Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:13-04-2016 Uruchomiony przez Piotrek (2016-04-15 15:12:48) Uruchomiony z E:\Chrome-pobrane Windows 7 Professional Service Pack 1 (X64) (2015-02-26 10:14:17) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-2762560903-3368116062-2236283052-500 - Administrator - Disabled) Gość (S-1-5-21-2762560903-3368116062-2236283052-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2762560903-3368116062-2236283052-1002 - Limited - Enabled) Piotrek (S-1-5-21-2762560903-3368116062-2236283052-1000 - Administrator - Enabled) => C:\Users\Piotrek ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: ESET NOD32 Antivirus 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET NOD32 Antivirus 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKU\S-1-5-21-2762560903-3368116062-2236283052-1000\...\uTorrent) (Version: 3.4.6.42094 - BitTorrent Inc.) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology) Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS) CCleaner (HKLM\...\CCleaner) (Version: 5.16 - Piriform) Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version: - Playsaurus) CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.27 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Dropbox (HKU\S-1-5-21-2762560903-3368116062-2236283052-1000\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.) ESET NOD32 Antivirus (HKLM\...\{155EC97B-FE09-4F23-BE22-F79440F1E22E}) (Version: 8.0.319.1 - ESET, spol s r. o.) ETDWare PS/2-X64 8.0.5.3_WHQL (HKLM\...\Elantech) (Version: 8.0.5.3 - ELAN Microelectronic Corp.) f.lux (HKU\S-1-5-21-2762560903-3368116062-2236283052-1000\...\Flux) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.75 - Google Inc.) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Guns of Icarus Online (HKLM\...\Steam App 209080) (Version: - Muse Games) HexChat (HKLM\...\HexChat_is1) (Version: 2.12.0 - HexChat) Intel(R) Driver Update Utility 2.0 (x32 Version: 2.0.0.29 - Intel) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Driver Update Utility (HKLM-x32\...\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel) Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) KeePass Password Safe 1.27 (HKLM-x32\...\KeePass Password Safe_is1) (Version: 1.27 - Dominik Reichl) Kodi (HKU\S-1-5-21-2762560903-3368116062-2236283052-1000\...\Kodi) (Version: - XBMC-Foundation) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Logitech Gaming Software 8.57 (HKLM\...\Logitech Gaming Software) (Version: 8.57.145 - Logitech Inc.) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Language Pack 2007 - Polish/Polski (HKLM-x32\...\OMUI.pl-pl) (Version: 12.0.4518.1020 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation) Mumble 1.2.15 (HKLM-x32\...\{0FC17F75-1DD4-4DAD-BA19-5574C8D5A5CF}) (Version: 1.2.15 - Thorvald Natvig) NapiProjekt (2.2.0.2399) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Napisy24 (HKLM-x32\...\{D1985DBC-F09E-4317-91B8-932AD0FD4A27}_is1) (Version: 1.1 - Napisy24.pl) NVIDIA Oprogramowanie systemu PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) NVIDIA Sterownik graficzny 359.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 359.00 - NVIDIA Corporation) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) Opera Stable 36.0.2130.65 (HKLM-x32\...\Opera 36.0.2130.65) (Version: 36.0.2130.65 - Opera Software) Oprogramowanie mikroukładu Intel® (x32 Version: 10.0.27 - Intel(R) Corporation) Hidden Orcs Must Die! Unchained (HKLM\...\Steam App 427270) (Version: - Robot Entertainment) osu! (HKLM-x32\...\{ff662288-d997-4705-80bb-fdde5263c767}) (Version: latest - ppy Pty Ltd) Panel sterowania NVIDIA 359.00 (Version: 359.00 - NVIDIA Corporation) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 6.2 - Power Software Ltd) Pushbullet version 312 (HKLM-x32\...\{7578F204-49E7-4830-B051-14C23F408BFE}_is1) (Version: 312 - Pushbullet Inc) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.) Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10001 - Realtek Semiconductor Corp.) Remove Empty Directories version 2.2 (HKLM-x32\...\{06F25DC8-71E2-44E2-805A-F15E15B51C74}_is1) (Version: 2.2 - Jonas John) ShareX (HKLM\...\82E6AC09-0FEF-4390-AD9F-0DD3F5561EFC_is1) (Version: 10.9.1 - ShareX Team) Skype™ 7.13 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-2762560903-3368116062-2236283052-1000\...\Spotify) (Version: 1.0.27.75.gdc223232 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Taiga (HKU\S-1-5-21-2762560903-3368116062-2236283052-1000\...\Taiga) (Version: 1.2 - erengy) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) TreeSize Free V3.3.2 (HKLM-x32\...\TreeSize Free_is1) (Version: 3.3.2 - JAM Software) Unchecky v0.4.3 (HKLM-x32\...\Unchecky) (Version: 0.4.3 - RaMMicHaeL) Unified Remote (HKLM-x32\...\{415B4714-4F8C-49C6-B310-881EAF892CFB}_is1) (Version: 3.2.7 - Unified Intents AB) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) WinRAR 5.20 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) Wooxy version 1.2 (HKLM-x32\...\{C183CD14-47D8-4F98-AF06-4744CB834C8E}_is1) (Version: 1.2 - Chewy) Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.5.2014.3 - URSoft, Inc.) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2762560903-3368116062-2236283052-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {089B117C-9EB2-402D-9219-DBCE68418193} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated) Task: {0A8ECE6B-460D-448C-89B0-2B028F143F34} - System32\Tasks\{5AB168D8-940F-4CDD-802C-16435548072C} => pcalua.exe -a C:\Users\Piotrek\AppData\Local\Temp\jre-8u60-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 Task: {493E44EB-7C8B-453F-99C6-DC50D90C0833} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2762560903-3368116062-2236283052-1000UA => C:\Users\Piotrek\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.) Task: {4A3C1DD8-2920-4580-B34E-9F9E918A0CF3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-03-11] (Piriform Ltd) Task: {523805A2-3BB9-4BF2-BE74-3E09437DBB50} - System32\Tasks\GameNet => C:\Program Files (x86)\QGNA\qgna.exe Task: {5B68FC7D-3BA0-4915-9EAE-1F6721516B2A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2762560903-3368116062-2236283052-1000Core => C:\Users\Piotrek\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.) Task: {6A7FEDA2-7FEC-45EE-87DF-033D1046FFFA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-26] (Google Inc.) Task: {6EF2CFA8-95A6-4EFF-A77F-0423CAF80C96} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {D53582DB-7CEF-4627-BAF8-2352F1B639AC} - System32\Tasks\Opera scheduled Autoupdate 1424948594 => C:\Program Files (x86)\Opera\launcher.exe [2016-04-11] (Opera Software) Task: {DC79C384-599E-4E3A-9781-576F2710DB39} - System32\Tasks\{E07ED377-35AA-4681-B4B9-18CFE8763D89} => pcalua.exe -a C:\Users\Piotrek\AppData\Local\Temp\jre-8u73-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 Task: {FC4F90B6-E900-4C06-8741-AFDF4F8DEBD7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-26] (Google Inc.) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2762560903-3368116062-2236283052-1000Core.job => C:\Users\Piotrek\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2762560903-3368116062-2236283052-1000UA.job => C:\Users\Piotrek\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2015-09-19 00:31 - 2015-09-19 00:31 - 00075064 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2015-09-19 00:31 - 2015-09-19 00:31 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2015-02-27 16:10 - 2015-11-16 05:35 - 00012080 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2015-02-27 16:16 - 2015-11-14 08:06 - 00116528 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-09-18 09:23 - 2014-09-18 09:23 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-10-14 20:51 - 2014-10-14 20:51 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-09-18 09:23 - 2014-09-18 09:23 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-10-14 20:51 - 2014-10-14 20:51 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2015-02-26 12:44 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll 2016-04-09 00:52 - 2016-03-12 13:57 - 00032256 _____ () C:\Program Files\HexChat\iconv.dll 2016-04-09 00:52 - 2016-03-12 13:59 - 01423872 _____ () C:\Program Files\HexChat\cairo.dll 2016-04-09 00:52 - 2016-03-12 13:58 - 00731136 _____ () C:\Program Files\HexChat\fontconfig.dll 2016-04-09 00:52 - 2016-03-12 13:58 - 01430016 _____ () C:\Program Files\HexChat\libxml2.dll 2016-04-09 00:52 - 2016-03-12 13:58 - 00597504 _____ () C:\Program Files\HexChat\pixman-1.dll 2016-04-09 00:52 - 2016-03-12 13:58 - 00217088 _____ () C:\Program Files\HexChat\libpng16.dll 2016-04-09 00:52 - 2016-03-12 13:57 - 00081408 _____ () C:\Program Files\HexChat\zlib1.dll 2016-04-09 00:52 - 2016-03-12 14:00 - 00975872 _____ () C:\Program Files\HexChat\harfbuzz.dll 2016-04-09 00:52 - 2016-03-12 14:00 - 00059904 _____ () C:\Program Files\HexChat\lib\gtk-2.0\i686-pc-vs14\engines\libwimp.dll 2016-04-09 00:52 - 2016-03-12 13:59 - 00292864 _____ () C:\Program Files\HexChat\lib\enchant\libenchant_myspell.dll 2016-04-09 00:52 - 2016-03-12 16:00 - 00011776 _____ () C:\Program Files\HexChat\plugins\hcupd.dll 2015-10-12 12:11 - 2015-04-24 16:40 - 00043520 _____ () C:\Users\Piotrek\AppData\Local\THORN\QtSolutions_Service-head.dll 2015-10-12 12:11 - 2014-08-28 10:36 - 00732160 _____ () C:\Users\Piotrek\AppData\Local\THORN\libGLESv2.dll 2015-10-12 12:11 - 2014-08-28 10:41 - 00856576 _____ () C:\Users\Piotrek\AppData\Local\THORN\platforms\qwindows.dll 2015-10-12 12:11 - 2014-08-28 10:36 - 00047104 _____ () C:\Users\Piotrek\AppData\Local\THORN\libEGL.dll 2015-02-27 16:10 - 2015-11-16 05:35 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2015-06-06 00:51 - 2015-11-16 05:35 - 00012080 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-02-26 13:39 - 2016-03-11 02:56 - 00783360 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2015-02-26 13:39 - 2015-07-03 18:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll 2015-02-26 13:39 - 2015-07-03 18:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2015-02-26 13:39 - 2015-07-03 18:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2015-02-26 13:39 - 2016-03-31 22:55 - 02549840 _____ () C:\Program Files (x86)\Steam\video.dll 2015-02-26 13:39 - 2016-02-09 01:14 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2015-02-26 13:39 - 2016-02-09 01:14 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2015-02-26 13:39 - 2016-02-09 01:14 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2015-02-26 13:39 - 2016-02-09 01:14 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2015-02-26 13:39 - 2016-02-09 01:14 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2015-02-26 13:39 - 2016-03-31 22:55 - 00829008 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2016-03-09 14:34 - 2016-02-18 00:25 - 00281088 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2015-12-10 08:32 - 2016-03-21 23:50 - 00034768 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd 2016-04-14 21:37 - 2016-03-21 23:51 - 00019408 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\faulthandler.pyd 2016-04-14 21:37 - 2016-03-21 23:50 - 00116688 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\pywintypes27.dll 2015-12-10 08:32 - 2016-03-21 23:50 - 00093640 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\_ctypes.pyd 2015-12-10 08:32 - 2016-03-21 23:50 - 00018376 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\select.pyd 2015-12-10 08:32 - 2016-04-08 20:20 - 00019760 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00105928 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32api.pyd 2016-04-14 21:37 - 2016-03-21 23:50 - 00392144 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\pythoncom27.dll 2015-12-10 08:32 - 2016-04-08 20:20 - 00381752 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd 2015-12-10 08:32 - 2016-03-21 23:50 - 00692688 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\unicodedata.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00020816 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd 2015-12-10 08:32 - 2016-03-21 23:51 - 00112592 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 01682760 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00020808 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd 2015-12-10 08:32 - 2016-04-08 20:20 - 00021840 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00038696 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\fastpath.pyd 2016-04-14 21:37 - 2016-03-21 23:52 - 00020936 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\mmapfile.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00024528 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32event.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00114640 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32security.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00124880 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32file.pyd 2016-02-19 14:03 - 2016-04-08 20:20 - 00021832 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00024016 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32clipboard.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00175560 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32gui.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00030160 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32pipe.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00043472 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32process.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00028616 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32ts.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00048592 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32service.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00026456 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00057808 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32evtlog.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00024016 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\win32profile.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00117056 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd 2015-12-10 08:32 - 2016-04-08 20:20 - 00023376 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd 2015-12-10 08:32 - 2016-03-21 23:50 - 00134608 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\_elementtree.pyd 2016-04-14 21:37 - 2016-03-21 23:50 - 00134088 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\pyexpat.pyd 2016-04-14 21:37 - 2016-03-21 23:51 - 00240584 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\jpegtran.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00024392 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd 2016-04-14 21:37 - 2016-03-21 23:52 - 00036296 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\librsync.dll 2016-04-14 21:37 - 2016-04-08 20:19 - 00052024 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd 2016-02-19 14:03 - 2016-04-08 20:20 - 00020800 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-02-19 14:03 - 2016-04-08 20:20 - 00021824 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd 2016-02-19 14:03 - 2016-04-08 20:20 - 00019776 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd 2016-02-19 14:03 - 2016-04-08 20:20 - 00020800 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00020280 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd 2015-12-10 08:32 - 2016-03-21 23:52 - 00350152 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\winxpgui.pyd 2016-02-19 14:03 - 2016-04-08 20:20 - 00022352 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd 2016-04-14 21:37 - 2016-04-08 20:19 - 00084280 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2016-04-14 21:37 - 2016-04-08 20:20 - 01826096 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd 2015-12-10 08:32 - 2016-03-21 23:51 - 00083912 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\sip.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 03928880 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 01971504 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00531248 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00132912 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00223544 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00207672 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00158008 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00042808 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd 2016-04-14 21:37 - 2016-03-21 23:54 - 00017864 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\libEGL.dll 2016-04-14 21:37 - 2016-03-21 23:54 - 01631184 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-12-10 08:32 - 2016-04-08 20:20 - 00024904 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00546096 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd 2016-04-14 21:37 - 2016-04-08 20:20 - 00357680 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd 2015-09-04 16:07 - 2016-03-21 23:56 - 00697304 _____ () C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-02-26 13:39 - 2016-02-09 03:33 - 48400672 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2016-04-14 12:56 - 2016-04-13 10:37 - 01738904 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.75\libglesv2.dll 2016-04-14 12:56 - 2016-04-13 10:36 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.75\libegl.dll 2016-04-14 12:56 - 2016-04-13 10:37 - 17536664 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.75\PepperFlash\pepflashplayer.dll 2015-07-24 22:06 - 2016-04-15 14:55 - 47503472 _____ () C:\Users\Piotrek\AppData\Roaming\Spotify\libcef.dll 2015-07-24 22:06 - 2016-04-15 14:55 - 01584240 _____ () C:\Users\Piotrek\AppData\Roaming\Spotify\libglesv2.dll 2015-07-24 22:06 - 2016-04-15 14:55 - 00082032 _____ () C:\Users\Piotrek\AppData\Roaming\Spotify\libegl.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [152] ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: ========================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 04:34 - 2016-04-15 09:17 - 00002024 ____A C:\Windows\system32\Drivers\etc\hosts 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com 0.0.0.0 media.opencandy.com 0.0.0.0 cdn.opencandy.com 0.0.0.0 tracking.opencandy.com 0.0.0.0 api.opencandy.com 0.0.0.0 api.recommendedsw.com 0.0.0.0 installer.betterinstaller.com 0.0.0.0 installer.filebulldog.com 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net 0.0.0.0 inno.bisrv.com 0.0.0.0 nsis.bisrv.com 0.0.0.0 cdn.file2desktop.com 0.0.0.0 cdn.goateastcach.us 0.0.0.0 cdn.guttastatdk.us 0.0.0.0 cdn.inskinmedia.com 0.0.0.0 cdn.insta.oibundles2.com 0.0.0.0 cdn.insta.playbryte.com 0.0.0.0 cdn.llogetfastcach.us 0.0.0.0 cdn.montiera.com 0.0.0.0 cdn.msdwnld.com 0.0.0.0 cdn.mypcbackup.com 0.0.0.0 cdn.ppdownload.com 0.0.0.0 cdn.riceateastcach.us 0.0.0.0 cdn.shyapotato.us 0.0.0.0 cdn.solimba.com 0.0.0.0 cdn.tuto4pc.com 0.0.0.0 cdn.appround.biz 0.0.0.0 cdn.bigspeedpro.com 0.0.0.0 cdn.bispd.com Wykryto więcej niż wyliczono: 4 linii. ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-2762560903-3368116062-2236283052-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Piotrek\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) MSCONFIG\startupreg: Napisy24Update => "C:\Program Files (x86)\Napisy24\Napisy24Update.exe" "sleep" MSCONFIG\startupreg: ProgLauncher => C:\Program Files\ProgDVB\ProgLauncher.exe ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{0BF0D815-24B6-4F26-880C-E1DCDC3B413D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{2FDF5737-62A5-48C6-9A93-12567A9DE515}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{AD0E5EAF-8A3F-47D8-AAA1-0B4CA85A5474}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{D30228FE-D529-45EF-8BA7-CEAADD661DCC}] => (Allow) C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{15A66646-F384-42B3-ABB3-70012DD24C6B}] => (Allow) C:\Users\Piotrek\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{18DDF880-825F-4D92-A387-BBBB0AF286D1}C:\users\piotrek\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\piotrek\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{3ADD5F36-0EBD-4212-80F8-0CAAE4BE622A}C:\users\piotrek\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\piotrek\appdata\roaming\spotify\spotify.exe FirewallRules: [{D1F2912F-B326-429D-8264-3E3CF2903F58}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe FirewallRules: [{B96F3264-7BD3-4BFD-AB19-08A999ACE36B}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe FirewallRules: [{032EF21A-63F3-45EE-8E61-1280859BB379}] => (Allow) C:\Users\Piotrek\AppData\Roaming\Spotify\spotify.exe FirewallRules: [{4B392E65-BAFC-4195-ABD8-27340EFEEAED}] => (Allow) C:\Users\Piotrek\AppData\Roaming\Spotify\spotify.exe FirewallRules: [TCP Query User{D154C3EB-0DA1-44EB-8A30-41DFDC54F7A1}C:\users\piotrek\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\piotrek\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{8853464E-7281-42FB-8A04-6E40C6263F66}C:\users\piotrek\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\piotrek\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{01AD8DFB-4A3B-4E9D-A357-443DB6D6B324}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{42BB40D7-3FB2-4889-98A2-32D9AC5D49B9}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{2DB75BE2-BD24-46AA-92D8-687B1E67DBDA}E:\gry\grysteam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\gry\grysteam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [UDP Query User{61475EEB-E42E-4FB2-B8E3-D8507E6AA48D}E:\gry\grysteam\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) E:\gry\grysteam\steamapps\common\counter-strike global offensive\csgo.exe FirewallRules: [{F1EC206E-9D7D-44CF-98AF-F2FCB8EE7AEB}] => (Allow) C:\Users\Piotrek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{3DB85333-E501-441C-9FEE-A2C6500F5353}] => (Allow) C:\Users\Piotrek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{BD84FDC3-5FDB-4DE9-955D-8769C8881E8E}C:\program files (x86)\hexchat\hexchat.exe] => (Allow) C:\program files (x86)\hexchat\hexchat.exe FirewallRules: [UDP Query User{395E6EB1-0161-4A7E-825B-B7109C868FDD}C:\program files (x86)\hexchat\hexchat.exe] => (Allow) C:\program files (x86)\hexchat\hexchat.exe FirewallRules: [{8B202E03-B372-4AD4-AD50-3D4AD3DC7981}] => (Allow) C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe FirewallRules: [{162F782E-0C57-4F58-9B92-0561278BEB47}] => (Allow) C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe FirewallRules: [{349186A9-EC20-471D-92AC-8129AF287C6A}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{4406D30B-A181-4253-9A6B-0601DB9ADE82}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{5D5A3271-DD25-4BCB-83A0-4EE6A337FD2E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{A0825CE6-602A-4E71-8D09-26F532FF8D66}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{A261B1A1-BB4A-42BE-9CBA-F3C1B903ADF4}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{BFA6233F-F1F6-40B8-A959-DFD31BA1B511}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{0B6BD5D7-0448-4B47-A7AF-5E55A692FE48}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [UDP Query User{5998E03F-C059-4E59-BB6A-C8E1C4D54324}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [{FED7CD0C-C2A6-4D62-A4EB-4F72867080D2}] => (Allow) E:\Gry\GrySteam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [{718E972B-006B-493C-87CA-334E9B6C4A07}] => (Allow) E:\Gry\GrySteam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe FirewallRules: [TCP Query User{5A7A6EAE-A1C3-49FC-816B-ED0D810E5A96}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [UDP Query User{14F5820B-E37C-46CF-B2E2-4BEF9216767C}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [{A8B48953-BE9C-4A6D-AA11-B15D0531509C}] => (Allow) E:\Gry\GrySteam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe FirewallRules: [{886F50C3-6BD9-4B74-BA2C-129419D1C800}] => (Allow) E:\Gry\GrySteam\SteamApps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe FirewallRules: [{C6320916-FF0D-4DBE-8BEC-B3FB771EDE59}] => (Allow) E:\Gry\GrySteam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe FirewallRules: [{42D22713-8437-4689-BFE5-C4192CD17290}] => (Allow) E:\Gry\GrySteam\SteamApps\common\Guns of Icarus Online\workshop\Workshop.exe FirewallRules: [TCP Query User{5A6B90AF-CBCE-4AB1-88AE-D7340B2E1C38}E:\gry\warcraft iii\warcraft iii\war3.exe] => (Allow) E:\gry\warcraft iii\warcraft iii\war3.exe FirewallRules: [UDP Query User{398AA047-2DEC-40F7-AB36-3A1F8474293E}E:\gry\warcraft iii\warcraft iii\war3.exe] => (Allow) E:\gry\warcraft iii\warcraft iii\war3.exe FirewallRules: [{576C75E3-AA27-4833-8C66-193E968D4D5E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{F9C8671A-1E85-409F-9A13-C6FE54FC6D33}] => (Allow) E:\Gry\GrySteam\SteamApps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe FirewallRules: [{656974EC-4B50-42F1-A847-7744F7D168BA}] => (Allow) E:\Gry\GrySteam\SteamApps\common\OrcsMustDieUnchained\Dashboard\Bin\SpitfireDashboard.exe ==================== Punkty Przywracania systemu ========================= 14-04-2016 18:19:15 Windows Update 14-04-2016 18:29:48 Windows Update ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Generic Bluetooth Adapter Description: Generic Bluetooth Adapter Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: GenericAdapter Service: BTHUSB Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (04/15/2016 02:48:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: ShareX.exe, wersja: 10.9.1.0, sygnatura czasowa: 0x56f5a359 Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 6.1.7601.23392, sygnatura czasowa: 0x56eb3604 Kod wyjątku: 0xe0434352 Przesunięcie błędu: 0x000000000001a06d Identyfikator procesu powodującego błąd: 0xec4 Godzina uruchomienia aplikacji powodującej błąd: 0xShareX.exe0 Ścieżka aplikacji powodującej błąd: ShareX.exe1 Ścieżka modułu powodującego błąd: ShareX.exe2 Identyfikator raportu: ShareX.exe3 Error: (04/15/2016 02:48:38 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Aplikacja: ShareX.exe Wersja architektury: v4.0.30319 Opis: proces został przerwany z powodu nieobsłużonego wyjątku. Informacje o wyjątku: System.OutOfMemoryException w System.Threading.WaitHandle.WaitOneNative(System.Runtime.InteropServices.SafeHandle, UInt32, Boolean, Boolean) w System.Threading.WaitHandle.InternalWaitOne(System.Runtime.InteropServices.SafeHandle, Int64, Boolean, Boolean) w System.Threading.WaitHandle.WaitOne(Int32, Boolean) w System.Windows.Forms.Control.WaitForWaitHandle(System.Threading.WaitHandle) w System.Windows.Forms.Control.MarshaledInvoke(System.Windows.Forms.Control, System.Delegate, System.Object[], Boolean) w System.Windows.Forms.Control.Invoke(System.Delegate, System.Object[]) w ShareX.WorkerTask.DoUploadJob() w ShareX.WorkerTask.ThreadDoWork() w ShareX.HelpersLib.ThreadWorker.WorkThread() w System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) w System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) w System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) w System.Threading.ThreadHelper.ThreadStart() Error: (04/15/2016 09:18:49 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 12:23:17 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: hexchat.exe, wersja: 2.12.0.0, sygnatura czasowa: 0x56e42f35 Nazwa modułu powodującego błąd: gdk-win32-2.0.dll, wersja: 2.24.30.0, sygnatura czasowa: 0x56e412f1 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000000235dd Identyfikator procesu powodującego błąd: 0x1254 Godzina uruchomienia aplikacji powodującej błąd: 0xhexchat.exe0 Ścieżka aplikacji powodującej błąd: hexchat.exe1 Ścieżka modułu powodującego błąd: hexchat.exe2 Identyfikator raportu: hexchat.exe3 Error: (04/14/2016 11:43:35 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program Explorer.EXE w wersji 6.1.7601.19135 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: b34 Godzina rozpoczęcia: 01d196848c8dd1e3 Godzina zakończenia: 0 Ścieżka aplikacji: C:\Windows\Explorer.EXE Identyfikator raportu: Error: (04/14/2016 11:37:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: perfmon.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce7972c Nazwa modułu powodującego błąd: wdc.dll, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce7c9f4 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000047589 Identyfikator procesu powodującego błąd: 0x14e8 Godzina uruchomienia aplikacji powodującej błąd: 0xperfmon.exe0 Ścieżka aplikacji powodującej błąd: perfmon.exe1 Ścieżka modułu powodującego błąd: perfmon.exe2 Identyfikator raportu: perfmon.exe3 Error: (04/14/2016 09:34:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2016 06:27:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2016 06:00:34 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2016 03:45:28 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: Usługa wyszukiwania systemu Windows nie może przetworzyć listy lokalizacji dołączonych i wykluczonych. Błąd: <30, 0x80040d07, „iehistory://{S-1-5-21-2762560903-3368116062-2236283052-1000}/”>. Dziennik System: ============= Error: (04/15/2016 09:17:08 AM) (Source: BTHUSB) (EventID: 17) (User: ) Description: W lokalnym adapterze Bluetooth wystąpił nieokreślony błąd. Adapter nie będzie używany. Sterownik został usunięty z pamięci. Error: (04/15/2016 09:17:07 AM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: Usługa ATKGFNEX Service zależy od następującej usługi: ASMMAP64. Ta usługa może nie być zainstalowana. Error: (04/14/2016 09:33:04 PM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: Usługa ATKGFNEX Service zależy od następującej usługi: ASMMAP64. Ta usługa może nie być zainstalowana. Error: (04/14/2016 09:33:03 PM) (Source: BTHUSB) (EventID: 17) (User: ) Description: W lokalnym adapterze Bluetooth wystąpił nieokreślony błąd. Adapter nie będzie używany. Sterownik został usunięty z pamięci. Error: (04/14/2016 06:26:16 PM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: Usługa ATKGFNEX Service zależy od następującej usługi: ASMMAP64. Ta usługa może nie być zainstalowana. Error: (04/14/2016 06:26:10 PM) (Source: BTHUSB) (EventID: 17) (User: ) Description: W lokalnym adapterze Bluetooth wystąpił nieokreślony błąd. Adapter nie będzie używany. Sterownik został usunięty z pamięci. Error: (04/14/2016 06:25:04 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED} Error: (04/14/2016 06:24:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Ochrona oprogramowania niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (04/14/2016 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Kopiowanie woluminów w tle niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (04/14/2016 06:24:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Instalator modułów systemu Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. CodeIntegrity: =================================== Date: 2015-06-06 00:39:05.447 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Chrome-pobrane\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-06-06 00:39:05.416 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Chrome-pobrane\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-06-06 00:39:04.531 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Piotrek\AppData\Local\Temp\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-06-06 00:39:04.503 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Piotrek\AppData\Local\Temp\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz Procent pamięci w użyciu: 41% Całkowita pamięć fizyczna: 8102.7 MB Dostępna pamięć fizyczna: 4711.63 MB Całkowita pamięć wirtualna: 16203.58 MB Dostępna pamięć wirtualna: 12543.79 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:90.61 GB) (Free:29.83 GB) NTFS ==>[dysk z komponentami startowymi (pozyskano odczytując BCD)] Drive d: (Multimedia) (Fixed) (Total:254.75 GB) (Free:105.49 GB) NTFS Drive e: (Gry i Programy) (Fixed) (Total:120.4 GB) (Free:44.71 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3C64A60F) Partition 1: (Not Active) - (Size=120.4 GB) - (Type=07 NTFS) Partition 2: (Active) - (Size=90.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=254.8 GB) - (Type=OF Extended) ==================== Koniec Addition.txt ============================