Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 24.02.2018 Uruchomiony przez syb3r (25-02-2018 17:38:24) Uruchomiony z E:\Z neta\Nowy folder Windows 10 Pro Wersja 1709 16299.248 (X64) (2018-02-24 14:47:14) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-1968750893-1063217592-1064336127-500 - Administrator - Disabled) Gość (S-1-5-21-1968750893-1063217592-1064336127-501 - Limited - Disabled) Konto domyślne (S-1-5-21-1968750893-1063217592-1064336127-503 - Limited - Disabled) syb3r (S-1-5-21-1968750893-1063217592-1064336127-1000 - Administrator - Enabled) => C:\Users\syb3r WDAGUtilityAccount (S-1-5-21-1968750893-1063217592-1064336127-504 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG Antivirus (Enabled - Up to date) {C50510DE-367A-330C-FD5C-556ACFB11243} AS: AVG Antivirus (Enabled - Up to date) {7E64F13A-1040-3C82-C7EC-6E18B43658FE} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated) Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated) Aktualizacje NVIDIA 31.0.11.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.0.11.0 - NVIDIA Corporation) Hidden ALLPlayer V7.X (HKLM-x32\...\ALLPlayer_is1) (Version: - ALLPlayer Group, Ltd.) AVG AntiVirus FREE (HKLM-x32\...\AVG Antivirus) (Version: 18.1.3044 - AVG Technologies) Backup and Sync from Google (HKLM-x32\...\{AC62F3F2-61A2-4357-93EC-C308E3FEDF4E}) (Version: 3.39.8370.7843 - Google, Inc.) Chrome Remote Desktop Host (HKLM-x32\...\{14C6B17A-F825-431E-9A36-8D89E65B24C8}) (Version: 65.0.3325.40 - Google Inc.) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 390.77 - NVIDIA Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.167 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}) (Version: 3.4.1942 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.0.36 - Intel Corporation) Intel® Small Business Advantage (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 3.1.53.8739 - Intel(R) Corporation) Intel® Small Business Advantage (HKLM-x32\...\{D1FE9A0B-C2F8-451C-9F83-17520C2DFDF4}) (Version: 4.000.0025 - Intel Corporation) Java 8 Update 161 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180161F0}) (Version: 8.0.1610.12 - Oracle Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1968750893-1063217592-1064336127-1000\...\OneDriveSetup.exe) (Version: 17.005.0107.0008 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Mozilla Firefox 58.0.2 (x64 pl) (HKLM\...\Mozilla Firefox 58.0.2 (x64 pl)) (Version: 58.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 58.0.2.6611 - Mozilla) Napisy24 (HKLM-x32\...\{D1985DBC-F09E-4317-91B8-932AD0FD4A27}_is1) (Version: 1.8 - Napisy24.pl) Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski (HKLM\...\{90150000-001F-0415-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden NVIDIA GeForce Experience 3.12.0.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.12.0.84 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) NVIDIA Sterownik 3D Vision 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 390.77 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.36.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.36.6 - NVIDIA Corporation) NVIDIA Sterownik graficzny 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 390.77 - NVIDIA Corporation) NVIDIA Sterownik kontrolera 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) Oprogramowanie mikroukładu Intel® (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 10.3.5.6379 - Electronic Arts, Inc.) Original War (HKLM-x32\...\original war) (Version: - ) Panel sterowania NVIDIA 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 390.77 - NVIDIA Corporation) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 6.7 - Power Software Ltd) Railroad Tycoon II - Platynowa edycja (HKLM-x32\...\Railroad Tycoon II_is1) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.107.323.2017 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7780 - Realtek Semiconductor Corp.) ROCCAT Isku Keyboard Driver (HKLM-x32\...\{4ABAF918-A6BD-43D8-AE0B-5292034B14CB}) (Version: - Roccat GmbH) ROCCAT Kova[+] Mouse Driver (HKLM-x32\...\{A86DDFE3-F661-461C-9BF2-876AC2CA57DE}) (Version: 1.10 - Roccat GmbH) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.1 - Rockstar Games) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) Uplay (HKLM-x32\...\Uplay) (Version: 26.1 - Ubisoft) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0) (Version: 1.0.65.0 - LunarG, Inc.) Hidden WinRAR 5.40 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) World of Tanks - Common Test (HKU\S-1-5-21-1968750893-1063217592-1064336127-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812ct}_is1) (Version: - Wargaming.net) World of Tanks - Sandbox (HKU\S-1-5-21-1968750893-1063217592-1064336127-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812sb}_is1) (Version: - Wargaming.net) World of Tanks (HKU\S-1-5-21-1968750893-1063217592-1064336127-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net) XVM wersja 6.5.4 (HKLM-x32\...\{2865cd27-6b8b-4413-8272-cd968f316050}_is1) (Version: 6.5.4 - XVM team) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-01-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-01-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-01-29] (Google) ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => E:\Program Files (x86)\Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => E:\Program Files (x86)\Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => E:\Program Files (x86)\Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => E:\Program Files (x86)\Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => E:\Program Files (x86)\Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => E:\Program Files (x86)\Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => E:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-02-20] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-01-29] (Google) ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => E:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2016-10-02] (Power Software Ltd) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-09-19] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-09-19] (Alexander Roshal) ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-01-29] (Google) ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => E:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2016-10-02] (Power Software Ltd) ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> Brak pliku ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-01-23] (NVIDIA Corporation) ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => E:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-02-20] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => E:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2016-10-02] (Power Software Ltd) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-09-19] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-09-19] (Alexander Roshal) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {00F9E6CE-E4F6-45D5-9A13-BBF564BA348C} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {015C3835-4081-4469-A6E1-85AB26F2FB5C} - System32\Tasks\Antivirus Emergency Update => E:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2018-02-20] (AVG Technologies CZ, s.r.o.) Task: {0251EA51-6AE5-4A68-A9FC-9B05E1887774} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {0496283B-23AF-43E6-81A2-09AF4A474C5C} - System32\Tasks\Microsoft Office 15 Sync Maintenance for syb3ryt-syb3r syb3ryt => E:\Program Files (x86)\Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation) Task: {0733D8A2-5D65-4A79-86D2-2CAB1ECE4414} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-01-10] (NVIDIA Corporation) Task: {094B354E-2632-4010-BEF7-297D53D9B9F5} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation) Task: {0B4259C8-ECB8-4856-A657-8EBAA8D23EAB} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {190A9F5A-43D8-4832-94BF-9BACB477543A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation) Task: {203B10BE-658F-475B-8F54-2AF2AFBD14AB} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {2948E9FE-7A1B-48EF-9687-9BCEB2A13936} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-01-10] (NVIDIA Corporation) Task: {2D72436A-5855-4CE1-9D73-8EA8761F3950} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {327D163C-973C-4A19-899E-7D770D93A0E8} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation) Task: {34829446-6F82-4C5A-BC12-76B4D063747F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => E:\Program Files (x86)\Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {34FFDE37-B7C2-4622-BA0C-E06538491B50} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {4A4F1BDB-B61F-48A3-82E0-A31F85EBA258} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {6C3BBD95-EA4E-4FCE-917A-68247DB6E6A0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {6C5151C3-6F63-4F4B-9243-227487760F70} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {76F4F843-1C6A-4780-886F-2FE737D1C8F3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => E:\Program Files (x86)\Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {7969015A-CFE4-455B-B3A7-9E95F80356BD} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {7B1064D0-46AB-4D68-B746-FBCA80999029} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-01-10] (NVIDIA Corporation) Task: {7D563C73-840D-41A1-B5C3-92D89488BBF4} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation) Task: {8D138C16-2CF1-4D4E-983A-F5502F6D899D} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation) Task: {982A6818-31F3-4947-9695-0F27341B827D} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {9BA4F6FE-D0AE-4036-ADE6-79A41F2F7B7A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {9E67E1CD-6058-405E-ADC5-DEAD42E38E45} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-01-17] (Adobe Systems Incorporated) Task: {A071A2F9-C430-4863-A07D-277A4269CD56} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation) Task: {A5B8CC67-8808-4B07-9A4A-02AD962049F7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {A8FDA0E0-B01D-4826-8528-215AEBFFB36D} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {B44CE565-86B2-441C-B092-A512867075F0} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2018-02-08] (AVG Technologies CZ, s.r.o.) Task: {BD0BDF6D-6D14-40C3-B9D0-B01F632E0F3B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-11] (Google Inc.) Task: {BE208A3F-36DD-40DD-8914-90D52D2FDB3E} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {C130C509-1285-4AF4-86D0-AEF65921318F} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {DE8481C5-F4D5-4B5A-965B-C3C217C7D591} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-11] (Google Inc.) Task: {E2A17C7A-9220-4AA2-A3D2-2F0B4030EEA1} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-01-10] (NVIDIA Corporation) Task: {E302E577-DA9D-410C-AC34-3F3B9E9A08FE} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {E74E9064-5F34-4394-B923-74F4564058D6} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EB8FCE04-D8F6-44A6-AEC2-60B7C0D888F7} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation) Task: {EBC04C0A-8177-429D-AE49-A6E6BAEFF8D6} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EC5267D4-46F6-4864-8DD0-775767F999D9} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EF1EB40C-2151-4196-8C00-017A04E6A8AF} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {F5B47329-7341-42DC-AAD6-673D66981A2B} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Skróty & WMI ======================== (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\syb3r\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Pulpit zdalny Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp ==================== Załadowane moduły (filtrowane) ============== 2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2018-02-03 09:27 - 2018-01-24 01:23 - 000544240 _____ () C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\DisplayDriverAnalyzer\_DisplayDriverCrashAnalyzer64.dll 2017-01-12 14:59 - 2018-01-10 15:33 - 001268024 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-02-25 16:02 - 2018-02-10 05:39 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2018-02-25 16:02 - 2018-02-10 05:36 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-02-24 16:22 - 2018-02-24 16:23 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-02-24 16:22 - 2018-02-24 16:23 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-02-24 16:22 - 2018-02-24 16:23 - 025135104 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-02-24 16:22 - 2018-02-24 16:23 - 002542592 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\skypert.dll 2018-02-24 16:22 - 2018-02-24 16:23 - 000667136 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-01-29 12:42 - 2018-01-29 12:42 - 041100328 _____ () C:\Program Files (x86)\Google\Drive\googledrivesync.exe 2017-01-11 21:49 - 2017-01-11 21:04 - 002493440 _____ () E:\Program Files (x86)\Origin\libGLESv2.dll 2017-01-12 14:59 - 2018-01-10 15:33 - 001041208 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-01-12 14:59 - 2018-01-10 15:33 - 066907448 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-07-05 20:58 - 2017-07-05 20:58 - 067109376 _____ () E:\Program Files (x86)\AVG\Antivirus\libcef.dll 2018-02-20 21:13 - 2018-02-20 21:13 - 000289008 _____ () E:\Program Files (x86)\AVG\Antivirus\streamback.dll 2018-02-20 21:13 - 2018-02-20 21:13 - 000281328 _____ () E:\Program Files (x86)\AVG\Antivirus\tasks_core.dll 2017-01-11 19:14 - 2017-11-29 06:09 - 000781088 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2017-01-11 19:14 - 2016-09-01 02:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2017-01-11 19:14 - 2017-12-15 20:59 - 002558752 _____ () C:\Program Files (x86)\Steam\video.dll 2017-01-11 19:14 - 2016-09-01 02:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2017-01-11 19:14 - 2016-09-01 02:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2017-12-14 20:56 - 2017-11-04 02:54 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll 2017-12-14 20:56 - 2017-11-04 02:54 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll 2017-12-14 20:56 - 2017-11-04 02:54 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll 2017-12-14 20:56 - 2017-11-04 02:54 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll 2017-12-14 20:56 - 2017-11-04 02:54 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll 2017-01-11 19:14 - 2017-12-15 20:59 - 000904992 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-01-11 19:14 - 2016-07-04 23:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2017-06-08 08:24 - 2017-09-07 03:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2017-01-11 19:15 - 2017-10-31 05:44 - 071471904 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2017-01-11 19:14 - 2015-09-25 00:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll 2018-02-25 17:14 - 2018-02-25 17:14 - 000088064 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_ctypes.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000069120 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\bz2.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000920064 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_hashlib.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000098816 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32api.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000110080 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\pywintypes27.dll 2018-02-25 17:14 - 2018-02-25 17:14 - 000364544 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\pythoncom27.dll 2018-02-25 17:14 - 2018-02-25 17:14 - 000686080 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\unicodedata.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000320512 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32com.shell.shell.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 001177088 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\wx._core_.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000806912 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\wx._gdi_.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000816640 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\wx._windows_.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 001067520 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\wx._controls_.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000733696 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\wx._misc_.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000736256 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\pysqlite2._sqlite.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000119808 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32file.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000108544 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32security.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000007168 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\hashobjs_ext.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000017920 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\thumbnails_ext.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000082432 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\usb_ext.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000013824 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\common.time34.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000018432 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32event.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000027648 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\windows.conditional.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000017408 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\windows.winwrap.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000089088 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\windows.volumes.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000167936 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32gui.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000046080 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_socket.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 001311232 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_ssl.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000135680 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_elementtree.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000133632 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\pyexpat.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000038912 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32inet.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000077824 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\wx._html2.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000036864 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_psutil_windows.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000524248 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\windows._lib_cacheinvalidation.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000010240 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\select.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000011264 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32crypt.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000218624 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\PIL._imaging.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000027648 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_multiprocessing.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000020480 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\_yappi.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000035840 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32process.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000024064 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32pipe.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000025600 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32pdh.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000059392 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\windows.device_monitor.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000017408 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32profile.pyd 2018-02-25 17:14 - 2018-02-25 17:14 - 000022528 _____ () C:\Users\syb3r\AppData\Local\Temp\_MEI104522\win32ts.pyd 2015-08-07 01:09 - 2015-08-07 01:09 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Powiązania plików (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: =============================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-1968750893-1063217592-1064336127-1000\Control Panel\Desktop\\Wallpaper -> c:\users\syb3r\appdata\roaming\microsoft\windows photo viewer\tapeta z przeglądarki fotografii systemu windows.jpg DNS Servers: 157.158.136.1 - 157.158.0.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == MSCONFIG\startupreg: ALLUpdate => "E:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" MSCONFIG\startupreg: Napisy24Update => "C:\Program Files (x86)\Napisy24\Napisy24Update.exe" "sleep" MSCONFIG\startupreg: RoccatIsku => "E:\Program Files (x86)\Roccat\Isku\IskuMonitor.EXE" MSCONFIG\startupreg: RoccatKova+ => "C:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.EXE" ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [{D739B7E9-C0BC-42A0-B7B3-C84EB7490989}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{62CD0146-F4CD-4854-9CA2-1873E8765F0D}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{977DD4CD-7631-4A1B-8199-4E735BC52997}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\65.0.3325.40\remoting_host.exe FirewallRules: [{4E20A258-A0FB-4FD8-8A92-5E1F38EAF97D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{75C9109E-426D-48C2-A176-9F7B58EC98C6}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\The Witcher 3\bin\x64\witcher3.exe FirewallRules: [{0D8B9BCD-D492-4A36-80C5-636003371D95}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\The Witcher 3\bin\x64\witcher3.exe FirewallRules: [{B9DB3905-9941-4185-BE1A-4D2C9E0F8B48}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{69E33740-9075-43A3-B2DE-52A37055A988}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{307FF442-AD69-4845-828E-F18D9169B492}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{B21278DD-61C2-44B3-BC20-E92A8EAEF9FD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{FFCBA799-5213-4FA5-862D-9BCC83F7DA89}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\Original War\Owar.exe FirewallRules: [{09AE43D7-F3DC-4A7C-96B3-ECCECBE329E8}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\Original War\Owar.exe FirewallRules: [{1012B2E6-E04B-4DAE-9D5E-4CE99A39795D}] => (Allow) E:\Gry\World_of_Tanks_SB\worldoftanks.exe FirewallRules: [{7EB6E6EA-FF72-415A-B000-4A7A71DA9C88}] => (Allow) E:\Gry\World_of_Tanks_SB\worldoftanks.exe FirewallRules: [{EE401673-BB34-4666-B90F-E9643A70A2FE}] => (Allow) E:\Gry\World_of_Tanks_SB\WoTLauncher.exe FirewallRules: [{1B7EBC60-25C8-4411-A0B6-7134067C6A00}] => (Allow) E:\Gry\World_of_Tanks_SB\WoTLauncher.exe FirewallRules: [{70ABCE9E-C06E-471C-9403-303F23F66293}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{B1206653-F714-4C69-9566-5C6CDBF7A526}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{5C35F0E9-B619-489E-9F5E-1F4B7BE64CE2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Factorio\bin\x64\factorio.exe FirewallRules: [{D31CD292-652B-4C59-AA62-64A040A40077}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Factorio\bin\x64\factorio.exe FirewallRules: [{E681EC85-3864-4D47-A088-D5FBB3D8CDA5}] => (Allow) E:\Program Files (x86)\Office\Office15\outlook.exe FirewallRules: [{2E1CACB8-95C0-4683-A739-024E1863E83B}] => (Allow) E:\Program Files (x86)\Office\Office15\UcMapi.exe FirewallRules: [{066CC192-32A2-41A1-9BD0-EBE4113086B4}] => (Allow) E:\Program Files (x86)\Office\Office15\UcMapi.exe FirewallRules: [{C2B9116E-888A-4896-A66C-09C92C8A2DC7}] => (Allow) E:\Program Files (x86)\Office\Office15\lync.exe FirewallRules: [{9AEFB9AE-0887-47D0-B713-9D015C58123B}] => (Allow) E:\Program Files (x86)\Office\Office15\lync.exe FirewallRules: [{4114F5EB-0FE5-46BB-89E5-2A295474858E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{E24C7548-3E8A-4C94-9DDE-38222DBAC560}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{527D3B53-E648-4C43-B43F-5A6D15B1C7A5}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{1F2FEF3F-00FD-485C-AA68-D43DBEF1D702}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{686CA82B-3AB8-44D1-97F1-8CD5AA47020F}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{32E359FA-A695-4CD5-AF2B-01EB56C33C1E}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{D0666537-F2DA-4EB3-84E9-2F1B8297C4FD}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [UDP Query User{6201A638-82CA-4ADF-9645-2C867AEF5DA7}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe FirewallRules: [TCP Query User{31025430-3175-4DB3-8D16-8786F200BFF3}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe FirewallRules: [UDP Query User{705B74B2-E261-44B3-ACB1-776EA763BAC8}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe FirewallRules: [TCP Query User{1997712F-852D-4A3A-8DF0-B8F43EBD7DE3}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe FirewallRules: [{D740B677-A954-44DF-8D28-1F493B48B8D7}] => (Allow) E:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{D6BE1ED3-E91C-43C9-87A6-F892A258668E}] => (Allow) E:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{28B683C7-04A1-441A-8108-9F2D74025C45}] => (Allow) E:\Gry\Steam\steamapps\common\Factorio\bin\x64\factorio.exe FirewallRules: [{A41FC772-EB7A-42F6-BE9D-1FACDC387277}] => (Allow) E:\Gry\Steam\steamapps\common\Factorio\bin\x64\factorio.exe FirewallRules: [{1CBD06F8-2DA5-4818-9AB1-31699F4A91AB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{1FE48CB4-509C-4909-9A74-3BBB0CB72006}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{55EB436C-05BF-489C-940C-BF68506B004C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{687DA6AE-1388-44B6-B104-71AB3DAD22AB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{E4982AF6-125E-4E00-84C9-254DD4B32B70}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{C494C28F-91CF-4BC5-9263-AC4F3C853C12}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{35FCAF50-99B3-4B0A-B944-54CBA587F336}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0CEA3F07-C507-4FA0-8BFE-889687DD8E92}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{B7EAD2DF-8375-4504-821E-B6F15439A13B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{56037BF2-DE4B-42C2-81CD-783A9C031A72}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{F3E470C9-70DB-44CA-8064-FBE0C16D5E33}] => (Allow) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage Next\Sba.exe FirewallRules: [{22868AEB-3683-4971-931B-9399AA15ED0E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{B21A9CB8-969E-48D5-BEC1-347D91DBC443}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{451AA5AB-0B34-438D-9589-5F4A2317E326}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{03C65419-922D-4A1C-B2BB-B47D0809DB3A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{EA842D9A-6E30-4DE3-BB5D-4B8ACF82DE0D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{1F132E04-D6A5-4633-8708-F8661D62BEDD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{57198A6E-3B8D-47C0-8C87-4B6CA769F6A3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{EE78C0AF-8203-404C-9EFF-05712F357DA0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{47943F18-D54D-48AB-94AD-88E2B88FF97A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe FirewallRules: [{DA88E7D5-D0BD-438F-8FB9-21B1EA1E9116}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.74.380.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe FirewallRules: [{CA700963-4766-4AAF-AB13-55723E3470DA}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\Factorio\bin\x64\factorio.exe FirewallRules: [{235023A9-BEC8-4509-8DE2-8A1DD1121578}] => (Allow) E:\Gry\SteamLibrary\steamapps\common\Factorio\bin\x64\factorio.exe ==================== Punkty Przywracania systemu ========================= 24-02-2018 15:51:31 Windows Update 24-02-2018 16:54:48 SlimDrivers Installing Drivers 24-02-2018 16:56:07 SlimDrivers Installing Drivers 24-02-2018 16:56:50 SlimDrivers Installing Drivers 24-02-2018 16:58:32 Usunięte Realtek High Definition Audio Driver 24-02-2018 17:00:27 Zainstalowane Realtek High Definition Audio Driver ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (02/25/2018 04:23:40 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: ) Description: Failed to schedule Software Protection service for re-start at 2018-02-25T17:17:40Z. Error Code: 0x80070005. Error: (02/25/2018 03:05:04 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: Nie powiodło się wykonanie procedury otwierania dla usługi „.NETFramework” w bibliotece DLL „C:\WINDOWS\system32\mscoree.dll”. Dane wydajności dla tej usługi nie będą dostępne. Pierwsze cztery bajty (DWORD) sekcji danych Data zawierają kod błędu. Error: (02/25/2018 02:55:05 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: Nie powiodło się wykonanie procedury otwierania dla usługi „BITS” w bibliotece DLL „C:\Windows\System32\bitsperf.dll”. Dane wydajności dla tej usługi nie będą dostępne. Pierwsze cztery bajty (DWORD) sekcji danych Data zawierają kod błędu. Error: (02/25/2018 02:55:05 PM) (Source: Perflib) (EventID: 1017) (User: ) Description: Wyłączono zbieranie danych licznika wydajności z usługi „ASP.NET_2.0.50727”, ponieważ biblioteka licznika wydajności dla tej usługi wygenerowała jeden lub więcej błędów. Błędy, które były przyczyną tej akcji, zostały zapisane w dzienniku zdarzeń aplikacji. Popraw błędy przed włączeniem liczników wydajności dla tej usługi. Error: (02/25/2018 02:55:05 PM) (Source: Perflib) (EventID: 1021) (User: ) Description: System Windows nie może otworzyć 32-bitowej biblioteki Extensible Counter DLL ASP.NET_2.0.50727 w środowisku 64-bitowym. Skontaktuj się z dostawcą pliku, aby uzyskać wersję 64-bitową. Alternatywnie można otworzyć 32-bitową bibliotekę Extensible Counter DLL przy użyciu wersji 32-bitowej monitora wydajności. Aby użyć tego narzędzia, otwórz folder Windows, otwórz folder Syswow64, a następnie uruchom plik Perfmon.exe. Error: (02/25/2018 10:52:14 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Event-ID 0 Error: (02/24/2018 07:12:41 PM) (Source: Microsoft-Windows-AppModel-State) (EventID: 10) (User: syb3ryt) Description: microsoft.windows.authhost.a_8wekyb3d8bbwe-2147024893 Error: (02/24/2018 07:12:41 PM) (Source: Microsoft-Windows-AppModel-State) (EventID: 10) (User: syb3ryt) Description: Microsoft.VCLibs.140.00_8wekyb3d8bbwe-2147024893 Dziennik System: ============= Error: (02/25/2018 05:14:14 PM) (Source: DCOM) (EventID: 10016) (User: ZARZĄDZANIE NT) Description: Zgodnie z ustawieniami uprawnienia właściwe dla aplikacji nie jest udzielane uprawnienie Lokalny Aktywacja do aplikacji serwera COM z identyfikatorem klasy CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} i identyfikatorem aplikacji APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} użytkownikowi ZARZĄDZANIE NT\USŁUGA LOKALNA o identyfikatorze zabezpieczeń SID (S-1-5-19) z adresu LocalHost (użycie LRPC) działającemu w kontenerze aplikacji o identyfikatorze SID Niedostępny (Niedostępny). To uprawnienie zabezpieczeń można modyfikować przy użyciu narzędzia administracyjnego Usługi składowe. Error: (02/25/2018 05:14:14 PM) (Source: DCOM) (EventID: 10016) (User: ZARZĄDZANIE NT) Description: Zgodnie z ustawieniami uprawnienia właściwe dla aplikacji nie jest udzielane uprawnienie Lokalny Aktywacja do aplikacji serwera COM z identyfikatorem klasy CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} i identyfikatorem aplikacji APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} użytkownikowi ZARZĄDZANIE NT\USŁUGA LOKALNA o identyfikatorze zabezpieczeń SID (S-1-5-19) z adresu LocalHost (użycie LRPC) działającemu w kontenerze aplikacji o identyfikatorze SID Niedostępny (Niedostępny). To uprawnienie zabezpieczeń można modyfikować przy użyciu narzędzia administracyjnego Usługi składowe. Error: (02/25/2018 05:14:14 PM) (Source: DCOM) (EventID: 10016) (User: ZARZĄDZANIE NT) Description: Zgodnie z ustawieniami uprawnienia właściwe dla aplikacji nie jest udzielane uprawnienie Lokalny Aktywacja do aplikacji serwera COM z identyfikatorem klasy CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} i identyfikatorem aplikacji APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} użytkownikowi ZARZĄDZANIE NT\USŁUGA LOKALNA o identyfikatorze zabezpieczeń SID (S-1-5-19) z adresu LocalHost (użycie LRPC) działającemu w kontenerze aplikacji o identyfikatorze SID Niedostępny (Niedostępny). To uprawnienie zabezpieczeń można modyfikować przy użyciu narzędzia administracyjnego Usługi składowe. Error: (02/25/2018 05:14:14 PM) (Source: DCOM) (EventID: 10016) (User: ZARZĄDZANIE NT) Description: Zgodnie z ustawieniami uprawnienia właściwe dla aplikacji nie jest udzielane uprawnienie Lokalny Aktywacja do aplikacji serwera COM z identyfikatorem klasy CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} i identyfikatorem aplikacji APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} użytkownikowi ZARZĄDZANIE NT\USŁUGA LOKALNA o identyfikatorze zabezpieczeń SID (S-1-5-19) z adresu LocalHost (użycie LRPC) działającemu w kontenerze aplikacji o identyfikatorze SID Niedostępny (Niedostępny). To uprawnienie zabezpieczeń można modyfikować przy użyciu narzędzia administracyjnego Usługi składowe. Error: (02/25/2018 05:11:58 PM) (Source: DCOM) (EventID: 10010) (User: syb3ryt) Description: Serwer {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (02/25/2018 05:11:58 PM) (Source: DCOM) (EventID: 10010) (User: syb3ryt) Description: Serwer {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (02/25/2018 03:49:14 PM) (Source: DCOM) (EventID: 10016) (User: ZARZĄDZANIE NT) Description: Zgodnie z ustawieniami uprawnienia właściwe dla aplikacji nie jest udzielane uprawnienie Lokalny Aktywacja do aplikacji serwera COM z identyfikatorem klasy CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} i identyfikatorem aplikacji APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} użytkownikowi ZARZĄDZANIE NT\USŁUGA LOKALNA o identyfikatorze zabezpieczeń SID (S-1-5-19) z adresu LocalHost (użycie LRPC) działającemu w kontenerze aplikacji o identyfikatorze SID Niedostępny (Niedostępny). To uprawnienie zabezpieczeń można modyfikować przy użyciu narzędzia administracyjnego Usługi składowe. Error: (02/25/2018 03:49:14 PM) (Source: DCOM) (EventID: 10016) (User: ZARZĄDZANIE NT) Description: Zgodnie z ustawieniami uprawnienia właściwe dla aplikacji nie jest udzielane uprawnienie Lokalny Aktywacja do aplikacji serwera COM z identyfikatorem klasy CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} i identyfikatorem aplikacji APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} użytkownikowi ZARZĄDZANIE NT\USŁUGA LOKALNA o identyfikatorze zabezpieczeń SID (S-1-5-19) z adresu LocalHost (użycie LRPC) działającemu w kontenerze aplikacji o identyfikatorze SID Niedostępny (Niedostępny). To uprawnienie zabezpieczeń można modyfikować przy użyciu narzędzia administracyjnego Usługi składowe. CodeIntegrity: =================================== Date: 2018-02-25 16:25:55.914 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-25 16:25:55.893 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-25 16:25:55.869 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-25 16:25:55.824 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-25 16:25:55.815 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-25 16:25:55.807 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-25 16:25:55.144 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. Date: 2018-02-25 16:25:55.050 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume6\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. ==================== Statystyki pamięci =========================== Procesor: Intel(R) Core(TM) i5-6500 CPU @ 3.20GHz Procent pamięci w użyciu: 52% Całkowita pamięć fizyczna: 8131.7 MB Dostępna pamięć fizyczna: 3868.34 MB Całkowita pamięć wirtualna: 16323.7 MB Dostępna pamięć wirtualna: 10871.51 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:232.19 GB) (Free:120.28 GB) NTFS Drive d: (Zastrzeżone przez system) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[system z komponentami startowymi (pozyskano odczytując dysk)] Drive e: (Dysk Ee) (Fixed) (Total:831.15 GB) (Free:126.37 GB) NTFS Drive f: () (Fixed) (Total:100.26 GB) (Free:12.28 GB) NTFS \\?\Volume{fc3b7435-b0e0-473d-8867-7318a21c63f7}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 \\?\Volume{d415caeb-0df8-4dac-bd28-910e3aacffd4}\ () (Fixed) (Total:0.47 GB) (Free:0.08 GB) NTFS ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 19E3C4A8) Partition 1: (Active) - (Size=101 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=831.2 GB) - (Type=0F Extended) ======================================================== Disk: 1 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000) Partition: GPT. ==================== Koniec Addition.txt ============================