-
👋 Witaj na MPCForum!
Przeglądasz forum jako gość, co oznacza, że wiele świetnych funkcji jest jeszcze przed Tobą! 😎
- ✅ Pełny dostęp do działów i ukrytych treści
- ✅ Możliwość pisania i odpowiadania w tematach
- ✅ System prywatnych wiadomości
- ✅ Zbieranie reputacji i rozwijanie swojego profilu
- ✅ Członkostwo w jednej z największych społeczności graczy
👉 Dołączenie zajmie Ci mniej niż minutę – a zyskasz znacznie więcej!
Zarejestruj się teraz
- 0

Pytanie
MR.ZiomuuSs
MR.ZiomuuSs
Witam.. Po raz kolejny mam problem z uporczywymi reklamami. Mam również pytanie: Jako że mam brata, do którego nie dociera że nie musi instalować wszystkiego co widzi na reklamach, to czy gdybym zrobił mu osobne konto (windows 7) a on by tam sobie instalował te surfvoxy i inne g***a to czy przeniosło by się to również na moje konto, czy tylko u niego byłyby te reklamy?
Tutaj logi FRST:
FRST
Addition:
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-07-2015 Ran by W at 2015-07-09 13:06:32 Running from C:\Users\W\Desktop\Pobrane Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3457423968-916553893-2173699218-500 - Administrator - Disabled) Gość (S-1-5-21-3457423968-916553893-2173699218-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3457423968-916553893-2173699218-1002 - Limited - Enabled) W (S-1-5-21-3457423968-916553893-2173699218-1001 - Administrator - Enabled) => C:\Users\W ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) "Assassin's Creed IV - Black Flag" (HKLM-x32\...\{959CF39B-F3FA-4A80-AECF-8AF6BA639276}_is1) (Version: 1.01.0.0 - ) µTorrent (HKU\S-1-5-21-3457423968-916553893-2173699218-1001\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) Adobe Flash Player 17 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.160 - Adobe Systems Incorporated) Aktualizacje NVIDIA 2.4.1.21 (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Audacity 2.1.0 (HKLM-x32\...\Audacity_is1) (Version: 2.1.0 - Audacity Team) AutoIt v3.3.12.0 (HKLM-x32\...\AutoItv3) (Version: 3.3.12.0 - AutoIt Team) Bitwa o Śródziemie™ II (HKLM-x32\...\{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) CPUID CPU-Z 1.72 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.27 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0407 - Disc Soft Ltd) Dark Messiah of Might & Magic Multi-Player (HKLM-x32\...\Steam App 2130) (Version: - Arkane Studios) Dark Messiah of Might & Magic Single Player (HKLM-x32\...\Steam App 2100) (Version: - Arkane Studios) Dead Island (HKLM-x32\...\Steam App 91310) (Version: - Techland) FileZilla Client 3.11.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.11.0.2 - Tim Kosse) GameRanger (HKU\S-1-5-21-3457423968-916553893-2173699218-1001\...\GameRanger) (Version: - GameRanger Technologies) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION GoHD (HKLM-x32\...\GoHD) (Version: 1.36.01.22 - InstallMoon) <==== ATTENTION Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.132 - Google Inc.) Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games) Heroes & Generals (HKLM-x32\...\Steam App 227940) (Version: - Reto-Moto) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) LEGO MARVEL Super Heroes (HKLM-x32\...\LEGO MARVEL Super Heroes_is1) (Version: - Warner Bros. Games) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.328 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.328 - LogMeIn, Inc.) Hidden Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mount&Blade Warband (HKLM-x32\...\Mount&Blade Warband) (Version: - ) Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski (x32 Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.5 - Notepad++ Team) NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) NVIDIA Sterownik 3D Vision 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.88 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation) NVIDIA Sterownik graficzny 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.88 - NVIDIA Corporation) NVIDIA Sterownik kontrolera 3D Vision 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation) Opera Stable 30.0.1835.88 (HKLM-x32\...\Opera 30.0.1835.88) (Version: 30.0.1835.88 - Opera Software) Panel sterowania NVIDIA 347.88 (Version: 347.88 - NVIDIA Corporation) Hidden Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile PLK Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended PLK Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Robocraft (HKLM-x32\...\Steam App 301520) (Version: - Freejam) SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Skype™ 7.4 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.4.102 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Forest (HKLM-x32\...\Steam App 242760) (Version: - Endnight Games Ltd) Tropico 4 1.00 (HKU\S-1-5-21-3457423968-916553893-2173699218-1001\...\Tropico 4) (Version: 1.00 - Kalypso Media) WinRAR 5.21 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 29-06-2015 09:20:36 Removed GTA San Andreas 30-06-2015 15:26:34 Installed GTA San Andreas 08-07-2015 10:45:54 Usunięte II Wojna Światowa ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2015-07-08 09:48 - 00000921 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 genuine.microsoft.com 127.0.0.1 mpa.one.microsoft.com 127.0.0.1 sls.microsoft.com ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {04C1207E-DAC2-4316-949A-1442157DDB14} - System32\Tasks\Opera scheduled Autoupdate 1428143704 => C:\Program Files (x86)\Opera\launcher.exe [2015-06-19] (Opera Software) Task: {347556B8-6B97-42B7-A8AF-C6FAEF899BA5} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-08] (globalUpdate) <==== ATTENTION Task: {3B6EBC4B-36EC-47BC-B196-B6E15E6CA735} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-08] (globalUpdate) <==== ATTENTION Task: {5BA8B0F8-2C93-4DD5-95CA-428B976DD5CE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-04] (Google Inc.) Task: {5BF1962F-747F-4DB0-992D-C8B475CBE204} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd) Task: {60A97DEB-2C5C-476D-8691-D15425D6A4D3} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-10_user => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-10.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {68575C5C-60F2-43A2-B5DB-B96BA5D8E7FA} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-1-6 => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-1-6.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {77800018-1EE0-46B8-846A-DBE43EFFED15} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {8C02E926-E2FF-429C-A175-774E8994E13F} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-11 => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-11.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {9A5DEEE8-72C5-40B4-B672-B14E0E05A574} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {9F53F466-7BD7-4AE8-9D13-5652BEA517FB} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-6 => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-6.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {AD0802A2-4B52-461C-80F2-733E7349E691} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-7 => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-7.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {AF3004F6-8EAA-4258-85A1-E004D0D7B51F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {C2D2CE3B-7C75-44D1-BEF1-9CF056B50771} - System32\Tasks\yoEkQGCvR => C:\Users\W\AppData\Roaming\yoEkQGCvR.exe <==== ATTENTION Task: {CAC75CC4-1EB1-4715-B7E2-0F8FCA81B8A1} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-5_user => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-5.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {CE15DCDB-CC54-4679-9495-4EBB0F2D23F2} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-3 => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-3.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {E39B3756-0453-48EE-B2EC-008A9F489B7C} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-5 => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-5.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: {E97C27E8-E234-4861-9403-255A4102469E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-04] (Google Inc.) Task: {F2DB8D18-1046-4080-BC54-C92CCD6A9111} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_188_pepper.exe [2015-05-17] (Adobe Systems Incorporated) Task: {F8AC7E3A-D8D6-4A9A-B65E-474B979CB90C} - System32\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-1-7 => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-1-7.exe [2015-07-08] (InstallMoon) <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-1-6.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-1-6.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-1-7.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-1-7.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-10_user.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-10.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-11.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-11.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-3.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-3.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-5.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-5.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-5_user.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-5.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-6.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-6.exe <==== ATTENTION Task: C:\Windows\Tasks\57baac5e-0bfc-427d-abf1-e855ada48942-7.job => C:\Program Files (x86)\GoHD\57baac5e-0bfc-427d-abf1-e855ada48942-7.exe <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_188_pepper.exe Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\yoEkQGCvR.job => C:\Users\W\AppData\Roaming\yoEkQGCvR.exe <==== ATTENTION ==================== Loaded Modules (Whitelisted) ============== 2015-04-04 13:04 - 2015-03-13 18:16 - 00118472 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-06-02 17:18 - 2015-06-02 17:18 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2015-04-04 13:24 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-06-25 13:54 - 2015-06-25 13:53 - 01649272 _____ () C:\Program Files (x86)\Opera\30.0.1835.88\libglesv2.dll 2015-06-25 13:54 - 2015-06-25 13:53 - 00081016 _____ () C:\Program Files (x86)\Opera\30.0.1835.88\libegl.dll 2015-05-17 13:05 - 2015-05-17 13:05 - 14982320 _____ () C:\Windows\SysWOW64\Macromed\Flash\pepflashplayer32_17_0_0_188.dll 2015-07-09 12:38 - 2015-07-09 12:38 - 00306176 _____ () C:\Users\W\AppData\Roaming\.minecraft\versions\1.8.3-OptiFine_HD_U_B1\1.8.3-OptiFine_HD_U_B1-natives-364981018160\lwjgl.dll 2015-07-09 12:38 - 2015-07-09 12:38 - 00246332 _____ () C:\Users\W\AppData\Roaming\.minecraft\versions\1.8.3-OptiFine_HD_U_B1\1.8.3-OptiFine_HD_U_B1-natives-364981018160\avutil-ttv-51.dll 2015-07-09 12:38 - 2015-07-09 12:38 - 00113171 _____ () C:\Users\W\AppData\Roaming\.minecraft\versions\1.8.3-OptiFine_HD_U_B1\1.8.3-OptiFine_HD_U_B1-natives-364981018160\swresample-ttv-0.dll 2015-07-09 12:38 - 2015-07-09 12:38 - 00394810 _____ () C:\Users\W\AppData\Roaming\.minecraft\versions\1.8.3-OptiFine_HD_U_B1\1.8.3-OptiFine_HD_U_B1-natives-364981018160\libmp3lame-ttv.dll 2015-07-09 12:38 - 2015-07-09 12:38 - 01145344 _____ () C:\Users\W\AppData\Roaming\.minecraft\versions\1.8.3-OptiFine_HD_U_B1\1.8.3-OptiFine_HD_U_B1-natives-364981018160\twitchsdk.dll 2015-07-09 12:38 - 2015-07-09 12:38 - 00390144 _____ () C:\Users\W\AppData\Roaming\.minecraft\versions\1.8.3-OptiFine_HD_U_B1\1.8.3-OptiFine_HD_U_B1-natives-364981018160\OpenAL32.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3457423968-916553893-2173699218-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\W\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Steam => "D:\Program Files (x86)\Steam\steam.exe" -silent ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{312799A6-959D-4325-BB00-BE112D69F18E}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{E32EEF6F-CFAA-4BD2-A57B-865487D2AF3E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{19C45C39-8E68-4744-BC38-521CB79C5EE8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{0EE25737-45CD-47CC-A69D-4938514AE4D8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{F6017EA0-477C-4986-AE6C-3FBB6D5CDCA2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{648057DD-F3FD-4DB2-B01C-4BC98CCC93F3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{92895859-7AFE-41B1-9621-058DD6A711BE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{353DEE53-90FB-42A1-A0B7-7A9A673372FC}] => (Allow) C:\Users\W\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{C2A2E3F2-BEE7-4474-B475-F047B056EB3C}] => (Allow) C:\Users\W\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{5488F1DC-3DF5-4D6C-992E-4CBB6DAE7A49}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{2A1F3785-5281-4086-9711-EBEDEFE2CF24}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{ECA90BF9-2344-491B-A98D-520549D0F880}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{0D740854-58EF-4CEB-B247-1D32EBFCAE11}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{4BC1D4E0-16A8-4491-A014-CD0CF9C1409A}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe FirewallRules: [UDP Query User{FF438CFF-863E-47F3-A21C-E1FA64D5FEE2}C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\bin\javaw.exe FirewallRules: [{DE013E78-6633-4AD7-93B5-8A34888CB355}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{5B7C3790-984C-4C2F-B6F5-1BA7254498BE}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{30B2E29D-8211-46E2-9136-AB4142BAC3CE}] => (Allow) D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\game.dat FirewallRules: [{E6247543-466A-4C58-8BCC-6C4076813910}] => (Allow) D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\game.dat FirewallRules: [TCP Query User{0B7FE6A1-EED1-4066-AEFB-74743AD485E6}C:\users\w\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\w\appdata\roaming\gameranger\gameranger\gameranger.exe FirewallRules: [UDP Query User{17CCA565-1F63-448A-84C6-837941B39A0D}C:\users\w\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\w\appdata\roaming\gameranger\gameranger\gameranger.exe FirewallRules: [{553E23A8-0A86-4C64-98FD-AC101C18AF76}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Dark Messiah Might and Magic Single Player\mm.exe FirewallRules: [{89898C3B-2650-4B3B-BFCB-38E6F5E8E558}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Dark Messiah Might and Magic Single Player\mm.exe FirewallRules: [{72ED80F4-150B-41BB-988D-E6E340FBD162}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Dark Messiah Might and Magic Multi-Player\runme.exe FirewallRules: [{8533253C-0E07-4FB4-B0CD-20DD044BC42A}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Dark Messiah Might and Magic Multi-Player\runme.exe FirewallRules: [TCP Query User{7BEC55D9-D3DD-4602-A5D5-A6447DB0B4DC}D:\program files (x86)\steam\steamapps\common\dark messiah might and magic multi-player\mm.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\dark messiah might and magic multi-player\mm.exe FirewallRules: [UDP Query User{A4A33F48-8924-4E7B-9D7B-3F25DCF821D6}D:\program files (x86)\steam\steamapps\common\dark messiah might and magic multi-player\mm.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\dark messiah might and magic multi-player\mm.exe FirewallRules: [{C48EC9C0-D2C3-4EC1-BC99-25160E4730D5}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{8BF38007-5787-4151-855D-2014A7933DED}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe FirewallRules: [{B77F02DE-910A-49A7-897F-C816B9E60581}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [{4D639B25-D46F-4B6A-87E1-C1A2782B9BFC}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngsteamlauncher.exe FirewallRules: [{02C69B51-1203-42E2-994A-64680BE4EC12}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Robocraft\Robocraft.exe FirewallRules: [{A04360E8-6BCA-4E6D-ABE9-0CD28382C41A}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Robocraft\Robocraft.exe FirewallRules: [TCP Query User{E583D1C2-F667-42B9-9C23-8F990D736306}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe FirewallRules: [UDP Query User{C47FAC96-74A4-491E-A017-93F7B37186C8}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe FirewallRules: [{49901500-A5BE-40F9-9AAF-A2B96FB9139F}] => (Allow) D:\Games\Assassin's Creed IV - Black Flag\AC4BFSP.exe FirewallRules: [{92D6DB4A-D131-478A-8A7B-2FFBD9892420}] => (Allow) D:\Games\Assassin's Creed IV - Black Flag\AC4BFSP.exe FirewallRules: [TCP Query User{E24F52B4-1B56-4E9F-88FE-EDBEF21371D3}D:\program files (x86)\ii wojna światowa\hoipol.exe] => (Allow) D:\program files (x86)\ii wojna światowa\hoipol.exe FirewallRules: [UDP Query User{D1862166-3BE8-4EB7-A7E0-51ECDACE80F9}D:\program files (x86)\ii wojna światowa\hoipol.exe] => (Allow) D:\program files (x86)\ii wojna światowa\hoipol.exe FirewallRules: [TCP Query User{765040F3-FF57-42F2-9F75-73DAA6D488D5}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [UDP Query User{A506F031-6038-4FAA-B428-8987CA561967}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [{7A3F0F63-38CD-4AC0-A451-14D1E867CB75}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{8B8FFE0E-49DA-4D53-A1E9-975DD5B71113}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe FirewallRules: [{DC112141-811A-42AA-9B19-BF1D32877DBC}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{54F5FB4A-3D39-4B2B-AF18-610A0566867B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{4A7DC2D0-0311-4E08-8FE7-04C836D1C8E8}] => (Allow) C:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\game.dat FirewallRules: [{9AD0D767-9FEA-4E69-9714-2172C3D8D38B}] => (Allow) C:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\game.dat FirewallRules: [{1A9F0DC8-0319-45CE-8F2F-1F1A4B444178}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Dead Island\DeadIslandGame.exe FirewallRules: [{08B3A8B7-F76B-4CF3-9A6C-5B01B364BA43}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Dead Island\DeadIslandGame.exe FirewallRules: [{F5A833DE-D5A1-4436-8787-C08CC24E91E0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/09/2015 00:33:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 00:33:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: NvStreamNetworkService.exe, wersja: 4.1.1943.6202, sygnatura czasowa: 0x551399be Nazwa modułu powodującego błąd: NvStreamNetworkService.exe, wersja: 4.1.1943.6202, sygnatura czasowa: 0x551399be Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000004e920f Identyfikator procesu powodującego błąd: 0x9f8 Godzina uruchomienia aplikacji powodującej błąd: 0xNvStreamNetworkService.exe0 Ścieżka aplikacji powodującej błąd: NvStreamNetworkService.exe1 Ścieżka modułu powodującego błąd: NvStreamNetworkService.exe2 Identyfikator raportu: NvStreamNetworkService.exe3 Error: (07/09/2015 00:32:39 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x00000000. Error: (07/09/2015 00:32:39 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Wystąpił błąd aktywacji licencji (slui.exe), kod błędu: 0x800401F9 Error: (07/09/2015 00:30:20 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (07/09/2015 08:56:43 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 08:55:52 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: NvStreamNetworkService.exe, wersja: 4.1.1943.6202, sygnatura czasowa: 0x551399be Nazwa modułu powodującego błąd: NvStreamNetworkService.exe, wersja: 4.1.1943.6202, sygnatura czasowa: 0x551399be Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000004e920f Identyfikator procesu powodującego błąd: 0x9bc Godzina uruchomienia aplikacji powodującej błąd: 0xNvStreamNetworkService.exe0 Ścieżka aplikacji powodującej błąd: NvStreamNetworkService.exe1 Ścieżka modułu powodującego błąd: NvStreamNetworkService.exe2 Identyfikator raportu: NvStreamNetworkService.exe3 Error: (07/09/2015 08:55:30 AM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x00000000. Error: (07/09/2015 08:55:29 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Wystąpił błąd aktywacji licencji (slui.exe), kod błędu: 0x800401F9 Error: (07/08/2015 06:38:23 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] System errors: ============= Error: (07/07/2015 00:07:56 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x0000007e (0xffffffffc0000005, 0xfffff80002ef5ae1, 0xfffff880031dc608, 0xfffff880031dbe60)C:\Windows\MEMORY.DMP070715-24195-01 Error: (07/07/2015 00:07:50 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 12:05:38 na 2015-07-07 było nieoczekiwane. Error: (07/07/2015 00:03:47 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 21:13:23 na 2015-07-06 było nieoczekiwane. Error: (07/04/2015 05:23:40 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 17:21:35 na 2015-07-04 było nieoczekiwane. Error: (07/03/2015 04:17:17 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} Error: (06/29/2015 05:46:28 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 17:42:29 na 2015-06-29 było nieoczekiwane. Error: (06/29/2015 01:51:12 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x0000007f (0x0000000000000008, 0x0000000080050031, 0x00000000000006f8, 0xfffff80002f0ffbc)C:\Windows\MEMORY.DMP062915-26379-01 Error: (06/29/2015 01:51:06 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 13:49:33 na 2015-06-29 było nieoczekiwane. Error: (06/29/2015 00:12:44 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 10:28:45 na 2015-06-29 było nieoczekiwane. Error: (06/29/2015 09:18:55 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 18:48:24 na 2015-06-28 było nieoczekiwane. Microsoft Office: ========================= Error: (07/09/2015 00:33:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 00:33:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f9f801d0ba329be0da80C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exedf65eac0-2625-11e5-b9f1-001e90021611 Error: (07/09/2015 00:32:39 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: 0x000000000x00000001 Error: (07/09/2015 00:32:39 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: 0x800401F9 Error: (07/09/2015 00:30:20 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (07/09/2015 08:56:43 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2015 08:55:52 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920f9bc01d0ba1445214180C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe8954d1a0-2607-11e5-ba63-001e90021611 Error: (07/09/2015 08:55:30 AM) (Source: Winlogon) (EventID: 4103) (User: ) Description: 0x000000000x00000001 Error: (07/09/2015 08:55:29 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: 0x800401F9 Error: (07/08/2015 06:38:23 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] CodeIntegrity Errors: =================================== Date: 2015-07-09 12:32:37.203 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-07-09 10:19:29.253 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-07-09 09:34:09.384 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-07-09 09:10:19.855 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-07-09 08:55:27.620 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-07-08 10:25:30.290 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-07-08 09:49:45.582 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system. Date: 2015-04-08 14:05:14.368 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\watchdog.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-04-08 14:05:14.321 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\watchdog.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-04-08 14:05:12.262 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\watchdog.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ Percentage of memory in use: 88% Total physical RAM: 2046.48 MB Available physical RAM: 230.39 MB Total Virtual: 4092.95 MB Available Virtual: 981.68 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:78.17 GB) (Free:35.43 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:212.03 GB) (Free:119.49 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 1549F232) Partition 1: (Not Active) - (Size=212 GB) - (Type=07 NTFS) Partition 2: (Active) - (Size=78.2 GB) - (Type=07 NTFS) ==================== End of log ============================Shortcut:
Proszę o pomoc i odpowiedź na powyższe pytanie... Z góry dziękuję.
ps. Program, który najprawdopodobniej wywołuje te reklamy nazywa się Gohd, jest w panelu sterowania ale nie da się go odinstalować w żaden sposób...
3 odpowiedzi na to pytanie
Rekomendowane odpowiedzi
Zarchiwizowany
Ten temat przebywa obecnie w archiwum. Dodawanie nowych odpowiedzi zostało zablokowane.