Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:27-02-2016 Uruchomiony przez WojSky (2016-04-16 00:14:31) Uruchomiony z C:\Users\WojSky\Downloads\FixPC Windows 7 Ultimate Service Pack 1 (X64) (2012-06-21 16:14:41) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-668491218-822267600-407935612-500 - Administrator - Disabled) Gość (S-1-5-21-668491218-822267600-407935612-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-668491218-822267600-407935612-1002 - Limited - Enabled) WojSky (S-1-5-21-668491218-822267600-407935612-1000 - Administrator - Enabled) => C:\Users\WojSky ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95} AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKU\S-1-5-21-668491218-822267600-407935612-1000\...\uTorrent) (Version: 3.4.6.42094 - BitTorrent Inc.) AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated) Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Aktualizacje NVIDIA 2.5.15.54 (Version: 2.5.15.54 - NVIDIA Corporation) Hidden Any Video Converter Ultimate 5.8.2 (HKLM-x32\...\Any Video Converter Ultimate_is1) (Version: - Any-Video-Converter.com) BlueSoleil 10.0.479.1 (HKLM\...\{9453A661-550D-4FB9-BC91-3C1EEDF2ABDB}) (Version: 10.0.479.1 - Nazwa firmy) BurnAware Free 8.7 (HKLM-x32\...\BurnAware Free_is1) (Version: - Burnaware) calibre 64bit (HKLM\...\{4DF0BC01-6D8A-4D2D-B2D6-2BB5F3203B3E}) (Version: 1.41.0 - Kovid Goyal) Counter-Strike Global Offensive No-Steam (HKLM-x32\...\Counter-Strike Global Offensive_is1) (Version: 1.34.6.9 - Valve Software) CyberLink PowerDVD 15 (HKLM-x32\...\{DE85B8F3-D088-4D6E-A970-EE0BC7883A66}) (Version: 15.0.2003.58 - CyberLink Corp.) Detektor Winampa (HKU\S-1-5-21-668491218-822267600-407935612-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) DLL Suite 9.0 (HKLM-x32\...\{E557052E-9828-40E4-BFF6-311D3E89DB81}_is1) (Version: 9.0.0.0 - ) eMule (HKLM-x32\...\eMule1.0.0.9) (Version: 1.0.0.9 - eMule) ePub to PDF Converter 2.0.4 (HKLM-x32\...\ePub to PDF Converter_is1) (Version: - DONGSOFT Company, Inc.) Ghostery (HKLM-x32\...\Ghostery) (Version: - Ghostery Inc) GOM Player (HKLM-x32\...\GOM Player) (Version: 2.3.0.5248 - Gretech Corporation) Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation) KaraFun Player 2 (HKLM-x32\...\KaraFun Player 2_is1) (Version: 2.2.7.245 - Recisio) KhalInstallWrapper (Version: 4.00.121 - Logitech) Hidden Malwarebytes Anti-Malware wersja 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) MediaInfo 0.7.80 (HKLM\...\MediaInfo) (Version: 0.7.80 - MediaArea.net) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Kalkulator Plus (HKLM-x32\...\{7CDE2F4E-F47C-45D3-97BE-E309F09F939C}) (Version: 1.0.0 - Microsoft) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: - ) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 45.0.2 (x86 pl) (HKLM-x32\...\Mozilla Firefox 45.0.2 (x86 pl)) (Version: 45.0.2 - Mozilla) Mp3tag v2.75 (HKLM-x32\...\Mp3tag) (Version: v2.75 - Florian Heidenreich) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden msxml4 (HKLM-x32\...\{5AE3D9F1-9E9E-4015-8787-E22705AA32C5}) (Version: 1.0.0 - Default Company Name) MuseScore 2 (HKLM-x32\...\{D0969A82-E79E-45D9-95D2-B2824880F780}) (Version: 2.0.2 - Werner Schweer and Others) Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden NbuExplorer version 3.3 (HKLM-x32\...\{6C58B3E8-0822-490B-BC94-40CC02A6B37F}_is1) (Version: 3.3 - Petr Vilem) NVIDIA GeForce Experience 2.5.15.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.54 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) NVIDIA Sterownik 3D Vision 358.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 358.91 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA Sterownik graficzny 358.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 358.91 - NVIDIA Corporation) NVIDIA Sterownik kontrolera 3D Vision 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) Odkurzacz (HKLM-x32\...\Odkurzacz 14.0_is1) (Version: 14.0.0.4000 - FranmoSoftware - Maciej Opaliński) Ontrack EasyRecovery Professional (HKLM-x32\...\{668CC71A-C2AD-4D56-866D-CF300BD1D5BE}_is1) (Version: 11.1.0.0 - Kroll Ontrack Inc.) Opera Stable 33.0.1990.115 (HKLM-x32\...\Opera 33.0.1990.115) (Version: 33.0.1990.115 - Opera Software) Opera Stable 36.0.2130.32 (HKLM-x32\...\Opera 36.0.2130.32) (Version: 36.0.2130.32 - Opera Software) Pakiet sterowników systemu Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) Panel sterowania NVIDIA 358.91 (Version: 358.91 - NVIDIA Corporation) Hidden Polski pakiet językowy dla narzędzi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PLK) (Version: 10.0.50903 - Microsoft Corporation) Q-Dir (HKLM\...\Q-Dir) (Version: - ) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.5.15.54 - NVIDIA Corporation) Hidden Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.16.3.201602121455 - Sony Mobile Communications Inc.) Sony PC Companion 2.10.303 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.303 - Sony) Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0415-1000-0000000FF1CE}_Office15.PROPLUSR_{67847964-08E2-4A8F-B09D-B08D5CE69250}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3114831) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{319F14FC-24A0-4A07-B84C-C7450AF9422F}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3114831) 64-Bit Edition (HKLM\...\{90150000-012B-0415-1000-0000000FF1CE}_Office15.PROPLUSR_{319F14FC-24A0-4A07-B84C-C7450AF9422F}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3114831) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{319F14FC-24A0-4A07-B84C-C7450AF9422F}) (Version: - Microsoft) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) WinRAR 5.10 beta 4 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) Youtube Downloader HD v. 2.9.9.27 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {03D0E403-CEB2-403D-B100-DBDC4645BC6F} - System32\Tasks\Odkurzacz => C:\Program Files (x86)\Odkurzacz\odkurzacz.exe [2016-03-26] (FranmoSoftware) Task: {3412A21D-F7E5-454F-B38F-4D54B0527050} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_213_pepper.exe [2016-04-14] (Adobe Systems Incorporated) Task: {4E524651-F26E-41D0-BEDA-892C5560B712} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {68E1085E-6652-43B3-8549-B42BC548482C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {D1724BCA-F55B-4416-9EDB-5E98B1B6ED4E} - System32\Tasks\ASUS\ASUS SIX Engine => C:\Program Files (x86)\ASUS\EPU-6 Engine\SixEngine.exe [2009-07-17] () Task: {D1B11A84-682E-4DDD-984E-58070D9AFC7A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-14] (Adobe Systems Incorporated) Task: {E65D3AAA-B198-4C50-8B26-03E1B49116F5} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_213_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\2to3.lnk -> C:\Program Files (x86)\eMule\python\Scripts\2to3.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\cxfreeze-postinstall.lnk -> C:\Program Files (x86)\eMule\python\Scripts\cxfreeze-postinstall.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\cxfreeze-quickstart.lnk -> C:\Program Files (x86)\eMule\python\Scripts\cxfreeze-quickstart.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\cxfreeze.lnk -> C:\Program Files (x86)\eMule\python\Scripts\cxfreeze.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\cygdb-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\cygdb-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\cython-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\cython-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\easy_install-2.7-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\easy_install-2.7-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\easy_install-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\easy_install-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\epylint-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\epylint-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\f2py.lnk -> C:\Program Files (x86)\eMule\python\Scripts\f2py.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\guidata-tests.lnk -> C:\Program Files (x86)\eMule\python\Scripts\guidata-tests.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\guiqwt-tests.lnk -> C:\Program Files (x86)\eMule\python\Scripts\guiqwt-tests.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\idle.lnk -> C:\Program Files (x86)\eMule\python\Lib\idlelib\idle.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipcluster-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipcluster-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipcluster2-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipcluster2-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipcontroller-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipcontroller-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipcontroller2-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipcontroller2-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipengine-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipengine-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipengine2-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipengine2-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\iptest-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\iptest-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\iptest2-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\iptest2-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipython-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipython-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipython2-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipython2-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ipython_win_post_install.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ipython_win_post_install.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\isympy.lnk -> C:\Program Files (x86)\eMule\python\Scripts\isympy.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\miniterm.lnk -> C:\Program Files (x86)\eMule\python\Scripts\miniterm.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\nosetests-2.7-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\nosetests-2.7-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\nosetests-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\nosetests-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pilconvert.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pilconvert.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pildriver.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pildriver.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pilfile.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pilfile.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pilfont.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pilfont.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pilprint.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pilprint.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pip-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pip-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pip2-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pip2-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pip2.7-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pip2.7-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pt2to3.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pt2to3.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ptdump.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ptdump.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ptrepack.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ptrepack.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pygmentize-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pygmentize-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pylint-gui-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pylint-gui-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pylint-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pylint-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pyreverse-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pyreverse-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pyside-uic-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pyside-uic-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pyside_postinstall.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pyside_postinstall.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pytest.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pytest.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pyuic4.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pyuic4.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pywin32_postinstall.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pywin32_postinstall.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\pywin32_testall.lnk -> C:\Program Files (x86)\eMule\python\Scripts\pywin32_testall.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\register_python.lnk -> C:\Program Files (x86)\eMule\python\Scripts\register_python.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2html.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2html.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2latex.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2latex.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2man.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2man.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2odt.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2odt.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2odt_prepstyles.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2odt_prepstyles.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2pdf-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2pdf-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2pseudoxml.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2pseudoxml.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2s5.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2s5.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2xetex.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2xetex.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rst2xml.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rst2xml.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\rstpep2html.lnk -> C:\Program Files (x86)\eMule\python\Scripts\rstpep2html.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\runxlrd.lnk -> C:\Program Files (x86)\eMule\python\Scripts\runxlrd.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\sift.lnk -> C:\Program Files (x86)\eMule\python\Scripts\sift.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\skivi-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\skivi-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\sphinx-apidoc-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\sphinx-apidoc-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\sphinx-autogen-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\sphinx-autogen-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\sphinx-build-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\sphinx-build-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\sphinx-quickstart-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\sphinx-quickstart-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\spyder.lnk -> C:\Program Files (x86)\eMule\python\Scripts\spyder.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\spyder_win_post_install.lnk -> C:\Program Files (x86)\eMule\python\Scripts\spyder_win_post_install.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\symilar-script.lnk -> C:\Program Files (x86)\eMule\python\Scripts\symilar-script.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ttffamily.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ttffamily.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ttffiles.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ttffiles.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ttfgroups.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ttfgroups.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ttfmetadata.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ttfmetadata.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\ttx.lnk -> C:\Program Files (x86)\eMule\python\Scripts\ttx.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\vitables.lnk -> C:\Program Files (x86)\eMule\python\Scripts\vitables.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\wpcp.lnk -> C:\Program Files (x86)\eMule\python\Scripts\wpcp.bat () Shortcut: C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eMule\wppm.lnk -> C:\Program Files (x86)\eMule\python\Scripts\wppm.bat () ==================== Załadowane moduły (filtrowane) ============== 2014-07-23 17:02 - 2014-07-23 17:02 - 00028920 _____ () C:\Windows\System32\BsTrace.dll 2012-01-17 12:24 - 2012-01-17 12:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2012-06-21 17:48 - 2009-04-02 05:27 - 00090112 ____R () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe 2014-07-23 17:02 - 2014-07-23 17:02 - 00017144 _____ () C:\Windows\system32\BsHelpCSps.dll 2014-07-23 17:02 - 2014-07-23 17:02 - 00028920 _____ () C:\Windows\system32\BsTrace.dll 2014-07-23 17:02 - 2014-07-23 17:02 - 00075512 _____ () C:\Windows\system32\BlueSoleilCSps.dll 2014-07-23 17:02 - 2014-07-23 17:02 - 00019704 _____ () C:\Windows\system32\BsMobileCSps.dll 2013-06-13 21:22 - 2013-06-13 21:22 - 00012520 _____ () C:\Users\WojSky\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll 2013-06-13 21:22 - 2013-06-13 21:22 - 00015080 _____ () C:\Users\WojSky\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\GetCoreTempInfoNET.dll 2013-06-13 21:22 - 2013-06-13 21:22 - 00014056 _____ () C:\Users\WojSky\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\SystemInfo.dll 2012-06-21 17:23 - 2010-08-11 11:32 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2012-06-21 17:23 - 2010-08-11 11:32 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2012-06-21 17:23 - 2010-08-11 11:32 - 00105584 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll 2012-06-21 17:23 - 2010-08-11 11:32 - 64643696 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll 2012-06-21 17:48 - 2009-07-17 13:48 - 06038016 _____ () C:\Program Files (x86)\ASUS\EPU-6 Engine\SixEngine.exe 2014-07-23 17:01 - 2014-07-23 17:01 - 00031480 _____ () C:\Windows\SysWow64\BsHelpCSps.dll 2014-07-23 17:01 - 2014-07-23 17:01 - 00813816 _____ () C:\Windows\SysWow64\BlueSoleilCSps.dll 2014-06-16 18:03 - 2014-06-16 18:03 - 00236280 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\BaseLib.dll 2014-06-16 18:03 - 2014-06-16 18:03 - 00056056 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\ExtraLib.dll 2014-06-16 18:03 - 2014-06-16 18:03 - 00048376 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\cscvt.dll 2014-07-23 17:01 - 2014-07-23 17:01 - 00016632 _____ () C:\Windows\SysWOW64\BsMobileCSps.dll 2014-06-16 18:03 - 2014-06-16 18:03 - 00039672 _____ () C:\Windows\SysWOW64\cPhoneSDKCSps.dll 2012-06-21 17:48 - 2009-04-22 20:20 - 00179712 _____ () C:\Program Files (x86)\ASUS\TurboV Remote\ASUSSERVICE.DLL 2012-06-21 17:48 - 2009-03-25 09:31 - 00253952 _____ () C:\Program Files (x86)\ASUS\TurboV Remote\pngio.dll 2012-06-21 17:48 - 2009-06-24 08:47 - 00061440 _____ () C:\Program Files (x86)\ASUS\TurboV Remote\flashobj.dll 2016-04-14 11:16 - 2016-04-14 11:16 - 19403968 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll 2014-07-23 17:02 - 2014-07-23 17:02 - 00162552 _____ () C:\Windows\system32\BsProfilefunc.dll 2014-06-16 18:03 - 2014-06-16 18:03 - 00126200 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\s40pack.dll 2012-06-21 17:48 - 2009-04-22 20:20 - 00179712 _____ () C:\Program Files (x86)\ASUS\EPU-6 Engine\ASUSSERVICE.DLL 2012-06-21 17:48 - 2009-04-20 13:55 - 00565248 _____ () C:\Program Files (x86)\ASUS\EPU-6 Engine\pngio.dll 2012-06-21 17:48 - 2009-04-20 13:55 - 00053248 _____ () C:\Program Files (x86)\ASUS\EPU-6 Engine\AsSpindownTimeout.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 03:34 - 2016-04-15 23:06 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-668491218-822267600-407935612-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\WojSky\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.43.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [{B11DE1DD-E9C1-4968-A7E9-E02CA98B1743}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\cPhoneSDKCS.exe FirewallRules: [{3BFCB0B5-16ED-4972-A1A8-498FF6732C15}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\cPhoneSDKCS.exe FirewallRules: [{3BC76007-850F-4044-8AFE-20AD28547565}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe FirewallRules: [{96AAC8F5-548C-4278-9574-7D4D326D148C}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe FirewallRules: [{3F7D6CC8-8022-4ADD-A6A2-C9B713C575F6}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe FirewallRules: [{C23DFA24-7AE8-453A-AF39-BBD81D409785}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe FirewallRules: [{B8AD9198-1DCC-40DC-880D-2F442056DE5E}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\cPhoneSDKCS.exe FirewallRules: [{79D66BAE-EFDD-433E-A778-73388FCEBA2F}] => (Allow) C:\Program Files (x86)\IVT Corporation\BlueSoleil\cPhoneSDKCS.exe ==================== Punkty Przywracania systemu ========================= 29-03-2016 17:06:37 Windows Update 03-04-2016 15:16:04 Windows Update 07-04-2016 21:34:49 Windows Update 12-04-2016 17:48:33 Windows Update 15-04-2016 20:06:45 ComboFix created restore point 15-04-2016 21:18:47 Windows Update 15-04-2016 23:05:55 Restore Point Created by FRST ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= Name: Linksys Wireless A+G PCI Adapter Description: Linksys Wireless A+G PCI Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Atheros Communications Inc. Service: athr Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Karta wirtualnego miniportu WiFi firmy Microsoft Description: Karta wirtualnego miniportu WiFi firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (04/16/2016 12:09:57 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 11:36:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 11:11:01 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 11:05:54 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas badania interfejsu IVssWriterCallback. hr = 0x80070005, Odmowa dostępu. . To jest często spowodowane przez niepoprawne ustawienia zabezpieczeń w procesie zapisującym lub żądającym. Operacja: Zbieranie danych modułu zapisującego Kontekst: Identyfikator klasy modułu zapisującego: {e8132975-6f93-4464-a53e-1050253ae220} Nazwa modułu zapisującego: System Writer Identyfikator wystąpienia modułu zapisującego: {4a0ecac4-702b-4174-a107-5b8c4b867af6} Error: (04/15/2016 11:00:04 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 10:45:31 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 09:57:51 PM) (Source: Office Software Protection Platform Service) (EventID: 1001) (User: ) Description: The Software Protection service failed to start. 0x80070005 15.0.169.500 Error: (04/15/2016 09:52:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 09:13:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 09:10:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Dziennik System: ============= Error: (04/16/2016 12:14:27 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Uruchom usługę ponownie) po nieoczekiwanym zakończeniu usługi Usługa profilów użytkowników, ale ta akcja nie powiodła się przy następującym błędzie: %%1056. Error: (04/16/2016 12:14:27 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Uruchom usługę ponownie) po nieoczekiwanym zakończeniu usługi Instrumentacja zarządzania Windows, ale ta akcja nie powiodła się przy następującym błędzie: %%1056. Error: (04/16/2016 12:11:27 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Uruchom usługę ponownie) po nieoczekiwanym zakończeniu usługi Serwer, ale ta akcja nie powiodła się przy następującym błędzie: %%1056. Error: (04/16/2016 12:09:57 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Error: (04/16/2016 12:09:27 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Windows Update niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. Error: (04/16/2016 12:09:27 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Instrumentacja zarządzania Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 300000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (04/16/2016 12:09:27 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Kompozycje niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 60000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (04/16/2016 12:09:27 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Usługa powiadamiania o zdarzeniach systemowych niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 300000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (04/16/2016 12:09:27 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Logowanie pomocnicze niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 300000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (04/16/2016 12:09:27 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Harmonogram zadań niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 60000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. CodeIntegrity: =================================== Date: 2016-04-15 20:20:43.598 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-04-15 20:20:43.523 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-07 22:16:51.726 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\1qazxsw23edc\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-07 22:16:51.664 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\1qazxsw23edc\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-07 22:16:51.601 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\1qazxsw23edc\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-07 22:16:51.523 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\1qazxsw23edc\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-07 19:34:12.633 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\1qazxsw23edc\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-07 19:34:12.568 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\1qazxsw23edc\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-07 19:02:18.244 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-07 19:02:18.089 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i7 CPU 860 @ 2.80GHz Procent pamięci w użyciu: 17% Całkowita pamięć fizyczna: 16374.05 MB Dostępna pamięć fizyczna: 13485.22 MB Całkowita pamięć wirtualna: 32746.32 MB Dostępna pamięć wirtualna: 29658.06 MB ==================== Dyski ================================ Drive c: (WD_250_System) (Fixed) (Total:232.88 GB) (Free:70.26 GB) NTFS ==>[dysk z komponentami startowymi (pozyskano odczytując BCD)] Drive e: (WD_250_Blue) (Fixed) (Total:232.83 GB) (Free:25.26 GB) NTFS Drive f: (Mój dysk) (CDROM) (Total:4.33 GB) (Free:0 GB) CDFS Drive g: (WD_3TB_Black) (Fixed) (Total:2794.39 GB) (Free:2003.96 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 2A798127) Partition 1: (Active) - (Size=232.9 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 232.8 GB) (Disk ID: 16A27432) Partition 1: (Active) - (Size=232.8 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ============================