• Ogłoszenie:

Problem z explorer.exe / hohosearch

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Problem z explorer.exe / hohosearch

Postprzez teem90 26 Kwi 2016, 22:23

reklama
Witam, mam ten sam problem co kolega który opisał go tutaj:
explorer-exe-nie-uruchamia-sie-vp1031447.html

W skrócie: Zainstalowalem hohosearch, zaczęła wyskakiwać masa reklam, skanowałem programem: Malwarebytes Anti-Malware, usunęło ponad 3000 elementów. Po uruchomieniu ponownie nie otwiera się explorer.exe. Syfiasta wyszukiwarka nadal jest, w firefoxie.

Logi z FRST:
Kod: Zaznacz wszystko
Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (administrator)  TOMEK-KOMPUTER (26-04-2016 22:11:52)
Uruchomiony z C:\Users\Tomek\Desktop
Załadowane profile: Tomek (Dostępne profile: Tomek)
Platform: Windows 7 Professional Service Pack 1 (X64) Język: Polski (Polska)
Internet Explorer Wersja 11 (Domyślna przeglądarka: "D:\Firefox\firefox.exe" -osint -url "%1")
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Avast Software s.r.o.) D:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Cisco Systems, Inc.) D:\VPN\cvpnd.exe
(Malwarebytes) D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Malwarebytes) D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(StarWind Software) D:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Malwarebytes) D:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Mozilla Corporation) D:\Firefox\firefox.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(OldTimer Tools) C:\Users\Tomek\Downloads\OTL_www.INSTALKI.pl.exe


==================== Rejestr (filtrowane) ===========================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5670448 2013-02-05] (VIA)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => d:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-05] (Avast Software s.r.o.)
HKLM-x32\...\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1627032 2014-02-05] (Autodesk, Inc.)
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [493960 2014-12-05] (Autodesk Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [GrpConv] => grpconv -o
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [55264 2016-03-10] (Malwarebytes)
HKLM\...\Winlogon: [Userinit] wscript,
HKLM-x32\...\Winlogon: [Userinit] wscript, [X]
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [GG] => C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe [4078144 2015-04-03] (GG Network S.A.)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [ALLUpdate] => "d:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6482200 2014-09-26] (Piriform Ltd)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Tomek\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => d:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-03] (Avast Software s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk [2016-04-26]
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe ()

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{58BF2190-27F1-451D-AC99-CF559FB07D52}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131060958388496093&GUID=897817A5-5981-4862-9AF4-316FD6C8B353
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> d:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-03] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> d:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-03] (Avast Software s.r.o.)
BHO-x32: Pomocnik logowania za pomocą konta Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-28] (Oracle Corporation)
Toolbar: HKLM - Brak nazwy - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  Brak pliku
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\user.js [2013-09-07]
FF user.js: detected! => C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\user.js [2013-09-07]
FF Extension: Google Translator for Firefox - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\translator@zoli.bod.xpi [2015-07-04]
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\2020Player_IKEA@2020Technologies.com [2016-04-26]
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\2020Player_IKEA@2020Technologies.com [2015-10-25]
FF Extension: NetVideoHunter - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\netvideohunter@netvideohunter.com [2015-11-14]
FF Extension: Google Translator for Firefox - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\translator@zoli.bod.xpi [2015-07-04]
FF Extension: Adblock Plus - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Adblock Plus - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - d:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - d:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10]
StartMenuInternet: FIREFOX.EXE - D:\Firefox\firefox.exe

Chrome:
=======
CHR HomePage: Default -> hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=0F822702A96A540618C97DD02EA3812F&v=20160425&ts=AHEqAHMmAHYnAk..
CHR StartupUrls: Default -> "hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=0F822702A96A540618C97DD02EA3812F&v=20160425&ts=AHEqAHMmAHYnAk.."
CHR DefaultSearchURL: Default -> hxxp://www.hohosearch.com/chrome.php?q={searchTerms}&ts=AHEqAHMmAHYnAk..&v=20160425&uid=0F822702A96A540618C97DD02EA3812F&ptid=isr&mode=nnnb
CHR DefaultSearchKeyword: Default -> hohosearch
CHR Profile: C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Sklep) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-12-14]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - d:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-03]

==================== Usługi (filtrowane) ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [599944 2014-12-05] (Autodesk Inc.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego]
R2 avast! Antivirus; d:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-03] (Avast Software s.r.o.)
S2 avast! Firewall; d:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-24] (AVAST Software)
S3 AvastVBoxSvc; d:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-07-03] (Avast Software)
S2 AxAutoMntSrv; d:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 CVPND; D:\VPN\cvpnd.exe [1529856 2011-03-04] (Cisco Systems, Inc.)
R2 MBAMScheduler; d:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; d:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S3 Origin Client Service; D:\Program Files\Origin\OriginClientService.exe [2007048 2015-08-22] (Electronic Arts)
R2 StarWindServiceAE; d:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Brak podpisu cyfrowego]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-12-11] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Sterowniki (filtrowane) ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-03] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-03] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-03] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-03] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-03] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-05] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-03] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-03] ()
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] ()
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-26] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-08-07] (Duplex Secure Ltd.)
R2 VBoxAswDrv; d:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-03] (Avast Software)
S3 WinRing0_1_2_0; d:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
U3 acc1in6j; C:\Windows\System32\Drivers\acc1in6j.sys [0 ] (Advanced Micro Devices) <==== UWAGA (zerobajtowy plik/folder)
S1 aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [X]

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-04-26 22:11 - 2016-04-26 22:12 - 00019888 _____ C:\Users\Tomek\Desktop\FRST.txt
2016-04-26 22:11 - 2016-04-26 22:11 - 00000000 ____D C:\FRST
2016-04-26 22:10 - 2016-04-26 22:10 - 02376192 _____ (Farbar) C:\Users\Tomek\Desktop\FRST64.exe
2016-04-26 22:07 - 2016-04-26 22:07 - 00000000 ____D C:\_OTL
2016-04-26 22:05 - 2016-04-26 22:06 - 00602112 _____ (OldTimer Tools) C:\Users\Tomek\Downloads\OTL_www.INSTALKI.pl.exe
2016-04-26 21:15 - 2016-04-26 21:15 - 00000080 _____ C:\Users\Tomek\Desktop\Komputer - skrót.lnk
2016-04-26 20:46 - 2016-04-26 21:55 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-04-26 20:45 - 2016-04-26 21:16 - 00000781 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-26 20:45 - 2016-04-26 20:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-26 20:45 - 2016-04-26 20:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-26 20:45 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-04-26 20:45 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-04-26 20:45 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-04-26 20:44 - 2016-04-26 20:44 - 22908888 _____ (Malwarebytes ) C:\Users\Tomek\Downloads\Malwarebytes Anti-Malware Free 2.2.0.1024 [1].exe
2016-04-26 20:27 - 2016-04-26 21:20 - 00000000 ____D C:\Users\Tomek\AppData\Local\app
2016-04-26 20:24 - 2016-04-26 21:13 - 00000000 ____D C:\Program Files (x86)\CleanBrowser
2016-04-26 19:51 - 2016-04-26 19:51 - 00000266 __RSH C:\Users\Tomek\ntuser.pol
2016-04-26 00:09 - 2016-04-26 21:21 - 00000000 ____D C:\Program Files (x86)\03000200-1461622155-0500-0006-000700080009
2016-04-26 00:06 - 2016-04-26 00:06 - 00621568 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Tomek\Downloads\libeay32.dll
2016-04-26 00:06 - 2016-04-26 00:06 - 00162304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Tomek\Downloads\ssleay32.dll
2016-04-26 00:05 - 2016-04-26 00:05 - 00000660 __RSH C:\ProgramData\ntuser.pol
2016-04-26 00:05 - 2016-04-26 00:05 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-04-25 23:56 - 2016-04-25 23:56 - 05113568 _____ C:\Users\Tomek\Downloads\CorelDraw Graphics Suit X6 Keygen _Serial Number Crack.exe
2016-04-22 22:23 - 2016-04-22 22:34 - 107952524 _____ C:\Users\Tomek\Downloads\Uwagi TV.mp4
2016-04-17 23:05 - 2016-04-17 23:22 - 00010704 _____ C:\Users\Tomek\Downloads\Kopia lampy.xlsx
2016-04-17 23:04 - 2016-04-17 23:04 - 05366407 _____ C:\Users\Tomek\Downloads\materiał do zakładki o nas.zip
2016-04-04 22:01 - 2016-04-04 22:01 - 00198650 _____ C:\Users\Tomek\Downloads\TSRA_190.pdf

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-04-26 22:11 - 2009-07-14 06:45 - 00031888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-26 22:11 - 2009-07-14 06:45 - 00031888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-26 21:54 - 2013-06-04 21:53 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-26 21:54 - 2013-06-02 13:48 - 00000000 ____D C:\ProgramData\NVIDIA
2016-04-26 21:54 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-26 21:52 - 2015-08-29 10:35 - 00529218 _____ C:\Windows\ntbtlog.txt
2016-04-26 21:26 - 2014-02-24 22:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-26 21:21 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\addins
2016-04-26 21:17 - 2013-06-04 21:54 - 00002278 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-26 21:17 - 2013-06-04 21:54 - 00001823 _____ C:\Users\Public\Desktop\Opera.lnk
2016-04-26 21:17 - 2013-06-02 13:38 - 00000784 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-04-26 21:16 - 2015-08-24 22:44 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp Viewer.lnk
2016-04-26 21:16 - 2015-08-24 22:44 - 00002435 _____ C:\Users\Public\Desktop\SketchUp Viewer.lnk
2016-04-26 21:16 - 2015-07-03 20:49 - 00000982 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-04-26 21:16 - 2015-01-10 18:32 - 00001778 _____ C:\Users\Public\Desktop\Revit 2015 - Polski (Polish).lnk
2016-04-26 21:16 - 2014-11-17 00:26 - 00001105 _____ C:\Users\Public\Desktop\Opera 36.lnk
2016-04-26 21:16 - 2014-11-17 00:26 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 36.lnk
2016-04-26 21:16 - 2014-10-28 00:06 - 00000872 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2016-04-26 21:16 - 2014-10-28 00:06 - 00000804 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2016-04-26 21:16 - 2014-10-09 21:48 - 00001005 _____ C:\Users\Public\Desktop\DriverEasy.lnk
2016-04-26 21:16 - 2014-10-04 00:19 - 00002511 _____ C:\Users\Public\Desktop\Skype.lnk
2016-04-26 21:16 - 2014-08-15 20:03 - 00000816 _____ C:\Users\Public\Desktop\SuperMemo UX.lnk
2016-04-26 21:16 - 2014-02-24 22:21 - 00001072 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk
2016-04-26 21:16 - 2014-02-03 22:02 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2016-04-26 21:16 - 2013-12-27 22:41 - 00001241 _____ C:\Users\Public\Desktop\LibreOffice 4.1.lnk
2016-04-26 21:16 - 2013-11-11 13:45 - 00001792 _____ C:\Users\Public\Desktop\Lightroom 4 64-bit.lnk
2016-04-26 21:16 - 2013-11-11 13:45 - 00001788 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4 64-bit.lnk
2016-04-26 21:16 - 2013-10-30 23:06 - 00000921 _____ C:\Users\Public\Desktop\FIFA 14.lnk
2016-04-26 21:16 - 2013-08-07 19:59 - 00002615 _____ C:\Users\Public\Desktop\Nero Burning ROM 12.lnk
2016-04-26 21:16 - 2013-08-07 19:24 - 00000855 _____ C:\Users\Public\Desktop\Alcohol 120%.lnk
2016-04-26 21:16 - 2013-06-30 20:36 - 00001374 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2016-04-26 21:16 - 2013-06-30 20:36 - 00001305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2016-04-26 21:16 - 2013-06-04 23:39 - 00002477 _____ C:\Users\Public\Desktop\ImageShack Uploader.lnk
2016-04-26 21:16 - 2013-06-04 21:54 - 00002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-26 21:16 - 2013-06-04 21:54 - 00001841 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-04-26 21:16 - 2013-06-02 22:38 - 00001196 _____ C:\Users\Public\Desktop\HD VDeck.lnk
2016-04-26 21:16 - 2013-06-02 21:03 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-04-26 21:16 - 2013-06-02 21:03 - 00002013 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-04-26 21:16 - 2013-06-02 20:13 - 00000883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
2016-04-26 21:16 - 2013-06-02 20:11 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2016-04-26 21:16 - 2013-06-02 20:11 - 00000958 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2016-04-26 21:16 - 2013-06-02 14:58 - 00000798 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2016-04-26 21:16 - 2013-06-02 14:58 - 00000728 _____ C:\Users\Public\Desktop\foobar2000.lnk
2016-04-26 21:16 - 2013-06-02 13:42 - 00000943 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2016-04-26 21:16 - 2013-06-02 13:42 - 00000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2016-04-26 21:16 - 2013-06-02 13:38 - 00000784 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-26 21:16 - 2013-06-02 13:28 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-04-26 21:16 - 2013-06-02 13:28 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-04-26 21:16 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-04-26 21:16 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-04-26 21:16 - 2009-07-14 06:57 - 00001352 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-04-26 21:16 - 2009-07-14 06:57 - 00001330 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-04-26 21:16 - 2009-07-14 06:57 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-04-26 21:16 - 2009-07-14 06:54 - 00001210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-04-26 21:15 - 2015-09-05 15:06 - 00000728 _____ C:\Users\Tomek\Desktop\WinDirStat.lnk
2016-04-26 21:15 - 2014-10-11 11:46 - 00002523 _____ C:\Users\Tomek\Desktop\VPN Client.lnk
2016-04-26 21:15 - 2014-05-14 21:46 - 00001007 _____ C:\Users\Tomek\Desktop\SpeedFan.lnk
2016-04-26 21:15 - 2014-05-01 01:42 - 00000970 _____ C:\Users\Tomek\Desktop\NapiProjekt.lnk
2016-04-26 21:15 - 2013-09-07 21:15 - 00002524 _____ C:\Users\Tomek\Desktop\Windows 7 USB DVD Download Tool.lnk
2016-04-26 21:15 - 2013-06-02 20:13 - 00000909 _____ C:\Users\Tomek\Desktop\Adobe Photoshop CS6 (64 Bit).lnk
2016-04-26 21:15 - 2013-06-02 14:02 - 00001622 _____ C:\Users\Tomek\Desktop\GG dysk.lnk
2016-04-26 21:15 - 2013-06-02 13:53 - 00001151 _____ C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk
2016-04-26 21:15 - 2013-06-02 13:53 - 00001143 _____ C:\Users\Tomek\Desktop\GG.lnk
2016-04-26 21:15 - 2013-06-02 13:32 - 00001421 _____ C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-26 21:15 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-04-26 21:15 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-04-26 21:13 - 2013-06-30 20:46 - 00000000 ____D C:\ProgramData\APN
2016-04-26 20:45 - 2013-06-02 13:52 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-26 20:37 - 2013-06-04 21:53 - 00001048 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-26 20:25 - 2013-06-27 21:36 - 00000000 ____D C:\ProgramData\Corel
2016-04-26 19:54 - 2015-01-06 13:59 - 00000000 ____D C:\Users\Tomek\AppData\Local\Akamai
2016-04-26 19:51 - 2013-06-02 13:31 - 00000000 ____D C:\Users\Tomek
2016-04-26 19:50 - 2013-06-02 13:53 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\GG
2016-04-26 00:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2016-04-26 00:03 - 2015-04-03 23:11 - 00000000 ____D C:\Users\Tomek\AppData\Local\ElevatedDiagnostics
2016-04-26 00:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2016-04-25 21:43 - 2013-06-13 22:03 - 00000132 _____ C:\Users\Tomek\AppData\Roaming\Preferencje formatu PNG CS6 firmy Adobe
2016-04-24 22:17 - 2013-06-02 13:53 - 00000000 ____D C:\Users\Tomek\AppData\Local\GG
2016-04-22 09:57 - 2010-11-21 05:27 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-14 19:32 - 2014-11-17 00:26 - 00003900 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1416176786
2016-04-14 19:32 - 2013-06-04 21:54 - 00000000 ____D C:\Program Files (x86)\Opera
2016-04-07 21:45 - 2013-06-02 13:52 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-07 21:45 - 2013-06-02 13:52 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 21:45 - 2013-06-02 13:52 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-03-31 21:29 - 2011-04-12 15:21 - 00740098 _____ C:\Windows\system32\perfh015.dat
2016-03-31 21:29 - 2011-04-12 15:21 - 00155672 _____ C:\Windows\system32\perfc015.dat
2016-03-31 21:29 - 2009-07-14 07:13 - 01669190 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-31 21:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf

==================== Pliki w katalogu głównym wybranych folderów =======

2015-01-05 13:57 - 2016-01-03 22:35 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje filtra IllExport CS6 firmy Adobe
2013-06-04 22:34 - 2013-06-04 22:35 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje formatu BMP CS6 firmy Adobe
2013-06-13 22:03 - 2016-04-25 21:43 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje formatu PNG CS6 firmy Adobe
2016-01-10 20:31 - 2016-01-10 20:31 - 0007605 _____ () C:\Users\Tomek\AppData\Local\Resmon.ResmonCfg

Niektóre pliki w TEMP:
====================
C:\Users\Tomek\AppData\Local\Temp\ggdrive-menu.exe
C:\Users\Tomek\AppData\Local\Temp\ggdrive-overlay.exe
C:\Users\Tomek\AppData\Local\Temp\installstats.exe


==================== Bamital & volsnap =================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo
C:\Windows\explorer.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
C:\Windows\system32\services.exe => Plik podpisany cyfrowo
C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo


LastRegBack: 2016-04-22 20:55

==================== Koniec  FRST.txt ============================


Kod: Zaznacz wszystko
Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (2016-04-26 22:12:44)
Uruchomiony z C:\Users\Tomek\Desktop
Windows 7 Professional Service Pack 1 (X64) (2013-06-02 11:31:25)
Tryb startu: Normal
==========================================================


==================== Konta użytkowników: =============================

Administrator (S-1-5-21-101701808-3503879185-1311691872-500 - Administrator - Disabled)
Gość (S-1-5-21-101701808-3503879185-1311691872-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-101701808-3503879185-1311691872-1002 - Limited - Enabled)
Tomek (S-1-5-21-101701808-3503879185-1311691872-1001 - Administrator - Enabled) => C:\Users\Tomek

==================== Centrum zabezpieczeń ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Zainstalowane programy ======================

(W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.)

Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 4 64-bit (HKLM\...\{669A82E0-43E2-4645-8A2E-1A3DE78F8312}) (Version: 4.0.1 - Adobe)
Adobe Reader XI (11.0.14) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.14 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Aktualizacje NVIDIA 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden
AMD Catalyst Install Manager (HKLM\...\{669D2C56-157D-508E-CC6D-5F4A8A9EAC9C}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 4.0.69.0 - Autodesk)
Autodesk BIM 360 Revit 2015 Add-in 64 bit (HKLM\...\{483308BD-F77F-4C23-9BD3-3DBA6E652BA5}) (Version: 4.35.1209 - Autodesk)
Autodesk Download Manager (HKLM-x32\...\{C897D9EC-13C6-4A22-ABF7-33F2126A7DB6}) (Version: 3.0.8.0 - Autodesk, Inc.)
Autodesk Revit 2015 - Polski (Polish) (HKLM\...\Autodesk Revit 2015 - Polski (Polish)) (Version: 15.0.207.0 - Autodesk)
Autodesk Revit Content Libraries 2015 - Polski (Polish) (HKLM\...\Autodesk Revit Content Libraries 2015 - Polski (Polish)) (Version: 15.0.207.0 - Autodesk)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5143 - CDBurnerXP)
Cisco Systems VPN Client 5.0.07.0440 (HKLM\...\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}) (Version: 5.0.7 - Cisco Systems, Inc.)
Corel Graphics - Windows Shell Extension (HKLM\...\_{B16BB34E-B7BF-47DF-8658-BEABCF40CD6A}) (Version: 16.1.0.843 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 16.1.843 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit (Version: 16.1.843 - Corel Corporation) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DriverEasy 4.7.8 (HKLM\...\DriverEasy_is1) (Version: 4.7.8.0 - Easeware)
FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production)
FIFA 14 (HKLM-x32\...\{AA7A2800-1E75-4240-855B-03AFF8E5171E}) (Version: 1.0.0.7 - Electronic Arts)
FileZilla Client 3.7.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.7.1.1 - Tim Kosse)
foobar2000 v1.2.6 (HKLM-x32\...\foobar2000) (Version: 1.2.6 - Peter Pawlowski)
Galeria fotografii (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Game Booster 3 (HKLM-x32\...\Game Booster_is1) (Version: 3.4 - IObit)
GG (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\GG) (Version: 11 - GG Network S.A.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
ImageShack Uploader 2.2.0 (HKLM-x32\...\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}) (Version: 2.2.0 - ImageShack Corp.)
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
LibreOffice 4.1.4.2 (HKLM-x32\...\{94E11973-ED58-47A0-907C-ABF6D95C5DD8}) (Version: 4.1.4.2 - The Document Foundation)
Malwarebytes Anti-Malware wersja 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.5.1 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Document Explorer 2008 (HKLM-x32\...\Microsoft Document Explorer 2008) (Version:  - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Language Pack 2010 - Polish/Polski (HKLM-x32\...\Office14.OMUI.pl-pl) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.0) (HKLM\...\SDKSetup_7.0.7600.16385.40715) (Version: 7.0.7600.16385.40715 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 21.0 (x86 pl) (HKLM-x32\...\Mozilla Firefox 21.0 (x86 pl)) (Version: 21.0 - Mozilla)
Mozilla Firefox 45.0.2 (x86 pl) (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Mozilla Firefox 45.0.2 (x86 pl)) (Version: 45.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 17.0.6 - Mozilla)
Mozilla Thunderbird 17.0.6 (x86 pl) (HKLM-x32\...\Mozilla Thunderbird 17.0.6 (x86 pl)) (Version: 17.0.6 - Mozilla)
Mozilla Thunderbird 38.7.2 (x86 pl) (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Mozilla Thunderbird 38.7.2 (x86 pl)) (Version: 38.7.2 - Mozilla)
NapiProjekt 2.0.0 (build 2151) (HKLM-x32\...\NapiProjekt_is1) (Version:  - )
Nero 6 Demo (HKLM-x32\...\Nero - Burning Rom!UninstallKey) (Version:  - )
Nero BurningROM 12 (HKLM-x32\...\{3DAFE920-1B88-4C66-A39B-D743F28AF10D}) (Version: 12.5.01300 - Nero AG)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.4.3 - Notepad++ Team)
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Oprogramowanie systemu PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA Sterownik 3D Vision 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Sterownik graficzny 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Sterownik kontrolera 3D Vision 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.3.1.4482 - Electronic Arts, Inc.)
Panel sterowania NVIDIA 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Podstawowe programy Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
RcwViewer 2015 (HKLM-x32\...\{E52D7D07-55C1-482D-A81C-B2E0E9245408}) (Version: 15.1.0 - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.69.304.2013 - Realtek)
Revit 2015 - Polski (Polish) (Version: 15.0.207.0 - Autodesk) Hidden
Revit 2015 Pakiet językowy - Polski (Polish) (Version: 15.0.207.0 - Autodesk) Hidden
Revit Content Libraries 2015 - Polski (Polish) (Version: 15.0.207.0 - Autodesk) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0415-0000-0000000FF1CE}_Office14.OMUI.pl-pl_{11B0F533-C8CF-420C-A43C-C7F93773CA62}) (Version:  - Microsoft)
SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
SketchUp Viewer (HKLM-x32\...\{469F7BEA-33FD-4711-A825-7CA7692EC886}) (Version: 15.3.330 - Trimble Navigation Limited)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
VIA Platforma Menedżera urządzeń (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Virtua Tennis 4™ (HKLM-x32\...\GFWL_{53450FA2-E900-456E-9715-501000008200}) (Version: 1.0.0000.130 - SEGA)
Virtua Tennis 4™ (x32 Version: 1.0.0000.130 - SEGA) Hidden
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
WinDirStat 1.1.2 (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\WinDirStat) (Version:  - )
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{3577E42B-3347-4EB8-BFDA-D36E8ED3C519}) (Version: 1.0.24.0 - Microsoft Corporation)
WinRAR 4.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)

==================== Niestandardowe rejestracje CLSID (filtrowane): ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

CustomCLSID: HKU\S-1-5-21-101701808-3503879185-1311691872-1001_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Tomek\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.)

==================== Zaplanowane zadania (filtrowane) =============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

Task: {084BEFA1-D915-4F16-B4CB-C2AC03296D18} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {2329FE74-95C1-4187-B51A-F8E281433FEF} - System32\Tasks\Opera scheduled Autoupdate 1416176786 => C:\Program Files (x86)\Opera\launcher.exe [2016-04-11] (Opera Software)
Task: {25B1C8EC-6D39-4CF8-95A9-47DFFEC32088} - System32\Tasks\{262E9419-FC0E-4236-8B4B-80DAC4A80516} => pcalua.exe -a C:\Users\Tomek\AppData\Roaming\Easeware\DriverEasy\drivers\ey3lqvox.r0z\audioentry.exe -d C:\Users\Tomek\AppData\Roaming\Easeware\DriverEasy\drivers\ey3lqvox.r0z
Task: {5DEA0560-F47E-422C-9B6B-22EC764B4347} - System32\Tasks\Game_Booster_AutoUpdate => d:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe [2014-10-11] ()
Task: {65AFF63F-C743-4248-B11D-AA4C53BDCB71} - System32\Tasks\{FCCB3189-9960-4110-9244-12DF1B3A4287} => pcalua.exe -a "D:\VPN\TETA_VPNClient 5.0.07 x64 - WIN7_VISTA\vpnclient-winx64-msi-5.0.07.0440-k9.exe" -d "D:\VPN\TETA_VPNClient 5.0.07 x64 - WIN7_VISTA"
Task: {65C6A104-36FF-4AAD-BFF2-15496933792B} - System32\Tasks\ASUS Patch for VIA Audio => C:\Windows\system32\AsPatchViaAudio.exe [2012-11-07] (ASUSTek Computer INC.)
Task: {75826214-B194-4575-AF43-0ED71730ED9D} - System32\Tasks\avast! Emergency Update => d:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-03-17] (Avast Software s.r.o.)
Task: {75D41BFF-E47E-4BC1-8442-3EDE79F90964} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {7A3C85F6-5505-4555-A513-782F216CD756} - System32\Tasks\DriverEasy Scheduled Scan => d:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: {8860096D-A5C4-43C6-8B01-8EA2C304F4AE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07] (Adobe Systems Incorporated)
Task: {9939A93E-65FE-450D-8A5F-A27A5DF99D42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {9F892F95-79DC-4406-9DF3-34CCE0E3C6C3} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-01-26] (AVAST Software)
Task: {C9D3B9AD-8D06-477A-AE64-60DCC46846A6} - Brak ścieżki do pliku
Task: {D7D2C521-66C4-4D49-9F46-48540BCA9DE4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd)

(Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DriverEasy Scheduled Scan.job => d:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Skróty =============================

(Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.)

==================== Załadowane moduły (filtrowane) ==============

2013-06-02 13:47 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-03-28 22:31 - 2013-03-28 22:31 - 00210944 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2012-09-23 13:53 - 2012-09-23 13:53 - 00748544 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2012-09-23 13:53 - 2012-09-23 13:53 - 03645952 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () d:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () d:\Program Files (x86)\Notepad++\NppShell_05.dll
2015-07-03 20:49 - 2015-07-03 20:49 - 00104400 _____ () d:\Program Files\AVAST Software\Avast\log.dll
2015-07-03 20:49 - 2015-07-03 20:49 - 00081728 _____ () d:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-04-26 21:27 - 2016-04-26 21:27 - 02891264 _____ () d:\Program Files\AVAST Software\Avast\defs\16042603\algo.dll
2015-01-10 18:37 - 2014-12-05 04:27 - 00055688 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-01-10 18:37 - 2014-12-05 04:27 - 00104328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2011-03-04 12:49 - 2011-03-04 12:49 - 00202752 _____ () D:\VPN\vpnapi.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

==================== Alternate Data Streams (filtrowane) =========

(Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]

==================== Tryb awaryjny (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.)


==================== EXE - Powiązania (filtrowane) ===============

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.)


==================== Internet Explorer - Witryny zaufane i z ograniczeniami ===============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.)


==================== Hosts - zawartość: ==========================

(Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.)

2009-07-14 04:34 - 2016-04-26 00:07 - 00001006 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       down.baidu2016.com
127.0.0.1       123.sogou.com
127.0.0.1       www.czzsyzgm.com
127.0.0.1       www.czzsyzxl.com
127.0.0.1       union.baidu2019.com

==================== Inne obszary ============================

(Obecnie brak automatycznej naprawy dla tej sekcji.)

HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Zapora systemu Windows [funkcja włączona]

==================== MSCONFIG/TASK MANAGER - Wyłączone elementy ==

(Obecnie brak automatycznej naprawy dla tej sekcji.)


==================== Reguły Zapory systemu Windows (filtrowane) ===============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{0E7F0D87-2165-49AB-9FB6-AF8836A9ED71}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{A179F009-3747-4E93-9CBA-99DCA08BB8E6}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{EB6624F2-07BC-4A38-9950-B7DCFDF88CCF}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{41D0A2AC-209F-495A-9238-CFA99ABB55B1}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{BFAC4786-6942-469F-9F48-EAA41DD5D096}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{140BB2C6-96C1-4454-A604-66CD7CB60AA5}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{3E098D42-8CDB-41B1-9EE2-F90375D6D745}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3846AF77-013C-4846-9EA2-D16F57C286FD}] => (Allow) LPort=2869
FirewallRules: [{AA3458C4-17CA-4783-932E-27CCF71BF26C}] => (Allow) LPort=1900
FirewallRules: [{341B9177-84F8-4AD4-9591-714D8D7ACE8A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{B6A79103-5104-4012-BD0A-FA49EF5D9D16}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{075A8A77-7E4C-4679-B901-0CFB885ABA29}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{027447EB-7123-4053-B668-1635258D763B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{2EA9446F-D260-43F0-B10C-628A21A4F1B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{394960EF-E30A-439C-9453-E6E861FC648B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{57705542-EB21-42D0-8AF4-ACD7C175171D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{FEE4ADEF-AF22-4CAE-B424-2483AC02E26A}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [{9D98F6F9-5A3C-4383-A066-C13491507A76}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [TCP Query User{9B76A2B3-992C-40BD-91DB-C4B1F1AE8D57}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{F94DAF02-3819-4471-B273-F3C0518B4EF7}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{43611F27-E6BB-4640-9833-CCA63C465C5B}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{943BCC8E-995E-4571-B857-0094586CA239}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [{95465677-90EE-4130-9B9F-A48BEDF542D6}] => (Allow) H:\DANE\tennis\Virtua Tennis 4\VT4.exe
FirewallRules: [{CEB7EEF4-672F-47D3-B520-F5E9EAA0ADEE}] => (Allow) H:\DANE\tennis\Virtua Tennis 4\VT4.exe
FirewallRules: [TCP Query User{544CAA44-936B-4C0E-86CC-F308EB3828DC}D:\firefox\firefox.exe] => (Allow) D:\firefox\firefox.exe
FirewallRules: [UDP Query User{E9B2D719-B607-4007-9AA4-324C4B8809E2}D:\firefox\firefox.exe] => (Allow) D:\firefox\firefox.exe
FirewallRules: [{105BD6D6-BA1B-465A-8A38-D24A235F75A0}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe
FirewallRules: [{6F9774C2-CA1E-48B6-9D9D-E56486833C63}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe
FirewallRules: [{F479D28A-9142-4090-90E9-711EA8EB2C97}] => (Allow) D:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{83564086-280F-4A7A-8EF0-69039165BA6D}] => (Allow) D:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{A778477E-140C-42D8-89C1-BB3F84F04BBD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Punkty Przywracania systemu =========================

17-04-2016 17:39:28 Windows Update
22-04-2016 20:24:52 Windows Update
25-04-2016 21:33:29 Windows Update

==================== Wadliwe urządzenia w Menedżerze urządzeń =============

Name: Cisco Systems VPN Adapter for 64-bit Windows
Description: Cisco Systems VPN Adapter for 64-bit Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Błędy w Dzienniku zdarzeń: =========================

Dziennik Aplikacja:
==================
Error: (04/26/2016 09:56:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2016 09:43:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2016 09:40:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2016 09:23:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2016 07:54:52 PM) (Source: MsiInstaller) (EventID: 11310) (User: Tomek-Komputer)
Description: Produkt: Akamai NetSession Interface - Błąd 1310. Błąd zapisu w pliku: C:\Users\Tomek\AppData\Local\Akamai\admintool.exe.  Błąd systemu 0. Sprawdź, czy masz dostęp do tego katalogu.

Error: (04/26/2016 07:51:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2016 12:10:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nazwa aplikacji powodującej błąd: CorelDRW.exe, wersja: 16.1.0.843, sygnatura czasowa: 0x4fff8c8c
Nazwa modułu powodującego błąd: ieframe.dll, wersja: 11.0.9600.17280, sygnatura czasowa: 0x53f26cbd
Kod wyjątku: 0xc0000005
Przesunięcie błędu: 0x0000000000146890
Identyfikator procesu powodującego błąd: 0x2f8
Godzina uruchomienia aplikacji powodującej błąd: 0xCorelDRW.exe0
Ścieżka aplikacji powodującej błąd: CorelDRW.exe1
Ścieżka modułu powodującego błąd: CorelDRW.exe2
Identyfikator raportu: CorelDRW.exe3

Error: (04/25/2016 11:39:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/25/2016 09:24:07 PM) (Source: MsiInstaller) (EventID: 11310) (User: Tomek-Komputer)
Description: Produkt: Akamai NetSession Interface - Błąd 1310. Błąd zapisu w pliku: C:\Users\Tomek\AppData\Local\Akamai\admintool.exe.  Błąd systemu 0. Sprawdź, czy masz dostęp do tego katalogu.

Error: (04/25/2016 09:23:26 PM) (Source: MsiInstaller) (EventID: 11310) (User: Tomek-Komputer)
Description: Produkt: Akamai NetSession Interface - Błąd 1310. Błąd zapisu w pliku: C:\Users\Tomek\AppData\Local\Akamai\admintool.exe.  Błąd systemu 0. Sprawdź, czy masz dostęp do tego katalogu.


Dziennik System:
=============
Error: (04/26/2016 09:54:52 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego:
aswKbd

Error: (04/26/2016 09:54:17 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: ZARZĄDZANIE NT)
Description: Usługa Harmonogram zadań nie może załadować zadań podczas uruchamiania usługi. Dane dodatkowe: Wartość błędu: 2147942402.

Error: (04/26/2016 09:54:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi avast! Firewall z powodu następującego błędu:
%%1053

Error: (04/26/2016 09:54:15 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą avast! Firewall.

Error: (04/26/2016 09:53:58 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: ZARZĄDZANIE NT)
Description: Niektóre funkcje zarządzania energią procesora w czasie wydajności zostały wyłączone z powodu znanego problemu z oprogramowaniem układowym. Skontaktuj się z producentem komputera w celu uzyskania aktualizacji oprogramowania układowego.

Error: (04/26/2016 09:52:06 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Produkt %ZARZĄDZANIE NT60 napotkał błąd podczas próby aktualizacji podpisów.

   Nowa wersja podpisu:

   Poprzednia wersja podpisu: 1.217.2339.0

   Źródło aktualizacji: %ZARZĄDZANIE NT59

   Etap aktualizacji: 4.6.0305.00

   Ścieżka źródła: 4.6.0305.01

   Typ podpisu: %ZARZĄDZANIE NT602

   Typ aktualizacji: %ZARZĄDZANIE NT604

   Użytkownik: ZARZĄDZANIE NT\SYSTEM

   Bieżąca wersja aparatu: %ZARZĄDZANIE NT605

   Poprzednia wersja aparatu: %ZARZĄDZANIE NT606

   Kod błędu: %ZARZĄDZANIE NT607

   Opis błędu: %ZARZĄDZANIE NT608

Error: (04/26/2016 09:52:06 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084wuauserv{E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error: (04/26/2016 09:51:04 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu:
%%1068

Error: (04/26/2016 09:51:04 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu:
%%1068

Error: (04/26/2016 09:51:04 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu:
%%1068


==================== Statystyki pamięci ===========================

Procesor: AMD Athlon(tm) 7750 Dual-Core Processor
Procent pamięci w użyciu: 53%
Całkowita pamięć fizyczna: 4095.3 MB
Dostępna pamięć fizyczna: 1911.71 MB
Całkowita pamięć wirtualna: 8188.79 MB
Dostępna pamięć wirtualna: 5699.48 MB

==================== Dyski ================================

Drive c: () (Fixed) (Total:68.36 GB) (Free:5.21 GB) NTFS ==>[dysk z komponentami startowymi (pozyskano odczytując BCD)]
Drive d: () (Fixed) (Total:80.59 GB) (Free:41.21 GB) NTFS
Drive f: () (Fixed) (Total:14.65 GB) (Free:14.54 GB) NTFS
Drive g: () (Fixed) (Total:59.87 GB) (Free:59.69 GB) NTFS

==================== MBR & Tablica partycji ==================

========================================================
Disk: 0 (Size: 74.5 GB) (Disk ID: 429F429F)
Partition 1: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=59.9 GB) - (Type=OF Extended)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 3CB12B75)
Partition 1: (Active) - (Size=68.4 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=80.6 GB) - (Type=07 NTFS)

==================== Koniec  Addition.txt ============================


Kod: Zaznacz wszystko
Rezultat skanowania skrótów użytkowników (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (2016-04-26 22:14:24)
Uruchomiony z C:\Users\Tomek\Desktop
Tryb startu: Normal

==================== Skróty =============================

(Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.)





Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk -> D:\Program Files (x86)\adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe (Adobe Systems, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk -> C:\Program Files (x86)\Adobe\Adobe Utilities - CS6\ExtendScript Toolkit CS6\ExtendScript Toolkit.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk -> D:\Program Files (x86)\adobe\Adobe Extension Manager CS6\Adobe Extension Manager CS6.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4 64-bit.lnk -> D:\Program Files\Adobe\Adobe Photoshop Lightroom 4\lightroom.exe (Adobe Systems)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk -> D:\Program Files (x86)\CDBurnerXP\cdbxpp.exe (Canneverbe Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk -> D:\Program Files (x86)\foobar2000\foobar2000.exe (Piotr Pawlowski)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk -> C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk -> C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 36.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk -> C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp Viewer.lnk -> C:\Windows\Installer\{469F7BEA-33FD-4711-A825-7CA7692EC886}\Icon_Viewer.exe (Trimble Navigation Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk -> C:\Windows\System32\WindowsAnytimeUpgradeUI.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Help (ENG).lnk -> D:\Program Files (x86)\WinDirStat\windirstat.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Help (PLK).lnk -> D:\Program Files (x86)\WinDirStat\wdsh0415.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Uninstall WinDirStat.lnk -> D:\Program Files (x86)\WinDirStat\Uninstall.exe (WDS Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\WinDirStat.lnk -> D:\Program Files (x86)\WinDirStat\windirstat.exe (Seifert)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VIA\HD VDeck.lnk -> C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperMemo UX\SuperMemo UX.lnk -> C:\Program Files (x86)\SuperMemo UX\supermemo.exe (SuperMemo World)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperMemo UX\Website.lnk -> C:\Program Files (x86)\SuperMemo UX\SuperMemo UX.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Help and HOW-TO.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Release info.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Uninstall SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk -> C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\grvicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoofCon\RoofCon Viewer.lnk -> D:\Program Files (x86)\RcwViewer\RcwViewer.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe (NVIDIA)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe (NVIDIA Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Notepad++.lnk -> D:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero StartSmart.lnk -> C:\Program Files (x86)\Ahead\Nero StartSmart\NeroStartSmart.exe (Ahead Software AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero BackItUp [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\NeroBackItUp_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Burning ROM [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroBurningRom_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Cover Designer [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\NeroCoverDesigner_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Express [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroExpress_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero SoundTrax [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\NeroSoundTrax_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Wave Editor [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\NeroWaveEditor_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero CD-DVD Speed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\CDSpeed.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero DriveSpeed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\DriveSpeed.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero InfoTool.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\InfoTool.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero BackItUp.lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\BackItUp.exe (Ahead Software AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Burning ROM.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Cover Designer.lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\CoverDes.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero SoundTrax.lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\SoundTrax.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Wave Editor.lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\WaveEdit.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero\Nero ControlCenter.lnk -> C:\Windows\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ScControlCenterSta_FC2653898C5047A6A872CAF6433C43A8.exe (Acresso Software Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero\Nero 12\Nero Burning ROM.lnk -> C:\Windows\Installer\{CF508721-0E1E-4F99-A359-59E4EA8DAEC1}\ARPPRODUCTICON.exe (Acresso Software Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Informacje o zmianach.lnk -> C:\Program Files (x86)\NapiProjekt\changelog.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Strona domowa NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\www.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Release Notes.lnk -> C:\Program Files\Microsoft SDKs\Windows\v7.0\ReleaseNotes.Htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Visual Studio Registration\Windows SDK Configuration Tool.lnk -> C:\Program Files\Microsoft SDKs\Windows\v7.0\Setup\WindowsSdkVer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Tools\Tools Reference.lnk -> C:\Program Files\Microsoft SDKs\Windows\v7.0\Bin\StartTools.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\Silverlight.Configuration.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\accicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\xlicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\inficon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\joticon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\outicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\pptico.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\pubs.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\grvicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Digitales Zertifikat für VBA-Projekte.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\cagicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office 2010 Upload Center.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\msouc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office 2010-Spracheinstellungen.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\oisicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace\Games for Windows Marketplace.lnk -> C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLive.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Deinstalacja programu Malwarebytes Anti-Malware.lnk -> D:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk -> D:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk -> D:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Base.lnk -> D:\Program Files (x86)\LibreOffice 4\program\sbase.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Calc.lnk -> D:\Program Files (x86)\LibreOffice 4\program\scalc.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Draw.lnk -> D:\Program Files (x86)\LibreOffice 4\program\sdraw.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Impress.lnk -> D:\Program Files (x86)\LibreOffice 4\program\simpress.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Math.lnk -> D:\Program Files (x86)\LibreOffice 4\program\smath.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Writer.lnk -> D:\Program Files (x86)\LibreOffice 4\program\swriter.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice.lnk -> D:\Program Files (x86)\LibreOffice 4\program\soffice.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe (Oracle Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImageShack Uploader\ImageShack Uploader.lnk -> C:\Windows\Installer\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}\ImageShackUploader.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3\Deinstalacja programu Game Booster 3.lnk -> D:\Program Files (x86)\IObit\Game Booster 3\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3\Game Booster 3.lnk -> D:\Program Files (x86)\IObit\Game Booster 3\GameBooster.exe (IObit)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk -> D:\Program Files (x86)\FileZilla FTP Client\filezilla.exe (FileZilla Project)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk -> D:\Program Files (x86)\FileZilla FTP Client\uninstall.exe (Tim Kosse)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe (Electronic Arts)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\Plik Przeczytaj.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Support\readme\Przeczytaj.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\Pomoc techniczna.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Support\EA Help\Pomoc techniczna.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\Umowa użytkownika FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Support\eula\pl_PL_eula.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverEasy\DriverEasy.lnk -> C:\Program Files\Easeware\DriverEasy\DriverEasy.exe (Easeware)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverEasy\Uninstall DriverEasy.lnk -> C:\Program Files\Easeware\DriverEasy\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Systems VPN Client\Set MTU.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\IconD4CBEB74.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Catalyst Control Center.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software\Avast Free Antivirus.lnk -> D:\Program Files\AVAST Software\Avast\avastui.exe (Avast Software s.r.o.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Download Manager.lnk -> C:\Windows\Installer\{C897D9EC-13C6-4A22-ABF7-33F2126A7DB6}\AdDLMgr.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Uninstall Tool.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\Uninstall Tool\R1\UninstallTool.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Application Manager\Autodesk Application Manager.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe (Autodesk Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\A.C.I.D. Wizard.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\ACID.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol 120%.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\Alcohol.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol Command Launcher.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxCmd.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol Manual.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\Help\ax_enu.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Data-Type Analyzer.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxDTA.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Uninstall Alcohol 120%.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\uninst.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk -> C:\Windows\System32\NetProj.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\Windowspowershell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\IObit\Game Booster 3\BackLnk\FIFA 15.lnk -> D:\Program Files (x86)\Origin Games\FIFA 15\fifa15.exe (Brak pliku)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Adobe Reader XI.lnk -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\Public\Desktop\Alcohol 120%.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\Alcohol.exe (Alcohol Soft Development Team)
Shortcut: C:\Users\Public\Desktop\Avast Free Antivirus.lnk -> D:\Program Files\AVAST Software\Avast\avastui.exe (Avast Software s.r.o.)
Shortcut: C:\Users\Public\Desktop\CDBurnerXP.lnk -> D:\Program Files (x86)\CDBurnerXP\cdbxpp.exe (Canneverbe Limited)
Shortcut: C:\Users\Public\Desktop\DriverEasy.lnk -> C:\Program Files\Easeware\DriverEasy\DriverEasy.exe (Easeware)
Shortcut: C:\Users\Public\Desktop\FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe (Electronic Arts)
Shortcut: C:\Users\Public\Desktop\foobar2000.lnk -> D:\Program Files (x86)\foobar2000\foobar2000.exe (Piotr Pawlowski)
Shortcut: C:\Users\Public\Desktop\HD VDeck.lnk -> C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
Shortcut: C:\Users\Public\Desktop\ImageShack Uploader.lnk -> C:\Windows\Installer\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}\ImageShackUploader.exe ()
Shortcut: C:\Users\Public\Desktop\LibreOffice 4.1.lnk -> D:\Program Files (x86)\LibreOffice 4\program\soffice.exe (The Document Foundation)
Shortcut: C:\Users\Public\Desktop\Lightroom 4 64-bit.lnk -> D:\Program Files\Adobe\Adobe Photoshop Lightroom 4\lightroom.exe (Adobe Systems)
Shortcut: C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk -> D:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes)
Shortcut: C:\Users\Public\Desktop\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\Users\Public\Desktop\Nero Burning ROM 12.lnk -> C:\Windows\Installer\{CF508721-0E1E-4F99-A359-59E4EA8DAEC1}\ARPPRODUCTICON.exe (Acresso Software Inc.)
Shortcut: C:\Users\Public\Desktop\Opera 36.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software)
Shortcut: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software)
Shortcut: C:\Users\Public\Desktop\SketchUp Viewer.lnk -> C:\Windows\Installer\{469F7BEA-33FD-4711-A825-7CA7692EC886}\Icon_Viewer.exe (Trimble Navigation Limited)
Shortcut: C:\Users\Public\Desktop\Skype.lnk -> C:\Windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe ()
Shortcut: C:\Users\Public\Desktop\SuperMemo UX.lnk -> C:\Program Files (x86)\SuperMemo UX\supermemo.exe (SuperMemo World)
Shortcut: C:\Users\Tomek\Links\Desktop.lnk -> C:\Users\Tomek\Desktop ()
Shortcut: C:\Users\Tomek\Links\Downloads.lnk -> C:\Users\Tomek\Downloads ()
Shortcut: C:\Users\Tomek\Links\GG dysk.lnk -> C:\Users\Tomek\GG dysk ()
Shortcut: C:\Users\Tomek\Favorites\GG dysk.lnk -> C:\Users\Tomek\GG dysk ()
Shortcut: C:\Users\Tomek\Documents\Corel\Próbki CorelDRAW X6\target.lnk -> D:\Program Files\Corel\CorelDRAW Graphics Suite X6\Draw\Samples (Brak pliku)
Shortcut: C:\Users\Tomek\Desktop\Adobe Photoshop CS6 (64 Bit).lnk -> D:\Program Files (x86)\adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe (Adobe Systems, Incorporated)
Shortcut: C:\Users\Tomek\Desktop\GG dysk.lnk -> C:\Users\Tomek\GG dysk ()
Shortcut: C:\Users\Tomek\Desktop\GG.lnk -> C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)
Shortcut: C:\Users\Tomek\Desktop\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe ()
Shortcut: C:\Users\Tomek\Desktop\SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
Shortcut: C:\Users\Tomek\Desktop\VPN Client.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A85.exe ()
Shortcut: C:\Users\Tomek\Desktop\WinDirStat.lnk -> D:\Program Files (x86)\WinDirStat\windirstat.exe (Seifert)
Shortcut: C:\Users\Tomek\Desktop\Windows 7 USB DVD Download Tool.lnk -> C:\Users\Tomek\AppData\Local\Apps\Windows 7 USB DVD Download Tool\Windows7-USB-DVD-Download-Tool.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk -> C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool\Uninstall Windows 7 USB DVD Download Tool.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool\Windows 7 USB DVD Download Tool.lnk -> C:\Users\Tomek\AppData\Local\Apps\Windows 7 USB DVD Download Tool\Windows7-USB-DVD-Download-Tool.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero StartSmart.lnk -> C:\Program Files (x86)\Ahead\Nero StartSmart\NeroStartSmart.exe (Ahead Software AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero BackItUp [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\NeroBackItUp_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Burning ROM [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroBurningRom_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Cover Designer [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\NeroCoverDesigner_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Express [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroExpress_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero SoundTrax [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\NeroSoundTrax_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Wave Editor [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\NeroWaveEditor_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero CD-DVD Speed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\CDSpeed.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero DriveSpeed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\DriveSpeed.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero InfoTool.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\InfoTool.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero BackItUp.lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\BackItUp.exe (Ahead Software AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Burning ROM.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Cover Designer.lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\CoverDes.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero SoundTrax.lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\SoundTrax.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Wave Editor.lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\WaveEdit.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Photoshop CS6 (64 Bit).lnk -> D:\Program Files (x86)\adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe (Adobe Systems, Incorporated)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe (Electronic Arts)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\ImageShack Uploader.lnk -> C:\Windows\Installer\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}\ImageShackUploader.exe ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Local\GG\Application\gg.lnk -> C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)




ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->                                                                                                                 
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> D:\Firefox\firefox.exe (Mozilla Corporation) ->                                                                                                                 
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe () -> -user_logon
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /show
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Disable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /disable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Enable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /enable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Express.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG) -> /w
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Napisy oczekujące na pobranie.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe () -> -kolejka
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\CMD Shell.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /E:ON /V:ON /T:0E /K "C:\Program Files\Microsoft SDKs\Windows\v7.0\Bin\SetEnv.cmd"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Windows SDK Documentation.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Help 9\dexplore.exe (Microsoft Corporation) -> /helpcol ms-help://MS.W7SDK.1033 /LaunchNamedUrlTopic DefaultPage /usehelpsettings WindowsSDK.1.0
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\inficon.exe () ->  /design
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe (Oracle Corporation) -> -tab about
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe (Oracle Corporation) -> -tab update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Pomoc.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (ATI Technologies Inc.) -> Start Help -help
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2015 - Polski (Polish)\Narzędzie transferu licencji - Revit 2015.lnk -> C:\Program Files\Common Files\Autodesk Shared\AdLM\R9\LTU.exe (Autodesk, Inc.) -> 829G1 2015.0.0.F -d SA -l pl-PL
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2015 - Polski (Polish)\Revit 2015 - Polski (Polish).lnk -> D:\Program Files (x86)\autodesk\Revit 2015\Revit.exe (Autodesk, Inc.) -> /language PLK
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2015 - Polski (Polish)\Revit Viewer 2015 - Polski (Polish).lnk -> D:\Program Files (x86)\autodesk\Revit 2015\Revit.exe (Autodesk, Inc.) -> /viewer /language PLK
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Public\Desktop\avast! SafeZone.lnk -> D:\Program Files\AVAST Software\Avast\avastui.exe (Avast Software s.r.o.) -> /sfzonebrowser
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> D:\Firefox\firefox.exe (Mozilla Corporation) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Public\Desktop\Revit 2015 - Polski (Polish).lnk -> D:\Program Files (x86)\autodesk\Revit 2015\Revit.exe (Autodesk, Inc.) -> /language PLK
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Express.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG) -> /w
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk -> C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) -> /sendto:
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> D:\Firefox\firefox.exe (Mozilla Corporation) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Excel\Kopia%20lampy305133904254217107\Kopia%20lampy.xlsx.lnk -> C:\Users\Tomek\Downloads\Kopia lampy.xlsx () -> 50


InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url -> hxxp://java.com/help
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url -> hxxp://java.com/
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Galeria gadżetów Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkID=70742
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Poczta usługi Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72681
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Programy usługi Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72700
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Windows Live Spaces.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72682
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Gospodarka.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68923
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Rozrywka.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68924
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Sport.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68921
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Technologie.url -> hxxp://go.microsoft.com/fwlink/?LinkId=55143
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Wideo.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68922
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\Portal MSN.url -> hxxp://go.microsoft.com/fwlink/?LinkId=54729
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Centrum bezpieczeństwa Microsoft.url -> hxxp://go.microsoft.com/fwlink/?LinkID=72887
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Dodatki programu Internet Explorer.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft Office Online.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72885
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft Technet.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72886
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft w Polsce.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72520
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Oryginalne oprogramowanie firmy Microsoft.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72900
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Strona główna programu Internet Explorer.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72186
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Strona główna systemu Windows.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72629
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Technologia RSS.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72889
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\W domu.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72406
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\W pracy.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72407
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Bezpieczeństwo w trybie online.url -> hxxp://go.microsoft.com/fwlink/?LinkId=142211
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Bezpieczny Internet.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129626
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Kultura.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129625
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Pogodynka.pl — oficjalny serwis pogodowy IMGW.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129624
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Polska.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129622
InternetURL: C:\Users\Tomek\Favorites\Links\Galeria obiektów Web Slice.url -> hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\Tomek\Favorites\Links\Sugerowane witryny.url -> hxxps://ieonline.microsoft.com/#ieslice

==================== Koniec  Shortcut.txt =============================
teem90
~user
 
Posty: 4
Dołączenie: 26 Kwi 2016, 22:15



Problem z explorer.exe / hohosearch

Postprzez ordynat 27 Kwi 2016, 01:21

Otwórz Notatnik i wklej w nim:
CHR HomePage: Default -> hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=0F822702A96A540618C97DD02EA3812F&v=20160425&ts=AHEqAHMmAHYnAk..
CHR StartupUrls: Default -> "hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=0F822702A96A540618C97DD02EA3812F&v=20160425&ts=AHEqAHMmAHYnAk.."
CHR DefaultSearchURL: Default -> hxxp://www.hohosearch.com/chrome.php?q={searchTerms}&ts=AHEqAHMmAHYnAk..&v=20160425&uid=0F822702A96A540618C97DD02EA3812F&ptid=isr&mode=nnnb
CHR DefaultSearchKeyword: Default -> hohosearch
C:\Users\Public\Documents\dmp
FF user.js: detected! => C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\user.js [2013-09-07]
FF user.js: detected! => C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\user.js [2013-09-07]
C:\Users\Tomek\AppData\Local\app
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Tomek\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
C:\Users\Tomek\AppData\Local\Akamai\netsession_win.exe
HKLM\...\Winlogon: [Userinit] wscript,
HKLM-x32\...\Winlogon: [Userinit] wscript, [X]
Task: {C9D3B9AD-8D06-477A-AE64-60DCC46846A6} - Brak ścieżki do pliku
Task: {65AFF63F-C743-4248-B11D-AA4C53BDCB71} - System32\Tasks\{FCCB3189-9960-4110-9244-12DF1B3A4287} => pcalua.exe -a "D:\VPN\TETA_VPNClient 5.0.07 x64 - WIN7_VISTA\vpnclient-winx64-msi-5.0.07.0440-k9.exe" -d "D:\VPN\TETA_VPNClient 5.0.07 x64 - WIN7_VISTA"
Task: {25B1C8EC-6D39-4CF8-95A9-47DFFEC32088} - System32\Tasks\{262E9419-FC0E-4236-8B4B-80DAC4A80516} => pcalua.exe -a C:\Users\Tomek\AppData\Roaming\Easeware\DriverEasy\drivers\ey3lqvox.r0z\audioentry.exe -d C:\Users\Tomek\AppData\Roaming\Easeware\DriverEasy\drivers\ey3lqvox.r0z
C:\Program Files (x86)\CleanBrowser
HOSTS:
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST.exe
Uruchom FRST i kliknij przycisk Fix (NAPRAW).
.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Problem z explorer.exe / hohosearch

Postprzez teem90 27 Kwi 2016, 22:59

Fixlog:
Kod: Zaznacz wszystko
Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (2016-04-27 22:46:15) Run:1
Uruchomiony z C:\Users\Tomek\Desktop
Załadowane profile: Tomek (Dostępne profile: Tomek)
Tryb startu: Normal
==============================================

fixlist - zawartość:
*****************
CHR HomePage: Default -> hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=0F822702A96A540618C97DD02EA3812F&v=20160425&ts=AHEqAHMmAHYnAk..
CHR StartupUrls: Default -> "hxxp://www.hohosearch.com/?mode=nnnb&ptid=isr&uid=0F822702A96A540618C97DD02EA3812F&v=20160425&ts=AHEqAHMmAHYnAk.."
CHR DefaultSearchURL: Default -> hxxp://www.hohosearch.com/chrome.php?q={searchTerms}&ts=AHEqAHMmAHYnAk..&v=20160425&uid=0F822702A96A540618C97DD02EA3812F&ptid=isr&mode=nnnb
CHR DefaultSearchKeyword: Default -> hohosearch
C:\Users\Public\Documents\dmp
FF user.js: detected! => C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\user.js [2013-09-07]
FF user.js: detected! => C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\user.js [2013-09-07]
C:\Users\Tomek\AppData\Local\app
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Tomek\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
C:\Users\Tomek\AppData\Local\Akamai\netsession_win.exe
HKLM\...\Winlogon: [Userinit] wscript,
HKLM-x32\...\Winlogon: [Userinit] wscript, [X]
Task: {C9D3B9AD-8D06-477A-AE64-60DCC46846A6} - Brak ścieżki do pliku
Task: {65AFF63F-C743-4248-B11D-AA4C53BDCB71} - System32\Tasks\{FCCB3189-9960-4110-9244-12DF1B3A4287} => pcalua.exe -a "D:\VPN\TETA_VPNClient 5.0.07 x64 - WIN7_VISTA\vpnclient-winx64-msi-5.0.07.0440-k9.exe" -d "D:\VPN\TETA_VPNClient 5.0.07 x64 - WIN7_VISTA"
Task: {25B1C8EC-6D39-4CF8-95A9-47DFFEC32088} - System32\Tasks\{262E9419-FC0E-4236-8B4B-80DAC4A80516} => pcalua.exe -a C:\Users\Tomek\AppData\Roaming\Easeware\DriverEasy\drivers\ey3lqvox.r0z\audioentry.exe -d C:\Users\Tomek\AppData\Roaming\Easeware\DriverEasy\drivers\ey3lqvox.r0z
C:\Program Files (x86)\CleanBrowser
HOSTS:
EmptyTemp:
*****************

Chrome HomePage => pomyślnie usunięto
Chrome StartupUrls => pomyślnie usunięto
Chrome DefaultSearchURL => pomyślnie usunięto
Chrome DefaultSearchKeyword => pomyślnie usunięto
C:\Users\Public\Documents\dmp => pomyślnie przeniesiono
C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\user.js => pomyślnie przeniesiono
C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\user.js => pomyślnie przeniesiono
C:\Users\Tomek\AppData\Local\app => pomyślnie przeniesiono
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Wartość pomyślnie usunięto
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => Wartość pomyślnie usunięto
C:\Users\Tomek\AppData\Local\Akamai\netsession_win.exe => pomyślnie przeniesiono
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Wartość pomyślnie przywrócono
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Wartość pomyślnie przywrócono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C9D3B9AD-8D06-477A-AE64-60DCC46846A6}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9D3B9AD-8D06-477A-AE64-60DCC46846A6}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65AFF63F-C743-4248-B11D-AA4C53BDCB71}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65AFF63F-C743-4248-B11D-AA4C53BDCB71}" => klucz pomyślnie usunięto
C:\Windows\System32\Tasks\{FCCB3189-9960-4110-9244-12DF1B3A4287} => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FCCB3189-9960-4110-9244-12DF1B3A4287}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{25B1C8EC-6D39-4CF8-95A9-47DFFEC32088}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25B1C8EC-6D39-4CF8-95A9-47DFFEC32088}" => klucz pomyślnie usunięto
C:\Windows\System32\Tasks\{262E9419-FC0E-4236-8B4B-80DAC4A80516} => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{262E9419-FC0E-4236-8B4B-80DAC4A80516}" => klucz pomyślnie usunięto
C:\Program Files (x86)\CleanBrowser => pomyślnie przeniesiono
C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono
Hosts pomyślnie przywrócono.
EmptyTemp: => 2.1 GB danych tymczasowych Usunięto.


System wymagał restartu.

==== Koniec  Fixlog 22:46:52 ====


Nowy FRST:
Kod: Zaznacz wszystko
Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (administrator)  TOMEK-KOMPUTER (27-04-2016 22:57:37)
Uruchomiony z C:\Users\Tomek\Desktop
Załadowane profile: Tomek (Dostępne profile: Tomek)
Platform: Windows 7 Professional Service Pack 1 (X64) Język: Polski (Polska)
Internet Explorer Wersja 11 (Domyślna przeglądarka: "D:\Firefox\firefox.exe" -osint -url "%1")
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avast Software s.r.o.) D:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Cisco Systems, Inc.) D:\VPN\cvpnd.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(StarWind Software) D:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(GG Network S.A.) C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe
(GG Network S.A.) C:\Users\Tomek\AppData\Local\GG\Application\ggapp.exe
(Avast Software s.r.o.) D:\Program Files\AVAST Software\Avast\avastui.exe
(Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Autodesk Inc.) C:\Users\Tomek\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe
(GG Network S.A.) C:\Users\Tomek\AppData\Local\GG\Application\ggdrive\ggdrive.exe
(Mozilla Corporation) D:\Firefox\firefox.exe


==================== Rejestr (filtrowane) ===========================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5670448 2013-02-05] (VIA)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => d:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-05] (Avast Software s.r.o.)
HKLM-x32\...\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1627032 2014-02-05] (Autodesk, Inc.)
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [493960 2014-12-05] (Autodesk Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
HKLM\...\Winlogon: [Userinit] wscript,
HKLM-x32\...\Winlogon: [Userinit] wscript, [X]
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [GG] => C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe [4078144 2015-04-03] (GG Network S.A.)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [ALLUpdate] => "d:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6482200 2014-09-26] (Piriform Ltd)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => d:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-03] (Avast Software s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk [2016-04-27]
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe ()

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{58BF2190-27F1-451D-AC99-CF559FB07D52}: [DhcpNameServer] 192.168.0.1
ManualProxies:

Internet Explorer:
==================
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131060958388496093&GUID=897817A5-5981-4862-9AF4-316FD6C8B353
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> d:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-03] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> d:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-03] (Avast Software s.r.o.)
BHO-x32: Pomocnik logowania za pomocą konta Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-28] (Oracle Corporation)
Toolbar: HKLM - Brak nazwy - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  Brak pliku
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\2020Player_IKEA@2020Technologies.com [2016-04-26]
FF Extension: Google Translator for Firefox - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\translator@zoli.bod.xpi [2016-04-27]
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\2020Player_IKEA@2020Technologies.com [2015-10-25]
FF Extension: NetVideoHunter - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\netvideohunter@netvideohunter.com [2015-11-14]
FF Extension: Google Translator for Firefox - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\translator@zoli.bod.xpi [2015-07-04]
FF Extension: Adblock Plus - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Adblock Plus - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - d:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - d:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10]
StartMenuInternet: FIREFOX.EXE - D:\Firefox\firefox.exe

Chrome:
=======
CHR Profile: C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Sklep) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-12-14]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - d:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-03]

==================== Usługi (filtrowane) ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [599944 2014-12-05] (Autodesk Inc.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego]
R2 avast! Antivirus; d:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-03] (Avast Software s.r.o.)
S2 avast! Firewall; d:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-24] (AVAST Software)
S3 AvastVBoxSvc; d:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-07-03] (Avast Software)
S2 AxAutoMntSrv; d:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 CVPND; D:\VPN\cvpnd.exe [1529856 2011-03-04] (Cisco Systems, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S3 Origin Client Service; D:\Program Files\Origin\OriginClientService.exe [2007048 2015-08-22] (Electronic Arts)
R2 StarWindServiceAE; d:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Brak podpisu cyfrowego]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-12-11] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Sterowniki (filtrowane) ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-03] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-03] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-03] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-03] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-03] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-05] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-03] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-03] ()
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] ()
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-08-07] (Duplex Secure Ltd.)
R2 VBoxAswDrv; d:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-03] (Avast Software)
S3 WinRing0_1_2_0; d:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
U3 atno208m; C:\Windows\System32\Drivers\atno208m.sys [0 ] (Advanced Micro Devices) <==== UWAGA (zerobajtowy plik/folder)
S1 aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [X]

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-04-27 22:46 - 2016-04-27 22:46 - 00005025 _____ C:\Users\Tomek\Desktop\Fixlog.txt
2016-04-26 22:29 - 2016-04-27 19:51 - 1035913583 _____ C:\Users\Tomek\Downloads\CorelDRAW.Graphics.Suite.X7.32bit.64bit.pl.rar
2016-04-26 22:14 - 2016-04-26 22:14 - 00054227 _____ C:\Users\Tomek\Desktop\Shortcut.txt
2016-04-26 22:12 - 2016-04-26 22:14 - 00035657 _____ C:\Users\Tomek\Desktop\Addition.txt
2016-04-26 22:11 - 2016-04-27 22:57 - 00018462 _____ C:\Users\Tomek\Desktop\FRST.txt
2016-04-26 22:11 - 2016-04-27 22:57 - 00000000 ____D C:\FRST
2016-04-26 22:10 - 2016-04-26 22:10 - 02376192 _____ (Farbar) C:\Users\Tomek\Desktop\FRST64.exe
2016-04-26 22:07 - 2016-04-26 22:07 - 00000000 ____D C:\_OTL
2016-04-26 22:05 - 2016-04-26 22:06 - 00602112 _____ (OldTimer Tools) C:\Users\Tomek\Downloads\OTL_www.INSTALKI.pl.exe
2016-04-26 21:15 - 2016-04-27 22:50 - 00000080 _____ C:\Users\Tomek\Desktop\Komputer - skrót.lnk
2016-04-26 20:45 - 2016-04-26 20:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-26 20:44 - 2016-04-26 20:44 - 22908888 _____ (Malwarebytes ) C:\Users\Tomek\Downloads\Malwarebytes Anti-Malware Free 2.2.0.1024 [1].exe
2016-04-26 19:51 - 2016-04-27 22:49 - 00000266 __RSH C:\Users\Tomek\ntuser.pol
2016-04-26 00:09 - 2016-04-26 21:21 - 00000000 ____D C:\Program Files (x86)\03000200-1461622155-0500-0006-000700080009
2016-04-26 00:06 - 2016-04-26 00:06 - 00621568 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Tomek\Downloads\libeay32.dll
2016-04-26 00:06 - 2016-04-26 00:06 - 00162304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Tomek\Downloads\ssleay32.dll
2016-04-26 00:05 - 2016-04-27 22:49 - 00000266 __RSH C:\ProgramData\ntuser.pol
2016-04-22 22:23 - 2016-04-22 22:34 - 107952524 _____ C:\Users\Tomek\Downloads\Uwagi TV.mp4
2016-04-17 23:05 - 2016-04-17 23:22 - 00010704 _____ C:\Users\Tomek\Downloads\Kopia lampy.xlsx
2016-04-17 23:04 - 2016-04-17 23:04 - 05366407 _____ C:\Users\Tomek\Downloads\materiał do zakładki o nas.zip
2016-04-04 22:01 - 2016-04-04 22:01 - 00198650 _____ C:\Users\Tomek\Downloads\TSRA_190.pdf

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-04-27 22:56 - 2009-07-14 06:45 - 00031888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-27 22:56 - 2009-07-14 06:45 - 00031888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-27 22:52 - 2013-06-02 13:53 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\GG
2016-04-27 22:51 - 2015-08-24 22:44 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp Viewer.lnk
2016-04-27 22:51 - 2014-11-17 00:26 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 36.lnk
2016-04-27 22:51 - 2014-10-28 00:06 - 00000804 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2016-04-27 22:51 - 2014-02-03 22:02 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2016-04-27 22:51 - 2013-11-11 13:45 - 00001788 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4 64-bit.lnk
2016-04-27 22:51 - 2013-06-30 20:36 - 00001374 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2016-04-27 22:51 - 2013-06-30 20:36 - 00001305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2016-04-27 22:51 - 2013-06-04 21:54 - 00002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-27 22:51 - 2013-06-04 21:54 - 00001841 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-04-27 22:51 - 2013-06-02 21:03 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-04-27 22:51 - 2013-06-02 20:13 - 00000883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
2016-04-27 22:51 - 2013-06-02 20:11 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2016-04-27 22:51 - 2013-06-02 20:11 - 00000958 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2016-04-27 22:51 - 2013-06-02 14:58 - 00000798 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2016-04-27 22:51 - 2013-06-02 13:53 - 00001151 _____ C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk
2016-04-27 22:51 - 2013-06-02 13:42 - 00000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2016-04-27 22:51 - 2013-06-02 13:38 - 00000784 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-27 22:51 - 2013-06-02 13:32 - 00001421 _____ C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-27 22:51 - 2013-06-02 13:28 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-04-27 22:51 - 2013-06-02 13:28 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-04-27 22:51 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001352 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001330 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-04-27 22:51 - 2009-07-14 06:54 - 00001210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-04-27 22:51 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-04-27 22:50 - 2015-09-05 15:06 - 00000728 _____ C:\Users\Tomek\Desktop\WinDirStat.lnk
2016-04-27 22:50 - 2015-08-24 22:44 - 00002441 _____ C:\Users\Public\Desktop\SketchUp Viewer.lnk
2016-04-27 22:50 - 2015-07-03 20:49 - 00000982 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-04-27 22:50 - 2015-01-10 18:32 - 00001778 _____ C:\Users\Public\Desktop\Revit 2015 - Polski (Polish).lnk
2016-04-27 22:50 - 2014-11-17 00:26 - 00001111 _____ C:\Users\Public\Desktop\Opera 36.lnk
2016-04-27 22:50 - 2014-10-28 00:06 - 00000872 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2016-04-27 22:50 - 2014-10-11 11:46 - 00002523 _____ C:\Users\Tomek\Desktop\VPN Client.lnk
2016-04-27 22:50 - 2014-10-09 21:48 - 00001011 _____ C:\Users\Public\Desktop\DriverEasy.lnk
2016-04-27 22:50 - 2014-10-04 00:19 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2016-04-27 22:50 - 2014-08-15 20:03 - 00000822 _____ C:\Users\Public\Desktop\SuperMemo UX.lnk
2016-04-27 22:50 - 2014-05-14 21:46 - 00001007 _____ C:\Users\Tomek\Desktop\SpeedFan.lnk
2016-04-27 22:50 - 2014-05-01 01:42 - 00000970 _____ C:\Users\Tomek\Desktop\NapiProjekt.lnk
2016-04-27 22:50 - 2014-02-24 22:21 - 00001072 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk
2016-04-27 22:50 - 2013-12-27 22:41 - 00001241 _____ C:\Users\Public\Desktop\LibreOffice 4.1.lnk
2016-04-27 22:50 - 2013-11-11 13:45 - 00001792 _____ C:\Users\Public\Desktop\Lightroom 4 64-bit.lnk
2016-04-27 22:50 - 2013-10-30 23:06 - 00000921 _____ C:\Users\Public\Desktop\FIFA 14.lnk
2016-04-27 22:50 - 2013-09-07 21:15 - 00002524 _____ C:\Users\Tomek\Desktop\Windows 7 USB DVD Download Tool.lnk
2016-04-27 22:50 - 2013-08-07 19:59 - 00002621 _____ C:\Users\Public\Desktop\Nero Burning ROM 12.lnk
2016-04-27 22:50 - 2013-08-07 19:24 - 00000855 _____ C:\Users\Public\Desktop\Alcohol 120%.lnk
2016-04-27 22:50 - 2013-06-04 23:39 - 00002483 _____ C:\Users\Public\Desktop\ImageShack Uploader.lnk
2016-04-27 22:50 - 2013-06-04 21:54 - 00002284 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-27 22:50 - 2013-06-04 21:54 - 00001829 _____ C:\Users\Public\Desktop\Opera.lnk
2016-04-27 22:50 - 2013-06-02 22:38 - 00001202 _____ C:\Users\Public\Desktop\HD VDeck.lnk
2016-04-27 22:50 - 2013-06-02 21:03 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-04-27 22:50 - 2013-06-02 14:58 - 00000728 _____ C:\Users\Public\Desktop\foobar2000.lnk
2016-04-27 22:50 - 2013-06-02 14:02 - 00001622 _____ C:\Users\Tomek\Desktop\GG dysk.lnk
2016-04-27 22:50 - 2013-06-02 13:53 - 00001143 _____ C:\Users\Tomek\Desktop\GG.lnk
2016-04-27 22:50 - 2013-06-02 13:42 - 00000943 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2016-04-27 22:50 - 2013-06-02 13:38 - 00000784 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-04-27 22:49 - 2013-06-02 20:13 - 00000909 _____ C:\Users\Tomek\Desktop\Adobe Photoshop CS6 (64 Bit).lnk
2016-04-27 22:49 - 2013-06-02 13:31 - 00000000 ____D C:\Users\Tomek
2016-04-27 22:48 - 2013-06-04 21:53 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-27 22:48 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-27 22:47 - 2013-06-02 13:48 - 00000000 ____D C:\ProgramData\NVIDIA
2016-04-27 22:46 - 2015-01-06 13:59 - 00000000 ____D C:\Users\Tomek\AppData\Local\Akamai
2016-04-27 22:46 - 2014-09-09 15:29 - 00000000 ____D C:\Users\Tomek\AppData\LocalLow\Temp
2016-04-26 21:52 - 2015-08-29 10:35 - 00529218 _____ C:\Windows\ntbtlog.txt
2016-04-26 21:26 - 2014-02-24 22:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-04-26 21:21 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\addins
2016-04-26 21:16 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-04-26 21:13 - 2013-06-30 20:46 - 00000000 ____D C:\ProgramData\APN
2016-04-26 20:45 - 2013-06-02 13:52 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-26 20:37 - 2013-06-04 21:53 - 00001048 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-26 20:25 - 2013-06-27 21:36 - 00000000 ____D C:\ProgramData\Corel
2016-04-26 00:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2016-04-26 00:03 - 2015-04-03 23:11 - 00000000 ____D C:\Users\Tomek\AppData\Local\ElevatedDiagnostics
2016-04-26 00:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2016-04-25 21:43 - 2013-06-13 22:03 - 00000132 _____ C:\Users\Tomek\AppData\Roaming\Preferencje formatu PNG CS6 firmy Adobe
2016-04-24 22:17 - 2013-06-02 13:53 - 00000000 ____D C:\Users\Tomek\AppData\Local\GG
2016-04-22 09:57 - 2010-11-21 05:27 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-14 19:32 - 2014-11-17 00:26 - 00003900 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1416176786
2016-04-14 19:32 - 2013-06-04 21:54 - 00000000 ____D C:\Program Files (x86)\Opera
2016-04-07 21:45 - 2013-06-02 13:52 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-07 21:45 - 2013-06-02 13:52 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 21:45 - 2013-06-02 13:52 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-03-31 21:29 - 2011-04-12 15:21 - 00740098 _____ C:\Windows\system32\perfh015.dat
2016-03-31 21:29 - 2011-04-12 15:21 - 00155672 _____ C:\Windows\system32\perfc015.dat
2016-03-31 21:29 - 2009-07-14 07:13 - 01669190 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-31 21:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf

==================== Pliki w katalogu głównym wybranych folderów =======

2015-01-05 13:57 - 2016-01-03 22:35 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje filtra IllExport CS6 firmy Adobe
2013-06-04 22:34 - 2013-06-04 22:35 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje formatu BMP CS6 firmy Adobe
2013-06-13 22:03 - 2016-04-25 21:43 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje formatu PNG CS6 firmy Adobe
2016-01-10 20:31 - 2016-01-10 20:31 - 0007605 _____ () C:\Users\Tomek\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap =================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo
C:\Windows\explorer.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
C:\Windows\system32\services.exe => Plik podpisany cyfrowo
C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo


LastRegBack: 2016-04-22 20:55

==================== Koniec  FRST.txt ============================
teem90
~user
 
Posty: 4
Dołączenie: 26 Kwi 2016, 22:15



Problem z explorer.exe / hohosearch

Postprzez ordynat 28 Kwi 2016, 06:43

Otwórz Notatnik i wklej w nim:
Toolbar: HKLM - Brak nazwy - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Brak pliku
HKLM\...\Winlogon: [Userinit] wscript,
HKLM-x32\...\Winlogon: [Userinit] wscript, [X]
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST.exe
Uruchom FRST i kliknij przycisk Fix (NAPRAW).

Jeśli będzie OK, to będziemy kończyć:
Otwórz Notatnik i wklej w nim:
DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).
przez SHIFT+DEL usuń pozostały folder C:\FRST.
.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Problem z explorer.exe / hohosearch

Postprzez teem90 28 Kwi 2016, 22:58

Zanim wykonam ostatni ruch, reklam nie ma, niby wszystko ok, ale wciąż domyślną wyszukiwarką jest jakaś OZIP. Jak się tego pozbyć?
teem90
~user
 
Posty: 4
Dołączenie: 26 Kwi 2016, 22:15



Problem z explorer.exe / hohosearch

Postprzez ordynat 28 Kwi 2016, 23:43

Zrób nowe logi FRST - zobaczymy, czy coś się pojawiło z OZIP.
.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Problem z explorer.exe / hohosearch

Postprzez teem90 02 Maj 2016, 22:47

Kod: Zaznacz wszystko
Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (administrator)  TOMEK-KOMPUTER (02-05-2016 22:38:19)
Uruchomiony z C:\Users\Tomek\Desktop
Załadowane profile: Tomek (Dostępne profile: Tomek)
Platform: Windows 7 Professional Service Pack 1 (X64) Język: Polski (Polska)
Internet Explorer Wersja 11 (Domyślna przeglądarka: "D:\Firefox\firefox.exe" -osint -url "%1")
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avast Software s.r.o.) D:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Cisco Systems, Inc.) D:\VPN\cvpnd.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(StarWind Software) D:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(GG Network S.A.) C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe
(GG Network S.A.) C:\Users\Tomek\AppData\Local\GG\Application\ggapp.exe
(Avast Software s.r.o.) D:\Program Files\AVAST Software\Avast\avastui.exe
(Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Autodesk Inc.) C:\Users\Tomek\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(GG Network S.A.) C:\Users\Tomek\AppData\Local\GG\Application\ggdrive\ggdrive.exe
(Mozilla Corporation) D:\Firefox\firefox.exe
(Mozilla Corporation) D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) D:\Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe


==================== Rejestr (filtrowane) ===========================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5670448 2013-02-05] (VIA)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => d:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-05] (Avast Software s.r.o.)
HKLM-x32\...\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1627032 2014-02-05] (Autodesk, Inc.)
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [493960 2014-12-05] (Autodesk Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [GG] => C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe [4078144 2015-04-03] (GG Network S.A.)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [ALLUpdate] => "d:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6482200 2014-09-26] (Piriform Ltd)
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => d:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-03] (Avast Software s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk [2016-04-27]
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe ()

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{58BF2190-27F1-451D-AC99-CF559FB07D52}: [DhcpNameServer] 192.168.0.1
ManualProxies:

Internet Explorer:
==================
HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131060958388496093&GUID=897817A5-5981-4862-9AF4-316FD6C8B353
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> d:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-03] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> d:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-03] (Avast Software s.r.o.)
BHO-x32: Pomocnik logowania za pomocą konta Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-28] (Oracle Corporation)
Toolbar: HKLM - Brak nazwy - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  Brak pliku
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\2020Player_IKEA@2020Technologies.com [2016-04-26]
FF Extension: Google Translator for Firefox - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\translator@zoli.bod.xpi [2016-04-27]
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\2020Player_IKEA@2020Technologies.com [2015-10-25]
FF Extension: NetVideoHunter - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\netvideohunter@netvideohunter.com [2015-11-14]
FF Extension: Google Translator for Firefox - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\translator@zoli.bod.xpi [2015-07-04]
FF Extension: Adblock Plus - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\ji26h2e8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Adblock Plus - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - d:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - d:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10]
StartMenuInternet: FIREFOX.EXE - D:\Firefox\firefox.exe

Chrome:
=======
CHR Profile: C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Sklep) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-12-14]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - d:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-03]

==================== Usługi (filtrowane) ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [599944 2014-12-05] (Autodesk Inc.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.) [Brak podpisu cyfrowego]
R2 avast! Antivirus; d:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-03] (Avast Software s.r.o.)
S2 avast! Firewall; d:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-24] (AVAST Software)
S3 AvastVBoxSvc; d:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-07-03] (Avast Software)
S2 AxAutoMntSrv; d:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 CVPND; D:\VPN\cvpnd.exe [1529856 2011-03-04] (Cisco Systems, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S3 Origin Client Service; D:\Program Files\Origin\OriginClientService.exe [2007048 2015-08-22] (Electronic Arts)
R2 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
R2 StarWindServiceAE; d:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Brak podpisu cyfrowego]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Brak podpisu cyfrowego]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-12-11] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Sterowniki (filtrowane) ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-03] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-03] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-03] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-03] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-03] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-05] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-03] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-03] ()
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] ()
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-08-07] (Duplex Secure Ltd.)
R2 VBoxAswDrv; d:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-03] (Avast Software)
S3 WinRing0_1_2_0; d:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
U3 a1q2tla5; C:\Windows\System32\Drivers\a1q2tla5.sys [0 ] (Advanced Micro Devices) <==== UWAGA (zerobajtowy plik/folder)
S1 aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [X]

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-04-28 23:36 - 2016-04-28 23:31 - 00002198 _____ C:\Users\Public\Desktop\Bitstream Font Navigator (64-Bit).lnk
2016-04-28 23:36 - 2016-04-28 23:26 - 00003015 _____ C:\Users\Public\Desktop\CorelDRAW X7 (64-Bit).lnk
2016-04-28 23:31 - 2016-04-28 23:31 - 00000000 ____D C:\Program Files\Common Files\Corel
2016-04-28 23:30 - 2016-04-28 23:30 - 00000000 ____D C:\Program Files\Common Files\Protexis
2016-04-28 23:29 - 2016-04-28 23:29 - 00000000 ____D C:\Users\Public\Documents\Corel
2016-04-28 23:26 - 2016-04-28 23:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)
2016-04-28 23:25 - 2016-04-28 23:25 - 00000000 ____D C:\Program Files\Corel
2016-04-28 23:12 - 2016-04-28 23:43 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2016-04-28 22:59 - 2015-09-05 15:14 - 00000000 ____D C:\Users\Tomek\Downloads\CorelDRAW.Graphics.Suite.X7.32bit.64bit.pl
2016-04-27 22:46 - 2016-04-28 22:50 - 00004470 _____ C:\Users\Tomek\Desktop\Fixlog.txt
2016-04-26 22:29 - 2016-04-27 19:51 - 1035913583 _____ C:\Users\Tomek\Downloads\CorelDRAW.Graphics.Suite.X7.32bit.64bit.pl.rar
2016-04-26 22:14 - 2016-04-26 22:14 - 00054227 _____ C:\Users\Tomek\Desktop\Shortcut.txt
2016-04-26 22:12 - 2016-04-26 22:14 - 00035657 _____ C:\Users\Tomek\Desktop\Addition.txt
2016-04-26 22:11 - 2016-05-02 22:39 - 00018966 _____ C:\Users\Tomek\Desktop\FRST.txt
2016-04-26 22:11 - 2016-05-02 22:38 - 00000000 ____D C:\FRST
2016-04-26 22:10 - 2016-04-26 22:10 - 02376192 _____ (Farbar) C:\Users\Tomek\Desktop\FRST64.exe
2016-04-26 22:07 - 2016-04-26 22:07 - 00000000 ____D C:\_OTL
2016-04-26 22:05 - 2016-04-26 22:06 - 00602112 _____ (OldTimer Tools) C:\Users\Tomek\Downloads\OTL_www.INSTALKI.pl.exe
2016-04-26 21:15 - 2016-04-27 22:50 - 00000080 _____ C:\Users\Tomek\Desktop\Komputer - skrót.lnk
2016-04-26 20:45 - 2016-04-26 20:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-26 20:44 - 2016-04-26 20:44 - 22908888 _____ (Malwarebytes ) C:\Users\Tomek\Downloads\Malwarebytes Anti-Malware Free 2.2.0.1024 [1].exe
2016-04-26 19:51 - 2016-04-27 22:49 - 00000266 __RSH C:\Users\Tomek\ntuser.pol
2016-04-26 00:09 - 2016-04-26 21:21 - 00000000 ____D C:\Program Files (x86)\03000200-1461622155-0500-0006-000700080009
2016-04-26 00:06 - 2016-04-26 00:06 - 00621568 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Tomek\Downloads\libeay32.dll
2016-04-26 00:06 - 2016-04-26 00:06 - 00162304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Tomek\Downloads\ssleay32.dll
2016-04-26 00:05 - 2016-04-27 22:49 - 00000266 __RSH C:\ProgramData\ntuser.pol
2016-04-22 22:23 - 2016-04-22 22:34 - 107952524 _____ C:\Users\Tomek\Downloads\Uwagi TV.mp4
2016-04-17 23:05 - 2016-04-17 23:22 - 00010704 _____ C:\Users\Tomek\Downloads\Kopia lampy.xlsx
2016-04-17 23:04 - 2016-04-17 23:04 - 05366407 _____ C:\Users\Tomek\Downloads\materiał do zakładki o nas.zip
2016-04-04 22:01 - 2016-04-04 22:01 - 00198650 _____ C:\Users\Tomek\Downloads\TSRA_190.pdf

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2016-05-02 22:37 - 2013-06-04 21:53 - 00001048 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-02 22:35 - 2009-07-14 06:45 - 00031888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-02 22:35 - 2009-07-14 06:45 - 00031888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-02 22:26 - 2013-06-04 21:53 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-02 22:24 - 2014-02-24 22:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-05-02 22:23 - 2013-06-02 13:53 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\GG
2016-05-02 22:22 - 2013-06-02 13:48 - 00000000 ____D C:\ProgramData\NVIDIA
2016-05-02 22:22 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-28 23:48 - 2013-06-27 21:39 - 00000000 ____D C:\Users\Tomek\Documents\Corel
2016-04-28 23:47 - 2013-06-27 21:41 - 00000000 ____D C:\ProgramData\Protexis64
2016-04-28 23:46 - 2013-06-27 21:41 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\Corel
2016-04-28 23:45 - 2013-06-02 13:52 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-28 23:35 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-04-28 23:33 - 2014-10-09 21:29 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-28 23:30 - 2013-06-27 21:36 - 00000000 ____D C:\ProgramData\Corel
2016-04-27 22:51 - 2015-08-24 22:44 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp Viewer.lnk
2016-04-27 22:51 - 2014-11-17 00:26 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 36.lnk
2016-04-27 22:51 - 2014-10-28 00:06 - 00000804 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2016-04-27 22:51 - 2014-02-03 22:02 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2016-04-27 22:51 - 2013-11-11 13:45 - 00001788 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4 64-bit.lnk
2016-04-27 22:51 - 2013-06-30 20:36 - 00001374 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2016-04-27 22:51 - 2013-06-30 20:36 - 00001305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2016-04-27 22:51 - 2013-06-04 21:54 - 00002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-27 22:51 - 2013-06-04 21:54 - 00001841 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-04-27 22:51 - 2013-06-02 21:03 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-04-27 22:51 - 2013-06-02 20:13 - 00000883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
2016-04-27 22:51 - 2013-06-02 20:11 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2016-04-27 22:51 - 2013-06-02 20:11 - 00000958 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2016-04-27 22:51 - 2013-06-02 14:58 - 00000798 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2016-04-27 22:51 - 2013-06-02 13:53 - 00001151 _____ C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk
2016-04-27 22:51 - 2013-06-02 13:42 - 00000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2016-04-27 22:51 - 2013-06-02 13:38 - 00000784 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-27 22:51 - 2013-06-02 13:32 - 00001421 _____ C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-27 22:51 - 2013-06-02 13:28 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-04-27 22:51 - 2013-06-02 13:28 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-04-27 22:51 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001352 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001330 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-04-27 22:51 - 2009-07-14 06:57 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-04-27 22:51 - 2009-07-14 06:54 - 00001210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-04-27 22:51 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-04-27 22:50 - 2015-09-05 15:06 - 00000728 _____ C:\Users\Tomek\Desktop\WinDirStat.lnk
2016-04-27 22:50 - 2015-08-24 22:44 - 00002441 _____ C:\Users\Public\Desktop\SketchUp Viewer.lnk
2016-04-27 22:50 - 2015-07-03 20:49 - 00000982 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-04-27 22:50 - 2015-01-10 18:32 - 00001778 _____ C:\Users\Public\Desktop\Revit 2015 - Polski (Polish).lnk
2016-04-27 22:50 - 2014-11-17 00:26 - 00001111 _____ C:\Users\Public\Desktop\Opera 36.lnk
2016-04-27 22:50 - 2014-10-28 00:06 - 00000872 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2016-04-27 22:50 - 2014-10-11 11:46 - 00002523 _____ C:\Users\Tomek\Desktop\VPN Client.lnk
2016-04-27 22:50 - 2014-10-09 21:48 - 00001011 _____ C:\Users\Public\Desktop\DriverEasy.lnk
2016-04-27 22:50 - 2014-10-04 00:19 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2016-04-27 22:50 - 2014-08-15 20:03 - 00000822 _____ C:\Users\Public\Desktop\SuperMemo UX.lnk
2016-04-27 22:50 - 2014-05-14 21:46 - 00001007 _____ C:\Users\Tomek\Desktop\SpeedFan.lnk
2016-04-27 22:50 - 2014-05-01 01:42 - 00000970 _____ C:\Users\Tomek\Desktop\NapiProjekt.lnk
2016-04-27 22:50 - 2014-02-24 22:21 - 00001072 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk
2016-04-27 22:50 - 2013-12-27 22:41 - 00001241 _____ C:\Users\Public\Desktop\LibreOffice 4.1.lnk
2016-04-27 22:50 - 2013-11-11 13:45 - 00001792 _____ C:\Users\Public\Desktop\Lightroom 4 64-bit.lnk
2016-04-27 22:50 - 2013-10-30 23:06 - 00000921 _____ C:\Users\Public\Desktop\FIFA 14.lnk
2016-04-27 22:50 - 2013-09-07 21:15 - 00002524 _____ C:\Users\Tomek\Desktop\Windows 7 USB DVD Download Tool.lnk
2016-04-27 22:50 - 2013-08-07 19:59 - 00002621 _____ C:\Users\Public\Desktop\Nero Burning ROM 12.lnk
2016-04-27 22:50 - 2013-08-07 19:24 - 00000855 _____ C:\Users\Public\Desktop\Alcohol 120%.lnk
2016-04-27 22:50 - 2013-06-04 23:39 - 00002483 _____ C:\Users\Public\Desktop\ImageShack Uploader.lnk
2016-04-27 22:50 - 2013-06-04 21:54 - 00002284 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-27 22:50 - 2013-06-04 21:54 - 00001829 _____ C:\Users\Public\Desktop\Opera.lnk
2016-04-27 22:50 - 2013-06-02 22:38 - 00001202 _____ C:\Users\Public\Desktop\HD VDeck.lnk
2016-04-27 22:50 - 2013-06-02 21:03 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2016-04-27 22:50 - 2013-06-02 14:58 - 00000728 _____ C:\Users\Public\Desktop\foobar2000.lnk
2016-04-27 22:50 - 2013-06-02 14:02 - 00001622 _____ C:\Users\Tomek\Desktop\GG dysk.lnk
2016-04-27 22:50 - 2013-06-02 13:53 - 00001143 _____ C:\Users\Tomek\Desktop\GG.lnk
2016-04-27 22:50 - 2013-06-02 13:42 - 00000943 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2016-04-27 22:50 - 2013-06-02 13:38 - 00000784 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-04-27 22:49 - 2013-06-02 20:13 - 00000909 _____ C:\Users\Tomek\Desktop\Adobe Photoshop CS6 (64 Bit).lnk
2016-04-27 22:49 - 2013-06-02 13:31 - 00000000 ____D C:\Users\Tomek
2016-04-27 22:46 - 2015-01-06 13:59 - 00000000 ____D C:\Users\Tomek\AppData\Local\Akamai
2016-04-27 22:46 - 2014-09-09 15:29 - 00000000 ____D C:\Users\Tomek\AppData\LocalLow\Temp
2016-04-26 21:52 - 2015-08-29 10:35 - 00529218 _____ C:\Windows\ntbtlog.txt
2016-04-26 21:21 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\addins
2016-04-26 21:16 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-04-26 21:13 - 2013-06-30 20:46 - 00000000 ____D C:\ProgramData\APN
2016-04-26 00:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2016-04-26 00:03 - 2015-04-03 23:11 - 00000000 ____D C:\Users\Tomek\AppData\Local\ElevatedDiagnostics
2016-04-26 00:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2016-04-25 21:43 - 2013-06-13 22:03 - 00000132 _____ C:\Users\Tomek\AppData\Roaming\Preferencje formatu PNG CS6 firmy Adobe
2016-04-24 22:17 - 2013-06-02 13:53 - 00000000 ____D C:\Users\Tomek\AppData\Local\GG
2016-04-22 09:57 - 2010-11-21 05:27 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-14 19:32 - 2014-11-17 00:26 - 00003900 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1416176786
2016-04-14 19:32 - 2013-06-04 21:54 - 00000000 ____D C:\Program Files (x86)\Opera
2016-04-07 21:45 - 2013-06-02 13:52 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-07 21:45 - 2013-06-02 13:52 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 21:45 - 2013-06-02 13:52 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

==================== Pliki w katalogu głównym wybranych folderów =======

2015-01-05 13:57 - 2016-01-03 22:35 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje filtra IllExport CS6 firmy Adobe
2013-06-04 22:34 - 2013-06-04 22:35 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje formatu BMP CS6 firmy Adobe
2013-06-13 22:03 - 2016-04-25 21:43 - 0000132 _____ () C:\Users\Tomek\AppData\Roaming\Preferencje formatu PNG CS6 firmy Adobe
2016-01-10 20:31 - 2016-01-10 20:31 - 0007605 _____ () C:\Users\Tomek\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap =================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\wininit.exe => Plik podpisany cyfrowo
C:\Windows\explorer.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\explorer.exe => Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\svchost.exe => Plik podpisany cyfrowo
C:\Windows\system32\services.exe => Plik podpisany cyfrowo
C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\User32.dll => Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
C:\Windows\SysWOW64\userinit.exe => Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\SysWOW64\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo


LastRegBack: 2016-04-22 20:55

==================== Koniec  FRST.txt ============================


Kod: Zaznacz wszystko
Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (2016-05-02 22:40:41)
Uruchomiony z C:\Users\Tomek\Desktop
Windows 7 Professional Service Pack 1 (X64) (2013-06-02 11:31:25)
Tryb startu: Normal
==========================================================


==================== Konta użytkowników: =============================

Administrator (S-1-5-21-101701808-3503879185-1311691872-500 - Administrator - Disabled)
Gość (S-1-5-21-101701808-3503879185-1311691872-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-101701808-3503879185-1311691872-1002 - Limited - Enabled)
Tomek (S-1-5-21-101701808-3503879185-1311691872-1001 - Administrator - Enabled) => C:\Users\Tomek

==================== Centrum zabezpieczeń ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Zainstalowane programy ======================

(W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.)

Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 4 64-bit (HKLM\...\{669A82E0-43E2-4645-8A2E-1A3DE78F8312}) (Version: 4.0.1 - Adobe)
Adobe Reader XI (11.0.14) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.14 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Aktualizacje NVIDIA 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden
AMD Catalyst Install Manager (HKLM\...\{669D2C56-157D-508E-CC6D-5F4A8A9EAC9C}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 4.0.69.0 - Autodesk)
Autodesk BIM 360 Revit 2015 Add-in 64 bit (HKLM\...\{483308BD-F77F-4C23-9BD3-3DBA6E652BA5}) (Version: 4.35.1209 - Autodesk)
Autodesk Download Manager (HKLM-x32\...\{C897D9EC-13C6-4A22-ABF7-33F2126A7DB6}) (Version: 3.0.8.0 - Autodesk, Inc.)
Autodesk Revit 2015 - Polski (Polish) (HKLM\...\Autodesk Revit 2015 - Polski (Polish)) (Version: 15.0.207.0 - Autodesk)
Autodesk Revit Content Libraries 2015 - Polski (Polish) (HKLM\...\Autodesk Revit Content Libraries 2015 - Polski (Polish)) (Version: 15.0.207.0 - Autodesk)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5143 - CDBurnerXP)
CGS17_Setup_x64 (Version: 17.1 - Corel Corporation) Hidden
Cisco Systems VPN Client 5.0.07.0440 (HKLM\...\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}) (Version: 5.0.7 - Cisco Systems, Inc.)
Corel Graphics - Windows Shell Extension (HKLM\...\_{4DC318F5-1640-4417-A218-912ED9905FAA}) (Version: 17.1.0.572 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 17.1.572 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.1.572 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Capture (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Common (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Connect (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Custom Data (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Draw (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Filters (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - FontNav (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - IPM Content (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - IPM T (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - PL (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Redist (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Setup Files (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - VBA (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - VideoBrowser (x64) (Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Writing Tools (x64) (Version: 17.1 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 (64-Bit) (HKLM\...\_{5CB73140-806C-42C6-A05A-1AFD0E92DEB5}) (Version: 17.1.0.572 - Corel Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DriverEasy 4.7.8 (HKLM\...\DriverEasy_is1) (Version: 4.7.8.0 - Easeware)
FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production)
FIFA 14 (HKLM-x32\...\{AA7A2800-1E75-4240-855B-03AFF8E5171E}) (Version: 1.0.0.7 - Electronic Arts)
FileZilla Client 3.7.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.7.1.1 - Tim Kosse)
foobar2000 v1.2.6 (HKLM-x32\...\foobar2000) (Version: 1.2.6 - Peter Pawlowski)
Galeria fotografii (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Game Booster 3 (HKLM-x32\...\Game Booster_is1) (Version: 3.4 - IObit)
GG (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\GG) (Version: 11 - GG Network S.A.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
ImageShack Uploader 2.2.0 (HKLM-x32\...\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}) (Version: 2.2.0 - ImageShack Corp.)
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
LibreOffice 4.1.4.2 (HKLM-x32\...\{94E11973-ED58-47A0-907C-ABF6D95C5DD8}) (Version: 4.1.4.2 - The Document Foundation)
Microsoft .NET Framework 4.5.1 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Document Explorer 2008 (HKLM-x32\...\Microsoft Document Explorer 2008) (Version:  - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Language Pack 2010 - Polish/Polski (HKLM-x32\...\Office14.OMUI.pl-pl) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.0) (HKLM\...\SDKSetup_7.0.7600.16385.40715) (Version: 7.0.7600.16385.40715 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 21.0 (x86 pl) (HKLM-x32\...\Mozilla Firefox 21.0 (x86 pl)) (Version: 21.0 - Mozilla)
Mozilla Firefox 45.0.2 (x86 pl) (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Mozilla Firefox 45.0.2 (x86 pl)) (Version: 45.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 17.0.6 - Mozilla)
Mozilla Thunderbird 17.0.6 (x86 pl) (HKLM-x32\...\Mozilla Thunderbird 17.0.6 (x86 pl)) (Version: 17.0.6 - Mozilla)
Mozilla Thunderbird 38.7.2 (x86 pl) (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\Mozilla Thunderbird 38.7.2 (x86 pl)) (Version: 38.7.2 - Mozilla)
NapiProjekt 2.0.0 (build 2151) (HKLM-x32\...\NapiProjekt_is1) (Version:  - )
Nero 6 Demo (HKLM-x32\...\Nero - Burning Rom!UninstallKey) (Version:  - )
Nero BurningROM 12 (HKLM-x32\...\{3DAFE920-1B88-4C66-A39B-D743F28AF10D}) (Version: 12.5.01300 - Nero AG)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.4.3 - Notepad++ Team)
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Oprogramowanie systemu PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA Sterownik 3D Vision 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Sterownik graficzny 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Sterownik kontrolera 3D Vision 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.3.1.4482 - Electronic Arts, Inc.)
Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden
Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
Panel sterowania NVIDIA 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Podstawowe programy Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
RcwViewer 2015 (HKLM-x32\...\{E52D7D07-55C1-482D-A81C-B2E0E9245408}) (Version: 15.1.0 - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.69.304.2013 - Realtek)
Revit 2015 - Polski (Polish) (Version: 15.0.207.0 - Autodesk) Hidden
Revit 2015 Pakiet językowy - Polski (Polish) (Version: 15.0.207.0 - Autodesk) Hidden
Revit Content Libraries 2015 - Polski (Polish) (Version: 15.0.207.0 - Autodesk) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0415-0000-0000000FF1CE}_Office14.OMUI.pl-pl_{11B0F533-C8CF-420C-A43C-C7F93773CA62}) (Version:  - Microsoft)
SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
SketchUp Viewer (HKLM-x32\...\{469F7BEA-33FD-4711-A825-7CA7692EC886}) (Version: 15.3.330 - Trimble Navigation Limited)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
VIA Platforma Menedżera urządzeń (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Virtua Tennis 4™ (HKLM-x32\...\GFWL_{53450FA2-E900-456E-9715-501000008200}) (Version: 1.0.0000.130 - SEGA)
Virtua Tennis 4™ (x32 Version: 1.0.0000.130 - SEGA) Hidden
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
WinDirStat 1.1.2 (HKU\S-1-5-21-101701808-3503879185-1311691872-1001\...\WinDirStat) (Version:  - )
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{3577E42B-3347-4EB8-BFDA-D36E8ED3C519}) (Version: 1.0.24.0 - Microsoft Corporation)
WinRAR 4.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden
Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden

==================== Niestandardowe rejestracje CLSID (filtrowane): ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

CustomCLSID: HKU\S-1-5-21-101701808-3503879185-1311691872-1001_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Tomek\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.)

==================== Zaplanowane zadania (filtrowane) =============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

Task: {084BEFA1-D915-4F16-B4CB-C2AC03296D18} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {2329FE74-95C1-4187-B51A-F8E281433FEF} - System32\Tasks\Opera scheduled Autoupdate 1416176786 => C:\Program Files (x86)\Opera\launcher.exe [2016-04-11] (Opera Software)
Task: {5DEA0560-F47E-422C-9B6B-22EC764B4347} - System32\Tasks\Game_Booster_AutoUpdate => d:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe [2014-10-11] ()
Task: {65C6A104-36FF-4AAD-BFF2-15496933792B} - System32\Tasks\ASUS Patch for VIA Audio => C:\Windows\system32\AsPatchViaAudio.exe [2012-11-07] (ASUSTek Computer INC.)
Task: {75826214-B194-4575-AF43-0ED71730ED9D} - System32\Tasks\avast! Emergency Update => d:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-03-17] (Avast Software s.r.o.)
Task: {75D41BFF-E47E-4BC1-8442-3EDE79F90964} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {7A3C85F6-5505-4555-A513-782F216CD756} - System32\Tasks\DriverEasy Scheduled Scan => d:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: {8860096D-A5C4-43C6-8B01-8EA2C304F4AE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07] (Adobe Systems Incorporated)
Task: {9939A93E-65FE-450D-8A5F-A27A5DF99D42} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {9F892F95-79DC-4406-9DF3-34CCE0E3C6C3} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-01-26] (AVAST Software)
Task: {D7D2C521-66C4-4D49-9F46-48540BCA9DE4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd)

(Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DriverEasy Scheduled Scan.job => d:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Skróty =============================

(Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.)

==================== Załadowane moduły (filtrowane) ==============

2013-06-02 13:47 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () d:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2013-03-28 22:31 - 2013-03-28 22:31 - 00210944 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2012-09-23 13:53 - 2012-09-23 13:53 - 00748544 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2012-09-23 13:53 - 2012-09-23 13:53 - 03645952 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2013-06-02 22:39 - 2012-11-14 15:22 - 00078456 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2013-06-02 22:39 - 2012-11-14 15:22 - 00386168 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2014-09-25 20:44 - 2014-09-25 20:44 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll
2015-07-03 20:49 - 2015-07-03 20:49 - 00104400 _____ () d:\Program Files\AVAST Software\Avast\log.dll
2015-07-03 20:49 - 2015-07-03 20:49 - 00081728 _____ () d:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-04-28 20:42 - 2016-04-28 20:42 - 02891264 _____ () d:\Program Files\AVAST Software\Avast\defs\16042802\algo.dll
2016-05-02 22:28 - 2016-05-02 22:28 - 02892288 _____ () d:\Program Files\AVAST Software\Avast\defs\16050200\algo.dll
2015-01-10 18:37 - 2014-12-05 04:27 - 00055688 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-01-10 18:37 - 2014-12-05 04:27 - 00104328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2011-03-04 12:49 - 2011-03-04 12:49 - 00202752 _____ () D:\VPN\vpnapi.dll
2016-01-06 20:14 - 2016-04-24 22:16 - 03716144 _____ () C:\Users\Tomek\AppData\Local\GG\Application\xulrunner\mozjs.dll
2015-07-03 20:49 - 2015-07-03 20:49 - 40540672 _____ () D:\Program Files\AVAST Software\Avast\libcef.dll
2015-07-03 20:49 - 2015-07-03 20:49 - 00104400 _____ () D:\Program Files\AVAST Software\Avast\log.dll
2015-07-03 20:49 - 2015-07-03 20:49 - 00081728 _____ () D:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-05-02 22:25 - 2014-12-05 04:27 - 00104328 _____ () C:\Users\Tomek\AppData\Local\Autodesk\.AdskAppManager\R1\qjson0.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2016-01-06 20:13 - 2015-11-18 21:44 - 00122432 _____ () C:\Users\Tomek\AppData\Local\GG\Application\ggdrive\ZLIB1.dll
2016-04-05 21:50 - 2016-04-05 21:51 - 00153032 _____ () D:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2016-04-05 21:50 - 2016-04-05 21:51 - 00022472 _____ () D:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2016-04-07 21:45 - 2016-04-07 21:45 - 19403968 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll
2012-09-23 20:43 - 2012-09-23 20:43 - 00313992 _____ () C:\Program Files (x86)\Adobe\Reader 11.0\Reader\sqlite.dll
2013-05-11 12:37 - 2013-05-11 12:37 - 14588632 _____ () C:\Program Files (x86)\Adobe\Reader 11.0\Reader\NPSWF32.dll

==================== Alternate Data Streams (filtrowane) =========

(Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]

==================== Tryb awaryjny (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.)


==================== EXE - Powiązania (filtrowane) ===============

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.)


==================== Internet Explorer - Witryny zaufane i z ograniczeniami ===============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.)


==================== Hosts - zawartość: ===============================

(Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.)

2009-07-14 04:34 - 2016-04-28 22:50 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Inne obszary ============================

(Obecnie brak automatycznej naprawy dla tej sekcji.)

HKU\S-1-5-21-101701808-3503879185-1311691872-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Zapora systemu Windows [funkcja włączona]

==================== MSCONFIG/TASK MANAGER - Wyłączone elementy ==

(Obecnie brak automatycznej naprawy dla tej sekcji.)


==================== Reguły Zapory systemu Windows (filtrowane) ===============

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{0E7F0D87-2165-49AB-9FB6-AF8836A9ED71}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{A179F009-3747-4E93-9CBA-99DCA08BB8E6}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{EB6624F2-07BC-4A38-9950-B7DCFDF88CCF}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{41D0A2AC-209F-495A-9238-CFA99ABB55B1}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{BFAC4786-6942-469F-9F48-EAA41DD5D096}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{140BB2C6-96C1-4454-A604-66CD7CB60AA5}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{3E098D42-8CDB-41B1-9EE2-F90375D6D745}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3846AF77-013C-4846-9EA2-D16F57C286FD}] => (Allow) LPort=2869
FirewallRules: [{AA3458C4-17CA-4783-932E-27CCF71BF26C}] => (Allow) LPort=1900
FirewallRules: [{341B9177-84F8-4AD4-9591-714D8D7ACE8A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{B6A79103-5104-4012-BD0A-FA49EF5D9D16}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{075A8A77-7E4C-4679-B901-0CFB885ABA29}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{027447EB-7123-4053-B668-1635258D763B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{2EA9446F-D260-43F0-B10C-628A21A4F1B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{394960EF-E30A-439C-9453-E6E861FC648B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{57705542-EB21-42D0-8AF4-ACD7C175171D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{FEE4ADEF-AF22-4CAE-B424-2483AC02E26A}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [{9D98F6F9-5A3C-4383-A066-C13491507A76}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [TCP Query User{9B76A2B3-992C-40BD-91DB-C4B1F1AE8D57}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{F94DAF02-3819-4471-B273-F3C0518B4EF7}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{43611F27-E6BB-4640-9833-CCA63C465C5B}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{943BCC8E-995E-4571-B857-0094586CA239}C:\users\tomek\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\tomek\appdata\local\akamai\netsession_win.exe
FirewallRules: [{95465677-90EE-4130-9B9F-A48BEDF542D6}] => (Allow) H:\DANE\tennis\Virtua Tennis 4\VT4.exe
FirewallRules: [{CEB7EEF4-672F-47D3-B520-F5E9EAA0ADEE}] => (Allow) H:\DANE\tennis\Virtua Tennis 4\VT4.exe
FirewallRules: [TCP Query User{544CAA44-936B-4C0E-86CC-F308EB3828DC}D:\firefox\firefox.exe] => (Allow) D:\firefox\firefox.exe
FirewallRules: [UDP Query User{E9B2D719-B607-4007-9AA4-324C4B8809E2}D:\firefox\firefox.exe] => (Allow) D:\firefox\firefox.exe
FirewallRules: [{105BD6D6-BA1B-465A-8A38-D24A235F75A0}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe
FirewallRules: [{6F9774C2-CA1E-48B6-9D9D-E56486833C63}] => (Allow) D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe
FirewallRules: [{F479D28A-9142-4090-90E9-711EA8EB2C97}] => (Allow) D:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{83564086-280F-4A7A-8EF0-69039165BA6D}] => (Allow) D:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{A778477E-140C-42D8-89C1-BB3F84F04BBD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{21E2453A-AF53-4F51-83DB-544A3F88C32D}] => (Block) d:\Program Files\Corel\CorelDRAW Graphics Suite X7\Programs64\CorelDrw.exe

==================== Punkty Przywracania systemu =========================

22-04-2016 20:24:52 Windows Update
25-04-2016 21:33:29 Windows Update
28-04-2016 23:04:10 Windows Update
28-04-2016 23:33:02 Microsoft Visual Studio Tools for Applications 2012
02-05-2016 22:34:37 Windows Update

==================== Wadliwe urządzenia w Menedżerze urządzeń =============

Name: Cisco Systems VPN Adapter for 64-bit Windows
Description: Cisco Systems VPN Adapter for 64-bit Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Błędy w Dzienniku zdarzeń: =========================

Dziennik Aplikacja:
==================
Error: (05/02/2016 10:25:20 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Usługa Windows Search jest zatrzymywana, ponieważ wystąpił problem z indeksatorem: The catalog is corrupt.

Szczegóły:
   Wykaz indeksów zawartości jest uszkodzony.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (05/02/2016 10:25:20 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Nie można zainicjować indeksu.

Szczegóły:
   Wykaz indeksów zawartości jest uszkodzony.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (05/02/2016 10:25:20 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Nie można zainicjować aplikacji.

Kontekst: aplikacja Windows

Szczegóły:
   Wykaz indeksów zawartości jest uszkodzony.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (05/02/2016 10:25:20 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Nie można zainicjować obiektu programu zbierającego.

Kontekst: aplikacja Windows, wykaz SystemIndex

Szczegóły:
   Wykaz indeksów zawartości jest uszkodzony.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (05/02/2016 10:25:20 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Nie można zainicjować dodatku typu plug-in w <Search.TripoliIndexer>.

Kontekst: aplikacja Windows, wykaz SystemIndex

Szczegóły:
   Nie można odnaleźć elementu.  (HRESULT : 0x80070490) (0x80070490)

Error: (05/02/2016 10:25:12 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Nie można zainicjować dodatku typu plug-in w <Search.JetPropStore>.

Kontekst: aplikacja Windows, wykaz SystemIndex

Szczegóły:
   Wykaz indeksów zawartości jest uszkodzony.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (05/02/2016 10:25:12 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Usługa Windows Search nie może załadować informacji z magazynu właściwości.

Kontekst: aplikacja Windows, wykaz SystemIndex

Szczegóły:
   Serwer indeksu zawartości nie może zaktualizować informacji albo uzyskać do nich dostępu z powodu błędu bazy danych. Zatrzymaj i uruchom ponownie usługę wyszukiwania. Jeżeli problem będzie się powtarzać, zresetuj i ponownie przeszukaj indeks zawartości. W niektórych przypadkach konieczne może być usunięcie i ponowne utworzenie indeksu zawartości.  (HRESULT : 0x8004117f) (0x8004117f)

Error: (05/02/2016 10:25:12 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Usługa wyszukiwania wykryła uszkodzone pliki danych w indeksie {id=1100}. Usługa podejmie próbę automatycznego rozwiązania tego problemu przez odbudowanie indeksu.

Szczegóły:
   Wykaz indeksów zawartości jest uszkodzony.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (05/02/2016 10:25:12 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: Usługa Windows Search nie może otworzyć magazynu właściwości aparatu Jet.

Szczegóły:
   0x%08x (0x8004117f - Serwer indeksu zawartości nie może zaktualizować informacji albo uzyskać do nich dostępu z powodu błędu bazy danych. Zatrzymaj i uruchom ponownie usługę wyszukiwania. Jeżeli problem będzie się powtarzać, zresetuj i ponownie przeszukaj indeks zawartości. W niektórych przypadkach konieczne może być usunięcie i ponowne utworzenie indeksu zawartości.  (HRESULT : 0x8004117f))

Error: (05/02/2016 10:25:09 PM) (Source: ESENT) (EventID: 454) (User: )
Description: Windows (312) Windows: Odzyskiwanie/przywracanie bazy danych nie powiodło się z powodu nieoczekiwanego błędu: -1032.


Dziennik System:
=============
Error: (05/02/2016 10:26:15 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie.

Error: (05/02/2016 10:26:12 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Usługa Windows Search zakończyła działanie; wystąpił specyficzny dla niej błąd %%-1073473535.

Error: (05/02/2016 10:24:09 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego:
aswKbd

Error: (05/02/2016 10:22:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi avast! Firewall z powodu następującego błędu:
%%1053

Error: (05/02/2016 10:22:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą avast! Firewall.

Error: (05/02/2016 10:22:09 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: ZARZĄDZANIE NT)
Description: Niektóre funkcje zarządzania energią procesora w czasie wydajności zostały wyłączone z powodu znanego problemu z oprogramowaniem układowym. Skontaktuj się z producentem komputera w celu uzyskania aktualizacji oprogramowania układowego.

Error: (04/28/2016 10:52:26 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego:
aswKbd

Error: (04/28/2016 10:52:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi avast! Firewall z powodu następującego błędu:
%%1053

Error: (04/28/2016 10:52:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą avast! Firewall.

Error: (04/28/2016 10:51:20 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: ZARZĄDZANIE NT)
Description: Niektóre funkcje zarządzania energią procesora w czasie wydajności zostały wyłączone z powodu znanego problemu z oprogramowaniem układowym. Skontaktuj się z producentem komputera w celu uzyskania aktualizacji oprogramowania układowego.


==================== Statystyki pamięci ===========================

Procesor: AMD Athlon(tm) 7750 Dual-Core Processor
Procent pamięci w użyciu: 71%
Całkowita pamięć fizyczna: 4095.3 MB
Dostępna pamięć fizyczna: 1170.73 MB
Całkowita pamięć wirtualna: 8188.79 MB
Dostępna pamięć wirtualna: 4875.71 MB

==================== Dyski ================================

Drive c: () (Fixed) (Total:68.36 GB) (Free:1.99 GB) NTFS ==>[dysk z komponentami startowymi (pozyskano odczytując BCD)]
Drive d: () (Fixed) (Total:80.59 GB) (Free:39.16 GB) NTFS
Drive f: () (Fixed) (Total:14.65 GB) (Free:14.54 GB) NTFS
Drive g: () (Fixed) (Total:59.87 GB) (Free:59.69 GB) NTFS
Drive i: (SAMSUNG) (Fixed) (Total:465.62 GB) (Free:1.8 GB) FAT32

==================== MBR & Tablica partycji ==================

========================================================
Disk: 0 (Size: 74.5 GB) (Disk ID: 429F429F)
Partition 1: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=59.9 GB) - (Type=OF Extended)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 3CB12B75)
Partition 1: (Active) - (Size=68.4 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=80.6 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 465.8 GB) (Disk ID: 492936E9)
Partition 1: (Active) - (Size=465.8 GB) - (Type=0C)

==================== Koniec  Addition.txt ============================


Kod: Zaznacz wszystko
Rezultat skanowania skrótów użytkowników (x64) Wersja:25-04-2016
Uruchomiony przez Tomek (2016-05-02 22:43:27)
Uruchomiony z C:\Users\Tomek\Desktop
Tryb startu: Normal

==================== Skróty =============================

(Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.)





Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk -> D:\Program Files (x86)\adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe (Adobe Systems, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk -> C:\Program Files (x86)\Adobe\Adobe Utilities - CS6\ExtendScript Toolkit CS6\ExtendScript Toolkit.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk -> D:\Program Files (x86)\adobe\Adobe Extension Manager CS6\Adobe Extension Manager CS6.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4 64-bit.lnk -> D:\Program Files\Adobe\Adobe Photoshop Lightroom 4\lightroom.exe (Adobe Systems)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk -> D:\Program Files (x86)\CDBurnerXP\cdbxpp.exe (Canneverbe Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk -> D:\Program Files (x86)\foobar2000\foobar2000.exe (Piotr Pawlowski)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk -> C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk -> C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 36.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk -> C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp Viewer.lnk -> C:\Windows\Installer\{469F7BEA-33FD-4711-A825-7CA7692EC886}\Icon_Viewer.exe (Trimble Navigation Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk -> C:\Windows\System32\WindowsAnytimeUpgradeUI.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Help (ENG).lnk -> D:\Program Files (x86)\WinDirStat\windirstat.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Help (PLK).lnk -> D:\Program Files (x86)\WinDirStat\wdsh0415.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Uninstall WinDirStat.lnk -> D:\Program Files (x86)\WinDirStat\Uninstall.exe (WDS Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\WinDirStat.lnk -> D:\Program Files (x86)\WinDirStat\windirstat.exe (Seifert)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VIA\HD VDeck.lnk -> C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperMemo UX\SuperMemo UX.lnk -> C:\Program Files (x86)\SuperMemo UX\supermemo.exe (SuperMemo World)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperMemo UX\Website.lnk -> C:\Program Files (x86)\SuperMemo UX\SuperMemo UX.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Help and HOW-TO.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Release info.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Uninstall SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk -> C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\grvicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoofCon\RoofCon Viewer.lnk -> D:\Program Files (x86)\RcwViewer\RcwViewer.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe (NVIDIA)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe (NVIDIA Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Notepad++.lnk -> D:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero StartSmart.lnk -> C:\Program Files (x86)\Ahead\Nero StartSmart\NeroStartSmart.exe (Ahead Software AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero BackItUp [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\NeroBackItUp_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Burning ROM [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroBurningRom_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Cover Designer [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\NeroCoverDesigner_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Express [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroExpress_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero SoundTrax [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\NeroSoundTrax_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Wave Editor [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\NeroWaveEditor_eng.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero CD-DVD Speed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\CDSpeed.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero DriveSpeed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\DriveSpeed.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero InfoTool.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\InfoTool.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero BackItUp.lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\BackItUp.exe (Ahead Software AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Burning ROM.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Cover Designer.lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\CoverDes.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero SoundTrax.lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\SoundTrax.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Wave Editor.lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\WaveEdit.exe (Nero AG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero\Nero ControlCenter.lnk -> C:\Windows\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ScControlCenterSta_FC2653898C5047A6A872CAF6433C43A8.exe (Acresso Software Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero\Nero 12\Nero Burning ROM.lnk -> C:\Windows\Installer\{CF508721-0E1E-4F99-A359-59E4EA8DAEC1}\ARPPRODUCTICON.exe (Acresso Software Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Informacje o zmianach.lnk -> C:\Program Files (x86)\NapiProjekt\changelog.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Strona domowa NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\www.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Release Notes.lnk -> C:\Program Files\Microsoft SDKs\Windows\v7.0\ReleaseNotes.Htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Visual Studio Registration\Windows SDK Configuration Tool.lnk -> C:\Program Files\Microsoft SDKs\Windows\v7.0\Setup\WindowsSdkVer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Tools\Tools Reference.lnk -> C:\Program Files\Microsoft SDKs\Windows\v7.0\Bin\StartTools.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\Silverlight.Configuration.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\accicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\xlicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\inficon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\joticon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\outicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\pptico.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\pubs.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\grvicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Digitales Zertifikat für VBA-Projekte.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\cagicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office 2010 Upload Center.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\msouc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office 2010-Spracheinstellungen.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\oisicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace\Games for Windows Marketplace.lnk -> C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLive.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Base.lnk -> D:\Program Files (x86)\LibreOffice 4\program\sbase.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Calc.lnk -> D:\Program Files (x86)\LibreOffice 4\program\scalc.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Draw.lnk -> D:\Program Files (x86)\LibreOffice 4\program\sdraw.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Impress.lnk -> D:\Program Files (x86)\LibreOffice 4\program\simpress.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Math.lnk -> D:\Program Files (x86)\LibreOffice 4\program\smath.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice Writer.lnk -> D:\Program Files (x86)\LibreOffice 4\program\swriter.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.1\LibreOffice.lnk -> D:\Program Files (x86)\LibreOffice 4\program\soffice.exe (The Document Foundation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe (Oracle Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImageShack Uploader\ImageShack Uploader.lnk -> C:\Windows\Installer\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}\ImageShackUploader.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3\Deinstalacja programu Game Booster 3.lnk -> D:\Program Files (x86)\IObit\Game Booster 3\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3\Game Booster 3.lnk -> D:\Program Files (x86)\IObit\Game Booster 3\GameBooster.exe (IObit)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk -> D:\Program Files (x86)\FileZilla FTP Client\filezilla.exe (FileZilla Project)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk -> D:\Program Files (x86)\FileZilla FTP Client\uninstall.exe (Tim Kosse)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe (Electronic Arts)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\Plik Przeczytaj.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Support\readme\Przeczytaj.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\Pomoc techniczna.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Support\EA Help\Pomoc techniczna.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14\Umowa użytkownika FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Support\eula\pl_PL_eula.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverEasy\DriverEasy.lnk -> C:\Program Files\Easeware\DriverEasy\DriverEasy.exe (Easeware)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverEasy\Uninstall DriverEasy.lnk -> C:\Program Files\Easeware\DriverEasy\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)\Bitstream Font Navigator (64-Bit).lnk -> D:\Program Files\Corel\CorelDRAW Graphics Suite X7\FontNav64\FontNav.exe (Bitstream Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)\CorelDRAW X7 (64-Bit).lnk -> c:\Windows\Installer\{2C0DDC74-5234-43DD-BB5A-0645B8FE5289}\NewShortcut1_68427AB8B2C044C58AA777A4C3F75634.exe (Flexera Software LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)\Duplexing Wizard (64-Bit).lnk -> c:\Windows\Installer\{2C0DDC74-5234-43DD-BB5A-0645B8FE5289}\NewShortcut10_BB562587DB944A668ECBA27E6BFD871C.exe (Flexera Software LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)\Video Tutorials X7 (64-Bit).lnk -> D:\Program Files\Corel\CorelDRAW Graphics Suite X7\VideoBrowser64\VideoBrowser.exe (Corel Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)\Documentation\Macro Programming Guide.lnk -> D:\Program Files\Corel\CorelDRAW Graphics Suite X7\Data\Macro Programming Guide.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Systems VPN Client\Set MTU.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\IconD4CBEB74.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Catalyst Control Center.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software\Avast Free Antivirus.lnk -> D:\Program Files\AVAST Software\Avast\avastui.exe (Avast Software s.r.o.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Download Manager.lnk -> C:\Windows\Installer\{C897D9EC-13C6-4A22-ABF7-33F2126A7DB6}\AdDLMgr.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Uninstall Tool.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\Uninstall Tool\R1\UninstallTool.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Application Manager\Autodesk Application Manager.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe (Autodesk Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\A.C.I.D. Wizard.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\ACID.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol 120%.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\Alcohol.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol Command Launcher.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxCmd.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Alcohol Manual.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\Help\ax_enu.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Data-Type Analyzer.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxDTA.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%\Uninstall Alcohol 120%.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\uninst.exe (Alcohol Soft Development Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk -> C:\Windows\System32\NetProj.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\Windowspowershell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\IObit\Game Booster 3\BackLnk\FIFA 15.lnk -> D:\Program Files (x86)\Origin Games\FIFA 15\fifa15.exe (Brak pliku)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Adobe Reader XI.lnk -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\Public\Desktop\Alcohol 120%.lnk -> D:\Program Files (x86)\Alcohol Soft\Alcohol 120\Alcohol.exe (Alcohol Soft Development Team)
Shortcut: C:\Users\Public\Desktop\Avast Free Antivirus.lnk -> D:\Program Files\AVAST Software\Avast\avastui.exe (Avast Software s.r.o.)
Shortcut: C:\Users\Public\Desktop\Bitstream Font Navigator (64-Bit).lnk -> D:\Program Files\Corel\CorelDRAW Graphics Suite X7\FontNav64\FontNav.exe (Bitstream Inc.)
Shortcut: C:\Users\Public\Desktop\CDBurnerXP.lnk -> D:\Program Files (x86)\CDBurnerXP\cdbxpp.exe (Canneverbe Limited)
Shortcut: C:\Users\Public\Desktop\CorelDRAW X7 (64-Bit).lnk -> C:\Windows\Installer\{2C0DDC74-5234-43DD-BB5A-0645B8FE5289}\NewShortcut1_68427AB8B2C044C58AA777A4C3F75634.exe (Flexera Software LLC)
Shortcut: C:\Users\Public\Desktop\DriverEasy.lnk -> C:\Program Files\Easeware\DriverEasy\DriverEasy.exe (Easeware)
Shortcut: C:\Users\Public\Desktop\FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe (Electronic Arts)
Shortcut: C:\Users\Public\Desktop\foobar2000.lnk -> D:\Program Files (x86)\foobar2000\foobar2000.exe (Piotr Pawlowski)
Shortcut: C:\Users\Public\Desktop\HD VDeck.lnk -> C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
Shortcut: C:\Users\Public\Desktop\ImageShack Uploader.lnk -> C:\Windows\Installer\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}\ImageShackUploader.exe ()
Shortcut: C:\Users\Public\Desktop\LibreOffice 4.1.lnk -> D:\Program Files (x86)\LibreOffice 4\program\soffice.exe (The Document Foundation)
Shortcut: C:\Users\Public\Desktop\Lightroom 4 64-bit.lnk -> D:\Program Files\Adobe\Adobe Photoshop Lightroom 4\lightroom.exe (Adobe Systems)
Shortcut: C:\Users\Public\Desktop\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\Users\Public\Desktop\Nero Burning ROM 12.lnk -> C:\Windows\Installer\{CF508721-0E1E-4F99-A359-59E4EA8DAEC1}\ARPPRODUCTICON.exe (Acresso Software Inc.)
Shortcut: C:\Users\Public\Desktop\Opera 36.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software)
Shortcut: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software)
Shortcut: C:\Users\Public\Desktop\SketchUp Viewer.lnk -> C:\Windows\Installer\{469F7BEA-33FD-4711-A825-7CA7692EC886}\Icon_Viewer.exe (Trimble Navigation Limited)
Shortcut: C:\Users\Public\Desktop\Skype.lnk -> C:\Windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe ()
Shortcut: C:\Users\Public\Desktop\SuperMemo UX.lnk -> C:\Program Files (x86)\SuperMemo UX\supermemo.exe (SuperMemo World)
Shortcut: C:\Users\Tomek\Links\Desktop.lnk -> C:\Users\Tomek\Desktop ()
Shortcut: C:\Users\Tomek\Links\Downloads.lnk -> C:\Users\Tomek\Downloads ()
Shortcut: C:\Users\Tomek\Links\GG dysk.lnk -> C:\Users\Tomek\GG dysk ()
Shortcut: C:\Users\Tomek\Favorites\GG dysk.lnk -> C:\Users\Tomek\GG dysk ()
Shortcut: C:\Users\Tomek\Documents\Corel\Próbki CorelDRAW X7\target.lnk -> D:\Program Files\Corel\CorelDRAW Graphics Suite X7\Draw\Samples ()
Shortcut: C:\Users\Tomek\Documents\Corel\Próbki CorelDRAW X6\target.lnk -> D:\Program Files\Corel\CorelDRAW Graphics Suite X6\Draw\Samples (Brak pliku)
Shortcut: C:\Users\Tomek\Desktop\Adobe Photoshop CS6 (64 Bit).lnk -> D:\Program Files (x86)\adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe (Adobe Systems, Incorporated)
Shortcut: C:\Users\Tomek\Desktop\GG dysk.lnk -> C:\Users\Tomek\GG dysk ()
Shortcut: C:\Users\Tomek\Desktop\GG.lnk -> C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)
Shortcut: C:\Users\Tomek\Desktop\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe ()
Shortcut: C:\Users\Tomek\Desktop\SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
Shortcut: C:\Users\Tomek\Desktop\VPN Client.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A85.exe ()
Shortcut: C:\Users\Tomek\Desktop\WinDirStat.lnk -> D:\Program Files (x86)\WinDirStat\windirstat.exe (Seifert)
Shortcut: C:\Users\Tomek\Desktop\Windows 7 USB DVD Download Tool.lnk -> C:\Users\Tomek\AppData\Local\Apps\Windows 7 USB DVD Download Tool\Windows7-USB-DVD-Download-Tool.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk -> C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool\Uninstall Windows 7 USB DVD Download Tool.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool\Windows 7 USB DVD Download Tool.lnk -> C:\Users\Tomek\AppData\Local\Apps\Windows 7 USB DVD Download Tool\Windows7-USB-DVD-Download-Tool.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero StartSmart.lnk -> C:\Program Files (x86)\Ahead\Nero StartSmart\NeroStartSmart.exe (Ahead Software AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero BackItUp [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\NeroBackItUp_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Burning ROM [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroBurningRom_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Cover Designer [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\NeroCoverDesigner_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Express [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero\NeroExpress_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero SoundTrax [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\NeroSoundTrax_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Przewodniki użytkownika\Nero Wave Editor [Pomoc w jęz. angielskim].lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\NeroWaveEditor_eng.chm ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero CD-DVD Speed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\CDSpeed.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero DriveSpeed.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\DriveSpeed.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero Toolkit\Nero InfoTool.lnk -> C:\Program Files (x86)\Ahead\Nero Toolkit\InfoTool.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero BackItUp.lnk -> C:\Program Files (x86)\Ahead\Nero BackItUp\BackItUp.exe (Ahead Software AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Burning ROM.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Cover Designer.lnk -> C:\Program Files (x86)\Ahead\CoverDesigner\CoverDes.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero SoundTrax.lnk -> C:\Program Files (x86)\Ahead\Nero SoundTrax\SoundTrax.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Wave Editor.lnk -> C:\Program Files (x86)\Ahead\Nero Wave Editor\WaveEdit.exe (Nero AG)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NapiProjekt.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Photoshop CS6 (64 Bit).lnk -> D:\Program Files (x86)\adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe (Adobe Systems, Incorporated)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CorelDRAW X7 (64-Bit).lnk -> C:\Windows\Installer\{2C0DDC74-5234-43DD-BB5A-0645B8FE5289}\NewShortcut1_68427AB8B2C044C58AA777A4C3F75634.exe (Flexera Software LLC)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Thunderbird.lnk -> D:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\FIFA 14.lnk -> D:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe (Electronic Arts)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\ImageShack Uploader.lnk -> C:\Windows\Installer\{8BCD7AE7-F713-4D50-BAB9-7839B9386870}\ImageShackUploader.exe ()
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software)
Shortcut: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Tomek\AppData\Local\GG\Application\gg.lnk -> C:\Users\Tomek\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)




ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->                                                                                                                 
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> D:\Firefox\firefox.exe (Mozilla Corporation) ->                                                                                                                 
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe () -> -user_logon
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /show
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Disable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /disable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Enable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /enable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Express.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG) -> /w
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt\Napisy oczekujące na pobranie.lnk -> C:\Program Files (x86)\NapiProjekt\napisy.exe () -> -kolejka
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\CMD Shell.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /E:ON /V:ON /T:0E /K "C:\Program Files\Microsoft SDKs\Windows\v7.0\Bin\SetEnv.cmd"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0\Windows SDK Documentation.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Help 9\dexplore.exe (Microsoft Corporation) -> /helpcol ms-help://MS.W7SDK.1033 /LaunchNamedUrlTopic DefaultPage /usehelpsettings WindowsSDK.1.0
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk -> C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\inficon.exe () ->  /design
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe (Oracle Corporation) -> -tab about
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe (Oracle Corporation) -> -tab update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Pomoc.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (ATI Technologies Inc.) -> Start Help -help
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2015 - Polski (Polish)\Narzędzie transferu licencji - Revit 2015.lnk -> C:\Program Files\Common Files\Autodesk Shared\AdLM\R9\LTU.exe (Autodesk, Inc.) -> 829G1 2015.0.0.F -d SA -l pl-PL
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2015 - Polski (Polish)\Revit 2015 - Polski (Polish).lnk -> D:\Program Files (x86)\autodesk\Revit 2015\Revit.exe (Autodesk, Inc.) -> /language PLK
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2015 - Polski (Polish)\Revit Viewer 2015 - Polski (Polish).lnk -> D:\Program Files (x86)\autodesk\Revit 2015\Revit.exe (Autodesk, Inc.) -> /viewer /language PLK
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Public\Desktop\avast! SafeZone.lnk -> D:\Program Files\AVAST Software\Avast\avastui.exe (Avast Software s.r.o.) -> /sfzonebrowser
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> D:\Firefox\firefox.exe (Mozilla Corporation) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Public\Desktop\Revit 2015 - Polski (Polish).lnk -> D:\Program Files (x86)\autodesk\Revit 2015\Revit.exe (Autodesk, Inc.) -> /language PLK
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nero (32-bit)\Nero 6 Demo\Nero Express.lnk -> C:\Program Files (x86)\Ahead\Nero\nero.exe (Ahead Software AG) -> /w
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk -> C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) -> /sendto:
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> D:\Firefox\firefox.exe (Mozilla Corporation) ->                                                                                                                 
ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Excel\Kopia%20lampy305133904254217107\Kopia%20lampy.xlsx.lnk -> C:\Users\Tomek\Downloads\Kopia lampy.xlsx () -> 50


InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url -> hxxp://java.com/help
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url -> hxxp://java.com/
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Galeria gadżetów Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkID=70742
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Poczta usługi Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72681
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Programy usługi Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72700
InternetURL: C:\Users\Tomek\Favorites\Windows Live\Windows Live Spaces.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72682
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Gospodarka.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68923
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Rozrywka.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68924
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Sport.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68921
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Technologie.url -> hxxp://go.microsoft.com/fwlink/?LinkId=55143
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\MSN Wideo.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68922
InternetURL: C:\Users\Tomek\Favorites\MSN — witryny sieci Web\Portal MSN.url -> hxxp://go.microsoft.com/fwlink/?LinkId=54729
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Centrum bezpieczeństwa Microsoft.url -> hxxp://go.microsoft.com/fwlink/?LinkID=72887
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Dodatki programu Internet Explorer.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft Office Online.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72885
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft Technet.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72886
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Microsoft w Polsce.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72520
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Oryginalne oprogramowanie firmy Microsoft.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72900
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Strona główna programu Internet Explorer.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72186
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Strona główna systemu Windows.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72629
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\Technologia RSS.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72889
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\W domu.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72406
InternetURL: C:\Users\Tomek\Favorites\Microsoft — witryny sieci Web\W pracy.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72407
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Bezpieczeństwo w trybie online.url -> hxxp://go.microsoft.com/fwlink/?LinkId=142211
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Bezpieczny Internet.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129626
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Kultura.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129625
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Pogodynka.pl — oficjalny serwis pogodowy IMGW.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129624
InternetURL: C:\Users\Tomek\Favorites\Links for Polska\Polska.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129622
InternetURL: C:\Users\Tomek\Favorites\Links\Galeria obiektów Web Slice.url -> hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\Tomek\Favorites\Links\Sugerowane witryny.url -> hxxps://ieonline.microsoft.com/#ieslice

==================== Koniec  Shortcut.txt =============================
teem90
~user
 
Posty: 4
Dołączenie: 26 Kwi 2016, 22:15



Problem z explorer.exe / hohosearch

Postprzez ordynat 03 Maj 2016, 07:05

w logach nie ma niczego podejrzanego.

Przeinstaluj przeglądarkę, na której to widzisz.
.
ordynat
~user
 
Posty: 4765
Dołączenie: 02 Kwi 2010, 11:18
Pochwały: 866



Problem z explorer.exe / hohosearch

Postprzez 2shy 27 Cze 2016, 15:01

Miałem podobny problem z hohosearch i pełne skanowanie systemu z AdwCleaner (http://manual-removal.com/hohosearch/) w Safe Mode with Networking pomógł mi.
2shy
~user
 
Posty: 1
Dołączenie: 27 Cze 2016, 14:58




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 11 gości