Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x86) Wersja:04-09-2015 Uruchomiony przez Adam (2015-09-05 19:23:03) Uruchomiony z C:\Users\Adam\Desktop Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Adam (S-1-5-21-341399229-4133988599-682913353-1000 - Administrator - Enabled) => C:\Users\Adam Administrator (S-1-5-21-341399229-4133988599-682913353-500 - Administrator - Disabled) Gość (S-1-5-21-341399229-4133988599-682913353-501 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) 2007 Microsoft Office system (HKLM\...\PROHYBRIDR) (Version: 12.0.6612.1000 - Microsoft Corporation) Adobe AIR (HKLM\...\Adobe AIR) (Version: 18.0.0.199 - Adobe Systems Incorporated) Adobe Creative Suite 5 Web Premium (HKLM\...\{11FCA050-2066-4351-A336-748D838C049C}) (Version: 5.0 - Adobe Systems Incorporated) Adobe Flash Player 18 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated) Adobe Reader X (10.1.15) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.15 - Adobe Systems Incorporated) Aktualizacja produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0415-0000-0000000FF1CE}_PROHYBRIDR_{04E205D6-88B1-4652-B162-42DF2C3B1228}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0415-0000-0000000FF1CE}_PROHYBRIDR_{442ECBCF-94A7-48CC-8CD9-D31FFFD5FA86}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0415-0000-0000000FF1CE}_PROHYBRIDR_{128A36ED-21BE-4547-9FFE-5B85AEC735DD}) (Version: - Microsoft) Apple Application Support (HKLM\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.) Ashampoo Burning Studio FREE v.1.14.5 (HKLM\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Avast Internet Security (HKLM\...\avast) (Version: 10.3.2225 - AVAST Software) BearPaw 2400CU Plus v1.0 (HKLM\...\BearPaw 2400CU Plus v1.0) (Version: - ) Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v8.00.02(T) - TOSHIBA CORPORATION) e-Deklaracje Desktop (HKLM\...\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1) (Version: 7.0.3 - Ministerstwo Finansow) e-Deklaracje Desktop (Version: 7.0.3 - Ministerstwo Finansow) Hidden Free HD Converter V 2.0 (HKLM\...\Free HD Converter_is1) (Version: 2.0.0.0 - Koyote Soft) Google Chrome (HKLM\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (Version: 1.3.28.13 - Google Inc.) Hidden Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - ) Java 8 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 40.0.3 (x86 pl) (HKLM\...\Mozilla Firefox 40.0.3 (x86 pl)) (Version: 40.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla) NEF Codec (HKLM\...\{A89768CF-CD21-44FD-A723-16D5A8557415}) (Version: 1.00.0000 - Nikon) novaPDF Standard Desktop 7.3 printer (HKLM\...\novaPDF Standard Desktop 7 printer_is1) (Version: - Softland) Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - plk) (Version: - Microsoft Corporation) PDF Settings CS5 (Version: 10.0 - Adobe Systems Incorporated) Hidden QuickTime 7 (HKLM\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.) SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - ) Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 7.56a - Ghisler Software GmbH) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinKey (HKLM\...\WinKey) (Version: - ) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-341399229-4133988599-682913353-1000_Classes\CLSID\{45C6AFA5-2C13-402f-BC5D-45CC8172EF6B}\InprocServer32 -> C:\Program Files\Toshiba\Bluetooth Toshiba Stack\sys\TosBtExt.dll (TOSHIBA) CustomCLSID: HKU\S-1-5-21-341399229-4133988599-682913353-1000_Classes\CLSID\{A51F3260-698A-22A9-0BBF-F3D72FCBC7E9}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation) ==================== Punkty Przywracania systemu ========================= 04-09-2015 18:06:07 ComboFix created restore point ==================== Hosts - zawartość: ========================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2006-11-02 12:23 - 2015-09-04 18:24 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {0B59988E-9B06-44C0-899C-87A1E2AEDFCD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {A6F7EBC6-7602-4423-9950-5E196BD65DA2} - System32\Tasks\AdobeAAMUpdater-1.0-twist-Adam => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {AB5C9990-0920-49B1-82AE-B3096FC3D572} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {C72DADFE-20BD-428D-B6ED-F4C988C65511} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-05] (AVAST Software) Task: {C8C30770-EC3F-4EDF-9AFF-12BBB9ECEF7D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {CA94AC47-755E-44F5-B881-17E6B54B9DF1} - System32\Tasks\{71F3D828-F4A4-4CE3-9A41-1F408EF9ED84} => pcalua.exe -a D:\instalki\winkey\winkey.exe -d D:\instalki\winkey Task: {CAD1BB76-3216-4EB7-B6CF-251646BE2FD6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Załadowane moduły (filtrowane) ============== 2015-08-05 08:53 - 2015-08-05 08:53 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-08-05 08:53 - 2015-08-05 08:53 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-09-05 18:37 - 2015-09-05 18:37 - 02964480 _____ () C:\Program Files\AVAST Software\Avast\defs\15090502\algo.dll 2015-03-27 19:54 - 2015-03-27 19:54 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2011-05-06 18:18 - 1999-07-04 00:00 - 00099840 ____C () C:\Programy\win_key2011\WinKey.exe 2009-02-26 14:46 - 2009-02-26 14:46 - 00064344 _____ () C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll 2011-06-22 12:46 - 2011-06-22 12:46 - 00434016 _____ () C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll 2011-05-26 21:18 - 2011-05-26 21:18 - 00136536 _____ () C:\Program Files\Microsoft Office\Office12\OUTLCTL.DLL 2015-07-14 18:20 - 2015-07-14 18:20 - 00756376 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\ProgramData\TEMP:7578EF04 ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-341399229-4133988599-682913353-1000\Control Panel\Desktop\\Wallpaper -> E:\2 FOTOGRAFIE RODZINNE\PULPIT\lipiec2015.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1) Zapora systemu Windows - funkcja włączona. ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk => C:\Windows\pss\Bluetooth Manager.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^mcserver.lnk => C:\Windows\pss\mcserver.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ITSecMng => %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START MSCONFIG\startupreg: QuickTime Plugin Install => C:\Program Files\QuickTime\Plugins\DeleteMe1.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SwitchBoard => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [SLSVC-In-TCP] => (Allow) %SystemRoot%\system32\slsvc.exe FirewallRules: [SLSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\slsvc.exe FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe FirewallRules: [{FD24F4AE-667C-40CA-92B2-933F516EFB5C}] => (Allow) C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{C16E43B0-4F43-4006-90D6-BAF3ED47FC08}] => (Allow) C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe FirewallRules: [{DC4EA1D5-47DB-4F3E-B831-88224E582638}] => (Allow) C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe FirewallRules: [{14AA6159-CC0F-4643-B505-A38F5B0BA03A}] => (Allow) C:\Users\Adam\AppData\Roaming\Tencent\QQPCMgr\Download\QQPCDownload.exe FirewallRules: [{06E82A55-40AE-4167-8434-8B430EADA43C}] => (Allow) C:\Users\Adam\AppData\Roaming\Tencent\QQPCMgr\Download\QQPCDownload.exe FirewallRules: [{CBAF686A-6330-40F8-9B9F-69BBDC8A4B91}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{A41F6A15-0734-488B-8CD6-14D970DD3B92}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{752854CB-A89C-42A6-9EE2-671AB6F92F05}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{B7CAAA30-9BEB-4F7C-8E47-2C384C2DA63B}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{3C260BEA-E25F-4927-B53D-708F0C7F4C5B}] => (Allow) LPort=53168 FirewallRules: [{20EF8ABA-CCA4-4B89-AE62-A5B7A7030BF7}] => (Allow) LPort=2869 FirewallRules: [{262F3F39-A9DF-4FDB-A331-EF274E5A8BCB}] => (Allow) LPort=1900 FirewallRules: [{78689440-962B-4726-908B-380451A5D37F}] => (Allow) LPort=53168 FirewallRules: [{334C0B18-A735-4879-BEE7-5E2811717DBA}] => (Allow) LPort=2869 FirewallRules: [{7F0B1FA1-1D86-49AD-A838-D1176B76D89A}] => (Allow) LPort=1900 FirewallRules: [{ACF2E818-96C1-478B-9011-B34C1561B695}] => (Allow) LPort=53168 FirewallRules: [{90FACCE0-C807-42AB-B1DF-BC2582FEA9A2}] => (Allow) LPort=2869 FirewallRules: [{D546065E-EB69-4226-A429-C4797AB8C179}] => (Allow) LPort=1900 FirewallRules: [{1C2D7D39-288C-4818-A2FB-E9329A072376}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{170938EB-A5B9-4FC8-9635-BB6F5A5BD047}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{A2750F3D-5F21-46B8-B996-2ED74ACEBB7B}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{6D12EAF2-CDCD-479E-AAED-14C0E553D68A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{80A521E9-0030-4520-91E7-60012D9D68DE}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= Name: Fingerprint Sensor Description: Fingerprint Sensor Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM CisFileRatingChangeCisFileRatingChange//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM CisStatusChangeCisStatusChange//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM CisNotificationCisNotification//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM FwAlertFwAlert//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM DfAlertDfAlert//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM AvAlertAvAlert//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM CisAlertCisAlert//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: CisWmiSELECT * FROM CisEventCisEvent//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: SELECT * FROM CisFileRatingChangeCisFileRatingChange//./root/cis Error: (09/02/2015 08:09:28 PM) (Source: WinMgmt) (EventID: 24) (User: ) Description: SELECT * FROM CisStatusChangeCisStatusChange//./root/cis Dziennik System: ============= Error: (09/05/2015 06:57:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: PEVSystemStart Error: (09/05/2015 06:50:24 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: PEVSystemStart Error: (09/05/2015 06:42:00 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: PEVSystemStart Error: (09/05/2015 06:26:14 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 18:24:35 na 2015-09-05 było nieoczekiwane. Error: (09/05/2015 05:49:43 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 17:47:15 na 2015-09-05 było nieoczekiwane. Error: (09/05/2015 11:18:40 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 11:08:22 na 2015-09-05 było nieoczekiwane. Error: (09/05/2015 10:16:29 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 10:14:21 na 2015-09-05 było nieoczekiwane. Error: (09/05/2015 09:56:29 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 09:54:34 na 2015-09-05 było nieoczekiwane. Error: (09/04/2015 08:42:03 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 20:40:04 na 2015-09-04 było nieoczekiwane. Error: (09/04/2015 06:24:06 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: PEVSystemStart Microsoft Office: ========================= Error: (08/24/2015 04:30:42 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6727.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 708 seconds with 120 seconds of active time. This session ended with a crash. Error: (08/05/2015 07:22:06 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6723.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 274 seconds with 240 seconds of active time. This session ended with a crash. Error: (08/04/2015 09:54:29 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6723.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1412 seconds with 480 seconds of active time. This session ended with a crash. Error: (08/01/2015 03:55:24 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6723.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 42 seconds with 0 seconds of active time. This session ended with a crash. Error: (08/01/2015 03:54:37 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6723.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 439 seconds with 60 seconds of active time. This session ended with a crash. Error: (07/15/2015 07:51:32 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6723.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 361 seconds with 240 seconds of active time. This session ended with a crash. Error: (07/11/2015 11:51:32 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6720.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/22/2015 06:44:28 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 967 seconds with 480 seconds of active time. This session ended with a crash. Error: (06/21/2015 09:03:54 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6720.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/13/2015 11:15:29 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6720.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 121 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity: =================================== Date: 2015-09-03 19:17:47.736 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:47.636 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:47.496 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:47.392 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:47.291 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:47.190 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:46.390 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:46.267 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:46.152 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system. Date: 2015-09-03 19:17:46.040 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz Procent pamięci w użyciu: 60% Całkowita pamięć fizyczna: 2037.25 MB Dostępna pamięć fizyczna: 806.14 MB Całkowita pamięć wirtualna: 4282.78 MB Dostępna pamięć wirtualna: 2906.8 MB ==================== Dyski ================================ Drive c: (SYSTEM) (Fixed) (Total:97.66 GB) (Free:59.2 GB) NTFS ==>[dysk z komponentami startowymi (pozyskano BCD)] Drive d: (TWIST) (Fixed) (Total:185.55 GB) (Free:50.56 GB) NTFS Drive e: (ADAM) (Fixed) (Total:182.55 GB) (Free:28.57 GB) NTFS Drive g: (ADAS) (Removable) (Total:3.73 GB) (Free:3.72 GB) FAT32 ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 9CFC855C) Partition 1: (Active) - (Size=97.7 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=368.1 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 3.7 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=3.7 GB) - (Type=0B) ==================== Koniec Addition.txt ============================