grant322 Opublikowano 9 Listopada Zgłoś Udostępnij Opublikowano 9 Listopada (edytowane) Dzień dobry Po uruchomieniu losowo pojawia się komunikat : "Program RdrServices2_x86.exe przestał działać." Nie zauważyłem by komputer zwolnił. Nie używam żadnego antywirusa. Proszę o opinie i sugestię. FRST_01-11-2024 20.18.46.txt Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 29-10-2024 Uruchomiony przez pysiol (administrator) PYSIOL-KOMPUTER (Sony Corporation VGN-NS21Z_S) (01-11-2024 20:15:08) Uruchomiony z C:\Users\pysiol\Downloads\FRST64.exe Załadowane profile: pysiol Platforma: Microsoft Windows 7 Ultimate Service Pack 1 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) () <==== UWAGA [zerobajtowy? (Błąd=3)] C:\Program Files\Mozilla Firefox\updated\firefox.exe <28> (atiesrxx.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe (C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\68.0.2.0\crashpad_handler.exe <4> (explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe <7> (explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\taskmgr.exe (explorer.exe ->) (voidtools -> voidtools) C:\Program Files\Everything\Everything.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (services.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (services.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Sony Corporation -> Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe Brak dostępu do procesu -> csrss.exe Brak dostępu do procesu -> csrss.exe Brak dostępu do procesu -> dllhost.exe Brak dostępu do procesu -> dllhost.exe Brak dostępu do procesu -> taskhost.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2240288 2019-02-04] (voidtools -> voidtools) HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKU\S-1-5-21-804025988-211181761-413787009-1000\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKU\S-1-5-21-804025988-211181761-413787009-1000\...\MountPoints2: {27bc6b00-eca5-11e1-89ce-001dbaaf1495} - F:\autorun.EXE HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKLM\...\Windows x64\Print Processors\hpzppWN7: C:\Windows\System32\spool\prtprocs\x64\hpzppWN7.dll [101376 2009-07-14] (Microsoft Windows -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\Bullzip PDF Print Monitor: C:\Windows\system32\bzpdf.dll [218624 2013-02-25] (Bullzip) [Brak podpisu cyfrowego] HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.120\Installer\chrmstp.exe [2008-01-01] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll",CreateReaderUserSettings ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {8A0006DD-E7C3-48D7-A11F-6A305F89E03B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1574856 2024-09-25] (Adobe Inc. -> Adobe Inc.) Task: {072BB159-A673-4D55-B84A-C1A5CEA30A64} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_293_Plugin.exe [1457720 2019-11-13] (Adobe Inc. -> Adobe) Task: {B36607BE-CBAD-4380-A434-0A30939B4F74} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe) Task: {D3EA5758-9075-43B2-A5CC-3C8ED34229B0} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe [647168 2012-07-16] () [Brak podpisu cyfrowego] Task: {D78F0346-E089-47F9-80C6-BE9DB7A4BA5C} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe [647168 2012-07-16] () [Brak podpisu cyfrowego] Task: {13298B14-5A65-41A2-848B-2B63253B3BA4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [3113312 2012-08-22] (Piriform Ltd -> Piriform Ltd) Task: {1534D2F0-684C-4DF9-967C-4F86F75A6DDE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {247960AE-2313-4311-A068-1309A33A06D2} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e9dd8579043 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {665D830F-F71F-47F2-9AF1-5BD7E8C3DDBF} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ab7f4e9eb527 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {93A2FCE4-BD43-4EA1-81B4-CE22CBEE68BC} - System32\Tasks\GoogleUpdateTaskMachineCore1d1eb5823270fee => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {94915A4C-2CCC-495C-8C82-2018689A7D42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {679283B8-5DF6-46E5-B46D-64FD489541A0} - System32\Tasks\GoogleUpdateTaskMachineUA1d15e9dd88bc067 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {EBBE3412-4076-4D07-A90C-A0125F6A42F9} - System32\Tasks\GoogleUpdateTaskMachineUA1d1ab7f4ecacedc => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {157EEC6C-54BA-4338-A8F1-BC9187D18328} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [684608 2024-11-01] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e9dd8579043.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab7f4e9eb527.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15e9dd88bc067.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 178.235.153.33 178.235.153.32 Tcpip\..\Interfaces\{17396F7C-6526-4E4C-A2FE-80C7EB217865}: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}: [DhcpNameServer] 178.235.153.33 178.235.153.32 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\05340574: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\14E64627F6964614050727A756D6F6: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\655636472716D275966496D2442483734343F5548545: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\655636472716D275966496D2442483734343F5548545: [DhcpDomain] TL-WA854RE Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\762716E647: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\762716E64723: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\845514755494D224533353D293731343: [DhcpNameServer] 192.168.8.1 Tcpip\..\Interfaces\{BA7290BD-F4E1-47EF-B7DB-BB68B3FAB700}: [DhcpNameServer] 192.168.42.129 HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,10.0.0.1,-1] FireFox: ======== FF DefaultProfile: 62n1d2sh.default FF ProfilePath: C:\Users\pysiol\AppData\Roaming\TomTom\HOME\Profiles\vcv1zphh.default [2012-11-06] FF Extension: (Brak nazwy) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [nie znaleziono] FF ProfilePath: C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\lq18snfm.default-esr [2024-11-01] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\lq18snfm.default-esr\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-11-01] FF ProfilePath: C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default [2024-02-25] FF DownloadDir: C:\Users\pysiol\Downloads FF Session Restore: Mozilla\Firefox\Profiles\62n1d2sh.default -> [funkcja włączona] FF Notifications: Mozilla\Firefox\Profiles\62n1d2sh.default -> hxxps://photos.google.com FF Extension: (YouTube Video Downloader/YouTube HD Download) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\youtubedownloader@youtubedownloadvideo1clickgroup.com.xpi [2023-06-13] FF Extension: (YouTube High Definition) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2023-05-09] FF Extension: (Video DownloadHelper) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2024-02-25] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-02-08] FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] [Przestarzałe] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2019-11-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2019-11-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2024-10-01] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default [2024-10-31] CHR DownloadDir: D:\Pobieranie CHR Notifications: Default -> hxxps://web.telegram.org; hxxps://www.bankmillennium.pl; hxxps://www.bzwbk.pl; hxxps://www.empikfoto.pl; hxxps://www.ingbank.pl CHR Session Restore: Default -> [funkcja włączona] CHR Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2024-04-14] CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-10-31] CHR Extension: (Dokumenty Google offline) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-06-13] CHR Extension: (Magic Enhancer For YouTube™) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2020-02-05] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-12] CHR Profile: C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\System Profile [2021-04-22] CHR HKU\S-1-5-21-804025988-211181761-413787009-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] Brave: ======= StartMenuInternet: Brave - ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-09-25] (Adobe Inc. -> Adobe Inc.) S4 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe) S4 DroidExplorerService; C:\Program Files\Droid Explorer\DroidExplorer.Service.exe [254976 2013-08-25] (Ryan Conrad) [Brak podpisu cyfrowego] S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG -> Nero AG) S3 ss_conn_launcher_service; C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe [182328 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13109776 2020-07-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) S2 .EsetTrialReset; C:\Windows\system32\regedt32.exe /s C:\Windows\esettrialreset.reg ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 ampa; C:\Windows\system32\ampa.sys [17008 2013-12-18] (ChengDu AoMei Tech Co., Ltd -> ) [Brak podpisu cyfrowego] R3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [6037504 2009-08-18] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.) S1 DMICall; C:\Windows\SysWOW64\DRIVERS\DMICall.sys [10216 2008-11-24] (Sony Corporation -> Sony Corporation) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET, spol. s r.o. -> ESET) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET, spol. s r.o. -> ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 googledrivefs3758; C:\Windows\System32\DRIVERS\googledrivefs3758.sys [386632 2022-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.) S3 mpfilt; C:\Windows\SysWOW64\drivers\mpfilt.sys [10588 2010-05-17] () [Brak podpisu cyfrowego] S3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Nokia) R2 rimsptsk; C:\Windows\System32\DRIVERS\rimspx64.sys [55296 2009-06-25] (Microsoft Windows Hardware Compatibility Publisher -> REDC) S2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc. -> SafeNet, Inc.) R3 SFEP; C:\Windows\System32\DRIVERS\SFEP.sys [12032 2010-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Sony Corporation) S3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [63568 2012-12-11] (SafeNet, Inc. -> SafeNet, Inc.) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-08-22] (Duplex Secure Ltd -> Duplex Secure Ltd.) R3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) R3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) R3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166760 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [43368 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2015-01-28] (Microsoft Windows Hardware Compatibility Publisher -> RealVNC Ltd.) S0 audas0; system32\DRIVERS\audas0.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2024-11-01 12:15 - 2024-11-01 12:18 - 000041127 _____ C:\Users\pysiol\Downloads\Addition.txt 2024-11-01 12:14 - 2024-11-01 20:15 - 000021609 _____ C:\Users\pysiol\Downloads\FRST.txt 2024-11-01 12:14 - 2024-11-01 20:15 - 000000000 ____D C:\FRST 2024-11-01 12:14 - 2024-11-01 12:14 - 002397696 _____ (Farbar) C:\Users\pysiol\Downloads\FRST64.exe 2024-11-01 11:01 - 2024-11-01 12:01 - 000000000 ____D C:\Program Files\Mozilla Firefox ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2024-11-01 12:47 - 2015-12-24 01:07 - 000000000 ____D C:\Program Files (x86)\Google 2024-11-01 12:08 - 2016-08-11 20:03 - 000000000 ____D C:\Users\pysiol\AppData\Roaming\Everything 2024-11-01 12:02 - 2022-02-20 22:38 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2024-11-01 12:01 - 2012-09-08 11:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2024-11-01 11:12 - 2017-12-17 15:10 - 000000000 ____D C:\Users\pysiol\AppData\Local\CrashDumps 2024-11-01 11:08 - 2009-07-14 05:45 - 000023760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2024-11-01 11:08 - 2009-07-14 05:45 - 000023760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2024-11-01 10:54 - 2019-07-25 18:29 - 000002740 _____ C:\Windows\system32\Tasks\AutoKMSDaily 2024-11-01 10:54 - 2019-07-25 18:29 - 000000202 _____ C:\Windows\Tasks\AutoKMSDaily.job 2024-11-01 10:54 - 2012-07-16 11:45 - 000000202 _____ C:\Windows\Tasks\AutoKMS.job 2024-11-01 10:54 - 2012-07-16 11:44 - 000078848 _____ C:\Windows\KMSEmulator.exe 2024-11-01 10:53 - 2013-11-01 13:39 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2024-11-01 10:53 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2024-10-31 10:27 - 2019-11-29 17:15 - 000000000 ____D C:\Users\pysiol\AppData\Local\Everything 2024-10-31 10:24 - 2015-05-12 20:41 - 000004476 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task 2024-10-31 10:23 - 2012-08-13 21:28 - 000000000 ____D C:\Users\pysiol\AppData\Roaming\Microsoft\Word 2024-10-23 12:11 - 2013-08-03 08:32 - 000000000 ____D C:\Windows\system32\MRT 2024-10-23 12:11 - 2012-07-16 16:02 - 201324920 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2024-10-23 10:41 - 2024-09-05 09:16 - 000000000 ____D C:\Users\pysiol\Desktop\do CV Kamila 2024-10-23 10:11 - 2022-10-17 11:25 - 000002025 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk ==================== Pliki w katalogu głównym wybranych folderów ======== 2013-10-26 20:35 - 2013-10-26 20:35 - 000068124 _____ () C:\Program Files (x86)\hminstalllog.txt 2012-09-07 21:06 - 2012-09-07 22:36 - 000099384 _____ () C:\Users\pysiol\AppData\Roaming\inst.exe 2012-09-07 21:06 - 2012-09-07 22:36 - 000007859 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.cat 2012-09-07 21:06 - 2012-09-07 22:36 - 000001167 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.inf 2012-09-07 21:06 - 2012-09-07 22:36 - 000000055 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.log 2012-09-07 21:06 - 2012-09-07 22:36 - 000082816 _____ (VSO Software) C:\Users\pysiol\AppData\Roaming\pcouffin.sys 2018-07-25 09:17 - 2018-07-25 09:17 - 000000107 ___SH () C:\Users\pysiol\AppData\Roaming\winuptstart.bat 2015-05-23 00:41 - 2015-05-23 00:41 - 000000001 _____ () C:\Users\pysiol\AppData\Local\llftool.4.40.agreement 2017-10-31 21:35 - 2017-10-31 22:19 - 000000600 _____ () C:\Users\pysiol\AppData\Local\PUTTY.RND 2014-02-18 17:29 - 2014-02-18 17:29 - 000002436 _____ () C:\Users\pysiol\AppData\Local\recently-used.xbel 2016-09-05 22:44 - 2020-04-07 19:42 - 000007601 _____ () C:\Users\pysiol\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) LastRegBack: 2024-10-23 11:14 ==================== Koniec FRST.txt ======================== ---Edit--- Zrobiłem reinstall Adobe reader i póki co problem zniknął. Aktualne logi FRST: Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 08-11-2024 01 Uruchomiony przez pysiol (administrator) PYSIOL-KOMPUTER (Sony Corporation VGN-NS21Z_S) (09-11-2024 10:28:59) Uruchomiony z C:\Users\pysiol\Downloads\FRST64.exe Załadowane profile: pysiol Platforma: Microsoft Windows 7 Ultimate Service Pack 1 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (atiesrxx.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe (C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\68.0.2.0\crashpad_handler.exe <2> (explorer.exe ->) (voidtools -> voidtools) C:\Program Files\Everything\Everything.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10> (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (services.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (services.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Sony Corporation -> Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2240288 2019-02-04] (voidtools -> voidtools) HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKU\S-1-5-21-804025988-211181761-413787009-1000\...\MountPoints2: {27bc6b00-eca5-11e1-89ce-001dbaaf1495} - F:\autorun.EXE HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKLM\...\Windows x64\Print Processors\hpzppWN7: C:\Windows\System32\spool\prtprocs\x64\hpzppWN7.dll [101376 2009-07-14] (Microsoft Windows -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\Bullzip PDF Print Monitor: C:\Windows\system32\bzpdf.dll [218624 2013-02-25] (Bullzip) [Brak podpisu cyfrowego] HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.120\Installer\chrmstp.exe [2008-01-01] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {77BBCD93-D1BA-4F2C-BD77-206D3B0196C5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1563080 2024-07-31] (Adobe Inc. -> Adobe Inc.) Task: {072BB159-A673-4D55-B84A-C1A5CEA30A64} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_293_Plugin.exe [1457720 2019-11-13] (Adobe Inc. -> Adobe) Task: {B36607BE-CBAD-4380-A434-0A30939B4F74} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe) Task: {D3EA5758-9075-43B2-A5CC-3C8ED34229B0} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe [647168 2012-07-16] () [Brak podpisu cyfrowego] Task: {D78F0346-E089-47F9-80C6-BE9DB7A4BA5C} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe [647168 2012-07-16] () [Brak podpisu cyfrowego] Task: {13298B14-5A65-41A2-848B-2B63253B3BA4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [3113312 2012-08-22] (Piriform Ltd -> Piriform Ltd) Task: {1534D2F0-684C-4DF9-967C-4F86F75A6DDE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {247960AE-2313-4311-A068-1309A33A06D2} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e9dd8579043 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {665D830F-F71F-47F2-9AF1-5BD7E8C3DDBF} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ab7f4e9eb527 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {93A2FCE4-BD43-4EA1-81B4-CE22CBEE68BC} - System32\Tasks\GoogleUpdateTaskMachineCore1d1eb5823270fee => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {94915A4C-2CCC-495C-8C82-2018689A7D42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {679283B8-5DF6-46E5-B46D-64FD489541A0} - System32\Tasks\GoogleUpdateTaskMachineUA1d15e9dd88bc067 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {EBBE3412-4076-4D07-A90C-A0125F6A42F9} - System32\Tasks\GoogleUpdateTaskMachineUA1d1ab7f4ecacedc => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {157EEC6C-54BA-4338-A8F1-BC9187D18328} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [684608 2024-11-01] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e9dd8579043.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab7f4e9eb527.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15e9dd88bc067.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 178.235.153.33 178.235.153.32 Tcpip\..\Interfaces\{17396F7C-6526-4E4C-A2FE-80C7EB217865}: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}: [DhcpNameServer] 178.235.153.33 178.235.153.32 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\05340574: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\14E64627F6964614050727A756D6F6: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\655636472716D275966496D2442483734343F5548545: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\655636472716D275966496D2442483734343F5548545: [DhcpDomain] TL-WA854RE Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\762716E647: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\762716E64723: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\845514755494D224533353D293731343: [DhcpNameServer] 192.168.8.1 Tcpip\..\Interfaces\{BA7290BD-F4E1-47EF-B7DB-BB68B3FAB700}: [DhcpNameServer] 192.168.42.129 HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,10.0.0.1,-1] FireFox: ======== FF DefaultProfile: 62n1d2sh.default FF ProfilePath: C:\Users\pysiol\AppData\Roaming\TomTom\HOME\Profiles\vcv1zphh.default [2012-11-06] FF Extension: (Brak nazwy) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [nie znaleziono] FF ProfilePath: C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\lq18snfm.default-esr [2024-11-09] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\lq18snfm.default-esr\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-11-09] FF ProfilePath: C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default [2024-02-25] FF DownloadDir: C:\Users\pysiol\Downloads FF Session Restore: Mozilla\Firefox\Profiles\62n1d2sh.default -> [funkcja włączona] FF Notifications: Mozilla\Firefox\Profiles\62n1d2sh.default -> hxxps://photos.google.com FF Extension: (YouTube Video Downloader/YouTube HD Download) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\youtubedownloader@youtubedownloadvideo1clickgroup.com.xpi [2023-06-13] FF Extension: (YouTube High Definition) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2023-05-09] FF Extension: (Video DownloadHelper) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2024-02-25] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-02-08] FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] [Przestarzałe] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2019-11-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2019-11-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2024-09-07] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default [2024-10-31] CHR DownloadDir: D:\Pobieranie CHR Notifications: Default -> hxxps://web.telegram.org; hxxps://www.bankmillennium.pl; hxxps://www.bzwbk.pl; hxxps://www.empikfoto.pl; hxxps://www.ingbank.pl CHR Session Restore: Default -> [funkcja włączona] CHR Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2024-04-14] CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-10-31] CHR Extension: (Dokumenty Google offline) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-06-13] CHR Extension: (Magic Enhancer For YouTube™) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2020-02-05] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-12] CHR Profile: C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\System Profile [2021-04-22] CHR HKU\S-1-5-21-804025988-211181761-413787009-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKU\S-1-5-21-804025988-211181761-413787009-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] Brave: ======= StartMenuInternet: Brave - ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-07-31] (Adobe Inc. -> Adobe Inc.) S4 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe) S4 DroidExplorerService; C:\Program Files\Droid Explorer\DroidExplorer.Service.exe [254976 2013-08-25] (Ryan Conrad) [Brak podpisu cyfrowego] S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG -> Nero AG) S3 ss_conn_launcher_service; C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe [182328 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13109776 2020-07-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) S2 .EsetTrialReset; C:\Windows\system32\regedt32.exe /s C:\Windows\esettrialreset.reg ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 ampa; C:\Windows\system32\ampa.sys [17008 2013-12-18] (ChengDu AoMei Tech Co., Ltd -> ) [Brak podpisu cyfrowego] R3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [6037504 2009-08-18] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.) S1 DMICall; C:\Windows\SysWOW64\DRIVERS\DMICall.sys [10216 2008-11-24] (Sony Corporation -> Sony Corporation) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET, spol. s r.o. -> ESET) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET, spol. s r.o. -> ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 googledrivefs3758; C:\Windows\System32\DRIVERS\googledrivefs3758.sys [386632 2022-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.) S3 mpfilt; C:\Windows\SysWOW64\drivers\mpfilt.sys [10588 2010-05-17] () [Brak podpisu cyfrowego] S3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Nokia) R2 rimsptsk; C:\Windows\System32\DRIVERS\rimspx64.sys [55296 2009-06-25] (Microsoft Windows Hardware Compatibility Publisher -> REDC) S2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc. -> SafeNet, Inc.) R3 SFEP; C:\Windows\System32\DRIVERS\SFEP.sys [12032 2010-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Sony Corporation) S3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [63568 2012-12-11] (SafeNet, Inc. -> SafeNet, Inc.) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-08-22] (Duplex Secure Ltd -> Duplex Secure Ltd.) R3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) R3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) R3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166760 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [43368 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2015-01-28] (Microsoft Windows Hardware Compatibility Publisher -> RealVNC Ltd.) S0 audas0; system32\DRIVERS\audas0.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2024-11-09 10:28 - 2024-11-09 10:28 - 000000000 ____D C:\Users\pysiol\Downloads\FRST-OlderVersion 2024-11-09 10:20 - 2024-11-09 10:20 - 000095362 _____ C:\Users\pysiol\Documents\cc_20241109_102016.reg 2024-11-09 10:09 - 2024-11-09 10:09 - 000000000 ____D C:\ProgramData\Adobe 2024-11-09 10:08 - 2024-11-09 10:08 - 000004476 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task 2024-11-09 10:07 - 2024-11-09 10:07 - 000002025 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk 2024-11-09 10:07 - 2024-11-09 10:07 - 000002013 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk 2024-11-09 10:03 - 2024-11-09 10:03 - 357631392 _____ (Adobe Systems Incorporated) C:\Users\pysiol\Downloads\AcroRdrDC2400320112_pl_PL.exe 2024-11-01 12:15 - 2024-11-01 20:18 - 000040892 _____ C:\Users\pysiol\Downloads\Addition.txt 2024-11-01 12:14 - 2024-11-09 10:29 - 000021113 _____ C:\Users\pysiol\Downloads\FRST.txt 2024-11-01 12:14 - 2024-11-09 10:29 - 000000000 ____D C:\FRST 2024-11-01 12:14 - 2024-11-09 10:28 - 002399744 _____ (Farbar) C:\Users\pysiol\Downloads\FRST64.exe 2024-11-01 11:01 - 2024-11-03 19:27 - 000000000 ____D C:\Program Files\Mozilla Firefox ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2024-11-09 10:25 - 2022-02-20 22:38 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2024-11-09 10:25 - 2015-12-24 01:07 - 000000000 ____D C:\Program Files (x86)\Google 2024-11-09 10:23 - 2019-11-29 17:15 - 000000000 ____D C:\Users\pysiol\AppData\Local\Everything 2024-11-09 10:23 - 2019-07-25 18:29 - 000002740 _____ C:\Windows\system32\Tasks\AutoKMSDaily 2024-11-09 10:23 - 2019-07-25 18:29 - 000000202 _____ C:\Windows\Tasks\AutoKMSDaily.job 2024-11-09 10:23 - 2016-08-11 20:03 - 000000000 ____D C:\Users\pysiol\AppData\Roaming\Everything 2024-11-09 10:23 - 2013-11-01 13:39 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2024-11-09 10:23 - 2012-07-16 11:45 - 000000202 _____ C:\Windows\Tasks\AutoKMS.job 2024-11-09 10:23 - 2012-07-16 11:44 - 000078848 _____ C:\Windows\KMSEmulator.exe 2024-11-09 10:23 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2024-11-09 10:21 - 2009-07-14 05:45 - 000023760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2024-11-09 10:21 - 2009-07-14 05:45 - 000023760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2024-11-09 10:19 - 2017-12-17 15:10 - 000000000 ____D C:\Users\pysiol\AppData\Local\CrashDumps 2024-11-09 10:19 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf 2024-11-03 19:27 - 2012-09-08 11:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2024-10-31 10:23 - 2012-08-13 21:28 - 000000000 ____D C:\Users\pysiol\AppData\Roaming\Microsoft\Word 2024-10-23 12:11 - 2013-08-03 08:32 - 000000000 ____D C:\Windows\system32\MRT 2024-10-23 12:11 - 2012-07-16 16:02 - 201324920 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2024-10-23 10:41 - 2024-09-05 09:16 - 000000000 ____D C:\Users\pysiol\Desktop\do CV Kamila ==================== Pliki w katalogu głównym wybranych folderów ======== 2013-10-26 20:35 - 2013-10-26 20:35 - 000068124 _____ () C:\Program Files (x86)\hminstalllog.txt 2012-09-07 21:06 - 2012-09-07 22:36 - 000099384 _____ () C:\Users\pysiol\AppData\Roaming\inst.exe 2012-09-07 21:06 - 2012-09-07 22:36 - 000007859 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.cat 2012-09-07 21:06 - 2012-09-07 22:36 - 000001167 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.inf 2012-09-07 21:06 - 2012-09-07 22:36 - 000000055 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.log 2012-09-07 21:06 - 2012-09-07 22:36 - 000082816 _____ (VSO Software) C:\Users\pysiol\AppData\Roaming\pcouffin.sys 2018-07-25 09:17 - 2018-07-25 09:17 - 000000107 ___SH () C:\Users\pysiol\AppData\Roaming\winuptstart.bat 2015-05-23 00:41 - 2015-05-23 00:41 - 000000001 _____ () C:\Users\pysiol\AppData\Local\llftool.4.40.agreement 2017-10-31 21:35 - 2017-10-31 22:19 - 000000600 _____ () C:\Users\pysiol\AppData\Local\PUTTY.RND 2014-02-18 17:29 - 2014-02-18 17:29 - 000002436 _____ () C:\Users\pysiol\AppData\Local\recently-used.xbel 2016-09-05 22:44 - 2020-04-07 19:42 - 000007601 _____ () C:\Users\pysiol\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) LastRegBack: 2024-10-23 11:14 ==================== Koniec FRST.txt ======================== Edytowane 9 Listopada przez grant322 reinstall Adobe Reader Odnośnik do komentarza
Illidan Opublikowano 10 Listopada Zgłoś Udostępnij Opublikowano 10 Listopada Cześć RdrServices2_x86.exe to plik wykonywalny, który zwykle jest częścią oprogramowania, które może być związane z usługami lub funkcjami druku. Może on być używany w kontekście różnych aplikacji, w tym oprogramowania do zarządzania drukarkami lub rozwiązań do zdalnego drukowania. Może on być używany w kontekście różnych aplikacji, w tym oprogramowania do zarządzania drukarkami lub rozwiązań do zdalnego drukowania. Może wspierać integrację z oprogramowaniem do zarządzania dokumentami lub innymi aplikacjami. Ważne jest, aby sprawdzić ścieżkę pliku oraz jego pochodzenie, , niektóre złośliwe oprogramowania mogą przybierać nazwy podobne do legalnych plików systemowych. Więc bardzo prawdopodobne, że aktualizacja Adobe właśnie naprawiła problem. Co do logów, to dostarcz ich komplet do analizy, sam FRST to za mało. Jeszcze zamieść "Addition.txt" i opcjonalnie "Shortcut.txt". Dobrze by było abyś w razie czego zaktualizował wszystkie programy w Windows i sam system, o ile są jakieś aktualizacje do pobrania. Do aktualizacji oprogramowania w systemie, możesz użyć takich aplikacji jak darmowy "PatchmyPc" czy "UnCheck". Odnośnik do komentarza
grant322 Opublikowano 10 Listopada Autor Zgłoś Udostępnij Opublikowano 10 Listopada Załączam aktualne logi: FRST Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 09-11-2024 Uruchomiony przez pysiol (administrator) PYSIOL-KOMPUTER (Sony Corporation VGN-NS21Z_S) (10-11-2024 13:06:53) Uruchomiony z C:\Users\pysiol\Downloads\FRST64.exe Załadowane profile: pysiol & postgres Platforma: Microsoft Windows 7 Ultimate Service Pack 1 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (atiesrxx.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe (C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\68.0.2.0\crashpad_handler.exe <2> (explorer.exe ->) (voidtools -> voidtools) C:\Program Files\Everything\Everything.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <19> (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe <2> (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (services.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (services.exe ->) (Sony Corporation -> Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Sony Corporation -> Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2240288 2019-02-04] (voidtools -> voidtools) HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKU\S-1-5-21-804025988-211181761-413787009-1000\...\MountPoints2: {27bc6b00-eca5-11e1-89ce-001dbaaf1495} - F:\autorun.EXE HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe [50728728 2008-01-01] (Google LLC -> Google, Inc.) HKLM\...\Windows x64\Print Processors\hpzppWN7: C:\Windows\System32\spool\prtprocs\x64\hpzppWN7.dll [101376 2009-07-14] (Microsoft Windows -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\Bullzip PDF Print Monitor: C:\Windows\system32\bzpdf.dll [218624 2013-02-25] (Bullzip) [Brak podpisu cyfrowego] HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\109.0.5414.120\Installer\chrmstp.exe [2008-01-01] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {58CB2152-FF98-4BE6-9E4B-37FB29678932} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1574856 2024-09-25] (Adobe Inc. -> Adobe Inc.) Task: {072BB159-A673-4D55-B84A-C1A5CEA30A64} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_293_Plugin.exe [1457720 2019-11-13] (Adobe Inc. -> Adobe) Task: {B36607BE-CBAD-4380-A434-0A30939B4F74} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe) Task: {D3EA5758-9075-43B2-A5CC-3C8ED34229B0} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe [647168 2012-07-16] () [Brak podpisu cyfrowego] Task: {D78F0346-E089-47F9-80C6-BE9DB7A4BA5C} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe [647168 2012-07-16] () [Brak podpisu cyfrowego] Task: {13298B14-5A65-41A2-848B-2B63253B3BA4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [3113312 2012-08-22] (Piriform Ltd -> Piriform Ltd) Task: {1534D2F0-684C-4DF9-967C-4F86F75A6DDE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {247960AE-2313-4311-A068-1309A33A06D2} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e9dd8579043 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {665D830F-F71F-47F2-9AF1-5BD7E8C3DDBF} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ab7f4e9eb527 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {93A2FCE4-BD43-4EA1-81B4-CE22CBEE68BC} - System32\Tasks\GoogleUpdateTaskMachineCore1d1eb5823270fee => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {94915A4C-2CCC-495C-8C82-2018689A7D42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {679283B8-5DF6-46E5-B46D-64FD489541A0} - System32\Tasks\GoogleUpdateTaskMachineUA1d15e9dd88bc067 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {EBBE3412-4076-4D07-A90C-A0125F6A42F9} - System32\Tasks\GoogleUpdateTaskMachineUA1d1ab7f4ecacedc => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) Task: {157EEC6C-54BA-4338-A8F1-BC9187D18328} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [684608 2024-11-01] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e9dd8579043.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab7f4e9eb527.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15e9dd88bc067.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 178.235.153.33 178.235.153.32 Tcpip\..\Interfaces\{17396F7C-6526-4E4C-A2FE-80C7EB217865}: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}: [DhcpNameServer] 178.235.153.33 178.235.153.32 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\05340574: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\14E64627F6964614050727A756D6F6: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\655636472716D275966496D2442483734343F5548545: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\655636472716D275966496D2442483734343F5548545: [DhcpDomain] TL-WA854RE Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\762716E647: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\762716E64723: [DhcpNameServer] 89.228.4.126 31.11.173.2 Tcpip\..\Interfaces\{6A08112C-2F5E-4894-A1B2-EFA8FCC78E0F}\845514755494D224533353D293731343: [DhcpNameServer] 192.168.8.1 Tcpip\..\Interfaces\{BA7290BD-F4E1-47EF-B7DB-BB68B3FAB700}: [DhcpNameServer] 192.168.42.129 HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,10.0.0.1,-1] FireFox: ======== FF DefaultProfile: 62n1d2sh.default FF ProfilePath: C:\Users\pysiol\AppData\Roaming\TomTom\HOME\Profiles\vcv1zphh.default [2012-11-06] FF Extension: (Brak nazwy) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [nie znaleziono] FF ProfilePath: C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\lq18snfm.default-esr [2024-11-10] FF Session Restore: Mozilla\Firefox\Profiles\lq18snfm.default-esr -> [funkcja włączona] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\lq18snfm.default-esr\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-11-09] FF ProfilePath: C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default [2024-02-25] FF DownloadDir: C:\Users\pysiol\Downloads FF Session Restore: Mozilla\Firefox\Profiles\62n1d2sh.default -> [funkcja włączona] FF Notifications: Mozilla\Firefox\Profiles\62n1d2sh.default -> hxxps://photos.google.com FF Extension: (YouTube Video Downloader/YouTube HD Download) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\youtubedownloader@youtubedownloadvideo1clickgroup.com.xpi [2023-06-13] FF Extension: (YouTube High Definition) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2023-05-09] FF Extension: (Video DownloadHelper) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2024-02-25] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Roaming\Mozilla\Firefox\Profiles\62n1d2sh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2024-02-08] FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] [Przestarzałe] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2019-11-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2019-11-24] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2024-11-04] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default [2024-11-09] CHR DownloadDir: D:\Pobieranie CHR Notifications: Default -> hxxps://web.telegram.org; hxxps://www.bankmillennium.pl; hxxps://www.bzwbk.pl; hxxps://www.empikfoto.pl; hxxps://www.ingbank.pl CHR Session Restore: Default -> [funkcja włączona] CHR Extension: (Adblock Plus - darmowy adblocker) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2024-04-14] CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-10-31] CHR Extension: (Dokumenty Google offline) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-06-13] CHR Extension: (Magic Enhancer For YouTube™) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2020-02-05] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-12] CHR Profile: C:\Users\pysiol\AppData\Local\Google\Chrome\User Data\System Profile [2021-04-22] CHR HKU\S-1-5-21-804025988-211181761-413787009-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKU\S-1-5-21-804025988-211181761-413787009-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] Brave: ======= StartMenuInternet: Brave - ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-09-25] (Adobe Inc. -> Adobe Inc.) S4 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe) S4 DroidExplorerService; C:\Program Files\Droid Explorer\DroidExplorer.Service.exe [254976 2013-08-25] (Ryan Conrad) [Brak podpisu cyfrowego] S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-24] (Google Inc -> Google Inc.) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG -> Nero AG) S3 ss_conn_launcher_service; C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe [182328 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13109776 2020-07-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) S2 .EsetTrialReset; C:\Windows\system32\regedt32.exe /s C:\Windows\esettrialreset.reg ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 ampa; C:\Windows\system32\ampa.sys [17008 2013-12-18] (ChengDu AoMei Tech Co., Ltd -> ) [Brak podpisu cyfrowego] R3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [6037504 2009-08-18] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.) S1 DMICall; C:\Windows\SysWOW64\DRIVERS\DMICall.sys [10216 2008-11-24] (Sony Corporation -> Sony Corporation) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET, spol. s r.o. -> ESET) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.) R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET, spol. s r.o. -> ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET, spol. s r.o. -> ESET) R1 googledrivefs3758; C:\Windows\System32\DRIVERS\googledrivefs3758.sys [386632 2022-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.) S3 mpfilt; C:\Windows\SysWOW64\drivers\mpfilt.sys [10588 2010-05-17] () [Brak podpisu cyfrowego] S3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Nokia) R2 rimsptsk; C:\Windows\System32\DRIVERS\rimspx64.sys [55296 2009-06-25] (Microsoft Windows Hardware Compatibility Publisher -> REDC) S2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc. -> SafeNet, Inc.) R3 SFEP; C:\Windows\System32\DRIVERS\SFEP.sys [12032 2010-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Sony Corporation) S3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [63568 2012-12-11] (SafeNet, Inc. -> SafeNet, Inc.) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-08-22] (Duplex Secure Ltd -> Duplex Secure Ltd.) R3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) R3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) R3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166760 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [43368 2020-04-24] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2015-01-28] (Microsoft Windows Hardware Compatibility Publisher -> RealVNC Ltd.) S0 audas0; system32\DRIVERS\audas0.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2024-11-09 10:28 - 2024-11-10 13:04 - 000000000 ____D C:\Users\pysiol\Downloads\FRST-OlderVersion 2024-11-09 10:20 - 2024-11-09 10:20 - 000095362 _____ C:\Users\pysiol\Documents\cc_20241109_102016.reg 2024-11-09 10:09 - 2024-11-09 10:09 - 000000000 ____D C:\ProgramData\Adobe 2024-11-09 10:08 - 2024-11-09 10:37 - 000004476 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task 2024-11-09 10:07 - 2024-11-09 10:37 - 000002025 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk 2024-11-09 10:07 - 2024-11-09 10:37 - 000002013 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk 2024-11-09 10:03 - 2024-11-09 10:03 - 357631392 _____ (Adobe Systems Incorporated) C:\Users\pysiol\Downloads\AcroRdrDC2400320112_pl_PL.exe 2024-11-01 12:15 - 2024-11-10 13:06 - 000000476 _____ C:\Users\pysiol\Downloads\Addition.txt 2024-11-01 12:14 - 2024-11-10 13:07 - 000021196 _____ C:\Users\pysiol\Downloads\FRST.txt 2024-11-01 12:14 - 2024-11-10 13:07 - 000000000 ____D C:\FRST 2024-11-01 12:14 - 2024-11-10 13:04 - 002400768 _____ (Farbar) C:\Users\pysiol\Downloads\FRST64.exe 2024-11-01 11:01 - 2024-11-03 19:27 - 000000000 ____D C:\Program Files\Mozilla Firefox ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2024-11-10 13:06 - 2017-12-17 15:10 - 000000000 ____D C:\Users\pysiol\AppData\Local\CrashDumps 2024-11-10 13:06 - 2009-07-14 05:45 - 000023760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2024-11-10 13:06 - 2009-07-14 05:45 - 000023760 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2024-11-10 13:04 - 2016-08-11 20:03 - 000000000 ____D C:\Users\pysiol\AppData\Roaming\Everything 2024-11-10 13:00 - 2015-12-24 01:07 - 000000000 ____D C:\Program Files (x86)\Google 2024-11-10 12:59 - 2022-02-20 22:38 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2024-11-10 12:58 - 2019-07-25 18:29 - 000002740 _____ C:\Windows\system32\Tasks\AutoKMSDaily 2024-11-10 12:58 - 2019-07-25 18:29 - 000000202 _____ C:\Windows\Tasks\AutoKMSDaily.job 2024-11-10 12:58 - 2013-11-01 13:39 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2024-11-10 12:58 - 2012-07-16 11:45 - 000000202 _____ C:\Windows\Tasks\AutoKMS.job 2024-11-10 12:58 - 2012-07-16 11:44 - 000078848 _____ C:\Windows\KMSEmulator.exe 2024-11-10 12:58 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2024-11-09 23:28 - 2019-11-29 17:15 - 000000000 ____D C:\Users\pysiol\AppData\Local\Everything 2024-11-09 20:07 - 2012-09-17 23:27 - 000000000 ____D C:\Users\pysiol\AppData\Local\PokerStars.EU 2024-11-09 20:07 - 2012-09-17 23:27 - 000000000 ____D C:\Program Files (x86)\PokerStars.EU 2024-11-09 19:54 - 2012-07-16 16:06 - 000000000 ____D C:\Users\pysiol\AppData\Roaming\Microsoft\Excel 2024-11-09 10:19 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf 2024-11-03 19:27 - 2012-09-08 11:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2024-10-31 10:23 - 2012-08-13 21:28 - 000000000 ____D C:\Users\pysiol\AppData\Roaming\Microsoft\Word 2024-10-23 12:11 - 2013-08-03 08:32 - 000000000 ____D C:\Windows\system32\MRT 2024-10-23 12:11 - 2012-07-16 16:02 - 201324920 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2024-10-23 10:41 - 2024-09-05 09:16 - 000000000 ____D C:\Users\pysiol\Desktop\do CV Kamila ==================== Pliki w katalogu głównym wybranych folderów ======== 2013-10-26 20:35 - 2013-10-26 20:35 - 000068124 _____ () C:\Program Files (x86)\hminstalllog.txt 2012-09-07 21:06 - 2012-09-07 22:36 - 000099384 _____ () C:\Users\pysiol\AppData\Roaming\inst.exe 2012-09-07 21:06 - 2012-09-07 22:36 - 000007859 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.cat 2012-09-07 21:06 - 2012-09-07 22:36 - 000001167 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.inf 2012-09-07 21:06 - 2012-09-07 22:36 - 000000055 _____ () C:\Users\pysiol\AppData\Roaming\pcouffin.log 2012-09-07 21:06 - 2012-09-07 22:36 - 000082816 _____ (VSO Software) C:\Users\pysiol\AppData\Roaming\pcouffin.sys 2018-07-25 09:17 - 2018-07-25 09:17 - 000000107 ___SH () C:\Users\pysiol\AppData\Roaming\winuptstart.bat 2015-05-23 00:41 - 2015-05-23 00:41 - 000000001 _____ () C:\Users\pysiol\AppData\Local\llftool.4.40.agreement 2017-10-31 21:35 - 2017-10-31 22:19 - 000000600 _____ () C:\Users\pysiol\AppData\Local\PUTTY.RND 2014-02-18 17:29 - 2014-02-18 17:29 - 000002436 _____ () C:\Users\pysiol\AppData\Local\recently-used.xbel 2016-09-05 22:44 - 2020-04-07 19:42 - 000007601 _____ () C:\Users\pysiol\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) LastRegBack: 2024-11-09 11:57 ==================== Koniec FRST.txt ======================== Shortcut_10-11-2024 13.12.19 Rezultat skanowania skrótów użytkowników (x64) Wersja: 09-11-2024 Uruchomiony przez pysiol (10-11-2024 13:12:19) Uruchomiony z C:\Users\pysiol\Downloads Tryb startu: Normal ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) Shortcut: C:\Users\pysiol\AppData\Local\Microsoft\Windows\GameExplorer\{86B41D1A-8BEA-46DC-8EF7-2CF7A4AE742B}\SupportTasks\1\Pomoc techniczna.lnk -> hxxp://www.gtisonline.com Shortcut: C:\Users\pysiol\AppData\Local\Microsoft\Windows\GameExplorer\{86B41D1A-8BEA-46DC-8EF7-2CF7A4AE742B}\SupportTasks\0\Więcej gier od firmy Microsoft.lnk -> hxxp://driver.gtgames.com/driver2.html Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk -> C:\Program Files (x86)\Audacity\audacity.exe (The Audacity Team) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Deklaracje.lnk -> C:\Program Files (x86)\edeklaracje\e-Deklaracje\e-Deklaracje.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox — tryb prywatny.lnk -> C:\Program Files\Mozilla Firefox\private_browsing.exe (Mozilla Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk -> C:\Program Files (x86)\foobar2000\foobar2000.exe (Piotr Pawlowski) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk -> C:\Program Files\Google\Drive File Stream\68.0.2.0\GoogleDriveFS.exe (Google, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk -> C:\Program Files (x86)\Pidgin\pidgin.exe (The Pidgin developer community) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server.lnk -> C:\Program Files (x86)\Universal Media Server\UMS.exe (Universal Media Server) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wielki słownik PWN-OXFORD.lnk -> C:\Program Files (x86)\PWN\WSPWNOUP2007\SPWNOUP.exe (WN PWN S.A.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files (x86)\WinRAR\Rar.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files (x86)\WinRAR\WinRAR.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files (x86)\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server\Uninstall.lnk -> C:\Program Files (x86)\Universal Media Server\uninst.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server\Universal Media Server.lnk -> C:\Program Files (x86)\Universal Media Server\UMS.exe (Universal Media Server) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SnadBoy's Revelation v2\Revelation.lnk -> C:\Program Files (x86)\SnadBoy's Revelation v2\Revelation.exe (SnadBoy Software) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft\CloneCD\CloneCD Help.lnk -> C:\Program Files (x86)\SlySoft\CloneCD\HelpLauncher.exe (SlySoft, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft\CloneCD\CloneCD Revision History.lnk -> C:\Program Files (x86)\SlySoft\CloneCD\Changes.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft\CloneCD\CloneCD Tray.lnk -> C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft\CloneCD\CloneCD.lnk -> C:\Program Files (x86)\SlySoft\CloneCD\CloneCD.exe (SlySoft, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft\CloneCD\Register CloneCD.lnk -> C:\Program Files (x86)\SlySoft\CloneCD\RegCloneCD.exe (SlySoft, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft\CloneCD\Uninstall.lnk -> C:\Program Files (x86)\SlySoft\CloneCD\ccd-uninst.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\grvicons.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter\SDFormatter.lnk -> C:\Program Files (x86)\SDA\SD Formatter\SDFormatter.exe (TRENDY Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Smart Switch PC\Smart Switch.lnk -> C:\Program Files (x86)\Samsung\Smart Switch PC\SmartSwitchPC.exe (Samsung Electronics) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies3\Samsung Kies 3.lnk -> C:\Program Files (x86)\Samsung\Kies3\Kies3.exe (Samsung) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies\Samsung Kies.lnk -> C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PZ Signer\PZ Signer.lnk -> C:\Program Files (x86)\PZ Signer\pz-signer.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3\OpenOffice Calc.lnk -> C:\Program Files (x86)\OpenOffice 4\program\scalc.exe (Apache Software Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3\OpenOffice Writer.lnk -> C:\Program Files (x86)\OpenOffice 4\program\swriter.exe (Apache Software Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3\OpenOffice.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Instrukcje\Nero Adobe Premiere Plug-In [Angielski].lnk -> C:\Program Files (x86)\Nero\Nero 7\Adobe\NeroDigitalPluginAdobePremiere_Eng.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Instrukcje\Nero Burn Plug-in (for MCE) [Instrukcja w języku angielskim].lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero Burn\NeroBurnBurnsettingsForMCE_Eng.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Instrukcje\Nero CD-DVD Speed [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero Toolkit\CDSpeed_eng.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Instrukcje\Nero Express [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Nero\Nero 7\Core\NeroExpress_eng.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Instrukcje\Nero MediaStreaming Plug-in (for MCE) [Instrukcja w języku angielskim].lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero MediaStreaming\NeroMediaStreamingForMCE_Eng.pdf () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Instrukcje\Nero StartSmart [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero StartSmart\NeroStartSmart_eng.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Informacje o zmianach.lnk -> C:\Program Files (x86)\NapiProjekt\changelog.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Strona domowa NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\www.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64\Changelog.lnk -> C:\Program Files\MPC-HC\Changelog.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64\Deinstalacja programu MPC-HC.lnk -> C:\Program Files\MPC-HC\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64\Dezinstalacja aplikacji MPC-HC.lnk -> C:\Program Files\MPC-HC\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64\MPC-HC x64.lnk -> C:\Program Files\MPC-HC\mpc-hc64.exe (MPC-HC Team) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\Silverlight.Configuration.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\accicons.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\xlicons.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\inficon.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\inficon.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\joticon.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\outicon.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pptico.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pubs.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\grvicons.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\wordicon.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Centrum Microsoft Office 2010 Upload Center.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\msouc.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Certyfikat cyfrowy dla projektów VBA.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\misc.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\cagicon.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\oisicon.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Preferencje językowe pakietu Microsoft Office 2010.lnk -> C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\misc.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodi\Kodi.lnk -> C:\Program Files (x86)\Kodi\kodi.exe (XBMC Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodi\Uninstall Kodi.lnk -> C:\Program Files (x86)\Kodi\Uninstall.exe (XBMC Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Codec Tweak Tool.lnk -> C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Uninstall\Uninstall K-Lite Codec Pack.lnk -> C:\Program Files (x86)\K-Lite Codec Pack\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext (x64).lnk -> C:\Program Files (x86)\K-Lite Codec Pack\Tools\GraphStudioNext64.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext.lnk -> C:\Program Files (x86)\K-Lite Codec Pack\Tools\GraphStudioNext.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\MediaInfo.lnk -> C:\Program Files (x86)\K-Lite Codec Pack\Tools\mediainfo.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\Win7DSFilterTweaker.lnk -> C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Help\Frequently Asked Questions.lnk -> C:\Program Files (x86)\K-Lite Codec Pack\Info\faq.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files\Java\jre1.8.0_231\bin\javacpl.exe (Oracle Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Handbrake.lnk -> C:\Program Files (x86)\Handbrake\Handbrake.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Uninstall.lnk -> C:\Program Files (x86)\Handbrake\uninst.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk -> C:\Program Files\Microsoft Games\Chess\Chess.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\FreeCell.lnk -> C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk -> C:\Windows\System32\gameux.dll (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Hearts.lnk -> C:\Program Files\Microsoft Games\Hearts\Hearts.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Backgammon.lnk -> C:\Program Files\Microsoft Games\Multiplayer\Backgammon\bckgzm.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Checkers.lnk -> C:\Program Files\Microsoft Games\Multiplayer\Checkers\chkrzm.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Spades.lnk -> C:\Program Files\Microsoft Games\Multiplayer\Spades\shvlzm.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Mahjong.lnk -> C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Minesweeper.lnk -> C:\Program Files\Microsoft Games\Minesweeper\Minesweeper.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\More Games from Microsoft.lnk -> C:\Program Files\Microsoft Games\More Games\MoreGames.dll (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Purble Place.lnk -> C:\Program Files\Microsoft Games\Purble Place\PurblePlace.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Solitaire.lnk -> C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Spider Solitaire.lnk -> C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk -> C:\Program Files\FileZilla FTP Client\filezilla.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk -> C:\Program Files\FileZilla FTP Client\uninstall.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskMark7\CrystalDiskMark 7 (32bit).lnk -> C:\Program Files\CrystalDiskMark7\DiskMark32.exe (Crystal Dew World) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskMark7\CrystalDiskMark 7 (64bit).lnk -> C:\Program Files\CrystalDiskMark7\DiskMark64.exe (Crystal Dew World) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo\CrystalDiskInfo.lnk -> C:\Program Files (x86)\CrystalDiskInfo\DiskInfo32.exe (Crystal Dew World) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\HWMonitor\HWMonitor.lnk -> C:\Program Files\CPUID\HWMonitor\HWMonitor.exe (CPUID) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\HWMonitor\Uninstall HWMonitor.lnk -> C:\Program Files\CPUID\HWMonitor\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 5\CDRWIN 5.lnk -> C:\Program Files (x86)\CDRWIN5\CDRWIN5.exe (Engelmann Media GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 5\Help.lnk -> C:\Program Files (x86)\CDRWIN5\CDRWIN.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 5\Labeleditor.lnk -> C:\Program Files (x86)\CDRWIN5\CDLabeler.exe (Engelmann Media GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 5\Quicktools.lnk -> C:\Program Files (x86)\CDRWIN5\Quicktools.exe (Engelmann Media GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk -> C:\Program Files\CCleaner\uninst.exe (Piriform Ltd) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip\PDF Printer\Bullzip PDF Printer Opcje.lnk -> C:\Program Files\Bullzip\PDF Printer\gui.exe (Bullzip) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip\PDF Printer\Dokumentacja.lnk -> C:\Program Files\Bullzip\PDF Printer\doc.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip\PDF Printer\Strona domowa.lnk -> C:\Program Files\Bullzip\PDF Printer\website.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip\PDF Printer\Debug\Bug Radar.lnk -> C:\Program Files\Bullzip\PDF Printer\Debug\BugRadar.exe (Bullzip) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip\PDF Printer\Debug\Installation Log.lnk -> C:\Program Files\Bullzip\PDF Printer\Debug\install.log () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blu-ray Converter Ultimate\2\Blu-ray Converter Ultimate.lnk -> C:\Program Files (x86)\Blu-ray Converter Ultimate\2\BlurayConverterUltimate.exe (VSO-Software SARL, France) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blu-ray Converter Ultimate\2\Deinstalacja programu Blu-ray Converter Ultimate.lnk -> C:\Program Files (x86)\Blu-ray Converter Ultimate\2\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Backup and Sync from Google.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth\AviSynth Documentation.lnk -> C:\Program Files (x86)\AviSynth\Docs\English\index.htm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth\Example Scripts.lnk -> C:\Program Files (x86)\AviSynth\Examples () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth\License.lnk -> C:\Program Files (x86)\AviSynth\gpl.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth\Plugin Directory.lnk -> C:\Program Files (x86)\AviSynth\plugins () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth\Uninstall AviSynth.lnk -> C:\Program Files (x86)\AviSynth\Uninstall.exe (The Public) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Partition Assistant Standard Edition 5.6\AOMEI Partition Assistant Standard Edition 5.6.lnk -> C:\Program Files (x86)\AOMEI Partition Assistant Standard Edition 5.6\PartAssist.exe (AOMEI Technology Co., Ltd.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Partition Assistant Standard Edition 5.6\Uninstall AOMEI Partition Assistant.lnk -> C:\Program Files (x86)\AOMEI Partition Assistant Standard Edition 5.6\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\A.C.I.D. Wizard.lnk -> C:\Program Files (x86)\Alcohol Soft\Alcohol 120\ACID.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol 120%.lnk -> C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxLaUn.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Uninstall Alcohol 120%.lnk -> C:\Program Files (x86)\Alcohol Soft\Alcohol 120\unins.exe ( ) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk -> C:\Windows\System32\NetProj.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\Windowspowershell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\Desktop\Handbrake.lnk -> C:\Program Files (x86)\Handbrake\Handbrake.exe (Brak pliku) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\postgres\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\Acrobat Reader.lnk -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) Shortcut: C:\Users\Public\Desktop\AOMEI Partition Assistant Standard Edition 5.6.lnk -> C:\Program Files (x86)\AOMEI Partition Assistant Standard Edition 5.6\PartAssist.exe (AOMEI Technology Co., Ltd.) Shortcut: C:\Users\Public\Desktop\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd) Shortcut: C:\Users\Public\Desktop\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\Public\Desktop\OpenOffice 4.1.3.lnk -> C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) Shortcut: C:\Users\Public\Desktop\Pidgin.lnk -> C:\Program Files (x86)\Pidgin\pidgin.exe (The Pidgin developer community) Shortcut: C:\Users\Public\Desktop\Samsung Kies 3.lnk -> C:\Program Files (x86)\Samsung\Kies3\Kies3.exe (Samsung) Shortcut: C:\Users\Public\Desktop\Smart Switch.lnk -> C:\Program Files (x86)\Samsung\Smart Switch PC\SmartSwitchPC.exe (Samsung Electronics) Shortcut: C:\Users\Public\Desktop\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) Shortcut: C:\Users\pysiol\Links\Desktop.lnk -> C:\Users\pysiol\Desktop () Shortcut: C:\Users\pysiol\Links\Downloads.lnk -> C:\Users\pysiol\Downloads () Shortcut: C:\Users\pysiol\Links\RecentPlaces.lnk -> [::{22877A6D-37A1-461A-91B0-DBDA5AAEBC99}] Shortcut: C:\Users\pysiol\Desktop\CrystalDiskInfo.lnk -> C:\Program Files (x86)\CrystalDiskInfo\DiskInfo32.exe (Crystal Dew World) Shortcut: C:\Users\pysiol\Desktop\CrystalDiskMark 7.lnk -> C:\Program Files\CrystalDiskMark7\DiskMark64.exe (Crystal Dew World) Shortcut: C:\Users\pysiol\Desktop\Kodi.lnk -> C:\Program Files (x86)\Kodi\kodi.exe (XBMC Foundation) Shortcut: C:\Users\pysiol\Desktop\lit.exe — skrót.lnk -> D:\Programy\literaki\lit.exe (Brak pliku) Shortcut: C:\Users\pysiol\Desktop\MPC-HC x64.lnk -> C:\Program Files\MPC-HC\mpc-hc64.exe (MPC-HC Team) Shortcut: C:\Users\pysiol\Desktop\mStatica.lnk -> C:\Statica\mStatica 4\mStatica.exe (Brak pliku) Shortcut: C:\Users\pysiol\Desktop\Tor Browser\Start Tor Browser.lnk -> C:\Users\pysiol\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Word\Nowy%20Dokument%20programu%20Microsoft%20Word309372152343021457\Nowy%20Dokument%20programu%20Microsoft%20Word.docx.lnk -> Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft\Video Converter 3\PSP Video Manager.lnk -> C:\Program Files (x86)\Xilisoft\Video Converter 3\psp-video-manager\pvm.exe () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft\Video Converter 3\Readme.lnk -> C:\Program Files (x86)\Xilisoft\Video Converter 3\readme.htm () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft\Video Converter 3\Uninstall.lnk -> C:\Program Files (x86)\Xilisoft\Video Converter 3\Uninstall.exe () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft\Video Converter 3\Xilisoft Video Converter 3.lnk -> C:\Program Files (x86)\Xilisoft\Video Converter 3\videoenc.exe () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft\Video Converter 3\Xilisoft Video Converter Help.lnk -> C:\Program Files (x86)\Xilisoft\Video Converter 3\videoenc.chm () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft\Video Converter 3\Xilisoft Video Converter Wizard 3.lnk -> C:\Program Files (x86)\Xilisoft\Video Converter 3\VCW.exe () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files (x86)\WinRAR\Rar.txt () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files (x86)\WinRAR\WinRAR.chm () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files (x86)\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\Odinstaluj PIT 2013 z Gazetą Wyborczą.lnk -> C:\Program Files\PIT2013 z Gazetą Wyborczą\unins000.exe (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\Odinstaluj PIT 2014 z Gazetą Wyborczą.lnk -> C:\Program Files\PIT2014 z Gazetą Wyborczą\unins000.exe (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2013 z Gazetą Wyborczą.lnk -> C:\Program Files\PIT2013 z Gazetą Wyborczą\PITy_2013.exe (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2014 z Gazetą Wyborczą.lnk -> C:\Program Files\PIT2014 z Gazetą Wyborczą\PITy_2014.exe (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Java Detection\Java Detection.lnk -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\javaws.exe (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\Driver™.lnk -> [LF6"pH,R GFSIF,t+Driver"!(1SPSXFL8C&m] Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Droid Explorer\DroidExplorer.lnk -> C:\Users\pysiol\AppData\Roaming\Microsoft\Installer\{5876342E-8D21-4ED6-AA03-549AB3170BC4}\AppIcon.exe (Ryan Conrad) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Agnosco DICOM Viewer 2.4\Agnosco DICOM Viewer 2.4.lnk -> C:\Program Files (x86)\Agnosco DICOM Viewer 2.4\Agnosco.exe (e-DICOM) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Agnosco DICOM Viewer 2.4\Agnosco DICOM Viewer Website.lnk -> C:\Program Files (x86)\Agnosco DICOM Viewer 2.4\AgnoscoDICOMViewer.url () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Agnosco DICOM Viewer 2.4\Help.lnk -> C:\Program Files (x86)\Agnosco DICOM Viewer 2.4\Agnosco.chm () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Agnosco DICOM Viewer 2.4\Uninstall Agnosco DICOM Viewer 2.4.lnk -> C:\Program Files (x86)\Agnosco DICOM Viewer 2.4\AgnoscoUninstall.exe (e-dicom.com) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\SendTo\Agnosco DICOM Viewer 2.4.lnk -> C:\Program Files (x86)\Agnosco DICOM Viewer 2.4\Agnosco.exe (e-DICOM) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe () Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies 3.lnk -> C:\Program Files (x86)\Samsung\Kies3\Kies3.exe (Samsung) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Smart Switch.lnk -> C:\Program Files (x86)\Samsung\Smart Switch PC\SmartSwitchPC.exe (Samsung Electronics) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Don't Sleep is a small portable Windows program to prevent system shutdown, Standby, Hibernate, Turn Off and Restart.lnk -> C:\Users\pysiol\Desktop\Dokumenty\DontSleep_x64\DontSleep_x64.exe (Nenad Hrg (SoftwareOK.com)) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Everything.lnk -> C:\Program Files\Everything\Everything.exe (voidtools) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\foobar2000.lnk -> C:\Program Files (x86)\foobar2000\foobar2000.exe (Piotr Pawlowski) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PokerStars.eu.lnk -> C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) Shortcut: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\f966724577ef19eb\PokerStars.EU.lnk -> C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series\1.2.392.200036.9107.500.305.0441.44116042710362.1244101.lnk -> D:\RTG\RTG po\CR1 (3).dcm (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series\1.2.392.200036.9107.500.305.0441.44116042710362.1244102.lnk -> D:\RTG\RTG po\CR1.dcm (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series\1.2.392.200036.9107.500.305.0441.44116042710362.1244103.lnk -> D:\RTG\RTG po\CR1 (2).dcm (Brak pliku) Shortcut: C:\Users\pysiol\AppData\Local\Microsoft\Windows\GameExplorer\{86B41D1A-8BEA-46DC-8EF7-2CF7A4AE742B}\PlayTasks\0\Zagraj.lnk -> D:\GT Interactive\Driver\Game.exe (Brak pliku) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Control Center.lnk -> C:\Program Files (x86)\Sony\VAIO Control Center\VAIO Control Center.exe (Sony Corporation) -> /VCC ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server\Universal Media Server (Select Profile).lnk -> C:\Program Files (x86)\Universal Media Server\UMS.exe (Universal Media Server) -> profiles ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Smart Switch PC\Uninstall Smart Switch.lnk -> C:\Program Files (x86)\InstallShield Installation Information\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}\setup.exe (Samsung Electronics Co., Ltd.) -> /removeonly ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies3\Uninstall Kies 3.lnk -> C:\Program Files (x86)\InstallShield Installation Information\{88547073-C566-4895-9005-EBE98EA3F7C7}\setup.exe (Samsung Electronics Co., Ltd.) -> /removeonly ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies\Samsung Kies (Lite).lnk -> C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe () -> /lite ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies\Uninstall Kies.lnk -> C:\Program Files (x86)\InstallShield Installation Information\{758C8301-2696-4855-AF45-534B1200980A}\setup.exe (Samsung Electronics Co., Ltd.) -> /removeonly ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Nero ProductSetup.lnk -> C:\Program Files (x86)\Common Files\Ahead\Nero Web\SetupX.exe (Nero AG) -> -ScParameter=8 MODE="update" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Nero StartSmart.lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Narzędzia\Nero BurnRights.lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero Toolkit\NeroBurnRights.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Narzędzia\Nero CD-DVD Speed.lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero Toolkit\CDSpeed.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Narzędzia\Nero DriveSpeed.lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero Toolkit\DriveSpeed.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Narzędzia\Nero InfoTool.lnk -> C:\Program Files (x86)\Nero\Nero 7\Nero Toolkit\InfoTool.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\Narzędzia\Nero Scout.lnk -> C:\Program Files (x86)\Common Files\Ahead\Lib\NeroScoutOptions.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\dane\Nero Burning ROM.lnk -> C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\dane\Nero Express.lnk -> C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8 /w ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\audio\Nero Burning ROM.lnk -> C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition\audio\Nero Express.lnk -> C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8 /w ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Napisy oczekujące na pobranie.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe () -> -kolejka ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\vsfilter64.dll",DirectVobSub ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\vsfilter.dll",DirectVobSub ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow audio decoder (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow64\ffdshow.ax",configureAudio ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow audio decoder.lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax",configureAudio ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow DXVA video decoder (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow64\ffdshow.ax",configureDXVA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow DXVA video decoder.lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax",configureDXVA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow video decoder (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow64\ffdshow.ax",configure ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow video decoder.lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax",configure ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV64\lavaudio.ax",OpenConfiguration ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio.lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV\lavaudio.ax",OpenConfiguration ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV64\lavsplitter.ax",OpenConfiguration ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter.lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV\lavsplitter.ax",OpenConfiguration ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video (x64).lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV64\lavvideo.ax",OpenConfiguration ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video.lnk -> C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) -> "C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV\lavvideo.ax",OpenConfiguration ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\Reset to recommended settings.lnk -> C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe () -> /resetsettings ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files\Java\jre1.8.0_231\bin\javacpl.exe (Oracle Corporation) -> -tab about ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files\Java\jre1.8.0_231\bin\javacpl.exe (Oracle Corporation) -> -tab update ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRWIN 5\Remove CDRWIN 5.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation) -> /i {9B2B0EAD-2CC7-4589-B3AA-D23BAB724065} ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Docs.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () -> --new_document ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Sheets.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () -> --new_spreadsheet ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Slides.lnk -> C:\Program Files\Google\Drive\googledrivesync.exe () -> --new_presentation ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\Users\Default\Desktop\Google Docs.lnk -> C:\Program Files\Google\Drive File Stream\launch.bat () -> -open_gdocs_root ShortcutWithArgument: C:\Users\Default\Desktop\Google Sheets.lnk -> C:\Program Files\Google\Drive File Stream\launch.bat () -> -open_gsheets_root ShortcutWithArgument: C:\Users\Default\Desktop\Google Slides.lnk -> C:\Program Files\Google\Drive File Stream\launch.bat () -> -open_gslides_root ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) -> --sendto ShortcutWithArgument: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\postgres\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Public\Desktop\Samsung Kies (Lite).lnk -> C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe () -> /lite ShortcutWithArgument: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft\Video Converter 3\Buy.lnk -> C:\Program Files (x86)\Xilisoft\Video Converter 3\videoenc.exe () -> -buyurl ShortcutWithArgument: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -extoff ShortcutWithArgument: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter ShortcutWithArgument: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH) -> --sendto ShortcutWithArgument: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE (Microsoft Corporation) -> /recycle ShortcutWithArgument: C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk -> C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe () -> /lite InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64\Strona internetowa aplikacji MPC-HC.url -> URL: hxxps://mpc-hc.org/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64\Strona WWW programu MPC-HC.url -> URL: hxxps://mpc-hc.org/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodi\Visit Kodi Online.url -> URL: hxxp://kodi.tv InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url -> URL: hxxp://java.com/help InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url -> URL: hxxp://java.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> URL: hxxp://www.piriform.com/ccleaner InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth\AviSynth Online.url -> URL: hxxp://www.avisynth.org InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth\Download Plugins.url -> URL: hxxp://www.avisynth.org/warpenterprises/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Partition Assistant Standard Edition 5.6\Visit our website.url -> URL: hxxp://www.disk-partition.com InternetURL: C:\Users\pysiol\Favorites\Windows Live\Galeria gadżetów Windows Live.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkID=70742 InternetURL: C:\Users\pysiol\Favorites\Windows Live\Poczta usługi Windows Live.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72681 InternetURL: C:\Users\pysiol\Favorites\Windows Live\Programy usługi Windows Live.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72700 InternetURL: C:\Users\pysiol\Favorites\Windows Live\Windows Live Spaces.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72682 InternetURL: C:\Users\pysiol\Favorites\MSN — witryny sieci Web\MSN Gospodarka.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=68923 InternetURL: C:\Users\pysiol\Favorites\MSN — witryny sieci Web\MSN Rozrywka.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=68924 InternetURL: C:\Users\pysiol\Favorites\MSN — witryny sieci Web\MSN Sport.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=68921 InternetURL: C:\Users\pysiol\Favorites\MSN — witryny sieci Web\MSN Technologie.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=55143 InternetURL: C:\Users\pysiol\Favorites\MSN — witryny sieci Web\MSN Wideo.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=68922 InternetURL: C:\Users\pysiol\Favorites\MSN — witryny sieci Web\Portal MSN.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=54729 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Centrum bezpieczeństwa Microsoft.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkID=72887 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Dodatki programu Internet Explorer.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Microsoft Office Online.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72885 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Microsoft Store.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=140813 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Microsoft Technet.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72886 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Microsoft w Polsce.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72520 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Oryginalne oprogramowanie firmy Microsoft.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72900 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Strona główna programu Internet Explorer.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72186 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Strona główna systemu Windows.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72629 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\Technologia RSS.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72889 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\W domu.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72406 InternetURL: C:\Users\pysiol\Favorites\Microsoft — witryny sieci Web\W pracy.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=72407 InternetURL: C:\Users\pysiol\Favorites\Links for Polska\Bezpieczeństwo w trybie online.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=142211 InternetURL: C:\Users\pysiol\Favorites\Links for Polska\Bezpieczny Internet.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129626 InternetURL: C:\Users\pysiol\Favorites\Links for Polska\Kultura.pl.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129625 InternetURL: C:\Users\pysiol\Favorites\Links for Polska\Pogodynka.pl — oficjalny serwis pogodowy IMGW.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129624 InternetURL: C:\Users\pysiol\Favorites\Links for Polska\Polska.pl.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129622 InternetURL: C:\Users\pysiol\Favorites\Links\Sugerowane witryny.url -> ==================== Koniec Shortcut.txt ============================= Addition Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 09-11-2024 Uruchomiony przez pysiol (10-11-2024 13:08:39) Uruchomiony z C:\Users\pysiol\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X64) (2012-07-16 01:22:26) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= (Załączenie wejścia w fixlist spowoduje jego usunięcie.) Administrator (S-1-5-21-804025988-211181761-413787009-500 - Administrator - Disabled) Gość (S-1-5-21-804025988-211181761-413787009-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-804025988-211181761-413787009-1008 - Limited - Enabled) postgres (S-1-5-21-804025988-211181761-413787009-1006 - Limited - Enabled) => C:\Users\postgres pysiol (S-1-5-21-804025988-211181761-413787009-1000 - Administrator - Enabled) => C:\Users\pysiol ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) Adobe Acrobat Reader - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 24.004.20243 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\{7D5344C9-E173-4148-93EC-6137D797835A}) (Version: 29.0.0.112 - Adobe Systems Incorporated) Hidden Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 29.0.0.112 - Adobe Systems Incorporated) Adobe Flash Player 32 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 32.0.0.293 - Adobe) Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.293 - Adobe) Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601102}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden Agnosco DICOM Viewer 2.4 (HKLM-x32\...\Agnosco DICOM Viewer 2.4) (Version: 2.4.0 - e-dicom.com) AOMEI Partition Assistant Standard Edition 5.6 (HKLM-x32\...\{02F850ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1) (Version: - AOMEI Technology Co., Ltd.) Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team) AviSynth (HKLM-x32\...\AviSynth) (Version: 2.6.0 MT - ) Backup and Sync from Google (HKLM\...\{696895F7-52C7-4C9E-998B-C7E0CC907092}) (Version: 3.57.4256.0809 - Google, Inc.) Bullzip PDF Printer 9.6.0.1582 (HKLM\...\Bullzip PDF Printer_is1) (Version: 9.6.0.1582 - Bullzip) CCleaner (HKLM\...\CCleaner) (Version: 3.22 - Piriform) CDRWIN 5 (HKLM-x32\...\{9B2B0EAD-2CC7-4589-B3AA-D23BAB724065}) (Version: 0 - Engelmann Media) CloneCD (HKLM-x32\...\CloneCD) (Version: - SlySoft) ConvertHelper 3.1.1 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version: - DownloadHelper) CPUID HWMonitor 1.34 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.34 - ) CrystalDiskInfo 7.0.5 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.5 - Crystal Dew World) CrystalDiskMark 7.0.0f (HKLM\...\CrystalDiskMark7_is1) (Version: 7.0.0f - Crystal Dew World) Droid Explorer 0.8.8.11 (x64) (HKLM\...\{5876342E-8D21-4ED6-AA03-549AB3170BC4}) (Version: 0.8.8.11 - Ryan Conrad) e-Deklaracje Desktop (HKLM-x32\...\{CD7DE859-AA5C-8266-0886-DCF6BD8BF283}) (Version: 7.0.3 - Ministerstwo Finansow) Hidden e-Deklaracje Desktop (HKLM-x32\...\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1) (Version: 11.0.1 - Ministerstwo Finansow) eReg (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden Everything 1.4.1.935 (x64) (HKLM\...\Everything) (Version: 1.4.1.935 - David Carpenter) foobar2000 v1.2.9 (HKLM-x32\...\foobar2000) (Version: 1.2.9 - Peter Pawlowski) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 109.0.5414.120 - Google LLC) Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 68.0.2.0 - Google LLC) Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden HDD Regenerator (HKLM-x32\...\{97A39919-9FEA-48B7-AB2B-4F99212D1E98}) (Version: 20.11.0011 - Abstradrome) Java 8 Update 231 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180231F0}) (Version: 8.0.2310.11 - Oracle Corporation) K-Lite Codec Pack 10.8.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.5 - ) Kodi (HKU\S-1-5-21-804025988-211181761-413787009-1000\...\Kodi) (Version: 19.3.0.0 - XBMC Foundation) Microsoft .NET Framework 4.8 (HKLM\...\{16735AF7-1D8D-3681-94A5-C578A61EC832}) (Version: 4.8.03761 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.8 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.8.03761 - Microsoft Corporation) Microsoft .NET Framework 4.8 (PLK) (HKLM\...\{AC22E632-A884-3236-AF80-02676EB22001}) (Version: 4.8.03761 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.8 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.8.03761 - Microsoft Corporation) Microsoft Office Access MUI (Polish) 2010 (HKLM-x32\...\{90140000-0015-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (Polish) 2010 (HKLM-x32\...\{90140000-0016-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (Polish) 2010 (HKLM-x32\...\{90140000-00BA-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (Polish) 2010 (HKLM-x32\...\{90140000-0044-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (HKLM\...\{90140000-002A-0000-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (Polish) 2010 (HKLM-x32\...\{90140000-00A1-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (Polish) 2010 (HKLM-x32\...\{90140000-001A-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (Polish) 2010 (HKLM-x32\...\{90140000-0018-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Polish) 2010 (HKLM-x32\...\{90140000-001F-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (Polish) 2010 (HKLM-x32\...\{90140000-002C-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (Polish) 2010 (HKLM-x32\...\{90140000-0019-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (Polish) 2010 (HKLM\...\{90140000-002A-0415-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (Polish) 2010 (HKLM-x32\...\{90140000-006E-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (Polish) 2010 (HKLM-x32\...\{90140000-001B-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215 (HKLM-x32\...\{69BCE4AC-9572-3271-A2FB-9423BDA36A43}) (Version: 14.0.24215 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215 (HKLM-x32\...\{BBF2AC74-720C-3CB3-8291-5E34039232FA}) (Version: 14.0.24215 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30133 (HKLM-x32\...\{295d1583-fdb9-414b-a4c8-da539362a26b}) (Version: 14.29.30133.0 - Microsoft Corporation) Microsoft Visual C++ 2019 X64 Additional Runtime - 14.29.30133 (HKLM\...\{E699E009-1C3C-4E50-9B57-2B39F0954C7F}) (Version: 14.29.30133 - Microsoft Corporation) Hidden Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.29.30133 (HKLM\...\{6CD9E9ED-906D-4196-8DC3-F987D2F6615F}) (Version: 14.29.30133 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}) (Version: 10.0.50908 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox ESR (x64 pl) (HKLM\...\Mozilla Firefox 115.17.0 ESR (x64 pl)) (Version: 115.17.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 115.8.0 - Mozilla) MPC-HC 1.7.13 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.13 - MPC-HC Team) MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden MSVCRT Redists (HKLM\...\{3BFC9CAE-091D-11E4-886A-F04DA23A5C58}) (Version: 1.0 - Sony Creative Software Inc.) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NapiProjekt (2.2.0.2399) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Nero 7 Ultra Edition (HKLM-x32\...\{91C0B95B-B83A-4828-A775-BBE2DD421045}) (Version: 7.02.9752 - Nero AG) neroxml (HKLM-x32\...\{56C049BE-79E9-4502-BEA7-9754A3E60F9B}) (Version: 1.0.0 - Nero AG) Hidden OpenOffice 4.1.3 (HKLM-x32\...\{4D71C348-C964-442D-B2DB-5160E46FB664}) (Version: 4.13.9783 - Apache Software Foundation) Pakiet sterowników systemu Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia) Pidgin (HKLM-x32\...\Pidgin) (Version: 2.10.6 - ) Polski pakiet językowy dla narzędzi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PLK) (Version: 10.0.50903 - Microsoft Corporation) RICOH R5U8xx Media Driver ver.3.62.02 (HKLM-x32\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.62.02 - RICOH) Samsung Kies (HKLM-x32\...\{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.) Hidden Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.) Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.) Hidden Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.) SDFormatter (HKLM-x32\...\{A5355F15-F98B-4704-9BAE-E53B9FE48F48}) (Version: 3.1.0 - SD Association) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0015-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0016-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0019-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001B-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{8925227F-C7B5-4C95-AB58-4FCF2433DAEE}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{09A9DF49-DA06-4093-A2FD-F339211E39EA}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{84B63E23-DC80-4D60-A0A4-059BB7D2B898}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E4D76E88-C65F-4003-9C71-EC4306679D17}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0415-1000-0000000FF1CE}_Office14.PROPLUSR_{E7104ED5-5798-4A5E-B02D-9C72E63AF3BE}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-002C-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{461F9A2C-A545-4E23-847C-7D0A587CCFE5}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0044-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-006E-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{4493E7C6-B2DA-427E-89DB-7068E3907400}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-00A1-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-00BA-0415-0000-0000000FF1CE}_Office14.PROPLUSR_{F1510A1E-4F3D-4390-AC2E-91C875BED1FC}) (Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Setting Utility Series (HKLM-x32\...\{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}) (Version: 5.0.0.08060 - Sony Corporation) Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.22083.3 - Samsung Electronics Co., Ltd.) Hidden Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.3.22083.3 - Samsung Electronics Co., Ltd.) SnadBoy's Revelation v2 (HKLM-x32\...\SnadBoy's Revelation v2) (Version: 2.0.1.100 - SnadBoy Software) TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.7.7 - TeamViewer) Universal Media Server (HKLM-x32\...\Universal Media Server) (Version: 6.5.0 - Universal Media Server) VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.0.0.07280 - Sony Corporation) VAIO Event Service (HKLM-x32\...\{C7477742-DDB4-43E5-AC8D-0259E1E661B1}) (Version: 4.2.0.11060 - Sony Corporation) VAIO Power Management (HKLM-x32\...\{5F5867F0-2D23-4338-A206-01A76C823924}) (Version: 3.2.0.10060 - Sony Corporation) Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) Wielki słownik angielsko-polski i polsko-angielski PWN-OXFORD (HKLM-x32\...\{1035B082-201E-466E-9084-D096589C05CD}) (Version: 3.0.0 - WN PWN SA) Wielki słownik polsko-angielski i angielsko-polski PWN-OXFORD (HKLM-x32\...\Wielki słownik polsko-angielski i angielsko-polski PWN-OXFORD) (Version: - ) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinRAR 4.11 (32-bitowy) (HKLM-x32\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) Xilisoft Video Converter (HKLM-x32\...\Xilisoft Video Converter) (Version: 3.1.38.0802b - Xilisoft) ==================== Niestandardowe rejestracje CLSID (filtrowane): ============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6671064 2013-12-19] (Microsoft Corporation -> Microsoft Corporation) ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4171480 2013-12-19] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll [2008-01-01] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll [2008-01-01] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll [2008-01-01] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll [2008-01-01] (Google LLC -> Google, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2022-02-01] (Google LLC -> Google) ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll [2008-01-01] (Google LLC -> Google, Inc.) ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2022-02-01] (Google LLC -> Google) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2012-03-31] (Alexander Roshal) [Brak podpisu cyfrowego] ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2012-02-17] (Alexander Roshal) [Brak podpisu cyfrowego] ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll [2008-01-01] (Google LLC -> Google, Inc.) ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2022-02-01] (Google LLC -> Google) ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2012-03-31] (Alexander Roshal) [Brak podpisu cyfrowego] ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2012-02-17] (Alexander Roshal) [Brak podpisu cyfrowego] ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\68.0.2.0\drivefsext.dll [2008-01-01] (Google LLC -> Google, Inc.) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2012-03-31] (Alexander Roshal) [Brak podpisu cyfrowego] ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2012-02-17] (Alexander Roshal) [Brak podpisu cyfrowego] ==================== Codecs (filtrowane) ==================== ==================== Skróty & WMI ======================== ==================== Załadowane moduły (filtrowane) ============= 2013-09-30 20:54 - 2008-11-05 17:32 - 000010752 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000009728 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll 2012-07-16 02:36 - 2012-03-31 22:36 - 000194048 _____ (Alexander Roshal) [Brak podpisu cyfrowego] C:\Program Files (x86)\WinRAR\rarext64.dll 2013-03-11 20:45 - 2013-02-25 18:24 - 000218624 _____ (Bullzip) [Brak podpisu cyfrowego] C:\Windows\System32\bzpdf.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000344064 _____ (Microsoft Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\MSVCR70.dll 2013-09-30 20:56 - 2008-09-01 12:58 - 000032768 _____ (Sony Corporation) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\Sony\VAIO Power Management\SPMDrv.dll 2013-09-30 20:56 - 2013-09-30 20:56 - 000081920 _____ (Sony Corporation) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Windows\assembly\GAC_64\SPMCommon\3.1.0.6020__e3c7096ba83f9295\SPMCommon.dll 2013-09-30 20:56 - 2013-09-30 20:56 - 000040960 _____ (Sony Corporation) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Windows\assembly\GAC_64\SPMDam\3.1.0.6020__1b3c579b6925895f\SPMDam.dll 2013-09-30 20:55 - 2008-11-24 19:46 - 000102400 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll 2013-09-30 20:40 - 2009-07-28 16:20 - 000196608 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Control Center\CommonSetting.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000102400 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESAppMon.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000565248 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESHKWndCommon.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000221184 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESPerform.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000090112 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESPowerMgr.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000090112 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESSemiPnP.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000135168 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESSetGamma.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000126976 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESStorageProtect.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000074240 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESSuEvent.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000094208 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESSuPerform.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000151552 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESTransform.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000077824 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESUSBKeyboard.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000139264 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESVideo.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000086016 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESWndMsg.dll 2013-09-30 20:54 - 2008-11-05 17:32 - 000005632 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files (x86)\Sony\VAIO Event Service\VESWndMsgHook.dll 2013-09-30 20:55 - 2008-11-24 19:46 - 000154112 _____ (Sony Corporation) [Brak podpisu cyfrowego] C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll ==================== Alternate Data Streams (filtrowane) ======== ==================== Tryb awaryjny (filtrowane) ================== ==================== Powiązania plików (filtrowane) ================= ==================== Internet Explorer (Wersja 11) (filtrowane) ============= Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Brak pliku ==================== Hosts - zawartość: ========================= (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 03:34 - 2019-11-29 21:28 - 000000988 _____ C:\Windows\system32\drivers\etc\hosts 127.0.0.1 serial.alcohol-soft.com 127.0.0.1 www.alcohol-soft.com 127.0.0.1 images.alcohol-soft.com 127.0.0.1 trial.alcohol-soft.com 127.0.0.1 alcohol-soft.com ==================== Inne obszary =========================== (Obecnie brak automatycznej naprawy dla tej sekcji.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\ HKU\S-1-5-21-804025988-211181761-413787009-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 178.235.153.33 - 178.235.153.32 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Załączenie wejścia w fixlist spowoduje jego usunięcie.) MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AllShare Framework DMS => 2 MSCONFIG\Services: DroidExplorerService => 2 MSCONFIG\Services: MoboroboDeviceService => 2 MSCONFIG\Services: Samsung Link Service => 2 MSCONFIG\Services: SentinelKeysServer => 2 MSCONFIG\Services: SentinelProtectionServer => 2 MSCONFIG\Services: SentinelSecurityRuntime => 2 MSCONFIG\Services: ServiceLayer => 3 MSCONFIG\Services: uCamMonitor => 2 MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== Reguły Zapory systemu Windows (filtrowane) ================ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [TCP Query User{D8826FA4-DDD0-4CFA-8442-DF334E285BAA}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe () [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{E9BD9D23-097C-4C64-96F7-35BF0F3F4075}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe () [Brak podpisu cyfrowego] FirewallRules: [{AC29704A-80C9-4696-A218-B2535473F7B4}] => (Allow) LPort=8743 FirewallRules: [{361485BC-A9BD-446B-AFF5-F4942FD09BE7}] => (Allow) LPort=8643 FirewallRules: [{0A81393F-21F5-4722-9F3C-9DF3392544AF}] => (Allow) LPort=7676 FirewallRules: [{995F5032-10BB-4E86-8CA9-42A25D2F319B}] => (Allow) LPort=7679 FirewallRules: [{D4C93E5D-3E06-48F9-9521-C42668CB87EB}] => (Allow) LPort=24234 FirewallRules: [{9B1CE0D1-3F75-432C-A3C8-5EC1604C5A8C}] => (Allow) LPort=7900 FirewallRules: [{2C2311F8-15C2-47F8-B711-8DA6F6694A08}] => (Allow) LPort=1900 FirewallRules: [{7D2601C9-AE2B-471D-B267-7A81986E2B1A}] => (Allow) LPort=5432 FirewallRules: [{AE361AF8-E3C4-4029-821C-94C6301E0544}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe () [Brak podpisu cyfrowego] FirewallRules: [{D64F34BF-F719-42F2-AFAD-B6D54C706BA9}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe () [Brak podpisu cyfrowego] FirewallRules: [TCP Query User{AFA3D895-7BDC-44C2-A614-A377F7F3B178}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe (XBMC Foundation) [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{28A839DF-9C40-4967-9EA8-67959A142A86}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe (XBMC Foundation) [Brak podpisu cyfrowego] FirewallRules: [TCP Query User{A458959D-DDF3-4EC1-BB7C-EABBA89B5E40}C:\program files (x86)\kodi\kodi.exe] => (Block) C:\program files (x86)\kodi\kodi.exe (XBMC Foundation) [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{A6EDD08E-1C35-4948-B0BA-FF18B5FE14DB}C:\program files (x86)\kodi\kodi.exe] => (Block) C:\program files (x86)\kodi\kodi.exe (XBMC Foundation) [Brak podpisu cyfrowego] FirewallRules: [{72898230-ED98-45F0-A0D6-FF878B073AB3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{92A7DD29-B12D-4437-8B64-37321694A436}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{EE430692-2328-4464-8E3C-8EFEB47D4DCF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{547C9006-42E0-4FA4-BF23-20B81990BE37}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{C357856F-6DAB-4DD2-87BC-6D43E0DF7723}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{54E0EBF6-38B7-4EBB-824F-67458B329C88}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{8B7CD895-529C-4BF1-BDD1-A4B8E5F20B02}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Punkty Przywracania systemu ========================= ==================== Wadliwe urządzenia w Menedżerze urządzeń ============ Name: Sentinel64 Description: Sentinel64 Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: Sentinel64 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Błędy w Dzienniku zdarzeń: ======================== Dziennik Aplikacja: ================== Error: (11/10/2024 01:06:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: FRST64.exe, wersja: 9.11.2024.1, sygnatura czasowa: 0x672f3eaa Nazwa modułu powodującego błąd: FRST64.exe, wersja: 9.11.2024.1, sygnatura czasowa: 0x672f3eaa Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000025fb4 Identyfikator procesu powodującego błąd: 0x1444 Godzina uruchomienia aplikacji powodującej błąd: 0x01db3368a533e623 Ścieżka aplikacji powodującej błąd: C:\Users\pysiol\Downloads\FRST64.exe Ścieżka modułu powodującego błąd: C:\Users\pysiol\Downloads\FRST64.exe Identyfikator raportu: 30f835c2-9f5c-11ef-a6b3-001dbaaf0c65 Error: (11/10/2024 01:05:57 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Nie można utworzyć punktu przywracania (Proces = C:\Windows\system32\svchost.exe -k netsvcs; Opis = Windows Update; Błąd = 0x80070422). Error: (11/10/2024 01:04:59 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: ZARZĄDZANIE NT) Description: Występująca w rejestrze wartość ciągu nazwy licznika wydajności jest niepoprawnie sformatowana. Wadliwie sformułowany ciąg to . Pierwszy wpis DWORD w sekcji danych (Data) zawiera wartość indeksu wadliwie sformułowanego ciągu, a drugi i trzeci wpis DWORD w sekcji danych zawiera ostatnie prawidłowe wartości indeksu. Error: (11/09/2024 08:06:56 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Nie można utworzyć punktu przywracania (Proces = C:\Windows\system32\msiexec.exe /V; Opis = Usunięto PokerStrategy.com Equilab.; Błąd = 0x80070422). Error: (11/09/2024 08:06:56 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Nie można utworzyć punktu przywracania (Proces = C:\Windows\system32\msiexec.exe /V; Opis = Removed PokerStrategy.com Equilab.; Błąd = 0x80070422). Error: (11/09/2024 08:05:43 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: ZARZĄDZANIE NT) Description: Występująca w rejestrze wartość ciągu nazwy licznika wydajności jest niepoprawnie sformatowana. Wadliwie sformułowany ciąg to . Pierwszy wpis DWORD w sekcji danych (Data) zawiera wartość indeksu wadliwie sformułowanego ciągu, a drugi i trzeci wpis DWORD w sekcji danych zawiera ostatnie prawidłowe wartości indeksu. Error: (11/09/2024 07:51:25 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: ZARZĄDZANIE NT) Description: Występująca w rejestrze wartość ciągu nazwy licznika wydajności jest niepoprawnie sformatowana. Wadliwie sformułowany ciąg to . Pierwszy wpis DWORD w sekcji danych (Data) zawiera wartość indeksu wadliwie sformułowanego ciągu, a drugi i trzeci wpis DWORD w sekcji danych zawiera ostatnie prawidłowe wartości indeksu. Error: (11/09/2024 04:33:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: ZARZĄDZANIE NT) Description: Występująca w rejestrze wartość ciągu nazwy licznika wydajności jest niepoprawnie sformatowana. Wadliwie sformułowany ciąg to . Pierwszy wpis DWORD w sekcji danych (Data) zawiera wartość indeksu wadliwie sformułowanego ciągu, a drugi i trzeci wpis DWORD w sekcji danych zawiera ostatnie prawidłowe wartości indeksu. Dziennik System: ============= Error: (11/10/2024 01:11:58 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: Serwer {BB6DF56B-CACE-11DC-9992-0019B93A3A84} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (11/10/2024 12:58:29 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: audas0 DMICall Error: (11/10/2024 12:58:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Eset Trial Reset z powodu następującego błędu: Usługa nie odpowiada na sygnał uruchomienia lub sygnał sterujący w oczekiwanym czasie. Error: (11/10/2024 12:58:27 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Eset Trial Reset. Error: (11/10/2024 12:58:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Sentinel64 z powodu następującego błędu: Nie można odnaleźć urządzenia. Error: (11/10/2024 12:58:23 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (11/10/2024 12:58:23 PM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (11/10/2024 12:58:18 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Ładowanie sterownika \SystemRoot\SysWow64\DRIVERS\DMICall.sys zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Windows Defender: ================Event[0]: Date: 2022-07-23 20:15:42.095 Description: Produkt Windows Defender napotkał błąd podczas próby aktualizacji podpisów. Nowa wersja podpisu:1.371.656.0 Poprzednia wersja podpisu:1.369.495.0 Źródło aktualizacji:Folder aktualizacji podpisów Typ podpisu:Oprogramowanie antyszpiegowskie Typ aktualizacji:Różnica Użytkownik:ZARZĄDZANIE NT\SYSTEM Bieżąca wersja aparatu:1.1.19400.3 Poprzednia wersja aparatu:1.1.19300.2 Kod błędu:0x80070666 Opis błędu:Inna wersja tego produktu jest już zainstalowana na tym komputerze. Nie można kontynuować instalowania tej wersji. Aby skonfigurować lub usunąć istniejącą wersję tego produktu, użyj aplikacji Dodaj/Usuń Programy z Panelu sterowania. Date: 2022-07-23 20:15:42.095 Description: Produkt Windows Defender napotkał błąd podczas próby aktualizacji aparatu. Nowa wersja aparatu:1.1.19400.3 Poprzednia wersja aparatu:1.1.19300.2 Źródło aktualizacji:Folder aktualizacji podpisów Użytkownik:ZARZĄDZANIE NT\SYSTEM Kod błędu:0x80070666 Opis błędu:Inna wersja tego produktu jest już zainstalowana na tym komputerze. Nie można kontynuować instalowania tej wersji. Aby skonfigurować lub usunąć istniejącą wersję tego produktu, użyj aplikacji Dodaj/Usuń Programy z Panelu sterowania. Date: 2022-07-23 19:55:29.362 Description: Produkt Windows Defender napotkał błąd podczas próby aktualizacji podpisów. Nowa wersja podpisu:1.371.656.0 Poprzednia wersja podpisu:1.369.495.0 Źródło aktualizacji:Folder aktualizacji podpisów Typ podpisu:Oprogramowanie antyszpiegowskie Typ aktualizacji:Różnica Użytkownik:ZARZĄDZANIE NT\SYSTEM Bieżąca wersja aparatu:1.1.19300.2 Poprzednia wersja aparatu:1.1.19300.2 Kod błędu:0x80070666 Opis błędu:Inna wersja tego produktu jest już zainstalowana na tym komputerze. Nie można kontynuować instalowania tej wersji. Aby skonfigurować lub usunąć istniejącą wersję tego produktu, użyj aplikacji Dodaj/Usuń Programy z Panelu sterowania. Date: 2022-03-28 23:17:12.148 Description: Produkt Windows Defender napotkał błąd podczas próby aktualizacji podpisów. Nowa wersja podpisu:1.361.163.0 Poprzednia wersja podpisu:1.359.1535.0 Źródło aktualizacji:Folder aktualizacji podpisów Typ podpisu:Oprogramowanie antyszpiegowskie Typ aktualizacji:Różnica Użytkownik:ZARZĄDZANIE NT\SYSTEM Bieżąca wersja aparatu:1.1.19000.8 Poprzednia wersja aparatu:1.1.18900.3 Kod błędu:0x80070666 Opis błędu:Inna wersja tego produktu jest już zainstalowana na tym komputerze. Nie można kontynuować instalowania tej wersji. Aby skonfigurować lub usunąć istniejącą wersję tego produktu, użyj aplikacji Dodaj/Usuń Programy z Panelu sterowania. Date: 2022-03-28 23:17:12.120 Description: Produkt Windows Defender napotkał błąd podczas próby aktualizacji aparatu. Nowa wersja aparatu:1.1.19000.8 Poprzednia wersja aparatu:1.1.18900.3 Źródło aktualizacji:Folder aktualizacji podpisów Użytkownik:ZARZĄDZANIE NT\SYSTEM Kod błędu:0x80070666 Opis błędu:Inna wersja tego produktu jest już zainstalowana na tym komputerze. Nie można kontynuować instalowania tej wersji. Aby skonfigurować lub usunąć istniejącą wersję tego produktu, użyj aplikacji Dodaj/Usuń Programy z Panelu sterowania. ==================== Statystyki pamięci =========================== BIOS: American Megatrends Inc. R1020Y3 09/18/2008 Płyta główna: Sony Corporation VAIO Procesor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz Procent pamięci w użyciu: 87% Całkowita pamięć fizyczna: 4063.04 MB Dostępna pamięć fizyczna: 507.92 MB Całkowita pamięć wirtualna: 8124.21 MB Dostępna pamięć wirtualna: 1573.31 MB ==================== Dyski ================================ Drive c: (System) (Fixed) (Total:57.61 GB) (Free:8.88 GB) (Model: ADATA SU750 ATA Device) NTFS ==>[dysk z komponentami startowymi (pozyskano odczytując BCD)] Drive d: (Dane) (Fixed) (Total:180.27 GB) (Free:131.26 GB) (Model: ADATA SU750 ATA Device) NTFS ==================== MBR & Tablica partycji ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 238.5 GB) (Disk ID: 0F111920) Partition 1: (Active) - (Size=57.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=180.3 GB) - (Type=07 NTFS) ==================== Koniec Addition.txt ======================= Odnośnik do komentarza
Illidan Opublikowano 11 Listopada Zgłoś Udostępnij Opublikowano 11 Listopada A więc tak... Jest trochę sprzątanie, głównie po nieistniejących już aplikacjach w systemie. Wpisy aktywatora Windows pominąłem w logach. Uruchom FRST. Skopiuj zawartość podaną niżej i nigdzie nie wklejaj-FRST sam znajdzie "fixlist" w schowku systemowym. Spoiler Start:: FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego] S0 audas0; system32\DRIVERS\audas0.sys [X] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Deklaracje.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PZ Signer\PZ Signer.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Centrum Microsoft Office 2010 Upload Center.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Certyfikat cyfrowy dla projektów VBA.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Clip Organizer.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Office Picture Manager.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Preferencje językowe pakietu Microsoft Office 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Handbrake.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Uninstall.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\A.C.I.D. Wizard.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol 120%.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Uninstall Alcohol 120%.lnk C:\Users\postgres\Desktop\Handbrake.lnk C:\Users\pysiol\Desktop\lit.exe — skrót.lnk C:\Users\pysiol\Desktop\mStatica.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\Odinstaluj PIT 2013 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\Odinstaluj PIT 2014 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2013 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2014 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Java Detection\Java Detection.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PokerStars.eu.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\f966724577ef19eb\PokerStars.EU.lnk C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series\1.2.392.200036.9107.500.305.0441.44116042710362.1244101.lnk C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series\1.2.392.200036.9107.500.305.0441.44116042710362.1244102.lnk C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series\1.2.392.200036.9107.500.305.0441.44116042710362.1244103.lnk C:\Users\pysiol\AppData\Local\Microsoft\Windows\GameExplorer\{86B41D1A-8BEA-46DC-8EF7-2CF7A4AE742B}\PlayTasks\0\Zagraj.lnk Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Brak pliku CreateRestorePoint: EmptyTemp: End:: Fixlist przeznaczona tylko dla autora tematu! W FRST kliknij opcję "Napraw" (Fix). Pokaż raport "fixlog.txt", który otrzymasz po restarcie komputera. Pobierz też darmowy "ADWCleaner" i tak samo, skanowanie, usuwanie jeśli coś zostanie wykryte, pokaż raport z usuwania. Co do systemu, to moja rada jest tak, kupić klucz licencyjny do systemu na OLX za ok. 10 zł, uaktualnić system do 10 i lub 11, da się w 11 pominąć wszystkie zbędne wymagania tego systemu co do procesora itp. i pozbyć się tego ustrojstwa jak aktywatory. Bezpieczniej, pewniej, no i nie trzeba ponawiać w razie czego aktywacji. Masz legalny system i do tego w pełni się aktualizujący, no i co ważne wspierany i rozwijany system. Co jeszcze, system raportuje jakieś problemy ze sterownikami, aktualizacja ich nie zaszkodzi, tutaj zobacz darmowy "DriverCloud" lub podobne oprogramowanie, lub przeprowadź aktualizację sterowników z buta, jak kto woli. Odnośnik do komentarza
grant322 Opublikowano 15 Listopada Autor Zgłoś Udostępnij Opublikowano 15 Listopada Dziękuję za cenne rady. Fixlog: Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 14-11-2024 Uruchomiony przez pysiol (15-11-2024 23:03:50) Run:1 Uruchomiony z C:\Users\pysiol\Downloads Załadowane profile: pysiol & postgres Tryb startu: Normal ============================================== fixlist - zawartość: ***************** Start:: FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind \StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego] S0 audas0; system32\DRIVERS\audas0.sys [X] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Deklaracje.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PZ Signer\PZ Signer.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Centrum Microsoft Office 2010 Upload Center.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Certyfikat cyfrowy dla projektów VBA.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Clip Organizer.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Office Picture Manager.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Preferencje językowe pakietu Microsoft Office 2010.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Handbrake.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Uninstall.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\A.C.I.D. Wizard.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol 120%.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Uninstall Alcohol 120%.lnk C:\Users\postgres\Desktop\Handbrake.lnk C:\Users\pysiol\Desktop\lit.exe — skrót.lnk C:\Users\pysiol\Desktop\mStatica.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą \Odinstaluj PIT 2013 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą \Odinstaluj PIT 2014 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2013 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2014 z Gazetą Wyborczą.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Java Detection\Java Detection.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar \PokerStars.eu.lnk C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned \ImplicitAppShortcuts\f966724577ef19eb\PokerStars.EU.lnk C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series \1.2.392.200036.9107.500.305.0441.44116042710362.1244101.lnk C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series \1.2.392.200036.9107.500.305.0441.44116042710362.1244102.lnk C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series \1.2.392.200036.9107.500.305.0441.44116042710362.1244103.lnk C:\Users\pysiol\AppData\Local\Microsoft\Windows\GameExplorer\{86B41D1A-8BEA-46DC-8EF7- 2CF7A4AE742B}\PlayTasks\0\Zagraj.lnk Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Brak pliku CreateRestorePoint: EmptyTemp: End:: ***************** HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => pomyślnie usunięto HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => pomyślnie usunięto HKLM\System\CurrentControlSet\Services\StarWindServiceAE => pomyślnie usunięto StarWindServiceAE => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\audas0 => pomyślnie usunięto audas0 => serwis pomyślnie usunięto C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Deklaracje.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PZ Signer\PZ Signer.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Centrum Microsoft Office 2010 Upload Center.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Certyfikat cyfrowy dla projektów VBA.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Clip Organizer.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Microsoft Office Picture Manager.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia pakietu Microsoft Office 2010\Preferencje językowe pakietu Microsoft Office 2010.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Handbrake.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake\Uninstall.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\A.C.I.D. Wizard.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol 120%.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Uninstall Alcohol 120%.lnk => pomyślnie przeniesiono C:\Users\postgres\Desktop\Handbrake.lnk => pomyślnie przeniesiono C:\Users\pysiol\Desktop\lit.exe — skrót.lnk => pomyślnie przeniesiono C:\Users\pysiol\Desktop\mStatica.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą \Odinstaluj PIT 2013 z Gazetą Wyborczą.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą \Odinstaluj PIT 2014 z Gazetą Wyborczą.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2013 z Gazetą Wyborczą.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIT z Gazetą Wyborczą\PIT 2014 z Gazetą Wyborczą.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Java Detection\Java Detection.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar \PokerStars.eu.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned \ImplicitAppShortcuts\f966724577ef19eb\PokerStars.EU.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series \1.2.392.200036.9107.500.305.0441.44116042710362.1244101.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series \1.2.392.200036.9107.500.305.0441.44116042710362.1244102.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Roaming\Agnosco DICOM Viewer\Recent Series \1.2.392.200036.9107.500.305.0441.44116042710362.1244103.lnk => pomyślnie przeniesiono C:\Users\pysiol\AppData\Local\Microsoft\Windows\GameExplorer\{86B41D1A-8BEA-46DC-8EF7- 2CF7A4AE742B}\PlayTasks\0\Zagraj.lnk => pomyślnie przeniesiono HKLM\Software\Classes\PROTOCOLS\Handler\skype4com => pomyślnie usunięto CreateRestorePoint: Błąd(2=8.59 GB ) -> Nie udało się utworzyć punktu przywracania. =========== EmptyTemp: ========== FlushDNS => ukończone BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12175588 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 1737583 B Edge => 0 B Chrome => 286264458 B Firefox => 1239752174 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 128 B systemprofile32 => 256 B LocalService => 256 B NetworkService => 1580 B pysiol => 173258921 B postgres => 173258921 B postgres.pysiol-Komputer => 173258921 B postgres.pysiol-Komputer.000 => 173258921 B RecycleBin => 0 B EmptyTemp: => 2.1 GB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 23:04:25 ==== Malware: # ------------------------------- # Malwarebytes AdwCleaner 8.4.2.0 # ------------------------------- # Build: 03-04-2024 # Database: 2024-10-23.4 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 11-15-2024 # Duration: 00:00:00 # OS: Windows 7 Service Pack 1 # Cleaned: 4 # Failed: 0 ***** [ Services ] ***** No malicious services cleaned. ***** [ Folders ] ***** Deleted C:\Program Files (x86)\myfree codec ***** [ Files ] ***** No malicious files cleaned. ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks cleaned. ***** [ Registry ] ***** Deleted HKCU\Software\InstallCore Deleted HKCU\Software\StartSearch Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{C915F573-4C11-4968-9080-29E611FDBE9F} ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ***** [ Hosts File Entries ] ***** No malicious hosts file entries cleaned. ***** [ Preinstalled Software ] ***** No Preinstalled Software cleaned. ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* AdwCleaner[S00].txt - [3862 octets] - [15/11/2024 23:12:19] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ########## Odnośnik do komentarza
Illidan Opublikowano 16 Listopada Zgłoś Udostępnij Opublikowano 16 Listopada Ok, wszystko zrobione. Jak teraz działa system? Odnośnik do komentarza
grant322 Opublikowano 20 Listopada Autor Zgłoś Udostępnij Opublikowano 20 Listopada Wszystko działa stabilnie i brak błędów. Odnośnik do komentarza
Illidan Opublikowano 21 Listopada Zgłoś Udostępnij Opublikowano 21 Listopada W takim razie kończymy. Usuń "FRST" i kwarntannę: C:\FRST "AdwCleaner" i "Malwaresbytes" zalecam pozostawić i używać co jakiś czas samemu do przeskanowania systemu i usunięcia ewentualnych szkodników. Odnośnik do komentarza
grant322 Opublikowano 25 Listopada Autor Zgłoś Udostępnij Opublikowano 25 Listopada Dziękuję ślicznie za pomoc Odnośnik do komentarza
Illidan Opublikowano 25 Listopada Zgłoś Udostępnij Opublikowano 25 Listopada Nie ma za co. Pozdrawiam. Odnośnik do komentarza
Rekomendowane odpowiedzi
Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto
Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.
Zarejestruj nowe konto
Załóż nowe konto. To bardzo proste!
Zarejestruj sięZaloguj się
Posiadasz już konto? Zaloguj się poniżej.
Zaloguj się