ADVERTISEMENT

Addition.txt

Reklamy w przeglądarce, Malwarebytes zatrzymuje się na skanowaniu pamięci

Witam, posiadam komputer w którym non stop wyskakują reklamy ale malwarebytes nie robi pełnego skanu zatrzymuje się na pamięci więc wnioskuje że cos "grubszego" siedzi. Dołączam skany z FRST. Pozdrawiam


Download file - link to post

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-04-2017
Ran by Start (20-04-2017 09:54:27)
Running from C:\Users\Start\Downloads
Windows 8 (X64) (2015-07-30 11:25:46)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1912849403-639712137-414092863-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1912849403-639712137-414092863-1002 - Limited - Enabled)
Guest (S-1-5-21-1912849403-639712137-414092863-501 - Limited - Disabled)
Start (S-1-5-21-1912849403-639712137-414092863-1001 - Administrator - Enabled) = & gt; C:\Users\Start

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Disabled - Out of date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Kaspersky Internet Security (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}

==================== Installed Programs ======================

(Only the adware programs with " Hidden " flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Adobe Reader X MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 3.6.142.61624 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 3.6.142.61624 - Alcor Micro Corp.) Hidden
asterpiece Fishing 3 (HKLM-x32\...\Masterpiece Fishing 3_is1) (Version: - Play Sp. z o.o.)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.8 - ASUS)
ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.2 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.4 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.8 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.0.3 - ASUS)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.0.29 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0002 - ASUS)
ASUS Tutor (HKLM-x32\...\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.7 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.4 - ASUS)
ASUS WebStorage Sync Agent (HKLM-x32\...\ASUS WebStorage) (Version: 1.1.9.120 - ASUS Cloud Corporation)
ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4126.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.) Hidden
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.10.168 - ASUSTEK)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0022 - ASUS)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Code of Honor 2 (1.0) (HKLM-x32\...\Code of Honor 2_is1) (Version: - City Interactive)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
Don't Starve (HKLM-x32\...\Steam App 219740) (Version: - Klei Entertainment)
Drakensang Online (HKLM-x32\...\Drakensang Online) (Version: - )
EA Download Manager (HKLM-x32\...\EADM) (Version: 5.0.0.255 - Electronic Arts, Inc.)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
InstallShieldHiRezCurrent (HKLM-x32\...\{9433FC1C-7405-433C-A26D-81076293BBCE}) (Version: 3.0.0.0 - Hi-Rez Studios)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2828 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{77E7AE5C-181C-4CAF-ADBF-946F11C1CE26}) (Version: 16.0.0.614 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 16.0.0.614 - Kaspersky Lab) Hidden
Klopsiki i inne zjawiska pogodowe(TM) (HKLM-x32\...\{B76BE192-7AD9-4A02-90A8-E3DA068D2F00}) (Version: 1.00.000 - Ubisoft)
KogamaLauncher-WWW (HKLM-x32\...\{1CC9F278-D898-43D2-BBED-B3B765045888}) (Version: 1.0.3.0 - Multiverse ApS)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Malwarebytes (wersja 3.0.6.1469) (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Marine Sharpshooter 4 (HKLM-x32\...\Marine Sharpshooter 4_is1) (Version: - )
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mozilla Firefox 45.0.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 45.0.1 (x86 pl)) (Version: 45.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.1.5918 - Mozilla)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Orbital Gear (HKLM-x32\...\Steam App 298520) (Version: - Night Node)
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.206 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Robocraft (HKLM-x32\...\Steam App 301520) (Version: - Freejam)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.24 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.24.104 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Terraria (HKLM-x32\...\Steam App 105600) (Version: - Re-Logic)
The Good the Egg and the Ugly (HKLM-x32\...\{A74FC1F0-5FAD-46B4-859D-99B755502B3E}) (Version: 1.00.0000 - )
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts)
The Sims™ 3 Ambitions (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.10.1 - Electronic Arts)
Unity Web Player (HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 12.1 - Ubisoft)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Warface Launcher (Beta) (HKLM-x32\...\{28D1723C-31C4-4A83-9799-DFFB3739026D}) (Version: 1.0.0 - Crytek GmbH)
Weso³a Szko³a 3 (HKLM-x32\...\Weso³a Szko³a 3_is1) (Version: - Next Generation Interactive)
Windows Driver Package - ASUS (ATP) Mouse (07/28/2012 1.0.0.108) (HKLM\...\9B634C8DF2662B6B0212BF0B7547894BF2B5359F) (Version: 07/28/2012 1.0.0.108 - ASUS)
World of Tanks (HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {1686777E-F815-4839-9F09-A7DF3EE5B58D} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} = & gt; C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [2016-12-20] (AO Kaspersky Lab)
Task: {328A2DE5-7888-4E3A-ACE9-16AB90A230ED} - System32\Tasks\ASUS P4G = & gt; C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-04] (ASUS)
Task: {44834AD7-55D1-4F58-B21C-C2D645842E91} - System32\Tasks\ASUS USB Charger Plus = & gt; C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-24] (ASUSTek Computer Inc.)
Task: {5DFF1F75-9552-4718-A263-1D469BE6E921} - System32\Tasks\ASUS InstantOn Config = & gt; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-08-06] (ASUS)
Task: {70A1DBCB-03BE-481B-8EDF-45F4B8C20CF4} - System32\Tasks\ASUS Live Update = & gt; C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-07-25] (ASUSTeK Computer Inc.)
Task: {76EF6A60-3CE6-46E3-9933-647DFF45A152} - System32\Tasks\{DB2344DD-3622-4C3C-B47B-9969605FEA06} = & gt; pcalua.exe -a E:\start.exe -d E:\
Task: {B3F80BCE-5D84-44E4-BC83-14A6D5EF2509} - System32\Tasks\Adobe Flash Player Updater = & gt; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-20] (Adobe Systems Incorporated)
Task: {F6D644D1-1F67-41F0-9FB2-9DF5622A640D} - System32\Tasks\{884C8D8B-D8D2-4C5E-B747-05F0651C1AA9} = & gt; pcalua.exe -a E:\start.exe -d E:\

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2012-08-04 10:34 - 2012-08-04 10:34 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2012-08-10 18:28 - 2012-08-10 18:28 - 00384128 _____ () C:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll
2012-08-10 18:23 - 2012-08-10 18:23 - 00020992 _____ () C:\Program Files (x86)\Bluetooth Suite\L10n\pl-PL\BtTray.pl-PL.dll
2012-08-28 07:21 - 2012-08-15 18:52 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2012-09-25 09:23 - 2012-08-16 11:04 - 00078480 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2012-09-25 09:23 - 2012-08-16 11:04 - 00386192 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2017-04-20 09:27 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-04-20 09:27 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2017-04-20 09:27 - 2017-01-20 07:47 - 02254800 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2015-07-09 00:18 - 2015-07-09 00:18 - 00794920 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\kpcengine.2.3.dll
2012-06-07 14:12 - 2012-06-07 14:12 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2012-09-25 09:22 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The " AlternateShell " will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService = & gt; " " = " Service "
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService = & gt; " " = " Service "

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-07-26 06:26 - 2015-12-26 22:23 - 00000830 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1912849403-639712137-414092863-1001\Control Panel\Desktop\\Wallpaper - & gt; C:\Windows\Web\Wallpaper\Theme1\img1.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System = & gt; (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run32: = & gt; " Adobe Reader Speed Launcher "
HKLM\...\StartupApproved\Run32: = & gt; " Adobe ARM "
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\StartupApproved\Run: = & gt; " EA Core "
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\StartupApproved\Run: = & gt; " BingSvc "
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\StartupApproved\Run: = & gt; " Skype "
HKU\S-1-5-21-1912849403-639712137-414092863-1001\...\StartupApproved\Run: = & gt; " Steam "

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] = & gt; (Allow) LPort=139
FirewallRules: [{A60C517B-B392-4EBC-ABF4-3BCFAB10AACD}] = & gt; (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{D7E89D3A-4AAD-4931-B64D-66A149FE6386}] = & gt; (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{56108D3B-0457-4A6D-B651-78807A9B339B}] = & gt; (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{A4EC2FFF-F32F-4B6D-A9D7-2EB12FF50F72}] = & gt; (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{F681E19A-C79D-4B9C-AC70-491A6AEC33A0}] = & gt; (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{26663829-DEDD-4D60-A853-629D9958E4EF}] = & gt; (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{09652758-BD88-4C10-B0F5-30CD0D2DC7BF}] = & gt; (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{64F149AC-8A40-4433-BA52-55B4B5A73C32}] = & gt; (Allow) D:\Klopsiki i inne zjawiska pogodowe\JadeEngine_Final.exe
FirewallRules: [{AFE74FB9-E960-4CB1-9E0C-4BF1AC18E007}] = & gt; (Allow) D:\Klopsiki i inne zjawiska pogodowe\JadeEngine_Final.exe
FirewallRules: [TCP Query User{EEC8CBAA-1CFE-4617-83E3-2E32C5CF74D9}C:\program files (x86)\electronic arts\eadm\core.exe] = & gt; (Block) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{052B376C-A02E-4DBF-8B23-316DDFA13C22}C:\program files (x86)\electronic arts\eadm\core.exe] = & gt; (Block) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [{9E0817A6-7029-41C2-AF3D-4AF7D32C166C}] = & gt; (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{9E7FABF9-ED95-4066-8F2A-5BC2B56AA761}] = & gt; (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{67CD1471-097B-459E-8B7A-6552FE6A640E}] = & gt; (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{2F3A71EA-FB31-45EA-A8A6-67AE29CF6212}] = & gt; (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{51A47629-400F-49C9-8232-647B9458973B}] = & gt; (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{9FF8FFF7-FC0C-41B2-99B5-B07ABD82A174}] = & gt; (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D4243C86-BB58-4711-A4A9-9F4B3D745F74}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{788BDEF7-E80A-47B6-9C34-6BBAFDD7D081}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{B83FD229-B464-484B-9E2C-2D1617BB263A}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\EvolveGame\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{E58BF5E6-116D-4D5C-8F91-19D6D1A07DC0}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\EvolveGame\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{7E501237-B8B9-4ADE-BF37-9DA0ED98ED19}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{AD41108D-6640-46CA-AD8E-38944F4324D9}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{4F51B159-F3F6-4DE0-BCF9-6725221E1981}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Robocraft\Robocraft.exe
FirewallRules: [{BAAF4F37-0DC6-4BD2-B6DC-1BCAD7049F36}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Robocraft\Robocraft.exe
FirewallRules: [TCP Query User{DBDB250D-F9E5-4626-8A91-518A63025C0B}C:\program files (x86)\skype\phone\skype.exe] = & gt; (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{D483FF60-56D5-43A0-A244-FF7C90073222}C:\program files (x86)\skype\phone\skype.exe] = & gt; (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{66F3C2E3-D67F-4DF2-8A72-B2767BF4FC93}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe
FirewallRules: [{E3515873-3B70-4B6B-8120-6E4A3F3128C8}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Warface\live\nw.exe
FirewallRules: [{97DE937F-960B-4784-A89E-17AC5ABA2CAA}] = & gt; (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5E797D40-6F41-42DE-871A-3ED9D48E5EF6}] = & gt; (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{CB33172A-14F4-4FA5-9178-3C64FE272619}C:\program files (x86)\skype\phone\skype.exe] = & gt; (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{A0332453-8B8B-4325-90CC-7C6F8AC77E5F}C:\program files (x86)\skype\phone\skype.exe] = & gt; (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{68843B06-24BC-4796-859F-52E6837B0FAB}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{66EB5C8D-E317-4103-AAD3-490254984DB5}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [TCP Query User{2AE4D939-F5A0-418F-8D01-8004400475B8}D:\masterpiece fishing 3\hearthstone\hearthstone.exe] = & gt; (Allow) D:\masterpiece fishing 3\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{E8602A27-DE89-45CE-A4AD-100DBAACE5BE}D:\masterpiece fishing 3\hearthstone\hearthstone.exe] = & gt; (Allow) D:\masterpiece fishing 3\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{EDD2E36B-F442-4B01-BD9A-39F8E8722D68}D:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe] = & gt; (Allow) D:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe
FirewallRules: [UDP Query User{27DC0E16-FDBE-446A-81C1-ADF8C39F212F}D:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe] = & gt; (Allow) D:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe
FirewallRules: [{6C144B9D-7980-496C-A959-AA3F0D095A81}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Orbital Gear\OrbitalGear.exe
FirewallRules: [{1E2BF79C-86D6-4C58-A937-0A11D798D44B}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\Orbital Gear\OrbitalGear.exe
FirewallRules: [{357FD1A0-A244-4AE2-B124-5C5432187DA4}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{34A1E597-C431-49A9-AA23-AF279DDC342A}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{A02E6E51-A56F-4894-B834-169589EFC423}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{1D9E378A-8981-4A29-BB6C-BCE76CFC27A5}] = & gt; (Allow) D:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{B01C8268-89AD-4583-9BA4-7421CE25CDF8}] = & gt; (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{397E2581-439F-4C80-9E2F-4C4FE87D321E}] = & gt; (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe

==================== Restore Points =========================

27-03-2016 20:21:52 Windows Update
29-04-2016 20:35:17 Scheduled Checkpoint
29-06-2016 20:33:35 Windows Update
20-12-2016 15:27:09 Installed League of Legends

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/20/2016 03:54:10 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: Z powodu wystąpienia problemu dane Programu poprawy jakości obsługi klienta nie zostały wysłane do firmy Microsoft. (Błąd 80070005).

Error: (07/03/2016 05:01:30 PM) (Source: EventSystem) (EventID: 4622) (User: )
Description: System zdarzeń modelu COM+ nie mógł połączyć subskrybenta z subskrypcją {DD21194B-55FE-4DD7-B8CE-228DDA54B640}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. Wynik HRESULT: 800401fb.

Error: (06/30/2016 08:25:19 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: Z powodu wystąpienia problemu dane Programu poprawy jakości obsługi klienta nie zostały wysłane do firmy Microsoft. (Błąd 80070005).

Error: (06/29/2016 08:44:01 PM) (Source: EventSystem) (EventID: 4622) (User: )
Description: System zdarzeń modelu COM+ nie mógł połączyć subskrybenta z subskrypcją {DD21194B-55FE-4DD7-B8CE-228DDA54B640}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. Wynik HRESULT: 800401fb.

Error: (06/29/2016 08:11:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SystemSettings.exe w wersji 6.2.9200.16420 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania.

Identyfikator procesu: e64

Godzina rozpoczęcia: 01d1d239f7c0a119

Godzina zakończenia: 4294967295

Ścieżka aplikacji: C:\Windows\ImmersiveControlPanel\SystemSettings.exe

Identyfikator raportu: 4148193e-3e2d-11e6-be93-dc85de34501c

Pełna nazwa pakietu powodującego błąd: windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy

Identyfikator aplikacji względem pakietu powodującego błąd: microsoft.windows.immersivecontrolpanel

Error: (06/29/2016 08:11:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: asas)
Description: Aplikacja windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel nie została uruchomiona w wyznaczonym czasie.

Error: (05/05/2016 07:02:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nazwa aplikacji powodującej błąd: BtvStack.exe, wersja: 8.0.0.206, sygnatura czasowa: 0x5024e144
Nazwa modułu powodującego błąd: MSVCR100.dll, wersja: 10.0.40219.325, sygnatura czasowa: 0x4df2bcac
Kod wyjątku: 0x40000015
Przesunięcie błędu: 0x00000000000761c9
Identyfikator procesu powodującego błąd: 0x2ac4
Godzina uruchomienia aplikacji powodującej błąd: 0x01d1a6e732a41531
Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\MSVCR100.dll
Identyfikator raportu: 7763e60b-12eb-11e6-be93-dc85de34501c
Pełna nazwa pakietu powodującego błąd:
Identyfikator aplikacji względem pakietu powodującego błąd:

Error: (03/15/2016 07:10:16 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: Z powodu wystąpienia problemu dane Programu poprawy jakości obsługi klienta nie zostały wysłane do firmy Microsoft. (Błąd 80070005).

Error: (03/11/2016 10:42:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: asas)
Description: Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa.

Error: (03/11/2016 10:42:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program wwahost.exe w wersji 6.2.9200.16420 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania.

Identyfikator procesu: 1580

Godzina rozpoczęcia: 01d17bded2150cb2

Godzina zakończenia: 4294967295

Ścieżka aplikacji: C:\Windows\system32\wwahost.exe

Identyfikator raportu: 290affc5-e7d2-11e5-be93-dc85de34501c

Pełna nazwa pakietu powodującego błąd: microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe

Identyfikator aplikacji względem pakietu powodującego błąd: Microsoft.WindowsLive.Mail


System errors:
=============
Error: (04/20/2017 09:46:46 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a117\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-1912849403-639712137-414092863-1001-04202017094646581-ntuser.dat

Error: (04/20/2017 09:43:20 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a117\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-1912849403-639712137-414092863-1001-04202017094319840-ntuser.dat

Error: (04/20/2017 09:42:31 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a117\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-1912849403-639712137-414092863-1001-04202017094231367-ntuser.dat

Error: (04/20/2017 09:42:08 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a117\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-1912849403-639712137-414092863-1001-04202017094207821-ntuser.dat

Error: (04/20/2017 09:29:58 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a117\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-1912849403-639712137-414092863-1001-04202017092958178-ntuser.dat

Error: (04/20/2017 09:28:52 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a117\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-1912849403-639712137-414092863-1001-04202017092852000-ntuser.dat

Error: (04/20/2017 09:20:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi McAfee SiteAdvisor Service z powodu następującego błędu:
Nie można odnaleźć określonego pliku.

Error: (04/20/2017 09:18:21 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Usługa Windows Update nie została poprawnie zamknięta po odebraniu kodu sterującego przed zamknięciem.

Error: (04/20/2017 09:12:54 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na odpowiedź transakcji z usługi WSearch.

Error: (04/20/2017 09:12:54 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na odpowiedź transakcji z usługi BITS.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz
Percentage of memory in use: 29%
Total physical RAM: 8075.81 MB
Available physical RAM: 5707.03 MB
Total Virtual: 9611.81 MB
Available Virtual: 7193.87 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:217.81 GB) NTFS == & gt; [system with boot components (obtained from drive)]
Drive d: (DATA) (Fixed) (Total:398.18 GB) (Free:334.47 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 52891CA4)

Partition: GPT.

==================== End of Addition.txt ============================