windows\ehome\McxTask.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1849503456-2863148246-254835565-1001Core.job => C:\Users\Czarny\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1849503456-2863148246-254835565-1001UA.job => C:\Users\Czarny\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-04-17 21:29 - 2014-04-17 21:29 - 00214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2014-02-11 06:08 - 2014-02-11 06:08 - 00817152 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2014-02-11 06:08 - 2014-02-11 06:08 - 03650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2013-04-10 06:58 - 2013-04-10 06:58 - 00351824 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2014-07-13 20:15 - 2014-10-12 21:55 - 00246112 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe 2014-04-17 21:29 - 2014-04-17 21:29 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2014-09-26 13:03 - 2014-09-25 09:37 - 01372280 _____ () C:\Program Files (x86)\Opera\24.0.1558.64\opera_crashreporter.exe 2014-10-04 19:28 - 2014-10-04 19:28 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 2014-11-03 18:57 - 2014-11-03 18:57 - 02899456 _____ () C:\Program Files\AVAST Software\Avast\defs\14110302\algo.dll 2015-01-10 22:21 - 2015-01-10 22:21 - 02131456 _____ () c:\Program Files (x86)\ProcessProc\ProcessProc.dll 2014-07-13 20:15 - 2014-07-13 20:14 - 00011362 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\mingwm10.dll 2014-07-13 20:15 - 2014-07-13 20:14 - 00043008 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\libgcc_s_dw2-1.dll 2014-07-13 20:15 - 2014-07-13 20:14 - 02415104 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtCore4.dll 2014-07-13 20:15 - 2014-07-13 20:14 - 01148416 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtNetwork4.dll 2014-07-13 20:15 - 2014-07-13 20:14 - 00384512 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QueryStrategy.dll 2014-07-13 20:15 - 2014-07-13 20:14 - 00398336 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtXml4.dll 2014-04-17 21:13 - 2014-04-17 21:13 - 00080896 _____ () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraPlk.dll 2014-09-26 13:03 - 2014-09-25 09:37 - 01378936 _____ () C:\Program Files (x86)\Opera\24.0.1558.64\libglesv2.dll 2014-09-26 13:03 - 2014-09-25 09:37 - 00182392 _____ () C:\Program Files (x86)\Opera\24.0.1558.64\libegl.dll 2014-09-26 13:03 - 2014-09-25 09:37 - 00974968 _____ () C:\Program Files (x86)\Opera\24.0.1558.64\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1849503456-2863148246-254835565-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Czarny\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.8.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Czarny^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^lsass.exe => C:\Windows\pss\lsass.exe.Startup MSCONFIG\startupreg: AvastUI.exe => "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui MSCONFIG\startupreg: CHotkey => mHotkey.exe MSCONFIG\startupreg: Gadu-Gadu 10 => "C:\Program Files (x86)\Gadu-Gadu 10\gg.exe" MSCONFIG\startupreg: Google Update => "C:\Users\Czarny\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: LiveSupport => "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log MSCONFIG\startupreg: Optimizer Pro => C:\Program Files (x86)\Optimizer Pro 3.11\OptProLauncher.exe MSCONFIG\startupreg: Pokki => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform MSCONFIG\startupreg: se => "C:\Users\Czarny\AppData\Roaming\SkypEmoticons\SE.exe" /minimized ==================== Accounts: ============================= Administrator (S-1-5-21-1849503456-2863148246-254835565-500 - Administrator - Disabled) Czarny (S-1-5-21-1849503456-2863148246-254835565-1001 - Administrator - Enabled) => C:\Users\Czarny Guest (S-1-5-21-1849503456-2863148246-254835565-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1849503456-2863148246-254835565-1002 - Limited - Enabled) Mcx1-CZARNY-PC (S-1-5-21-1849503456-2863148246-254835565-1006 - Limited - Enabled) => C:\Users\Mcx1-CZARNY-PC ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/18/2015 07:17:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. Error: (03/18/2015 07:17:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error: (03/18/2015 07:17:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error: (03/18/2015 07:14:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: mspaint.exe, wersja: 6.1.7600.16385, sygnatura czasowa: 0x4a5bca29 Nazwa modułu powodującego błąd: msvcrt.dll, wersja: 7.0.7601.17744, sygnatura czasowa: 0x4eeb033f Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000000011fd Identyfikator procesu powodującego błąd: 0xd18 Godzina uruchomienia aplikacji powodującej błąd: 0xmspaint.exe0 Ścieżka aplikacji powodującej błąd: mspaint.exe1 Ścieżka modułu powodującego błąd: mspaint.exe2 Identyfikator raportu: mspaint.exe3 Error: (03/18/2015 07:14:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/18/2015 06:32:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. Error: (03/18/2015 06:32:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error: (03/18/2015 06:32:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error: (03/18/2015 06:27:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/18/2015 03:08:11 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: League of Legends.exe, wersja: 5.5.0.278, sygnatura czasowa: 0x55035bb6 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x2b1a0c38 Identyfikator procesu powodującego błąd: 0xef8 Godzina uruchomienia aplikacji powodującej błąd: 0xLeague of Legends.exe0 Ścieżka aplikacji powodującej błąd: League of Legends.exe1 Ścieżka modułu powodującego błąd: League of Legends.exe2 Identyfikator raportu: League of Legends.exe3 System errors: ============= Error: (03/18/2015 07:13:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi PLAY ONLINE. OUC z powodu następującego błędu: %%1053 Error: (03/18/2015 07:13:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą PLAY ONLINE. OUC. Error: (03/18/2015 06:26:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi PLAY ONLINE. OUC z powodu następującego błędu: %%1053 Error: (03/18/2015 06:26:17 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą PLAY ONLINE. OUC. Error: (03/18/2015 06:26:11 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x0000000a (0x0000000000f8001e, 0x0000000000000002, 0x0000000000000000, 0xfffff800032ed9b5)C:\Windows\MEMORY.DMP031815-25818-01 Error: (03/18/2015 06:26:02 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 18:24:14 na ‎2015-‎03-‎18 było nieoczekiwane. Error: (03/18/2015 05:40:07 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {45597C98-80F6-4549-84FF-752CF55E2D29} Error: (03/18/2015 01:23:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi PLAY ONLINE. OUC z powodu następującego błędu: %%1053 Error: (03/18/2015 01:23:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą PLAY ONLINE. OUC. Error: (03/17/2015 06:39:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi PLAY ONLINE. OUC z powodu następującego błędu: %%1053 Microsoft Office Sessions: ========================= Error: (03/18/2015 07:17:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (03/18/2015 07:17:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Performance1637070000000000000000000009030000 Error: (03/18/2015 07:17:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Performance1637070000000000000000000009030000 Error: (03/18/2015 07:14:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: mspaint.exe6.1.7600.163854a5bca29msvcrt.dll7.0.7601.177444eeb033fc000000500000000000011fdd1801d061a751e91627C:\Windows\system32\mspaint.exeC:\Windows\system32\msvcrt.dllaf96e170-cd9a-11e4-8b87-448a5b5c7405 Error: (03/18/2015 07:14:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/18/2015 06:32:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: WmiApRplWmiApRpl8F20300004D070000 Error: (03/18/2015 06:32:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Performance1637070000000000000000000009030000 Error: (03/18/2015 06:32:03 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: Performance1637070000000000000000000009030000 Error: (03/18/2015 06:27:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/18/2015 03:08:11 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: League of Legends.exe5.5.0.27855035bb6unknown0.0.0.000000000c00000052b1a0c38ef801d0618220e3704aC:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.81\deploy\League of Legends.exeunknown35bdaf60-cd78-11e4-987f-448a5b5c7405 ==================== Memory info =========================== Processor: AMD FX(tm)-6350 Six-Core Processor Percentage of memory in use: 50% Total physical RAM: 8141.51 MB Available physical RAM: 4018.62 MB Total Pagefile: 16281.21 MB Available Pagefile: 11333.41 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:1862.92 GB) (Free:1584.66 GB) NTFS Drive e: (PĘDRAK) (Removable) (Total:14.9 GB) (Free:8.29 GB) FAT32 Drive f: (Huawei E5372) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 258A9FFD) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 14.9 GB) (Disk ID: 3732674A) Partition 1: (Active) - (Size=14.9 GB) - (Type=0C) ==================== End Of Log ============================