Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2016 Ran by [removed] (03-09-2016 22:38:58) Running from C:\Users\[removed]\Desktop Windows 10 Pro Version 1607 (X64) (2016-07-20 01:31:33) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2874853799-4015820732-1586648415-500 - Administrator - Disabled) Bartek (S-1-5-21-2874853799-4015820732-1586648415-1001 - Administrator - Enabled) => C:\Users\Bartek DefaultAccount (S-1-5-21-2874853799-4015820732-1586648415-503 - Limited - Disabled) Guest (S-1-5-21-2874853799-4015820732-1586648415-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2874853799-4015820732-1586648415-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-2874853799-4015820732-1586648415-1001\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.) Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) Adobe Dreamweaver CC 2015 (HKLM-x32\...\{EE2A0AA8-0386-11E5-8603-BC82F5DB1A71}) (Version: 16.1.0 - Adobe Systems Incorporated) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Adobe Flash Player 22 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Adobe Illustrator CC 2015 (HKLM-x32\...\{5680D629-B263-49CC-821E-3CEBD4507B51}) (Version: 19.2.1 - Adobe Systems Incorporated) Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.4 - Adobe Systems Incorporated) Adobe Photoshop CC 2015.5 (HKLM-x32\...\PHSP_17_0) (Version: 17.0.0 - Adobe Systems Incorporated) Adobe Premiere Pro CC 2015 (HKLM-x32\...\{38C72D42-0672-43B1-9E05-E7631684F9A1}) (Version: 9.2.0 - Adobe Systems Incorporated) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0017 - ASUS) AVerMedia H830 USB Hybrid DVB-T 10.2.64.103 (HKLM-x32\...\AVerMedia H830 USB Hybrid DVB-T) (Version: 10.2.64.103 - AVerMedia TECHNOLOGIES, Inc.) AVerTV 3D (HKLM-x32\...\InstallShield_{5016185F-05AF-455F-AA70-6B6E5D6D4E70}) (Version: 6.9.1.9.16032501 - AVerMedia Technologies, Inc.) AVerTV 3D (x32 Version: 6.9.1.9.16032501 - AVerMedia Technologies, Inc.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.2.0.0115 - Disc Soft Ltd) DB Browser for SQLite (HKLM-x32\...\SqliteBrowser3) (Version: 3.8.0 - oldsch00l) Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.11 - Bloodshed Software) ELAN Touchpad 11.5.16.2_X64_WHQL (HKLM\...\Elantech) (Version: 11.5.16.2 - ELAN Microelectronic Corp.) FileZilla Client 3.21.0 (HKLM-x32\...\FileZilla Client) (Version: 3.21.0 - Tim Kosse) Free M4a to MP3 Converter 9.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) Galeria fotografii (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden GoodSync (HKLM\...\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}) (Version: 9.9.54.4 - Siber Systems) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 53.0.2785.89 - Google Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden HandBrake 0.10.5 (HKLM-x32\...\HandBrake) (Version: 0.10.5 - ) IntelliJ IDEA Community Edition 15.0.3 (HKLM-x32\...\IntelliJ IDEA Community Edition 15.0.3) (Version: 143.1821.5 - JetBrains s.r.o.) IntelliJ IDEA Community Edition 2016.2.1 (HKLM-x32\...\IntelliJ IDEA Community Edition 2016.2.1) (Version: 162.1447.26 - JetBrains s.r.o.) IrfanView 64 (remove only) (HKLM\...\IrfanView64) (Version: 4.41 - Irfan Skiljan) Java 8 Update 74 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418074F0}) (Version: 8.0.740.2 - Oracle Corporation) Java SE Development Kit 8 Update 74 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180740}) (Version: 8.0.740.2 - Oracle Corporation) Komunikator WTW 1.20.0.4800 (HKLM\...\{1DF5019A-68B5-4ba1-8E59-E185C7B7FF11}) (Version: 1.20.0.4800 - K2T.eu) Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Minimal ADB and Fastboot version 1.4 (HKLM-x32\...\{C5564379-582D-457A-9E68-A9E7C1F1C4EC}_is1) (Version: 1.4 - Sam Rodberg) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 47.0.1 (x64 pl) (HKLM\...\Mozilla Firefox 47.0.1 (x64 pl)) (Version: 47.0.1 - Mozilla) Mp3tag v2.75 (HKLM-x32\...\Mp3tag) (Version: v2.75 - Florian Heidenreich) MuseScore 2 (HKLM-x32\...\{D0969A82-E79E-45D9-95D2-B2824880F780}) (Version: 2.0.2 - Werner Schweer and Others) NapiProjekt (2.2.0.2399) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Narzędzia sprawdzające pakietu Microsoft Office 2016 — polski (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9.2 - Notepad++ Team) NVIDIA Sterownik 3D Vision 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.91 - NVIDIA Corporation) NVIDIA Sterownik graficzny 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.91 - NVIDIA Corporation) Opera 12.18 (HKLM\...\Opera 12.18.1873) (Version: 12.18.1873 - Opera Software ASA) Opera developer 41.0.2329.0 (HKLM-x32\...\Opera 41.0.2329.0) (Version: 41.0.2329.0 - Opera Software) Pakiet sterowników systemu Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (01/27/2014 9.0.0000.00000) (HKLM\...\9CA77E2A8332A0824C54DA611BBE4CA24AB1F750) (Version: 01/27/2014 9.0.0000.00000 - Google, Inc.) Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7571 - Realtek Semiconductor Corp.) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Splash PRO EX (HKLM-x32\...\Mirillis Splash PRO EX) (Version: 1.13.2 - Mirillis) Spotify (HKU\S-1-5-21-2874853799-4015820732-1586648415-1001\...\Spotify) (Version: 1.0.32.96.g3c8a06e6 - Spotify AB) Universal Adb Driver (HKLM-x32\...\{C0E08D8D-6076-4117-B644-2AF34F35B757}) (Version: 1.0.4 - ClockworkMod) Vivaldi (HKLM-x32\...\Vivaldi) (Version: 1.4.589.2 - Vivaldi) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) WinDjView 2.1 (HKLM\...\WinDjView) (Version: 2.1 - Andrew Zhezherun) WinRAR 5.31 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) Wtyczka e-Deklaracje (HKLM-x32\...\{81BF6353-3C5B-4E6E-A566-7E162A00BF72}_is1) (Version: 4.2.0 - Ministerstwo Finansów) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2874853799-4015820732-1586648415-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {183B89F3-9468-D082-A519-4AE985889A47} => No File CustomCLSID: HKU\S-1-5-21-2874853799-4015820732-1586648415-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Bartek\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2874853799-4015820732-1586648415-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-2874853799-4015820732-1586648415-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5AF8A6D4-9468-D082-8236-89AB85889A47} => No File ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0D7594DF-C7AE-4D3D-A39C-22AD7AC8A254} - System32\Tasks\Microsoft\Windows\Windows Subsystem for Linux\AptPackageIndexUpdate => %comspec% [Argument = /c start "AptPackageIndexUpdate" /min %windir%\System32\LxRun.exe /update] Task: {0FAA496D-FBCC-40AD-8119-2ABCA2B8B935} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-03] (Google Inc.) Task: {4B160275-8EE4-4CD3-BD7E-EAA0C2B704FE} - System32\Tasks\AutoPico Daily Restart => C:\Users\Bartek\Desktop\KMSpico [Argument = v10.1.9\KMSpico Portable\AutoPico.exe /silent] Task: {4C62779C-9ECE-4400-B1D2-441AD392E6AC} - System32\Tasks\Opera scheduled Autoupdate 1455927312 => C:\Program Files (x86)\Opera developer\launcher.exe [2016-08-22] (Opera Software) Task: {595C2D94-F71C-4BE6-873A-EA1E852CC686} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation) Task: {667E347D-377E-4B29-AADD-7FB2FA0FA298} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {74DB0BF0-6036-486E-A4E6-822161CC53C9} - System32\Tasks\InstallShield® Update Service Scheduler => C:\Program Files (x86)\Common Files\InstallShield\Update\ISUSPM.exe [2016-06-29] (InstallShield®) Task: {74F53049-1E6F-46DC-997C-05BB0693B861} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_22_0_0_209_pepper.exe [2016-07-18] (Adobe Systems Incorporated) Task: {8147ADD5-3384-4005-A41C-A9ADA1B06163} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation) Task: {8ECE3D46-EFDE-4AAA-9172-FEA72C3612D3} - \Microsoft\XblGameSave\XblGameSaveTask\Logon -> No File <==== ATTENTION Task: {B62171AF-3FE8-4FAF-B8A8-A946F7395F11} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation) Task: {C0B2CB71-C140-450D-85F5-41B86EE076A2} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-18] (Adobe Systems Incorporated) Task: {C4A4D93C-9FF3-4B67-8610-B7556A9705FC} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Bartek\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-08-25] (Microsoft Corporation) Task: {E8AEECFA-DB88-4098-8E22-E7F6240A4A6B} - System32\Tasks\Optimize Thumbnail Cache Files => Wscript.exe //nologo //E:jscript //B "C:\ProgramData\InstallShield\Update\isuspm.ini" <==== ATTENTION Task: {EE9D0CA1-C934-4012-A0CF-7E179E5DA75F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-03] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_22_0_0_209_pepper.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\InstallShield® Update Service Scheduler.job => C:\Program Files (x86)\Common Files\InstallShield\Update\ISUSPM.exe Task: C:\WINDOWS\Tasks\Optimize Thumbnail Cache Files.job => Wscript.exe J/nologo /E:jscript /B C:\ProgramData\InstallShield\Update\isuspm.ini <==== ATTENTION ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Bartek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\K2T\WTW\Forum.lnk -> hxxp://forum.k2t.eu/ Shortcut: C:\Users\Bartek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\K2T\WTW\Zgłoś błąd.lnk -> hxxp://bugtraq.k2t.eu/ Shortcut: C:\Users\Bartek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\K2T\WTW\Zgłoś propozycję.lnk -> hxxp://bugtraq.k2t.eu/ ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-02-20 02:19 - 2015-06-25 13:07 - 00412480 _____ () C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe 2016-08-16 07:08 - 2016-08-16 07:08 - 09808608 _____ () C:\Program Files\Siber Systems\GoodSync\gs-server.exe 2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-08-25 13:39 - 2016-08-25 13:39 - 01864384 _____ () C:\Users\Bartek\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll 2016-02-21 23:38 - 2016-02-21 23:38 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2016-08-26 10:09 - 2016-08-26 10:09 - 00071168 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.113.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-08-26 10:09 - 2016-08-26 10:09 - 00178176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.113.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-08-26 10:09 - 2016-08-26 10:09 - 35288064 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.113.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2016-07-16 13:42 - 2016-07-16 13:42 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-07-16 13:43 - 2016-08-26 09:51 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-07-16 13:43 - 2016-08-26 09:51 - 09761280 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-08-26 09:53 - 2016-08-20 06:54 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-07-16 13:43 - 2016-08-26 09:51 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-08-26 09:53 - 2016-08-20 06:54 - 02438144 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-08-26 09:53 - 2016-08-20 06:56 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-09-03 10:43 - 2016-09-03 10:43 - 00055808 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11608.1001.17.0_x64__8wekyb3d8bbwe\WinStoreTasksWrapper.dll 2016-08-27 09:43 - 2016-08-27 09:43 - 30085120 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_19.20.24006.0_x64__8wekyb3d8bbwe\XboxApp.dll 2016-07-16 16:37 - 2016-07-16 16:37 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_19.20.24006.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 01022464 _____ () C:\Program Files\Opera\gstreamer\gstreamer.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00108544 _____ () C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00106496 _____ () C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00062464 _____ () C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00108032 _____ () C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00073216 _____ () C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00074752 _____ () C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00201216 _____ () C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00340480 _____ () C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00045056 _____ () C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00077312 _____ () C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll 2016-02-20 02:17 - 2016-02-20 02:17 - 00115712 _____ () C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll 2016-07-13 02:04 - 2016-07-13 02:04 - 26858688 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll 2016-05-03 18:03 - 2012-06-09 18:33 - 00053248 _____ () C:\Program Files (x86)\Common Files\AVerMedia\dll\MsgLog.DLL ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-02-13 19:30 - 2016-04-30 15:21 - 00001314 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na1r.services.adobe.com 127.0.0.1 hlrcv.stage.adobe.com 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2874853799-4015820732-1586648415-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Bartek\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "AVerQuick.lnk" HKLM\...\StartupApproved\StartupFolder: => "AVer HID Receiver.lnk" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "Logitech Download Assistant" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKU\S-1-5-21-2874853799-4015820732-1586648415-1001\...\StartupApproved\StartupFolder: => "AsusTPCenter — skrót.lnk" HKU\S-1-5-21-2874853799-4015820732-1586648415-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-2874853799-4015820732-1586648415-1001\...\StartupApproved\Run: => "Spotify Web Helper" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [UDP Query User{C5E42AB8-CC94-44BF-B2B4-A119DF29F365}C:\users\bartek\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\bartek\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{D2DD05AE-AF7A-43A4-8179-00DBC62154AF}C:\users\bartek\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\bartek\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{05919FD4-DCD5-41D3-8F29-672FAA2EEAD9}C:\program files\java\jdk1.8.0_74\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_74\bin\java.exe FirewallRules: [TCP Query User{B7CF069A-E6F1-412B-B3CC-A7C3B146FF63}C:\program files\java\jdk1.8.0_74\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_74\bin\java.exe FirewallRules: [{71F8BE7A-6146-4E14-8914-31E8CCDE2CA9}] => (Allow) C:\Program Files\PostgreSQL\python2\python.exe FirewallRules: [{80827213-614B-4907-80D6-A7D0BAA41503}] => (Allow) C:\Program Files\PostgreSQL\pg95\bin\postgres.exe FirewallRules: [UDP Query User{DF2F95ED-A9A9-482D-A2DD-3DEBD8B10813}C:\fiji.app\imagej-win64.exe] => (Allow) C:\fiji.app\imagej-win64.exe FirewallRules: [TCP Query User{81B7324A-12C6-4878-828B-292998E42E73}C:\fiji.app\imagej-win64.exe] => (Allow) C:\fiji.app\imagej-win64.exe FirewallRules: [UDP Query User{4B49991B-01B0-401E-B6B6-F1F4C9F205AF}C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe FirewallRules: [TCP Query User{DAF8E37D-6F01-4B74-9FDC-58B1FA711A91}C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe FirewallRules: [UDP Query User{2D226020-F886-4BF5-BA87-15439214DDB0}C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe FirewallRules: [TCP Query User{53777196-41AC-474D-81D9-B879B886A280}C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe FirewallRules: [UDP Query User{9387DE12-8E35-4051-B099-4B908AC0BF4A}C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe FirewallRules: [TCP Query User{6648538A-0D31-4F9F-ADA7-06BAF0852031}C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\bin\idea.exe FirewallRules: [UDP Query User{3B679BC7-7305-43A0-AA9D-07C375ADE6B7}C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe FirewallRules: [TCP Query User{B1EA134A-3F03-4BCF-A472-5232542D7914}C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\jre\jre\bin\java.exe FirewallRules: [{CA31F624-72A8-4A6E-9770-E73B892312FD}] => (Allow) C:\Users\Bartek\Desktop\KMSpico v10.1.9\KMSpico Portable\KMSELDI.exe FirewallRules: [{67A95335-04EA-484B-8F6F-ED54BB874D70}] => (Allow) C:\Users\Bartek\Desktop\KMSpico v10.1.9\KMSpico Portable\KMSELDI.exe FirewallRules: [{5D0ACDD1-26A3-4B16-B19C-92ACC5832BD2}] => (Allow) C:\Program Files\Opera\opera.exe FirewallRules: [{CD85E6E5-3102-4E72-AE12-BA35CFB50546}] => (Allow) C:\Program Files\Opera\opera.exe FirewallRules: [{DF7680EF-DF1D-4183-A2A5-19C3AB8F725B}] => (Allow) C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper_32.exe FirewallRules: [{547F5573-9189-4CCC-ABAE-34402F22A851}] => (Allow) C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper_32.exe FirewallRules: [{9F8056AD-B787-4C3E-A349-D884BB4572F4}] => (Allow) C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe FirewallRules: [{E42A20E6-7AFE-423D-846A-0795CCE133AF}] => (Allow) C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe FirewallRules: [{505BED9E-1349-4A6E-9943-DBF67B334996}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{34AA5222-4117-4E32-8C69-45869ECC3D7A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{1EB88F3E-D3C2-478C-8C04-F1E53889BE5A}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{AD5BBD26-5D13-49A6-A70F-22C42E096592}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{A4E6F964-3F1C-407E-8EBE-23E9DCF25669}] => (Allow) LPort=1900 FirewallRules: [{FD02DD3F-FCE9-4DEA-99B3-37F876A39ACB}] => (Allow) LPort=2869 FirewallRules: [{C5548D53-13F1-4440-871C-D770E15A60AC}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{57CD27A2-8AEB-40A5-BF1D-6571D2CABB03}] => (Allow) C:\Users\Bartek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{EC0EEBD8-2BB4-40D2-98CA-BAD29014FD91}] => (Allow) C:\Users\Bartek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{0B95B523-2AB8-4E7A-9012-4C77FBBD8A58}] => (Allow) C:\Users\Bartek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{48D91CF1-C443-41BB-B0D4-C3DFD936F255}] => (Allow) C:\Users\Bartek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{07CB8BB5-F67B-4503-BF85-66AA6C426F9F}] => (Allow) C:\Users\Bartek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{B1F00DFC-E5CD-4AA4-BB3D-0A99F5F17870}] => (Allow) C:\Users\Bartek\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{1CDEDBBC-3562-419A-B881-03983B6C3468}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{D41146DA-A061-4CCC-B6D1-99E06F74BB94}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{5645A9D5-EAD2-4116-9D20-6BC4CFEDCD96}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{92E46547-5A2A-44DF-95DE-A4DD86A791A0}C:\program files\java\jdk1.8.0_74\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_74\bin\java.exe FirewallRules: [UDP Query User{31BF1357-2E80-4B88-B149-45A06E647459}C:\program files\java\jdk1.8.0_74\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_74\bin\java.exe FirewallRules: [{EFDD7BFC-BDC6-48A7-9D98-C927530BB990}] => (Allow) C:\Program Files\Vivaldi\Application\vivaldi.exe FirewallRules: [TCP Query User{C205F690-4DA3-40C0-BB64-44027EE56ED4}C:\users\bartek\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\bartek\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{B4B45DF5-0C7D-48BE-BBDD-1EC287A19F65}C:\users\bartek\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\bartek\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{23AFD381-8120-4315-98C0-BCD44EFC1CCE}C:\program files\java\jdk1.8.0_74\jre\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_74\jre\bin\java.exe FirewallRules: [UDP Query User{B5F09A9B-D54D-4C2C-94EB-AECE92357F8C}C:\program files\java\jdk1.8.0_74\jre\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_74\jre\bin\java.exe FirewallRules: [TCP Query User{8E09FDAA-79B5-4C67-9F34-0AEF45B3C68E}C:\program files (x86)\jetbrains\intellij idea\bin\idea64.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\bin\idea64.exe FirewallRules: [UDP Query User{2A83794A-0324-40D4-9F3D-861DC52F97DE}C:\program files (x86)\jetbrains\intellij idea\bin\idea64.exe] => (Allow) C:\program files (x86)\jetbrains\intellij idea\bin\idea64.exe FirewallRules: [{9C41DA79-D220-4786-9729-6EA9704106FA}] => (Allow) C:\Program Files\Siber Systems\GoodSync\gs-server.exe FirewallRules: [{E12477BE-3007-4C09-97FD-148DED24D172}] => (Allow) C:\Program Files\Vivaldi\Application\vivaldi.exe FirewallRules: [{89782C17-6CC2-47EE-B922-61DD12387CAD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 27-08-2016 17:37:48 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 31-08-2016 20:31:00 Windows Update 03-09-2016 22:36:09 JRT Pre-Junkware Removal ==================== Faulty Device Manager Devices ============= Name: Bluetooth module Description: Bluetooth module Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Qualcomm Atheros Communications Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/03/2016 10:36:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (09/03/2016 10:27:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: ISUSPM.exe, wersja: [removed], sygnatura czasowa: 0x5773d1be Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0a748a0e Identyfikator procesu powodującego błąd: 0x137c Godzina uruchomienia aplikacji powodującej błąd: 0x01d206217a029b7b Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Common Files\InstallShield\Update\ISUSPM.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: 2ed29326-bef1-43b1-8110-fe118df38686 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (09/03/2016 10:27:19 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Aplikacja: ISUSPM.exe Wersja architektury: v4.0.30319 Opis: proces został przerwany z powodu nieobsłużonego wyjątku. Informacje o wyjątku: System.NullReferenceException w  .(​) w  .(​) w ​. () w ​.(System.IAsyncResult) w ​.() w ​.() w ​.(System.IAsyncResult) w  +.(System.IAsyncResult) w System.Net.LazyAsyncResult.Complete(IntPtr) w System.Net.ContextAwareResult.CompleteCallback(System.Object) w System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) w System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) w System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) w System.Net.ContextAwareResult.Complete(IntPtr) w System.Net.LazyAsyncResult.ProtectedInvokeCallback(System.Object, IntPtr) w System.Net.Dns.ResolveCallback(System.Object) w System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() w System.Threading.ThreadPoolWorkQueue.Dispatch() w System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (09/03/2016 10:24:44 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid. . Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet Error: (09/03/2016 10:24:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (09/03/2016 10:24:32 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas badania interfejsu IVssWriterCallback. hr = 0x80070005, Access is denied. . To jest często spowodowane przez niepoprawne ustawienia zabezpieczeń w procesie zapisującym lub żądającym. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {76ae6041-ea3c-40c7-83e0-bcbf3c7dc396} Error: (09/03/2016 08:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: BARTEK-LAPTOP) Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147023170. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (09/03/2016 08:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: BARTEK-LAPTOP) Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147023170. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (09/03/2016 08:03:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: BARTEK-LAPTOP) Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147023673. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (09/03/2016 08:03:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: BARTEK-LAPTOP) Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 nie powiodła się. Błąd: -2147023673. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. System errors: ============= Error: (09/03/2016 10:36:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa NVIDIA Display Driver Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (09/03/2016 10:35:20 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: Zgodnie z ustawieniami uprawnienia application-specific nie jest udzielane uprawnienie Local Activation do aplikacji serwera COM z identyfikatorem klasy CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} i identyfikatorem aplikacji APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} użytkownikowi NT AUTHORITY\SYSTEM o identyfikatorze zabezpieczeń SID (S-1-5-18) z adresu LocalHost (Using LRPC) działającemu w kontenerze aplikacji o identyfikatorze SID Unavailable (Unavailable). To uprawnienie zabezpieczeń można modyfikować przy użyciu narzędzia administracyjnego Usługi składowe. Error: (09/03/2016 10:34:51 PM) (Source: DCOM) (EventID: 10010) (User: BARTEK-LAPTOP) Description: Serwer {F9717507-6651-4EDB-BFF7-AE615179BCCF} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (09/03/2016 10:34:49 PM) (Source: DCOM) (EventID: 10010) (User: BARTEK-LAPTOP) Description: Serwer {F9717507-6651-4EDB-BFF7-AE615179BCCF} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (09/03/2016 10:34:49 PM) (Source: DCOM) (EventID: 10010) (User: BARTEK-LAPTOP) Description: Serwer {F9717507-6651-4EDB-BFF7-AE615179BCCF} nie zarejestrował się w modelu DCOM w wymaganym czasie. Error: (09/03/2016 10:34:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Restart the service. Error: (09/03/2016 10:34:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Print Spooler niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna: Restart the service. Error: (09/03/2016 10:33:09 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Restart the service) po nieoczekiwanym zakończeniu usługi Windows Search, ale ta akcja nie powiodła się przy następującym błędzie: Jedno wystąpienie usługi już działa. . Error: (09/03/2016 10:32:39 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Restart the service. Error: (09/03/2016 10:32:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa GoodSync Server niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. CodeIntegrity: =================================== Date: 2016-09-03 22:27:25.702 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.701 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.699 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.685 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.684 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.682 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.668 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.667 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.665 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-09-03 22:27:25.651 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-3610QM CPU @ 2.30GHz Percentage of memory in use: 25% Total physical RAM: 8077.59 MB Available physical RAM: 5992.41 MB Total Virtual: 12429.59 MB Available Virtual: 10467.54 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:222.3 GB) (Free:49.67 GB) NTFS Drive d: () (Fixed) (Total:315 GB) (Free:20.86 GB) NTFS Drive e: () (Fixed) (Total:340 GB) (Free:50.97 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 5BE3933F) Partition: GPT. ==================== End of Addition.txt ============================