Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 20-11-2016 01 Uruchomiony przez Dorota (22-11-2016 09:01:01) Uruchomiony z C:\Users\Dorota\Desktop\lecz Windows 7 Home Premium Service Pack 1 (X64) (2010-01-12 22:53:44) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-3512223367-1628738116-3398761023-500 - Administrator - Disabled) Dorota (S-1-5-21-3512223367-1628738116-3398761023-1001 - Administrator - Enabled) => C:\Users\Dorota Gość (S-1-5-21-3512223367-1628738116-3398761023-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3512223367-1628738116-3398761023-1002 - Limited - Enabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) Adobe Flash Player 23 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 23.0.0.207 - Adobe Systems Incorporated) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated) Adobe Reader 9.5.0 - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-A95000000001}) (Version: 9.5.0 - Adobe Systems Incorporated) Anti-Twin (Installation 2015-08-28) (HKLM-x32\...\Anti-Twin 2015-08-28 11.27.16) (Version: - Joerg Rosenthal, Germany) Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Archiwizator WinRAR (HKLM\...\WinRAR archiver) (Version: - ) ATI Catalyst Install Manager (HKLM\...\{0FB2E75A-1024-331F-77EF-D45F71505D58}) (Version: 3.0.732.0 - ATI Technologies, Inc.) Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v7.00.08(T) - TOSHIBA CORPORATION) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Card Detector for Option Icon 225 (HKLM-x32\...\CardDetectorICON225) (Version: 0.0.0.1 - ) ccc-core-static (x32 Version: 2009.0729.2238.38827 - Nazwa firmy) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform) CDBurnerXP (HKLM-x32\...\{5932A5C4-BB44-4CFB-AD66-1B826F4D788B}) (Version: 4.2.7.1893 - Canneverbe Limited) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\Dropbox) (Version: 14.4.19 - Dropbox, Inc.) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation) Gadu-Gadu 10 (HKLM-x32\...\Gadu-Gadu 10) (Version: - GG Network S.A.) Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.) Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Hot CPU Tester Pro 4.4.1 (HKLM-x32\...\{5A39D5C2-A28B-421D-925A-0390FD1E5529}_is1) (Version: 4.4 LE - 7Byte Computers) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) iTunes (HKLM\...\{BFEAB774-C7DC-4032-B05A-DA5F7CB7B365}) (Version: 12.2.2.25 - Apple Inc.) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation) Java(TM) 6 Update 22 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.220 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden K-Lite Codec Pack 6.2.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.2.0 - ) Malwarebytes Anti-Malware wersja 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{306B39C9-3AB1-4161-8567-9C7E50B41AE3}) (Version: 9.7.0621 - Microsoft Corporation) Moduł Szybka instalacja pakietu Microsoft Office 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Moduł Szybka instalacja pakietu Microsoft Office 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden OpenOffice.org 3.3 (HKLM-x32\...\{EB87675F-5281-4767-A54B-31931794C23D}) (Version: 3.3.9567 - OpenOffice.org) PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.34.26215 - pdfforge GmbH) PDF Architect 4 Edit Module (Version: 4.0.12.26604 - pdfforge GmbH) Hidden PDF Architect 4 View Module (Version: 4.0.12.26604 - pdfforge GmbH) Hidden PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.2.2 - pdfforge) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.8 - Google, Inc.) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pomocnik Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Program TOSHIBA HDD/SSD Alert (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.0 - TOSHIBA Corporation) Program TOSHIBA HDD/SSD Alert (Version: 3.1.64.0 - TOSHIBA Corporation) Hidden Program TOSHIBA HDD/SSD Alert (x32 Version: 3.1.64.0 - TOSHIBA Corporation) Hidden QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) RayV (HKLM-x32\...\RayV) (Version: 2.0.1.65 - RayV) Realtek 8136 8168 8169 Ethernet Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0005 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5904 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30101 - Realtek Semiconductor Corp.) Realtek WLAN Driver (HKLM-x32\...\{0FB630AB-7BD8-40AE-B223-60397D57C3C9}) (Version: 2.00.0006 - Realtek) Room Arranger (32-bit) (HKLM-x32\...\Room Arranger) (Version: 8.4.1 - Jan Adamec) Sprzęt instalacyjny TOSHIBA (HKLM-x32\...\InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}) (Version: 1.63.0.11C - TOSHIBA CORPORATION) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 13.2.6.1 - Synaptics Incorporated) Toshiba Assist (HKLM-x32\...\{1B87C40B-A60B-4EF3-9A68-706CF4B69978}) (Version: 3.00.09 - TOSHIBA) TOSHIBA ConfigFree (HKLM-x32\...\{F3529665-D75E-4D6D-98F0-745C78C68E9B}) (Version: 8.0.21 - TOSHIBA Corporation) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.1 for x64 - TOSHIBA Corporation) TOSHIBA DVD PLAYER (HKLM-x32\...\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 3.01.0.07-A - TOSHIBA Corporation) TOSHIBA eco Utility (HKLM-x32\...\InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}) (Version: 1.1.10.64 - TOSHIBA Corporation) TOSHIBA Extended Tiles for Windows Mobility Center (HKLM-x32\...\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version: - ) TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.1.64 - TOSHIBA Corporation) TOSHIBA Flash Cards Support Utility (HKLM-x32\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.63.0.4C - TOSHIBA CORPORATION) TOSHIBA Hasło administratora (HKLM-x32\...\InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}) (Version: 1.63.0.7C - TOSHIBA CORPORATION) Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.00 - TOSHIBA) Toshiba Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 2.08.0001 - TOSHIBA) TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.4.1.64 - TOSHIBA Corporation) Toshiba Photo Service - powered by myphotobook (HKLM-x32\...\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1) (Version: 1.0.0-663 - myphotobook GmbH) TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.2 for x64 - TOSHIBA Corporation) TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA) TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{C2DDF845-7107-40E8-8D2A-8719F1799570}) (Version: 1.0.04.64 - TOSHIBA Corporation) TOSHIBA SD Memory Utilities (HKLM\...\{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}) (Version: 1.9.1.12 - TOSHIBA) TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.33 - TOSHIBA) Toshiba TEMPRO (HKLM-x32\...\{9E4FF410-471F-49E3-9358-74FF0D5E9901}) (Version: 3.05 - Toshiba Europe GmbH) TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.2.25.64 - TOSHIBA Corporation) TOSHIBA Web Camera Application (HKLM-x32\...\{5E6F6CF3-BACC-4144-868C-E14622C658F3}) (Version: 1.1.1.4 - TOSHIBA Corporation) TRORMCLauncher (HKLM-x32\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version: - ) TRORMCLauncher (Version: 1.0.0.7 - TOSHIBA) Hidden Unity Web Player (HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\UnityWebPlayer) (Version: 5.0.1f1 - Unity Technologies ApS) Utility Common Driver (x32 Version: 1.0.50.27C - TOSHIBA) Hidden Virtual Garden (HKLM-x32\...\Virtual Garden) (Version: - ) VS10Runtimex64 (Version: 1.0.0 - sourcefire) Hidden Windows Live Sync (HKLM-x32\...\{2E522ED6-01E2-4207-82D5-B3BFB31B8BD4}) (Version: 14.0.8089.726 - Microsoft Corporation) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{45C6AFA5-2C13-402f-BC5D-45CC8172EF6B}\InprocServer32 -> C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\sys\x64\TosBtExt.dll (TOSHIBA) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Dorota\AppData\Roaming\Dropbox\bin\DropboxExt64.3.0.dll (Dropbox, Inc.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {1FA6AAE9-49D3-417E-8D0C-96EF11BB726D} - System32\Tasks\eAHPeNhIUJBrowserUpdateUA => C:\Program Files (x86)\eAHPeNhIUJ\eAHPeNhIUJ\bin\eAHPeNhIUJ_server.exe <==== UWAGA Task: {2B6F5A01-8B85-4C3B-AA12-68EB5E82DF23} - System32\Tasks\{6C9F0B87-A3A4-42BF-890B-C70397818DF8} => pcalua.exe -a F:\Setup.exe -d F:\ Task: {3404D3C9-8DCA-4C52-9E2A-9294FDA2E832} - System32\Tasks\AVG-SSU_0616tb_DELETE => C:\ProgramData\Avg_Update_0616tb\AVG-Secure-Search-Update_0616tb.exe Task: {34DC6B8C-FA34-4E2A-9C68-2B215CF10575} - System32\Tasks\eAHPeNhIUJCheckTask => C:\Program Files (x86)\eAHPeNhIUJ\eAHPeNhIUJ\bin\eAHPeNhIUJ_server.exe <==== UWAGA Task: {392C1AF9-B94B-47C7-8063-2C23EE5A9B59} - System32\Tasks\DorotaDiscaseOneidasV2 => Rundll32.exe UxorialFiberized.dll,main 7 1 <==== UWAGA Task: {43AF9EB8-90A8-46A6-8400-2D8A7720F2F0} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001Core => C:\Users\Dorota\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {6337BCFE-E86A-448B-98CA-EF336E0B8C41} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-08] (Adobe Systems Incorporated) Task: {7C70F5AD-CC6D-4CD9-B595-78A585018097} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {8C3663B8-37A3-41BF-9E0B-F07BAC286966} - System32\Tasks\eAHPeNhIUJBrowserUpdateCore => C:\Program Files (x86)\eAHPeNhIUJ\eAHPeNhIUJ\bin\eAHPeNhIUJ_server.exe <==== UWAGA Task: {939700E1-8316-499D-B231-F52A8D2B9CC2} - System32\Tasks\{512A5FC6-7B3B-48EB-9D60-E024516A89EE} => pcalua.exe -a C:\Users\Dorota\Downloads\sweetimsetup.exe -d C:\Users\Dorota\Downloads Task: {9DE5057E-8249-421B-8964-2DD82C3559AE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd) Task: {A0886467-DBF0-4E4D-8A3F-D48B00E574EB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001UA => C:\Users\Dorota\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {ABDCACBD-C2B1-466B-8086-3A942AFBB508} - System32\Tasks\{F5A8C19A-0103-407B-BE0F-1BAF14493C88} => C:\Program Files (x86)\Skype\Phone\Skype.exe Task: {AC371F0A-43B0-415A-93B8-6702461CCA5F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001UA => C:\Users\Dorota\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {AD838059-FB1C-4FCA-8174-7E0CC32DCBB4} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2009-07-13] (TOSHIBA CORPORATION) Task: {B214A06F-5686-4660-B0D3-137324F0A76C} - System32\Tasks\{4C50AACB-A010-9E86-8F74-0171D192AFB8} => C:\Users\Dorota\AppData\Roaming\{4C50A~1\SYNCVE~1.EXE <==== UWAGA Task: {C10629E1-64A0-467E-B23B-54F3EC2F1EF8} - System32\Tasks\AVG-SSU_0616tb => C:\ProgramData\Avg_Update_0616tb\AVG-Secure-Search-Update_0616tb.exe Task: {C2DE1F66-F55A-423F-B072-DECD9228D3F8} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{24BCF86C-EFFF-4547-9961-F7B0E595E2E9}.exe <==== UWAGA Task: {C359EB99-476B-46A1-A028-02781717A7D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {C9ED8943-C308-4984-B852-42C8F09BDDA8} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{DC104E6D-0351-4709-A53F-931F1716AF9F}.exe <==== UWAGA Task: {D623F6B5-441A-4A9B-A963-066682F5C054} - System32\Tasks\{7541C4C4-4EA7-4A1F-B903-570B243487C0} => pcalua.exe -a "E:\Worms Armageddon\Install.exe" -d "E:\Worms Armageddon" Task: {DA2A660A-B589-4CF2-8DD6-E38F22271FC9} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001Core => C:\Users\Dorota\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {F9D16D18-4892-478E-B38E-44C628DCFAC1} - System32\Tasks\{CDC78F7E-BD02-422B-AB0A-5A16E29846E0} => pcalua.exe -a C:\Users\Dorota\AppData\Local\Temp\jre-8u111-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== UWAGA (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{DC104E6D-0351-4709-A53F-931F1716AF9F}.exe <==== UWAGA Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{24BCF86C-EFFF-4547-9961-F7B0E595E2E9}.exe <==== UWAGA Task: C:\Windows\Tasks\AVG-SSU_0616tb.job => C:\ProgramData\Avg_Update_0616tb\AVG-Secure-Search-Update_0616tb.exe Task: C:\Windows\Tasks\AVG-SSU_0616tb_DELETE.job => C:\ProgramData\Avg_Update_0616tb\AVG-Secure-Search-Update_0616tb.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001Core.job => C:\Users\Dorota\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001UA.job => C:\Users\Dorota\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001Core.job => C:\Users\Dorota\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3512223367-1628738116-3398761023-1001UA.job => C:\Users\Dorota\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\{4C50AACB-A010-9E86-8F74-0171D192AFB8}.job => C:\Users\Dorota\AppData\Roaming\{4C50A~1\SYNCVE~1.EXE <==== UWAGA ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\Dorota\AppData\Local\Eastness\User Data\Program uruchamiający aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list ShortcutWithArgument: C:\Users\Dorota\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\5d696d521de238c3\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default ==================== Załadowane moduły (filtrowane) ============== 2015-05-15 15:26 - 2015-05-15 15:26 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-05-15 15:26 - 2015-05-15 15:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2009-11-12 13:48 - 2009-11-12 13:48 - 00071096 _____ () C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe 2016-11-22 08:02 - 2016-11-08 22:03 - 02367080 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libglesv2.dll 2016-11-22 08:02 - 2016-11-08 22:03 - 00107112 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libegl.dll 2016-11-20 17:32 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2016-11-20 17:32 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2016-11-20 17:32 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2016-11-20 17:32 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2016-11-20 17:32 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2016-11-12 02:56 - 2016-10-10 17:29 - 00035792 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd 2016-11-12 02:58 - 2016-10-10 17:29 - 00145864 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\pyexpat.pyd 2016-11-12 02:58 - 2016-10-10 17:29 - 00019408 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\faulthandler.pyd 2016-11-12 02:58 - 2016-10-10 17:29 - 00116688 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\pywintypes27.dll 2016-11-12 02:56 - 2016-10-10 17:29 - 00100296 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\_ctypes.pyd 2016-11-12 02:56 - 2016-10-10 17:29 - 00018888 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\select.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00019760 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd 2016-11-12 02:56 - 2016-10-10 17:29 - 00694224 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\unicodedata.pyd 2016-11-12 02:58 - 2016-11-07 23:58 - 00020816 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd 2016-11-12 02:56 - 2016-10-10 17:30 - 00123856 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd 2016-11-12 02:58 - 2016-11-07 23:58 - 01682760 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd 2016-11-12 02:58 - 2016-11-07 23:58 - 00020808 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00105928 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32api.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00021312 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00052024 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00038696 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\fastpath.pyd 2016-11-12 02:58 - 2016-10-10 17:29 - 00392144 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\pythoncom27.dll 2016-11-12 02:58 - 2016-10-10 17:31 - 00020936 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\mmapfile.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00024528 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32event.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00116176 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32security.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00381752 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00124880 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32file.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00025424 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00024016 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32clipboard.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00175560 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32gui.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00030160 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32pipe.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00043472 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32process.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00048592 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32service.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00057808 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32evtlog.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00024016 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32profile.pyd 2016-11-12 02:58 - 2016-11-07 23:58 - 00246592 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00026456 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-11-12 02:56 - 2016-10-10 17:30 - 00241104 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\_jpegtran.pyd 2016-11-12 02:58 - 2016-11-07 23:58 - 00020280 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00028616 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32ts.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00023376 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00020800 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00019776 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00020800 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00350152 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winxpgui.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00022352 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00024392 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd 2016-11-12 02:58 - 2016-10-10 17:27 - 00036296 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\librsync.dll 2016-11-12 02:58 - 2016-11-07 23:59 - 00084280 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2016-11-12 02:58 - 2016-11-07 23:59 - 01826096 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd 2016-11-12 02:56 - 2016-10-10 17:29 - 00083912 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\sip.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00531248 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 03928880 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 01972528 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00133424 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00224056 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00207672 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00020288 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winffi.user32._winffi_user32.pyd 2016-11-12 02:58 - 2016-10-10 17:33 - 00017864 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\libEGL.dll 2016-11-12 02:58 - 2016-10-10 17:34 - 01631184 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2016-11-12 02:58 - 2016-11-07 23:59 - 00042808 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00168760 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00357680 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd 2016-11-12 02:56 - 2016-10-10 17:31 - 00060880 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\win32print.pyd 2016-11-12 02:56 - 2016-11-07 23:59 - 00024904 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd 2016-11-12 02:58 - 2016-11-07 23:59 - 00546096 _____ () C:\Users\Dorota\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd 2011-01-17 15:19 - 2012-06-12 13:12 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== Powiązania plików (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com Wykryto więcej niż wyliczono: 7916 witryn. IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\...\123simsen.com -> www.123simsen.com Wykryto więcej niż wyliczono: 7916 witryn. ==================== Hosts - zawartość: ========================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 03:34 - 2016-11-20 17:49 - 00453374 ___RA C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123haustiereundmehr.com 127.0.0.1 123moviedownload.com 127.0.0.1 www.123moviedownload.com Wykryto więcej niż wyliczono: 15558 linii. ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-3512223367-1628738116-3398761023-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Dorota\Pictures\life_saver.bmp DNS Servers: 188.127.0.41 - 208.67.220.220 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk => C:\Windows\pss\Bluetooth Manager.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Dorota^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: 00TCrdMain => %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: ALLUpdate => "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: avast5 => "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui MSCONFIG\startupreg: CardDetectorICON225 => C:\Program Files (x86)\CardDetector\ICON225\CardDetector.exe MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: Dropbox Update => "C:\Users\Dorota\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c MSCONFIG\startupreg: Facebook Update => "C:\Users\Dorota\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: HWSetup => "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP MSCONFIG\startupreg: IPLA! => C:\Program Files (x86)\ipla\ipla.exe /autorun MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KeNotify => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe MSCONFIG\startupreg: mcagent_exe => C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe /runkey MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: RayV => C:\Program Files (x86)\RayV\RayV\RayV.exe /background MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized MSCONFIG\startupreg: SmartFaceVWatcher => %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe MSCONFIG\startupreg: SmoothView => %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SVPWUTIL => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: Teco => "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r MSCONFIG\startupreg: TOSHIBA Online Product Information => C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe MSCONFIG\startupreg: Toshiba Registration => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe MSCONFIG\startupreg: Toshiba TEMPRO => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe MSCONFIG\startupreg: TosNC => %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe MSCONFIG\startupreg: TosReelTimeMonitor => %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe MSCONFIG\startupreg: TosSENotify => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe MSCONFIG\startupreg: TosWaitSrv => %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe MSCONFIG\startupreg: TPwrMain => %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Punkty Przywracania systemu ========================= 20-11-2016 03:22:41 Zaplanowany punkt kontrolny 20-11-2016 04:03:01 Windows Defender Checkpoint 20-11-2016 19:00:09 Kopia zapasowa systemu Windows ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (11/20/2016 04:25:00 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla „c:\users\dorota\appdata\local\microsoft\windows\temporary internet files\content.ie5\4qku8cpm\esetsmartinstaller_plk.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu . Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna. Składniki powodujące konflikt: Składnik 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Składnik 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (11/20/2016 04:03:01 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas badania interfejsu IVssWriterCallback. hr = 0x80070005, Odmowa dostępu. . To jest często spowodowane przez niepoprawne ustawienia zabezpieczeń w procesie zapisującym lub żądającym. Operacja: Zbieranie danych modułu zapisującego Kontekst: Identyfikator klasy modułu zapisującego: {e8132975-6f93-4464-a53e-1050253ae220} Nazwa modułu zapisującego: System Writer Identyfikator wystąpienia modułu zapisującego: {0d1f6a05-7445-4dbd-9492-374a94b55d09} Error: (11/20/2016 12:00:08 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla „C:\Users\Dorota\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QKU8CPM\esetsmartinstaller_plk.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu . Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna. Składniki powodujące konflikt: Składnik 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Składnik 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (11/19/2016 11:59:54 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla „C:\Users\Dorota\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4QKU8CPM\esetsmartinstaller_plk.exe”. Błąd w pliku manifestu lub w pliku zasad „” w wierszu . Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna. Składniki powodujące konflikt: Składnik 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Składnik 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (11/19/2016 11:04:12 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program adwcleaner_6.030.exe w wersji 6.0.3.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: bd4 Godzina rozpoczęcia: 01d242aff448f726 Godzina zakończenia: 0 Ścieżka aplikacji: C:\Users\Dorota\Desktop\adwcleaner_6.030.exe Identyfikator raportu: 13dd2eda-aea4-11e6-be94-0026224855a4 Error: (11/19/2016 10:49:00 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program adwcleaner_6.030.exe w wersji 6.0.3.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 72c Godzina rozpoczęcia: 01d242ae17be3962 Godzina zakończenia: 0 Ścieżka aplikacji: C:\Users\Dorota\Desktop\adwcleaner_6.030.exe Identyfikator raportu: f788c31d-aea1-11e6-a46d-0026224855a4 Error: (11/19/2016 10:10:31 PM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: Nie można zainicjować indeksu. Szczegóły: Wykaz indeksów zawartości jest uszkodzony. (HRESULT : 0xc0041801) (0xc0041801) Error: (11/19/2016 10:10:31 PM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: Nie można zainicjować aplikacji. Kontekst: aplikacja Windows Szczegóły: Wykaz indeksów zawartości jest uszkodzony. (HRESULT : 0xc0041801) (0xc0041801) Error: (11/19/2016 10:10:31 PM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: Nie można zainicjować obiektu programu zbierającego. Kontekst: aplikacja Windows, wykaz SystemIndex Szczegóły: Wykaz indeksów zawartości jest uszkodzony. (HRESULT : 0xc0041801) (0xc0041801) Error: (11/19/2016 10:10:31 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: Nie można zainicjować dodatku typu plug-in w . Kontekst: aplikacja Windows, wykaz SystemIndex Szczegóły: Nie można odnaleźć elementu. (HRESULT : 0x80070490) (0x80070490) Dziennik System: ============= Error: (11/22/2016 08:35:38 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: amqhvhs Error: (11/22/2016 08:34:58 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (11/22/2016 08:34:58 AM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (11/22/2016 08:15:07 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Application Virtualization Client niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (11/22/2016 08:15:04 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Ochrona oprogramowania niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/22/2016 08:15:04 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Instalator modułów systemu Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/22/2016 08:15:03 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa ConfigFree Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (11/22/2016 08:15:03 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa ConfigFree WiMAX Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (11/22/2016 08:15:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Usługa udostępniania w sieci programu Windows Media Player niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/22/2016 08:15:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz Procent pamięci w użyciu: 41% Całkowita pamięć fizyczna: 4060.88 MB Dostępna pamięć fizyczna: 2376.54 MB Całkowita pamięć wirtualna: 8119.93 MB Dostępna pamięć wirtualna: 6339.3 MB ==================== Dyski ================================ Drive c: (WINDOWS) (Fixed) (Total:149.04 GB) (Free:8.69 GB) NTFS Drive d: (Data) (Fixed) (Total:148.65 GB) (Free:19.1 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: A2882F0C) Partition 1: (Active) - (Size=400 MB) - (Type=27) Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=148.7 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ============================