Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:30-04-2016 Uruchomiony przez Arek (2016-05-01 20:56:43) Uruchomiony z C:\Users\Arek\Desktop Windows 10 Enterprise (X64) (2015-10-26 14:53:02) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-1585059127-2730434103-678098393-500 - Administrator - Disabled) Arek (S-1-5-21-1585059127-2730434103-678098393-1002 - Administrator - Enabled) => C:\Users\Arek Gość (S-1-5-21-1585059127-2730434103-678098393-501 - Limited - Disabled) Konto domyślne (S-1-5-21-1585059127-2730434103-678098393-503 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\uTorrent) (Version: 3.4.5.41712 - BitTorrent Inc.) Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.00 - Adobe Systems) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Illustrator CC (HKLM-x32\...\{F2321021-08A2-44D6-B1DF-BDB415F23EC3}) (Version: 17.0 - Adobe Systems Incorporated) Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) AMD Catalyst Install Manager (HKLM\...\{66AFB595-BC05-2913-7696-6D58F9B733E1}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Android SDK Tools (HKLM-x32\...\Android SDK Tools) (Version: 1.16 - Google Inc.) Aslain's XVM WoT Modpack wersja 9.13.32 (HKLM-x32\...\ZRwTINhSZfduKONYrSCTiCiGPggQZdcLRvoAVxyCOXXpkHeC~1DC3968F_is1) (Version: 9.13.32 - Aslain) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield: Bad Company™ 2 (HKLM-x32\...\{3AC8457C-0385-4BEA-A959-E095F05D6D67}) (Version: 1.0.1.0 - Electronic Arts) CCleaner (HKLM\...\CCleaner) (Version: 5.17 - Piriform) Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine) Counter-Strike (HKLM-x32\...\Steam App 10) (Version: - Valve) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CPUID CPU-Z 1.74 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse) GG (HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\GG) (Version: 12 - GG Network S.A.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.94 - Google Inc.) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software) IrfanView 64 (remove only) (HKLM\...\IrfanView) (Version: 4.40 - Irfan Skiljan) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) Java SE Development Kit 7 Update 79 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170790}) (Version: 1.7.0.790 - Oracle) K-Lite Codec Pack 11.5.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.5.5 - ) Malwarebytes Anti-Malware wersja 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 43.0.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 pl)) (Version: 43.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla) MSI Afterburner 4.2.0 (HKLM-x32\...\Afterburner) (Version: 4.2.0 - MSI Co., LTD) Mumble 1.2.10 (HKLM-x32\...\{53A341CC-C9F7-4CBE-A79E-879530B31210}) (Version: 1.2.10 - Thorvald Natvig) Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Nero 2015 Content Pack (HKLM-x32\...\{55192BC6-EDBA-4F48-A2C4-3D164E41AF55}) (Version: 16.0.00300 - Nero AG) Nero 8 (HKLM-x32\...\{D6D5CB84-0E6E-4E69-B300-C690B6911045}) (Version: 8.3.38 - Nero AG) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.5 - Notepad++ Team) Oracle VM VirtualBox 5.0.18 (HKLM\...\{4D4859BB-681D-45A1-81C8-520B382D3034}) (Version: 5.0.18 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.11.6.18139 - Electronic Arts, Inc.) PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden Prerequisite installer (x32 Version: 16.0.0000 - Nero AG) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.) RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software) Skype™ 7.21 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.53254 - TeamViewer) The Forest (HKLM-x32\...\Steam App 242760) (Version: - Endnight Games Ltd) Tibia (HKLM-x32\...\Tibia_is1) (Version: 10.90 - CipSoft GmbH) Tibiacast (HKLM-x32\...\{A896B081-44F1-4774-B3E7-E1F6BCA8B134}) (Version: 3.1.05900 - Silver Squirrel Software HB) VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) WinRAR 4.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) World of Tanks (HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net) XenoBot Binary (HKLM-x32\...\{82F4416B-8461-4817-A09D-BBBD7FC00DE6}) (Version: 15.11.28 - XenoBot) XVM wersja 6.1.5 (HKLM-x32\...\{2865cd27-6b8b-4413-8272-cd968f316050}_is1) (Version: 6.1.5 - XVM team) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-1585059127-2730434103-678098393-1002_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Arek\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {0A29C980-55F7-4645-B79A-8AB0582EE683} - System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-78KDRPR-Arek DESKTOP-78KDRPR => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2014-01-23] (Microsoft Corporation) Task: {1143C527-AC9D-486B-A085-CC36461D5564} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2015-10-16] () Task: {1C2C1CE4-2620-4FE3-B789-9A82684DD27E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-26] (Google Inc.) Task: {2230A2C2-7D40-4FA9-B7C7-8E2841CDC569} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-26] (Google Inc.) Task: {5014399C-B215-4645-BDBE-167F75CA7994} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {8C36A24F-14D7-408B-AF8D-74035EE55A2B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {919F1A4A-EC4D-491E-BBF3-FCF858D17E40} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-78KDRPR-Arek => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-03-21] (Adobe Systems Incorporated) Task: {C007F004-A783-4B1A-B1D5-F79ED0560FC5} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-13] (Adobe Systems Incorporated) Task: {CE42D637-CFD8-40F5-A510-F63AF14C7874} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation) Task: {F0B63ED3-0859-43CA-B4F0-4D2F39FD7248} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-04-15] (Piriform Ltd) Task: {F40AD928-1820-4AF0-BE5D-E83CDF749509} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2015-10-18 14:26 - 2015-07-15 03:04 - 00032768 ____N () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll 2015-10-18 14:26 - 2015-08-11 10:13 - 00413184 ____N () C:\WINDOWS\System32\diagtrack_win.dll 2016-04-24 13:23 - 2016-04-24 15:37 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2016-04-13 22:20 - 2016-03-16 05:55 - 02495768 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 22:20 - 2016-03-16 05:55 - 02495768 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-10-18 14:26 - 2015-09-17 06:48 - 00429056 ____N () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-07-10 11:59 - 2015-07-10 11:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll 2015-12-09 17:54 - 2015-11-25 05:20 - 06569472 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-12-09 17:54 - 2015-11-25 05:17 - 00471040 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-09 17:54 - 2015-11-25 05:17 - 01808384 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-10-18 14:27 - 2015-09-17 06:43 - 02274816 ____N () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-07-10 12:00 - 2015-07-10 17:32 - 00210432 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll 2015-10-28 22:48 - 2007-09-02 14:58 - 00495616 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe 2015-10-28 22:48 - 2007-09-02 14:57 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll 2016-04-28 22:22 - 2016-04-28 00:25 - 01738904 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.94\libglesv2.dll 2016-04-28 22:22 - 2016-04-28 00:25 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.94\libegl.dll 2016-04-28 22:22 - 2016-04-28 00:25 - 17536664 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.94\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2015-10-26 14:33 - 2015-10-26 14:31 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-1585059127-2730434103-678098393-1002\Control Panel\Desktop\\Wallpaper -> H:\Tapety\HD google\168973-1920x1200.jpg DNS Servers: 192.168.0.1 - 192.168.0.2 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja wyłączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\StartupApproved\StartupFolder: => "XenoSuite.lnk" HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\StartupApproved\Run: => "GG" HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\StartupApproved\Run: => "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-1585059127-2730434103-678098393-1002\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{457AEF1D-A184-4117-BB27-05C50C8DB851}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{4E1E8951-B0A5-4C5A-BCD4-303FE2F3B663}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{E11C4220-F656-4C29-89F8-AE2D81A89590}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{766D11B4-AB77-4088-89AE-A19DC93A5E22}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{F485106E-7480-4793-8149-E6EA7C31F10B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{3FC24333-835B-46FD-A144-91DCFA44D4CE}] => (Allow) D:\WoT\WoTLauncher.exe FirewallRules: [{C1FF66DB-79EE-4669-A7B3-85573561B838}] => (Allow) D:\WoT\WorldofTanks.exe FirewallRules: [{CA2AE186-9B5D-4397-8692-291C9BF4897A}] => (Allow) C:\Users\Arek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{85184912-B3DE-42DE-A9B3-44A672E68F55}] => (Allow) C:\Users\Arek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{7582601E-E6CF-4008-ABBD-1C24DD3EAD63}] => (Allow) C:\Users\Arek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{19EEA634-ADA5-4A23-A140-440505FA9A15}] => (Allow) C:\Users\Arek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{25F78770-6550-49BB-B3A7-C0902891C9EE}] => (Allow) C:\Users\Arek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{CD7A2343-ECA7-4388-8531-3EC7391B9DAE}] => (Allow) C:\Users\Arek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{77FA19A7-3F4F-4581-B264-4E97E6098430}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{D91418AD-EFD8-4CDB-B6F3-A565D0FCBB8E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{7626E9F4-D44C-4D15-AE1F-843AE556C3AC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{77DF0632-A185-4D46-83B1-6BA479F236F8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{47A5E05F-24F9-436E-9098-94113A759282}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{5543F8DD-59D0-4A04-939C-429D3BC90479}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{B8890DD6-9957-4428-A5FC-5B3F59817A4A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{EE3D3EE5-7257-4E1A-9370-360AE194D58F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{05041954-F8B9-47E0-9EC0-C1AC11019560}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{03EFC593-4B2C-4BC0-91C0-A81536985CBA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{EF0E45BE-15BA-4BCD-83A1-210908B129EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe FirewallRules: [{E3155A4A-6DE5-4931-9B41-BF105F2014F9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe FirewallRules: [{AD11B46D-516A-4710-81B8-2A9EB8D15865}] => (Allow) H:\Steam\Steam.exe FirewallRules: [{DADA7412-F6ED-4297-9A1A-9D4C82F800B7}] => (Allow) H:\Steam\Steam.exe FirewallRules: [{3CAC7AFA-98DB-4717-A72C-73CE1268BEB7}] => (Allow) H:\Steam\bin\steamwebhelper.exe FirewallRules: [{6152214D-0AF0-4B33-AEA1-80C0CC7FD488}] => (Allow) H:\Steam\bin\steamwebhelper.exe FirewallRules: [{54BD4468-472C-453C-AE31-ED90683A1961}] => (Allow) H:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{B2174F7F-F16E-4FBE-923E-D79325AF5D30}] => (Allow) H:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{F4ABE84C-5C05-4E57-9244-193C5C991981}] => (Allow) H:\WoT\WoTLauncher.exe FirewallRules: [{1A004616-3459-44C8-852F-CF407946EEC2}] => (Allow) H:\WoT\WoTLauncher.exe FirewallRules: [{D4F61463-9DFA-4584-A610-C5D8833A5FBE}] => (Allow) H:\WoT\worldoftanks.exe FirewallRules: [{26A24094-B57D-43FB-AC28-AAA9A74F3683}] => (Allow) H:\WoT\worldoftanks.exe FirewallRules: [{6B4717EC-B6A4-4EBD-9783-532DF915CDF3}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe FirewallRules: [{9CE4364A-22AB-4926-8131-D01A7EC8008C}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShare.exe FirewallRules: [{40A87ECE-5179-40B8-99F5-A55B90A5C52E}] => (Allow) C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe FirewallRules: [{3555073B-9215-4291-8D0B-A10379EEDB0E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{884141AF-DBBA-4EA4-B554-A7E75CF1706B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{048EE8C7-208C-4700-BC98-C706B5BE210F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{78B6FA48-CDA0-4308-BE15-E3DBF371F8B0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{817393B5-922F-45A9-BC82-FFEF72B67CE3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{FF8C8069-C7EC-48BF-BAEA-F110EE91BBE2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{9326319A-754C-4262-8793-DEE5040755E8}] => (Allow) H:\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{BC8ECDE3-EE1A-4A0D-BC40-1A3587AEB832}] => (Allow) H:\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{3483B278-085A-41BF-8339-B4540F7EDA71}] => (Allow) H:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{B1B3F84A-836E-405C-A79D-A56C21D4F734}] => (Allow) H:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{1220EB6E-AAED-40CB-968A-69F5517E113C}] => (Allow) C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{B73CB7DD-B545-4F5A-A04F-851003923300}] => (Allow) C:\Windows\syswow64\PnkBstrA.exe FirewallRules: [{A93E55AE-0899-4975-95BA-9944C01B4082}] => (Allow) C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{A8973AC2-6E2C-4C8C-997E-E3C11AF3F7F2}] => (Allow) C:\Windows\syswow64\PnkBstrB.exe FirewallRules: [{A4D03423-42C4-4872-B870-B1541D16A18D}] => (Allow) H:\Program Files (x86)\Origin Games\Battlefield Bad Company 2\BFBC2Game.exe FirewallRules: [{EBC6BCB1-6906-4C5D-AE47-083FF6462145}] => (Allow) H:\Program Files (x86)\Origin Games\Battlefield Bad Company 2\BFBC2Game.exe FirewallRules: [{E8EA37D7-CD6D-41AE-B3E2-8AD27E9E2138}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Punkty Przywracania systemu ========================= 13-04-2016 22:37:48 Windows Update 21-04-2016 17:05:27 Installed Java SE Development Kit 7 Update 79 (64-bit) 23-04-2016 14:41:09 Instalacja pakietu sterownika urządzenia: Fuzhou Rockchip Class for rockusb devices 27-04-2016 22:28:16 Installed Tibiacast 01-05-2016 20:49:27 Restore Point Created by FRST ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (05/01/2016 08:52:38 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (05/01/2016 08:52:30 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable Error: (05/01/2016 08:49:38 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to back up image of binary Protokół LLDP (Link-Layer Discovery Protocol) firmy Microsoft. System Error: Odmowa dostępu. . Error: (05/01/2016 08:49:17 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas badania interfejsu IVssWriterCallback. hr = 0x80070005, Odmowa dostępu. . To jest często spowodowane przez niepoprawne ustawienia zabezpieczeń w procesie zapisującym lub żądającym. Operacja: Zbieranie danych modułu zapisującego Kontekst: Identyfikator klasy modułu zapisującego: {e8132975-6f93-4464-a53e-1050253ae220} Nazwa modułu zapisującego: System Writer Identyfikator wystąpienia modułu zapisującego: {965d65cc-dab9-4f39-bb8c-6e0fe5584086} Error: (05/01/2016 06:37:32 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (05/01/2016 06:37:32 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable Error: (05/01/2016 06:35:00 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0x80004005 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (05/01/2016 06:35:00 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0x8007045B Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable Error: (05/01/2016 03:52:58 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (05/01/2016 03:52:50 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable Dziennik System: ============= Error: (05/01/2016 08:50:08 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-78KDRPR) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (05/01/2016 08:50:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Synchronizuj hosta_Session1 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 10000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Nero Update niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa MBAMService niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa TeamViewer 11 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 2000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa PnkBstrA niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa MBAMScheduler niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Adobe Acrobat Update Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (05/01/2016 08:49:15 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Bufor wydruku niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz Procent pamięci w użyciu: 17% Całkowita pamięć fizyczna: 8155.77 MB Dostępna pamięć fizyczna: 6745.5 MB Całkowita pamięć wirtualna: 9435.77 MB Dostępna pamięć wirtualna: 7944.62 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:181.48 GB) (Free:54.71 GB) NTFS Drive d: (Nowy) (Fixed) (Total:50.85 GB) (Free:33.64 GB) NTFS Drive f: () (Fixed) (Total:98.09 GB) (Free:14.37 GB) NTFS Drive h: () (Fixed) (Total:199.9 GB) (Free:92.8 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (Size: 232.9 GB) (Disk ID: AF95240E) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 873E51F5) Partition 1: (Not Active) - (Size=199.9 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=98.1 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ============================