Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:09-12-2015 Uruchomiony przez Karol (2015-12-10 13:24:59) Uruchomiony z C:\Users\Karol\Downloads Windows 8 (X64) (2013-07-16 12:31:17) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-1826867425-3326814921-3507148508-500 - Administrator - Disabled) Gość (S-1-5-21-1826867425-3326814921-3507148508-501 - Limited - Disabled) Karol (S-1-5-21-1826867425-3326814921-3507148508-1002 - Administrator - Enabled) => C:\Users\Karol ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) 64 Bit HP CIO Components Installer (Version: 17.2.1 - Hewlett-Packard) Hidden Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.009.20069 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 17.0.0.124 - Adobe Systems Incorporated) Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.) AMD Catalyst Install Manager (HKLM\...\{DA51A69D-5D86-8A3D-1A4E-CB7CA80BA803}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.4.2233 - AVAST Software) Classic Shell (HKLM\...\{2368907C-E8F6-4750-A023-254C3E2B5E8D}) (Version: 4.0.4 - IvoSoft) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.44.50 - Conexant) Cyberduck 18004 (4.7.2) (HKLM-x32\...\Cyberduck) (Version: 18004 (4.7.2) - ) DesignPro 5 (HKLM-x32\...\InstallShield_{DF57E946-4885-4EEA-A958-D5F82CB21B99}) (Version: 5.0.1056 - Avery Dennison) DesignPro 5 (x32 Version: 5.0.1056 - Avery Dennison) Hidden Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.16 - Dolby Laboratories Inc) Dropbox (HKU\S-1-5-21-1826867425-3326814921-3507148508-1002\...\Dropbox) (Version: 3.10.11 - Dropbox, Inc.) Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.3 - Lenovo) Energy Management (x32 Version: 8.0.2.3 - Lenovo) Hidden Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.80 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33057) (Version: 3.6.1.33057.10 - Intel) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.8400.10189 - Realtek Semiconductor Corp.) Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.1519 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.0.0.1519 - CyberLink Corp.) Hidden Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4310.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.4310.52 - CyberLink Corp.) Hidden Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3127 - CyberLink Corp.) Lenovo YouCam (x32 Version: 4.1.3127 - CyberLink Corp.) Hidden Media Go (HKLM-x32\...\{7547239C-FA8A-4FA4-84A6-31EAC0777E1B}) (Version: 2.7.341 - Sony) Media Go Network Downloader (HKLM-x32\...\{73FA7631-3015-4EEC-A002-09488C47A07C}) (Version: 1.5.19.0 - Sony) Media Go Video Playback Engine 2.4.130.12060 (HKLM-x32\...\{7C5AEEE1-6D7C-8922-4548-7BF9096077EC}) (Version: 2.4.130.12060 - Sony) Metric Collection SDK (x32 Version: 1.1.0012.00 - Lenovo Group Limited) Hidden Microsoft Office 2013 dla Użytkowników Domowych i Małych Firm - pl-pl (HKLM\...\HomeBusinessRetail - pl-pl) (Version: 15.0.4771.1004 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1826867425-3326814921-3507148508-1002\...\OneDriveSetup.exe) (Version: 17.0.4023.1211 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 pl)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4771.1004 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden Pakiet sterowników systemu Windows - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (HKLM\...\71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42) (Version: 06/15/2012 8.1.0.1 - Lenovo) Pakiet sterowników systemu Windows - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (HKLM\...\8A223E56FB1ED4F697B54E5BF96F1EB63B512684) (Version: 06/19/2012 10.13.29.733 - Lenovo) PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH) PDF Architect 2 View Module (HKLM-x32\...\{D691E998-CF53-4F6C-AC20-E4284660E0E7}) (Version: 2.1.6.19758 - pdfforge GmbH) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.0 - pdfforge) Podręcznik użytkownika (x32 Version: 1.0.0.9 - Lenovo) Hidden PolkaSQL (HKLM-x32\...\PolkaSQL) (Version: - ) Polski pakiet językowy dla narzędzi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PLK) (Version: 10.0.50903 - Microsoft Corporation) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.9109 - CyberLink Corp.) PowerXpressHybrid (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.210 - Qualcomm Atheros Communications) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation) Skype™ 7.12 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.12.101 - Skype Technologies S.A.) Sony PC Companion 2.10.259 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.259 - Sony) SQL Anywhere 12 (HKLM\...\{1DFA77E6-91B2-4DCC-B8BE-98EA70705D39}) (Version: 12.1.4183 - iAnywhere Solutions, Inc.) SQL Anywhere 9 for Windows x64 (HKLM-x32\...\{88A74695-D9B6-4F26-9252-40DCD3A6659E}) (Version: 9.0.2.3924 - iAnywhere Solutions, Inc.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.13 - Synaptics Incorporated) Undelete 360 (HKLM-x32\...\Undelete 360_is1) (Version: - File Recovery Ltd.) UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.9 - Lenovo) VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) WinZip 19.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240ED}) (Version: 19.5.11532 - WinZip Computing, S.L. ) XnView 2.22 (HKLM-x32\...\XnView_is1) (Version: 2.22 - Gougelet Pierre-e) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.dll () CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1826867425-3326814921-3507148508-1002_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Karol\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) ==================== Punkty Przywracania systemu ========================= 13-11-2015 11:00:58 Windows Update 23-11-2015 15:15:21 Zaplanowany punkt kontrolny 04-12-2015 10:34:47 Zaplanowany punkt kontrolny 09-12-2015 11:07:29 Windows Update ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {1A93C6ED-9205-4742-A5E1-7322296C9E41} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {1FBFCD51-3D7F-4F9A-AEA5-481CA077525D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-09] (Microsoft Corporation) Task: {2FCE1BCA-6C56-441F-B2DF-6E3C8F42A107} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1826867425-3326814921-3507148508-1002Core => C:\Users\Karol\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.) Task: {510EF459-2B94-465F-A6E8-AE3D14C79C0C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {5E18D0E6-BAAB-4CD3-9C3D-F595490ADC34} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-09] (Adobe Systems Incorporated) Task: {7E1C199C-3879-485F-BAB5-B9C2D12A9A37} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe Task: {850255A3-38B4-4F31-BBA1-01514FBA3A7C} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-09-26] (AVAST Software) Task: {9E64DF26-F0FF-47EC-84BE-9151E8C3B8E7} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink) Task: {AC22D2B1-6039-47CE-BBA4-DC8C56703B2A} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation) Task: {B75FF0E3-0C23-46B0-9A78-1AB44D71A56C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated) Task: {C3F6065C-583A-452D-B365-A805A16C5370} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1826867425-3326814921-3507148508-1002UA => C:\Users\Karol\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.) Task: {C60B3025-791F-487B-A3DC-A25620290A1D} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-12-04] (AVAST Software) Task: {D20A95AB-38F1-492E-9B9D-DFDB34A32B44} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation) Task: {D9431957-A715-48AE-A284-C9DDEC923CE7} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-08] (Lenovo) Task: {E26A3E36-02D9-4415-A486-56FD81424267} - System32\Tasks\Synaptics TouchPad Enhancements => Program Files\Synaptics\SynTP\SynTPEnh.exe Task: {FADA148A-27A5-424B-8E83-94CCDA37D6C3} - System32\Tasks\{FF1E3851-D923-4C58-915B-5BBB69DC30DE} => pcalua.exe -a "C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" -d C:\WINDOWS\system32 -c /user (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1826867425-3326814921-3507148508-1002Core.job => C:\Users\Karol\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1826867425-3326814921-3507148508-1002UA.job => C:\Users\Karol\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\Karol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647985&z=8dd84dff958f350747fe074g2z8z7t7q9zcmct2beo&from=ient07021&uid=ST500LT012-9WS142_S0V37ELEXXXXS0V37ELE <==== UWAGA ShortcutWithArgument: C:\Users\Karol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647985&z=8dd84dff958f350747fe074g2z8z7t7q9zcmct2beo&from=ient07021&uid=ST500LT012-9WS142_S0V37ELEXXXXS0V37ELE <==== UWAGA ShortcutWithArgument: C:\Users\Karol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647985&z=8dd84dff958f350747fe074g2z8z7t7q9zcmct2beo&from=ient07021&uid=ST500LT012-9WS142_S0V37ELEXXXXS0V37ELE <==== UWAGA ShortcutWithArgument: C:\Users\Karol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647985&z=8dd84dff958f350747fe074g2z8z7t7q9zcmct2beo&from=ient07021&uid=ST500LT012-9WS142_S0V37ELEXXXXS0V37ELE <==== UWAGA ShortcutWithArgument: C:\Users\Karol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647985&z=8dd84dff958f350747fe074g2z8z7t7q9zcmct2beo&from=ient07021&uid=ST500LT012-9WS142_S0V37ELEXXXXS0V37ELE <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647985&z=8dd84dff958f350747fe074g2z8z7t7q9zcmct2beo&from=ient07021&uid=ST500LT012-9WS142_S0V37ELEXXXXS0V37ELE <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647985&z=8dd84dff958f350747fe074g2z8z7t7q9zcmct2beo&from=ient07021&uid=ST500LT012-9WS142_S0V37ELEXXXXS0V37ELE <==== UWAGA ==================== Załadowane moduły (filtrowane) ============== 2014-06-23 08:03 - 2012-09-18 14:27 - 00192512 _____ () C:\WINDOWS\System32\zlhp1020.dll 2014-07-21 08:11 - 2012-09-29 12:25 - 00409088 _____ () C:\WINDOWS\System32\HPM1210LM.DLL 2014-06-23 08:03 - 2012-09-18 14:27 - 00065024 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\pphp1020.dll 2014-07-21 08:11 - 2012-09-29 12:25 - 00074240 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\HPM1210PP.dll 2012-08-06 12:09 - 2012-08-06 12:09 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2014-03-24 12:11 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-07-25 08:59 - 2013-07-25 09:08 - 00176048 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll 2014-06-20 12:17 - 2009-12-18 10:42 - 00136496 _____ () C:\Program Files\Sybase\Shared\Sybase Central 4.3\win32\scjview.exe 2014-06-23 08:03 - 2012-09-18 14:27 - 03162624 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\suhp1020.dll 2014-06-23 08:03 - 2012-09-18 14:27 - 01236992 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\gchp1020.dll 2014-06-23 08:03 - 2012-09-18 14:27 - 00676864 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\sdhp1020.dll 2015-09-26 17:25 - 2015-09-26 17:25 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-09-26 17:25 - 2015-09-26 17:25 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-12-10 08:42 - 2015-12-10 08:42 - 02803200 _____ () C:\Program Files\AVAST Software\Avast\defs\15120901\algo.dll 2014-11-22 13:01 - 2014-11-22 13:01 - 00316576 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll 2014-06-20 12:17 - 2009-12-18 10:44 - 00062768 _____ () C:\Program Files\Sybase\Shared\Sybase Central 4.3\win32\scjlgEN.dll 2014-06-20 12:17 - 2008-05-27 21:55 - 00028791 _____ () C:\Program Files\Sybase\Shared\sun\jre142\bin\hpi.dll 2014-06-20 12:17 - 2008-05-27 21:55 - 00057453 _____ () C:\Program Files\Sybase\Shared\sun\jre142\bin\verify.dll 2014-06-20 12:17 - 2008-05-27 22:00 - 00102515 _____ () C:\Program Files\Sybase\Shared\sun\jre142\bin\java.dll 2014-06-20 12:17 - 2008-05-27 22:01 - 00057460 _____ () C:\Program Files\Sybase\Shared\sun\jre142\bin\zip.dll 2014-06-20 12:17 - 2009-12-18 10:44 - 00083248 _____ () C:\Program Files\Sybase\Shared\win32\jsyblib142.dll 2014-06-20 12:17 - 2008-05-27 22:09 - 00057455 _____ () C:\Program Files\Sybase\Shared\Sun\jre142\bin\net.dll 2014-06-20 12:17 - 2008-05-27 22:27 - 00995438 _____ () C:\Program Files\Sybase\Shared\Sun\jre142\bin\awt.dll 2014-06-20 12:17 - 2008-05-27 22:34 - 00331907 _____ () C:\Program Files\Sybase\Shared\Sun\jre142\bin\fontmanager.dll 2014-06-20 12:17 - 2008-05-27 22:32 - 00139375 _____ () C:\Program Files\Sybase\Shared\Sun\jre142\bin\dcpr.dll 2015-12-10 09:30 - 2015-12-10 09:30 - 00071168 _____ () c:\users\karol\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpyhttiw.dll 2015-08-13 07:54 - 2015-09-03 01:11 - 00012800 _____ () C:\Users\Karol\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll 2015-03-04 22:45 - 2015-09-03 01:11 - 00779776 _____ () C:\Users\Karol\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-08-13 07:54 - 2015-09-03 01:11 - 00056320 _____ () C:\Users\Karol\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll 2015-08-13 07:54 - 2015-09-03 01:11 - 00012288 _____ () C:\Users\Karol\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00891392 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtNetwork4.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 02281984 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtCore4.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00016896 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\featureController.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\osEvents.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00322048 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\log4cplus.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00339456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtXml4.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00400384 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\sqlite3.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00195584 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\libgsoap.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00062464 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\zlib1.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00446976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\deviceProfile.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00019456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\eventsSender.dll 2013-03-18 11:56 - 2012-07-12 13:59 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\serviceManagerStarter.dll 2015-09-26 17:25 - 2015-09-26 17:25 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-12-09 13:54 - 2015-12-04 22:32 - 01583432 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.80\libglesv2.dll 2015-12-09 13:54 - 2015-12-04 22:32 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.80\libegl.dll 2015-12-09 13:54 - 2015-12-04 22:32 - 16573256 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.80\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\ProgramData\Temp:0E08FC17 ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-1826867425-3326814921-3507148508-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Karol\Pictures\2015-10-07.jpg DNS Servers: 10.0.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) HKLM\...\StartupApproved\Run: => "BtPreLoad" HKLM\...\StartupApproved\Run32: => "SmartAudio" HKLM\...\StartupApproved\Run32: => "UpdateP2GShortCut" HKLM\...\StartupApproved\Run32: => "YouCam Mirage" HKLM\...\StartupApproved\Run32: => "YouCam Tray" HKU\S-1-5-21-1826867425-3326814921-3507148508-1002\...\StartupApproved\Run: => "Sony PC Companion" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{0CA542C2-DE95-421F-849A-2C13A4E19238}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{56743B06-D4F8-4804-92A7-B7B9E1D52A5C}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [TCP Query User{E3373E51-0B1E-49FA-B448-5B1E74FC2A2F}C:\program files (x86)\intel\intelappstore\bin\ismagent.exe] => (Allow) C:\program files (x86)\intel\intelappstore\bin\ismagent.exe FirewallRules: [UDP Query User{DB42C09B-A562-420A-A937-97A4720FFF25}C:\program files (x86)\intel\intelappstore\bin\ismagent.exe] => (Allow) C:\program files (x86)\intel\intelappstore\bin\ismagent.exe FirewallRules: [TCP Query User{B22EE92F-5D12-4893-A1AB-223AFE3EB9F9}C:\program files (x86)\intel\intelappstore\bin\ismagent.exe] => (Block) C:\program files (x86)\intel\intelappstore\bin\ismagent.exe FirewallRules: [UDP Query User{6F429330-8DA5-4467-A2C6-732B44A09509}C:\program files (x86)\intel\intelappstore\bin\ismagent.exe] => (Block) C:\program files (x86)\intel\intelappstore\bin\ismagent.exe FirewallRules: [{2CD47CCC-BE87-45E3-86E3-5E7BD0585724}] => (Allow) C:\Users\Karol\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{EE050A1C-8C32-4C78-9C85-D5B1FF21A0D6}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [TCP Query User{3D15D240-D38C-4E32-ACDA-B29D58048C5E}C:\program files\sybase\shared\sybase central 4.3\win32\scjview.exe] => (Allow) C:\program files\sybase\shared\sybase central 4.3\win32\scjview.exe FirewallRules: [UDP Query User{BFD3773A-C0B7-4E16-970F-849A7A7FCD0D}C:\program files\sybase\shared\sybase central 4.3\win32\scjview.exe] => (Allow) C:\program files\sybase\shared\sybase central 4.3\win32\scjview.exe FirewallRules: [{DC6A5BBA-388B-4CB2-A27F-EEF2C8669137}] => (Allow) C:\Users\Karol\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{11BC5A3E-8798-4CC2-A3F6-2B78F5CEACBA}] => (Allow) C:\Users\Karol\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{7D1EA70D-3034-4BFF-B265-B5DE9816D7E0}C:\users\karol\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\karol\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{1A0C0D3A-881F-4041-87E0-CB8B70BA384D}C:\users\karol\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\karol\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{352D1665-BCEB-4C0D-B873-45A75B97433D}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{A5B77F39-A1A4-4BB2-8E68-B556302247B3}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{E872EC37-7B49-475B-A536-5F62F502B5A1}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{FA8616E7-76A7-4A48-A3CD-9CA798984C05}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{85FADE2A-0B1F-4158-B174-99F8FDBE9A6E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{14A0D428-65A6-4ADC-B653-EA55E9FEAF52}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{82598A4E-3D96-4459-99D7-C599FABF1719}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (12/10/2015 12:13:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 12:11:30 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 12:01:35 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 11:59:59 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 11:50:25 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 11:48:51 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 11:34:07 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 11:33:59 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 11:33:50 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (12/10/2015 11:32:30 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: ZARZĄDZANIE NT) Description: The performance counter explain text string value in the registry is not formatted correctly. The malformed string is Liczba dostawców WMI High Performance zwrócona przez kartę WMI. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Dziennik System: ============= Error: (12/10/2015 12:13:03 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 12:11:33 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 12:01:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 12:00:02 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 11:50:28 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 11:48:54 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 11:34:10 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 11:34:02 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 11:33:53 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 Error: (12/10/2015 11:32:33 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący błąd: %%2147500037 CodeIntegrity: =================================== Date: 2014-03-28 13:52:41.022 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:38.198 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:20.118 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:15.313 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:12.115 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:09.400 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:07.014 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:03.207 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:52:00.555 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. Date: 2014-03-28 13:51:57.638 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2hooks32.dll with signing level Unsigned while the system requires signing level 6 or better to load. ==================== Statystyki pamięci =========================== Procesor: AMD E1-1200 APU with Radeon(tm) HD Graphics Procent pamięci w użyciu: 66% Całkowita pamięć fizyczna: 3654.25 MB Dostępna pamięć fizyczna: 1231.18 MB Całkowita pamięć wirtualna: 5638.25 MB Dostępna pamięć wirtualna: 2867.54 MB ==================== Dyski ================================ Drive c: (Windows8_OS) (Fixed) (Total:417.99 GB) (Free:314.4 GB) NTFS ==>[system z komponentami startowymi (pozyskano odczytując dysk)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.8 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 64D0C6CE) Partition: GPT. ==================== Koniec Addition.txt ============================