Wątek zamknięty

Komputer włącza się 10-20 minut.

 
Remciol
Nowy
Liczba postów: 7
Post: #1

Komputer włącza się 10-20 minut.


Witam, mam komputer od 2 lat, od jakiegoś roku mam problem z rozruchem komputera. Gdy go włączam wszystkie procesy związane z włączaniem przebiegają sprawnie, następnie bardzo długo jest napis 'Zapraszamy' (5 minut), następnie pojawia się czarny ekran, tak przez 5 minut, a potem przechodzi do pulpitu, i zanim mi się pulpit załaduje to mija kolejne 5 minut, łącznie około 20tu minut. Nie wiem czym to jest spowodowane.

Specyfikacja mojego komputera:

Procesor: AMD Phenom II X4 965 3,40 Ghz
Ram: 8 GB
System 64 bitowy

Gdzieś na forum przeczytałem żeby zeskanować komputer programem RSIT w celu uzyskania informacji, log ten przedstawia się następująco:

Kod:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Remik at 2015-03-24 13: 16: 25
Microsoft Windows 7 Professional  Service Pack 1
System drive C:  has 9 GB (13%) free of 70 GB
Total RAM:  8154 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13: 16: 29, on 2015-03-24
Platform:  Windows 7 SP1 (WinNT 6.00.3505)
MSIE:  Internet Explorer v8.00 (8.00.7601.17514)
Boot mode:  Normal

Running processes:
C: \Program Files\AVAST Software\Avast\AvastUI.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
D: \Pobieranie z Chrome\RSIT.exe
C: \Program Files (x86)\trend micro\Remik.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http: //go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about: blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http: //isearch.omiga-plus.com/web/?type=ds&ts=1419445834&from=cor&uid=WDCXWD5002AALX-00J37A0_WD-WMAYUL16806268062&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http: //isearch.omiga-plus.com/web/?type=ds&ts=1419445834&from=cor&uid=WDCXWD5002AALX-00J37A0_WD-WMAYUL16806268062&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about: blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C: \Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook:  (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
F2 - REG: system.ini:  UserInit=userinit.exe
O2 - BHO:  AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C: \Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO:  Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C: \PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO:  Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO:  avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO:  Pomocnik logowania za pomocą konta Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C: \Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO:  URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C: \PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO:  Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar:  avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run:  [avast] "C: \Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run:  [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C: \Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\RunOnce:  [SymInstallStub] C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=5 /launchedby=3
O4 - HKUS\S-1-5-19\..\Run:  [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce:  [mctadmin] C: \Windows\System32\mctadmin.exe (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run:  [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce:  [mctadmin] C: \Windows\System32\mctadmin.exe (User 'USŁUGA SIECIOWA')
O8 - Extra context menu item:  Add to Google Photos Screensa&ver - res: //C: \Windows\system32\GPhotos.scr/200
O8 - Extra context menu item:  E&ksportuj do programu Microsoft Excel - res: //D: \PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item:  Wyślij &do programu OneNote - res: //D: \PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button:  Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem:  Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button:  &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem:  &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP:  c: \program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP:  c: \program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone:  http: //*.aeriagames.com
O16 - DPF:  {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http: //fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol:  skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C: \PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol:  wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C: \Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack:  text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C: \Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service:  @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C: \Windows\System32\alg.exe (file missing)
O23 - Service:  AMD External Events Utility - Unknown owner - C: \Windows\system32\atiesrxx.exe (file missing)
O23 - Service:  AMD FUEL Service - Advanced Micro Devices, Inc. - C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service:  Apple Mobile Device - Apple Inc. - C: \Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service:  Autodesk Content Service - Autodesk, Inc. - C: \Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service:  avast! Antivirus - AVAST Software - C: \Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service:  @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C: \Windows\System32\lsass.exe (file missing)
O23 - Service:  @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C: \Windows\system32\fxssvc.exe (file missing)
O23 - Service:  FLEXnet Licensing Service 64 - Flexera Software, Inc. - C: \Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service:  Usługa Google Update (gupdate) (gupdate) - Google Inc. - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service:  Usługa Google Update (gupdatem) (gupdatem) - Google Inc. - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service:  Google Updater Service (gusvc) - Google - C: \Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service:  LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C: \Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service:  InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service:  @keyiso.dll,-100 (KeyIso) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  LMIGuardianSvc - LogMeIn, Inc. - C: \Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service:  @comres.dll,-2797 (MSDTC) - Unknown owner - C: \Windows\System32\msdtc.exe (file missing)
O23 - Service:  @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  nProtect GameGuard Service (npggsvc) - Unknown owner - C: \Windows\system32\GameMon.des.exe (file missing)
O23 - Service:  PnkBstrA - Unknown owner - C: \Windows\system32\PnkBstrA.exe
O23 - Service:  @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C: \Windows\system32\locator.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  Skype Updater (SkypeUpdate) - Skype Technologies - C: \Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service:  @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C: \Windows\System32\snmptrap.exe (file missing)
O23 - Service:  @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C: \Windows\System32\spoolsv.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C: \Windows\system32\sppsvc.exe (file missing)
O23 - Service:  Steam Client Service - Valve Corporation - C: \Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service:  UI Assistant Service - Unknown owner - C: \Program Files (x86)\blueconnect\AssistantServices.exe
O23 - Service:  @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C: \Windows\system32\UI0Detect.exe (file missing)
O23 - Service:  Update Faster Light - Unknown owner - C: \Program Files (x86)\Faster Light\updateFasterLight.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service:  @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C: \Windows\System32\vds.exe (file missing)
O23 - Service:  @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C: \Windows\system32\vssvc.exe (file missing)
O23 - Service:  @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C: \Windows\system32\wbengine.exe (file missing)
O23 - Service:  @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C: \Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service:  @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C: \Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10743 bytes

======Scheduled tasks folder======

C: \Windows\tasks\avast! Emergency Update.job - C: \Program Files\AVAST Software\Avast\AvastEmUpdate.exe  
C: \Windows\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job - C: \Windows\TEMP\{84A298C5-02DA-4EC7-8033-C230F3CCD2AD}.exe  --uninstall=1
C: \Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job - C: \Windows\TEMP\{C8FD8911-23EE-45D2-BED5-F458EDFFEBFD}.exe  --uninstall=1
C: \Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3955949626-2034052818-4075005931-1000Core.job - C: \Users\Remik\AppData\Local\Facebook\Update\FacebookUpdate.exe  /c /nocrashserver
C: \Windows\tasks\GoogleUpdateTaskMachineCore1cf8e0bc175db89.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe  /c
C: \Windows\tasks\GoogleUpdateTaskMachineCore1cfed9721f4610b.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe  /c
C: \Windows\tasks\GoogleUpdateTaskMachineCore1cfff394434aaa.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe  /c
C: \Windows\tasks\GoogleUpdateTaskMachineCore1d040b46633b925.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe  /c
C: \Windows\tasks\GoogleUpdateTaskMachineUA.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler
C: \Windows\tasks\MegaCloud Backup.job - C: \Users\Remik\AppData\Roaming\MegaCloudBackup\MegaCloudBackup.exe  /scheduler
C: \Windows\tasks\Norton Product Installer.job - C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe  /partnerid=adobe /productlist=nss /staging=false /delay=0 /launchedby=2
C: \Windows\tasks\Norton Product InstallerIdle.job - C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe  /partnerid=adobe /productlist=nss /staging=false /delay=0 /launchedby=4
C: \Windows\tasks\Opera N.job - C: \Program Files (x86)\Opera\launcher.exe  
C: \Windows\tasks\ROC_JAN2013_TB_rmv.job - C: \Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe  --uninstall=1
C: \Windows\tasks\RunOW.job - C: \Program Files (x86)\Overwolf\OverwolfLauncher.exe  

=========Mozilla firefox=========

ProfilePath - C: \Users\Remik\AppData\Roaming\Mozilla\Firefox\Profiles\edcpdnl2.default

"wrc@avast.com"=C: \Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C: \Windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C: \Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C: \Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C: \Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C: \PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C: \Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ncsoft.com/Plugin]
"Description"=NCSOFT login launcher module for FireFox and Chrome
"Path"=C: \Program Files (x86)\plaync\NCPlugin\npncllm3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=D: \Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C: \Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C: \Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C: \Program Files (x86)\Mozilla Firefox\searchplugins\
allegro-pl.xml
fbc-pl.xml
google.xml
merlin-pl.xml
pwn-pl.xml
wikipedia-pl.xml
wp-pl.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C: \Pro [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C: \PRO [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C: \Pro [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C: \Pro [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocnik logowania za pomocą konta Microsoft - C: \Pro [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C: \PRO [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C: \Pro [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C: \Pro [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C: \Pro [2013-09-02 6583664]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C: \Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SymInstallStub"=C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe [2014-06-24 358752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C: \PRO [2013-09-02 6583664]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRecentDocsNetHood"=1
"NoDriveTypeAutoRun"=145
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standard​profile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainpr​ofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.vorbis"=vorbis.acm
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C: \Windows\System32\Notepad.exe %1
.js - open - C: \Windows\System32\WScript.exe "%1" %*
.scr - open - C: \Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2015-03-24 13: 16: 26 ----D---- C: \Program Files (x86)\trend micro
2015-03-24 13: 16: 25 ----D---- C: \rsit
2015-03-24 11: 47: 26 ----ASH---- C: \pagefile.sys
2015-03-24 01: 21: 18 ----SHD---- C: \Config.Msi
2015-03-18 20: 26: 30 ----D---- C: \Users\Remik\AppData\Roaming\Dropbox
2015-03-17 08: 58: 23 ----D---- C: \Users\Remik\AppData\Roaming\Just Aion Launcher
2015-02-25 21: 27: 39 ----D---- C: \Users\Remik\AppData\Roaming\OpenOffice

======List of files/folders modified in the last 1 month======

2015-03-24 13: 16: 28 ----D---- C: \Windows\Temp
2015-03-24 13: 16: 26 ----RD---- C: \Program Files (x86)
2015-03-24 13: 15: 07 ----D---- C: \Windows\pss
2015-03-24 12: 18: 30 ----D---- C: \Users\Remik\AppData\Roaming\Curse Client
2015-03-24 11: 49: 42 ----SHD---- C: \System Volume Information
2015-03-24 11: 47: 19 ----D---- C: \Windows\SysWOW64
2015-03-24 11: 47: 19 ----D---- C: \Windows\System32
2015-03-24 01: 47: 37 ----D---- C: \lisa
2015-03-24 01: 47: 19 ----D---- C: \Users\Remik\AppData\Roaming\uTorrent
2015-03-24 01: 36: 12 ----D---- C: \Windows\Tasks
2015-03-24 01: 35: 44 ----D---- C: \Windows\winsxs
2015-03-24 01: 35: 08 ----D---- C: \Windows\inf
2015-03-24 01: 30: 06 ----HD---- C: \Program Files (x86)\InstallShield Installation Information
2015-03-24 01: 29: 23 ----SHD---- C: \Windows\Installer
2015-03-24 01: 29: 23 ----HD---- C: \ProgramData
2015-03-24 01: 29: 06 ----RD---- C: \Program Files
2015-03-24 01: 26: 57 ----RSD---- C: \Windows\assembly
2015-03-24 01: 25: 05 ----D---- C: \Program Files (x86)\Google
2015-03-24 01: 23: 19 ----D---- C: \Program Files (x86)\LooksBuilder
2015-03-24 01: 22: 25 ----D---- C: \Program Files (x86)\GameforgeLive
2015-03-24 01: 21: 26 ----D---- C: \ProgramData\Apple
2015-03-24 01: 21: 26 ----D---- C: \Program Files (x86)\Common Files\Apple
2015-03-24 01: 20: 42 ----D---- C: \ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-24 01: 19: 38 ----D---- C: \Program Files (x86)\Common Files\Adobe
2015-03-24 01: 13: 34 ----D---- C: \ProgramData\Samsung
2015-03-24 01: 13: 18 ----D---- C: \Windows
2015-03-24 01: 07: 26 ----D---- C: \Windows\Help
2015-03-21 20: 06: 55 ----D---- C: \Program Files (x86)\Battle.net
2015-03-20 22: 19: 30 ----D---- C: \Windows\Minidump
2015-02-26 17: 17: 42 ----SD---- C: \Users\Remik\AppData\Roaming\Microsoft
2015-02-25 21: 25: 44 ----RSD---- C: \Windows\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C: \Windows\system32\DRIVERS\amd_sata.sys []
R0 amd_xata;amd_xata; C: \Windows\system32\DRIVERS\amd_xata.sys []
R0 aswRvrt;aswRvrt; C: \Windows\SysWOW64\drivers\aswRvrt.sys []
R0 aswVmm;aswVmm; C: \Windows\SysWOW64\drivers\aswVmm.sys []
R0 JRAID;JRAID; C: \Windows\system32\DRIVERS\jraid.sys []
R0 pciide;pciide; C: \Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C: \Windows\System32\drivers\rdyboost.sys []
R0 sptd;sptd; C: \Windows\System32\Drivers\sptd.sys []
R1 aswRdr;aswRdr; C: \Windows\System32\Drivers\aswrdr2.sys []
R1 aswSnx;aswSnx; C: \Windows\SysWOW64\drivers\aswSnx.sys []
R1 aswSP;aswSP; C: \Windows\SysWOW64\drivers\aswSP.sys []
R1 aswTdi;avast! Network Shield Support; C: \Windows\SysWOW64\drivers\aswTdi.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C: \Windows\system32\drivers\csc.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C: \Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C: \Windows\system32\DRIVERS\vwififlt.sys []
R2 AODDriver4.1;AODDriver4.1; \?\C: \Pro [2013-09-02 6583664]
R2 aswFsBlk;aswFsBlk; C: \Windows\SysWOW64\drivers\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; \?\C: \Windows\system32\drivers\aswMonFlt.sys []
R3 amdiox64;AMD IO Driver; C: \Windows\system32\DRIVERS\amdiox64.sys []
R3 amdkmdag;amdkmdag; C: \Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C: \Windows\system32\DRIVERS\atikmpag.sys []
R3 asmthub3;ASMedia USB3 Hub Service; C: \Windows\system32\DRIVERS\asmthub3.sys []
R3 asmtxhci;ASMEDIA XHCI Service; C: \Windows\system32\DRIVERS\asmtxhci.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C: \Windows\system32\drivers\AtihdW76.sys []
R3 hamachi;Hamachi Network Interface; C: \Windows\system32\DRIVERS\hamachi.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C: \Windows\system32\drivers\RTKVHD64.sys []
R3 RTL8167;Realtek 8167 NT Driver; C: \Windows\system32\DRIVERS\Rt64win7.sys []
S3 1394hub;1394 Enabled Hub; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S3 ALSysIO;ALSysIO; \?\C: \Users\Remik\AppData\Local\Temp\ALSysIO64.sys []
S3 dk;dk; \?\D: \AeriaGames\DKOnline\avital\dkol64.sys []
S3 dmvsc;dmvsc; C: \Windows\system32\drivers\dmvsc.sys []
S3 EagleX64;EagleX64; \?\C: \Windows\system32\drivers\EagleX64.sys []
S3 massfilter;ZTE Mass Storage Filter Driver; C: \Windows\system32\drivers\massfilter.sys []
S3 netr7364;Sterownik karty RT73 USB Wireless LAN dla systemu Vista; C: \Windows\system32\DRIVERS\netr7364.sys []
S3 NLNdisMP;NLNdisMP; C: \Windows\system32\DRIVERS\nlndis.sys []
S3 NLNdisPT;NetLimiter Ndis Protocol Service; C: \Windows\system32\DRIVERS\nlndis.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C: \Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C: \Windows\system32\drivers\vms3cap.sys []
S3 slb;slb; \?\D: \AeriaGames\ScarletBlade\avital\scarlb64.sys []
S3 storvsc;storvsc; C: \Windows\system32\drivers\storvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C: \Windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C: \Windows\system32\drivers\TsUsbGD.sys []
S3 usb_rndisx;Karta USB RNDIS; C: \Windows\system32\DRIVERS\usb8023x.sys []
S3 vmbus;vmbus; C: \Windows\system32\drivers\vmbus.sys []
S3 VMBusHID;VMBusHID; C: \Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;SAMSUNG Android USB Driver; C: \Windows\system32\DRIVERS\WinUsb.sys []
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C: \Windows\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C: \Windows\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C: \Windows\system32\DRIVERS\ZTEusbser6k.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C: \Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C: \Pro [2013-09-02 6583664]
R2 Autodesk Content Service;Autodesk Content Service; C: \Pro [2013-09-02 6583664]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C: \Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C: \Pro [2013-09-02 6583664]
R2 LMIGuardianSvc;LMIGuardianSvc; C: \Pro [2013-09-02 6583664]
R2 PnkBstrA;PnkBstrA; C: \Windows\system32\PnkBstrA.exe [2013-01-31 76888]
R2 UI Assistant Service;UI Assistant Service; C: \Pro [2013-09-02 6583664]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C: \Pro [2013-09-02 6583664]
R3 osppsvc;Office Software Protection Platform; C: \Pro [2013-09-02 6583664]
S2 Apple Mobile Device;Apple Mobile Device; C: \Pro [2013-09-02 6583664]
S2 avast! Antivirus;avast! Antivirus; C: \Pro [2013-09-02 6583664]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C: \Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Usługa Google Update (gupdate); C: \Pro [2013-09-02 6583664]
S2 SkypeUpdate;Skype Updater; C: \Pro [2013-09-02 6583664]
S2 Update Faster Light;Update Faster Light; C: \Pro [2013-09-02 6583664]
S3 AppMgmt;@appmgmts.dll,-3250; C: \Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;„Usługa stanu ASP.NET; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C: \Pro [2013-09-02 6583664]
S3 gupdatem;Usługa Google Update (gupdatem); C: \Pro [2013-09-02 6583664]
S3 gusvc;Google Updater Service; C: \Pro [2013-09-02 6583664]
S3 IDriverT;InstallDriver Table Manager; C: \Pro [2013-09-02 6583664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; D: \Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 npggsvc;nProtect GameGuard Service; C: \Windows\system32\GameMon.des [2013-10-30 5284208]
S3 ose64;Office 64 Source Engine; C: \Pro [2013-09-02 6583664]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C: \Pro [2013-09-02 6583664]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C: \Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C: \Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C: \Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 WindowsMangerProtect;WindowsMangerProtect Service; C: \Pro [2013-09-02 6583664]

-----------------EOF-----------------

Przeprowadziłem skan programem Malwarebytes, wykryło mi 250 plików które usunąłem. Nie wiem czy to ma znaczenie, ale średnio raz na miesiąc mam blue screena, czasem częściej, czasem rzadziej. Generalnie na kompie mam porządek, nie mam zawalonych dysków. Proszę o pomoc!

24.03.2015 13:36

Znajdź wszystkie posty użytkownika
Nostromo
Administrator

Liczba postów: 2.387
Post: #2

RE: Komputer włącza się 10-20 minut.


Zrób skan AdwCleaner pokaż raport na forum i usuń co znajdzie.

24.03.2015 21:17

Znajdź wszystkie posty użytkownika
Remciol
Nowy
Liczba postów: 7
Post: #3

RE: Komputer włącza się 10-20 minut.


To jest raport. Plik się utworzył o 2:44:57 (czyli jak mi kompa zrestartowało), a komputer włączył się i był gotowy do działania równo o 3:00.

Kod:
# AdwCleaner v4.201 - Logfile created 09/04/2015 at 02: 44: 57
# Updated 08/04/2015 by Xplode
# Database :  2015-04-08.1 [Server]
# Operating system :  Windows 7 Professional Service Pack 1 (x64)
# Username :  Remik - AMD-DRAGON
# Running from :  D: \Pobieranie z Chrome\adwcleaner_4.201.exe
# Option :  Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted :  C: \ProgramData\Ask
Folder Deleted :  C: \ProgramData\Tarma Installer
Folder Deleted :  C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files.com Fixer
Folder Deleted :  C: \Program Files (x86)\Conduit
Folder Deleted :  C: \Users\Remik\AppData\Local\apn
Folder Deleted :  C: \Users\Remik\AppData\Local\Conduit
Folder Deleted :  C: \Users\Remik\AppData\Local\genienext
Folder Deleted :  C: \Users\Remik\AppData\Local\Mobogenie
Folder Deleted :  C: \Users\Remik\AppData\Local\FileViewPro
Folder Deleted :  C: \Users\Remik\AppData\LocalLow\Conduit
Folder Deleted :  C: \Users\Remik\AppData\Roaming\Solvusoft
Folder Deleted :  C: \Users\Remik\AppData\Roaming\dll-files.com
Folder Deleted :  C: \Users\Remik\Documents\Mobogenie
File Deleted :  C: \Windows\System32\roboot64.exe
File Deleted :  C: \Users\Remik\daemonprocess.txt
File Deleted :  C: \Users\Remik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
File Deleted :  C: \Users\Remik\AppData\Roaming\Mozilla\Firefox\Profiles\edcpdnl2.default\user.js
File Deleted :  C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_isearch.avg.com_0.localstorage
File Deleted :  C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_photoscape.softonic.pl_0.localstorage
File Deleted :  C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.omiga-plus.com_0.localstorage
File Deleted :  C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.omiga-plus.com_0.localstorage-journal
File Deleted :  C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.pl_0.localstorage

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted :  HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted :  HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted :  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted :  HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted :  HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted :  HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted :  HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted :  HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted :  HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted :  HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted :  HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted :  HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted :  HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted :  HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted :  HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted :  HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted :  HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted :  HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted :  HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted :  HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted :  HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted :  HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted :  [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted :  [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted :  [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted :  [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted :  [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted :  [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted :  HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key Deleted :  HKCU\Software\powerpack
Key Deleted :  HKCU\Software\Softonic
Key Deleted :  HKCU\Software\gameo
Key Deleted :  HKCU\Software\dll-files.com
Key Deleted :  HKLM\SOFTWARE\Conduit
Key Deleted :  HKLM\SOFTWARE\dll-files.com
Key Deleted :  [x64] HKLM\SOFTWARE\Tarma Installer
Data Deleted :  HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - local;<local>

***** [ Web browsers ] *****

-\\ Internet Explorer v8.0.7601.17514


-\\ Mozilla Firefox v18.0.1 (pl)


-\\ Google Chrome v41.0.2272.118

[C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] :  ndibdjnfmopecpmkdieinmbadjfpblof
[C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] :  niapdbllcanepiiimjjndipklodoedlc
[C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Startup_URLs] :  hxxp: //isearch.avg.com/?cid={71A64F14-C181-4F92-A9A5-BC2E3CEF18C0}&mid=7e1caa57666b47d0a7ee192946e1ce10-0aea1eda5f2fb4657fea637790ab2adb0a955b54&lang=pl&ds=xn011&pr=sa&d=2012-11-17 02: 50: 46&v=13.2.0.4&sap=hp

-\\ Chromium v


*************************

AdwCleaner[R0].txt - [6399 bytes] - [09/04/2015 02: 43: 39]
AdwCleaner[S0].txt - [6029 bytes] - [09/04/2015 02: 44: 57]

########## EOF - C: \AdwCleaner\AdwCleaner[S0].txt - [6088  bytes] ##########

09.04.2015 02:08

Znajdź wszystkie posty użytkownika
Nostromo
Administrator

Liczba postów: 2.387
Post: #4

RE: Komputer włącza się 10-20 minut.


Ładnie, system z grubsza oczyszczony ze śmieci które sobie zainstalowałeś przy okazji pobierania pożytków, korzystając z asystentów pobierania bądź bez zastanowienia klikając TAK na instalatory jak leci, zamiast wybierać składniki które chcesz.
Jedyna rada - pobierać oprogramowanie tylko ze strony producenta, bez dodatków.

Kolejna sprawa, lokalizacja programu, który opóźnia start twojego systemu przez Podgląd zdarzeń.
Naciśnij klawisz [Windows R], wpisz(wklej) polecenie eventvwr i potwierdź przyciskiem OK.
Rozwiń - Dzienniki aplikacji i usług>Microsoft>Windows>Diagnostics-Performance>Działa
Dla uproszczenia wyczyść dziennik - z prawej tabelka Akcje>wyczyść dziennik, pozamykaj wszystko i uruchom system ponownie.

Po uruchomieniu i załadowaniu wszystkiego powtórz:
klawisz [Windows R], wpisz(wklej) polecenie eventvwr i potwierdź przyciskiem OK.
Rozwiń - Dzienniki aplikacji i usług>Microsoft>Windows>Diagnostics-Performance>Działa
Interesują nas zdarzenia o identyfikatorze z przedziału od 100-199

Tu jest wskazówka jakie programy opóźniają uruchomienie systemu, warto je wyłączyć z auto startu.

Klawisz [Windows R], wpisz(wklej) polecenie msconfig.exe
Zakładka- Uruchamianie, odznacz to co chcesz wyłączyć z autostartu.

Podejrzewam, że opóźnienia może powodować Avast, złe sterowniki bądź usługa.

Zrób logi OTL i Extras i wklej na forum w znacznikach code.
http://www.geekstogo.com/forum/files/fil...s-list-it/

http://traxter-online.net/otl-by-oldtime...elementow/

09.04.2015 16:29

Znajdź wszystkie posty użytkownika
Glover
Młodszy user systemu

Liczba postów: 83
Post: #5

RE: Komputer włącza się 10-20 minut.


Jęzeli podczas uruchamiania Windows 7 po ekranie witamy jest czarny ekran to może to być spowodowane ustawieniem w biosie, a dokładnie jeżeli ustawienia portów Sata mają włączoną opcję ESP, to efekt jest właśnie taki i objawia się czarnym ekranem (długi freeze) podczas uruchamiania windows.

09.04.2015 19:50

Znajdź wszystkie posty użytkownika
Remciol
Nowy
Liczba postów: 7
Post: #6

RE: Komputer włącza się 10-20 minut.


Kod:
OTL logfile created on:  2015-04-09 21: 11: 21 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = D: \Pobieranie z Chrome
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale:  00000415 | Country:  Polska | Language:  PLK | Date Format:  yyyy-MM-dd

7,96 Gb Total Physical Memory | 3,84 Gb Available Physical Memory | 48,27% Memory free
15,92 Gb Paging File | 10,91 Gb Available in Paging File | 68,49% Paging File free
Paging file location(s):  ?: \pagefile.sys [binary data]

%SystemDrive% = C:  | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C:  | 68,26 Gb Total Space | 7,67 Gb Free Space | 11,24% Space Free | Partition Type:  NTFS
Drive D:  | 397,40 Gb Total Space | 194,31 Gb Free Space | 48,89% Space Free | Partition Type:  NTFS

Computer Name:  AMD-DRAGON | User Name:  Remik | Logged in as Administrator.
Boot Mode:  Normal | Scan Mode:  Current user | Include 64bit Scans
Company Name Whitelist:  Off | Skip Microsoft Files:  Off | No Company Name Whitelist:  On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2015-04-09 21: 11: 11 | 000,602,112 | ---- | M] (OldTimer Tools) -- D: \Pobieranie z Chrome\OTL.exe
PRC - [2015-04-08 20: 31: 05 | 003,800,568 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_patcher\releases\0.0.0.27\deploy\LoLPatcher.exe
PRC - [2015-04-08 20: 30: 47 | 002,324,472 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_launcher\releases\0.0.0.243\deploy\LoLLauncher.exe
PRC - [2015-04-07 23: 35: 27 | 007,169,072 | ---- | M] (Blizzard Entertainment) -- C: \ProgramData\Battle.net\Agent\Agent.3918\Agent.exe
PRC - [2015-04-07 03: 40: 48 | 010,103,344 | ---- | M] (Blizzard Entertainment) -- C: \Program Files (x86)\Battle.net\Battle.net.5669\Battle.net.exe
PRC - [2015-03-31 20: 23: 00 | 011,632,176 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone.exe
PRC - [2015-03-30 23: 07: 57 | 000,809,288 | ---- | M] (Google Inc.) -- C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015-02-13 12: 05: 00 | 003,037,736 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\gfl_client.exe
PRC - [2014-01-03 19: 04: 00 | 000,074,752 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_air_client\releases\0.0.1.139\deploy\LolClient.exe
PRC - [2014-01-03 18: 40: 38 | 001,294,336 | ---- | M] () -- D: \Riot Games\League of Legends\rads\system\rads_user_kernel.exe
PRC - [2013-08-30 09: 47: 34 | 004,858,968 | ---- | M] (AVAST Software) -- C: \Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013-08-30 09: 47: 33 | 000,046,808 | ---- | M] (AVAST Software) -- C: \Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013-01-31 17: 20: 30 | 000,076,888 | ---- | M] () -- C: \Windows\SysWOW64\PnkBstrA.exe
PRC - [2012-01-31 10: 46: 56 | 000,019,232 | ---- | M] (Autodesk, Inc.) -- C: \Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
PRC - [2010-08-02 19: 05: 40 | 000,247,152 | ---- | M] () -- C: \Program Files (x86)\blueconnect\AssistantServices.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2015-04-08 20: 31: 05 | 003,800,568 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_patcher\releases\0.0.0.27\deploy\LoLPatcher.exe
MOD - [2015-04-08 20: 31: 05 | 001,672,184 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_patcher\releases\0.0.0.27\deploy\RiotLauncher.dll
MOD - [2015-04-08 20: 30: 47 | 002,324,472 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_launcher\releases\0.0.0.243\deploy\LoLLauncher.exe
MOD - [2015-04-07 03: 40: 47 | 000,908,288 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\platforms\qwindows.dll
MOD - [2015-04-07 03: 40: 47 | 000,739,840 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\libGLESv2.dll
MOD - [2015-04-07 03: 40: 47 | 000,054,272 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\qml\QtQuick\Layouts\qquicklayoutsplugin.dll
MOD - [2015-04-07 03: 40: 47 | 000,010,240 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\qml\QtQuick.2\qtquick2plugin.dll
MOD - [2015-04-07 03: 40: 47 | 000,010,240 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\qml\QtQml\Models.2\modelsplugin.dll
MOD - [2015-04-07 03: 40: 46 | 026,065,408 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\libcef.dll
MOD - [2015-04-07 03: 40: 46 | 000,312,832 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qtiff.dll
MOD - [2015-04-07 03: 40: 46 | 000,225,792 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qmng.dll
MOD - [2015-04-07 03: 40: 46 | 000,205,312 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qjpeg.dll
MOD - [2015-04-07 03: 40: 46 | 000,130,048 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\libEGL.dll
MOD - [2015-04-07 03: 40: 46 | 000,021,504 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qico.dll
MOD - [2015-04-07 03: 40: 46 | 000,020,992 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qgif.dll
MOD - [2015-04-07 03: 40: 46 | 000,015,872 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qsvg.dll
MOD - [2015-03-31 20: 23: 05 | 002,122,752 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone_Data\Plugins\Connect.dll
MOD - [2015-03-31 20: 23: 04 | 000,029,184 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone_Data\Plugins\PlayErrors32.dll
MOD - [2015-03-31 20: 23: 02 | 002,102,784 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone_Data\Mono\mono.dll
MOD - [2015-03-31 20: 23: 00 | 011,632,176 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone.exe
MOD - [2015-03-30 23: 07: 56 | 014,974,280 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll
MOD - [2015-03-30 23: 07: 56 | 009,279,304 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\pdf.dll
MOD - [2015-03-30 23: 07: 54 | 001,174,856 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libglesv2.dll
MOD - [2015-03-30 23: 07: 54 | 000,080,200 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libegl.dll
MOD - [2015-02-13 12: 05: 00 | 003,037,736 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\gfl_client.exe
MOD - [2015-02-10 12: 13: 38 | 000,141,312 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\qjson.dll
MOD - [2014-10-16 00: 07: 29 | 016,832,176 | ---- | M] () -- C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll
MOD - [2014-02-14 14: 19: 00 | 005,686,669 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libtorrent.dll
MOD - [2014-02-14 13: 55: 56 | 000,530,432 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\log4qt.dll
MOD - [2014-02-14 12: 32: 30 | 000,097,659 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libboost_system-mgw47-mt-1_53.dll
MOD - [2014-02-13 13: 33: 58 | 001,765,301 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libgcrypt-11.dll
MOD - [2014-02-13 13: 33: 58 | 000,126,959 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libgpg-error-0.dll
MOD - [2014-02-13 13: 32: 58 | 000,863,744 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libstdc++-6.dll
MOD - [2014-02-13 13: 32: 58 | 000,088,064 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libgcc_s_sjlj-1.dll
MOD - [2014-01-03 19: 04: 00 | 000,074,752 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_air_client\releases\0.0.1.139\deploy\LolClient.exe
MOD - [2014-01-03 18: 52: 12 | 004,774,248 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_air_client\releases\0.0.1.139\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll
MOD - [2014-01-03 18: 40: 38 | 001,294,336 | ---- | M] () -- D: \Riot Games\League of Legends\rads\system\rads_user_kernel.exe
MOD - [2010-01-30 02: 41: 12 | 004,254,560 | ---- | M] () -- C: \PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV: [b]64bit: [/b] - [2013-08-30 09: 47: 33 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C: \Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV: [b]64bit: [/b] - [2012-10-21 14: 33: 13 | 001,432,400 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C: \Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV: [b]64bit: [/b] - [2012-04-06 04: 16: 02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C: \Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV: [b]64bit: [/b] - [2012-04-05 21: 57: 34 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV: [b]64bit: [/b] - [2009-07-14 03: 41: 27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C: \Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV: [b]64bit: [/b] - [2009-07-14 03: 40: 01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015-03-30 15: 29: 00 | 002,490,216 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C: \Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2015-03-30 15: 25: 28 | 000,417,552 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C: \Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2015-03-24 06: 22: 24 | 000,836,288 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C: \Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2015-03-17 07: 14: 08 | 001,080,120 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- D: \Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013-10-30 18: 54: 36 | 005,284,208 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C: \Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2013-10-23 09: 15: 08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C: \Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-01-31 17: 20: 30 | 000,076,888 | ---- | M] () [Auto | Running] -- C: \Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012-01-31 10: 46: 56 | 000,019,232 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C: \Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2010-08-02 19: 05: 40 | 000,247,152 | ---- | M] () [Auto | Running] -- C: \Program Files (x86)\blueconnect\AssistantServices.exe -- (UI Assistant Service)
SRV - [2010-03-25 10: 41: 00 | 051,456,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- D: \Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010-03-18 13: 16: 28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C: \Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 23: 23: 09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C: \Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV: [b]64bit: [/b] - [2015-03-17 07: 15: 38 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV: [b]64bit: [/b] - [2015-03-17 07: 15: 24 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C: \Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV: [b]64bit: [/b] - [2014-12-01 13: 15: 07 | 001,031,392 | ---- | M] (AVAST Software) [File_System | System | Running] -- C: \Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,378,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,204,880 | ---- | M] () [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,072,016 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,064,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 09 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C: \Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 09 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C: \Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV: [b]64bit: [/b] - [2012-12-28 13: 56: 21 | 000,564,824 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV: [b]64bit: [/b] - [2012-05-14 18: 54: 47 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV: [b]64bit: [/b] - [2012-04-06 07: 22: 40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV: [b]64bit: [/b] - [2012-04-06 03: 10: 44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV: [b]64bit: [/b] - [2012-03-05 16: 04: 30 | 000,053,888 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C: \Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)
DRV: [b]64bit: [/b] - [2012-02-23 14: 32: 04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV: [b]64bit: [/b] - [2011-03-21 15: 22: 06 | 000,452,200 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV: [b]64bit: [/b] - [2011-03-04 07: 46: 20 | 000,078,976 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV: [b]64bit: [/b] - [2011-03-04 07: 46: 20 | 000,038,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV: [b]64bit: [/b] - [2011-02-24 10: 30: 50 | 000,389,608 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV: [b]64bit: [/b] - [2011-02-24 10: 30: 50 | 000,126,952 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV: [b]64bit: [/b] - [2010-11-25 05: 27: 42 | 000,120,408 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV: [b]64bit: [/b] - [2010-11-21 05: 24: 33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,011,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\massfilter.sys -- (massfilter)
DRV: [b]64bit: [/b] - [2010-02-18 09: 18: 24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV: [b]64bit: [/b] - [2009-07-14 03: 52: 20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV: [b]64bit: [/b] - [2009-07-14 03: 48: 04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV: [b]64bit: [/b] - [2009-07-14 03: 47: 48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C: \Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV: [b]64bit: [/b] - [2009-07-14 03: 45: 55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV: [b]64bit: [/b] - [2009-07-14 03: 39: 46 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\svchost.exe -- (1394hub)
DRV: [b]64bit: [/b] - [2009-07-14 02: 09: 50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV: [b]64bit: [/b] - [2009-06-10 22: 35: 38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\netr7364.sys -- (netr7364)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV: [b]64bit: [/b] - [2009-06-10 22: 31: 59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV: [b]64bit: [/b] - [2009-03-18 18: 35: 42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009-07-14 03: 19: 10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C: \Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about: blank
IE: [b]64bit: [/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:  "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C: \Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about: blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:  "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about: blank
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:  "URL" = http: //www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:  "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..extensions.enabledAddons:  faststartff%40gmail.com: 4.3.0
FF - prefs.js..extensions.enabledAddons:  %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D: 18.0.1
FF - user.js - File not found

FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:  C: \Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  D: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:  C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer:  C: \Windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0:  C: \Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2:  C: \Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2:  C: \Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  C: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0:  C: \PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331:  C: \Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ncsoft.com/Plugin:  C: \Program Files (x86)\plaync\NCPlugin\npncllm3.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin:   File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3:  C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9:  C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader:  D: \Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin:  C: \Users\Remik\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com:  C: \Program Files\AVAST Software\Avast\WebRep\FF [2013-09-03 00: 30: 15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components:  C: \Program Files (x86)\Mozilla Firefox\components [2013-02-04 21: 07: 00 | 000,000,000 | ---D | M]

[2013-02-04 21: 07: 17 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Remik\AppData\Roaming\mozilla\Extensions
[2012-05-19 16: 00: 28 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Remik\AppData\Roaming\mozilla\Firefox\extensions
[2012-05-19 16: 00: 28 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C: \Users\Remik\AppData\Roaming\mozilla\Firefox\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2014-12-24 22: 16: 55 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Remik\AppData\Roaming\mozilla\Firefox\Profiles\edcpdnl2.default\extensions
[2013-02-04 21: 07: 00 | 000,000,000 | ---D | M] (No name found) -- C: \Program Files (x86)\mozilla firefox\extensions
[2013-01-16 22: 10: 14 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C: \Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013-01-17 02: 46: 35 | 000,002,767 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2013-01-17 02: 46: 35 | 000,001,406 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2013-01-17 02: 46: 35 | 000,000,917 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2013-01-17 02: 46: 35 | 000,000,858 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2013-01-17 02: 46: 35 | 000,001,183 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2013-01-17 02: 46: 35 | 000,001,683 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

[color=#E56717]========== Chrome  ==========[/color]

CHR - default_search_provider:   ()
CHR - default_search_provider:  search_url =
CHR - default_search_provider:  suggest_url =
CHR - plugin:  Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin:  Native Client (Enabled) = C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll
CHR - plugin:  Chrome PDF Viewer (Enabled) = C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\pdf.dll
CHR - plugin:  Shockwave Flash (Enabled) = C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\gcswf32.dll
CHR - plugin:  Adobe Acrobat (Enabled) = D: \Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin:  Microsoft Office 2010 (Enabled) = C: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin:  Microsoft Office 2010 (Enabled) = C: \PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin:  Google Update (Enabled) = C: \Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension:  No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.12_0\
CHR - Extension:  No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\enjonnlehciedbcidabdglnnihcncbml\3.0.6_0\
CHR - Extension:  No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi\1.264.7_0\
CHR - Extension:  No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.22_0\
CHR - Extension:  No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\3.0.9_0\
CHR - Extension:  No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\

O1 HOSTS File:  ([2012-05-10 02: 04: 35 | 000,000,864 | ---- | M]) - C: \Windows\SysNative\drivers\etc\hosts
O1 - Hosts:  127.0.0.1 validation.sls.microsoft.com
O2: [b]64bit: [/b] - BHO:  (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C: \Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2: [b]64bit: [/b] - BHO:  (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D: \Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2: [b]64bit: [/b] - BHO:  (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D: \Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO:  (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C: \PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO:  (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO:  (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO:  (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C: \PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO:  (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3: [b]64bit: [/b] - HKLM\..\Toolbar:  (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C: \Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar:  (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run:  [AMD AVT] C: \Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run:  [avast] C: \Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\RunOnce:  [SymInstallStub] C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:  ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:  NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:   =
O8: [b]64bit: [/b] - Extra context menu item:  Add to Google Photos Screensa&ver - res: //C: \Windows\system32\GPhotos.scr/200 File not found
O8: [b]64bit: [/b] - Extra context menu item:  E&ksportuj do programu Microsoft Excel - D: \Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8: [b]64bit: [/b] - Extra context menu item:  Wyślij &do programu OneNote - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item:  Add to Google Photos Screensa&ver - C: \Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item:  E&ksportuj do programu Microsoft Excel - D: \Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item:  Wyślij &do programu OneNote - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra Button:  Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra 'Tools' menuitem :  Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra Button:  &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D: \Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra 'Tools' menuitem :  &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D: \Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13[b]64bit: [/b] - gopher Prefix:  missing
O13 - gopher Prefix:  missing
O15 - HKCU\..Trusted Domains:  4game.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains:  aeriagames.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains:  aeriagames.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Ranges:  Range1 ([https] in Trusted sites)
O16 - DPF:  {D27CDB6E-AE6D-11CF-96B8-444553540000} http: //fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters:  DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D86E966-B3E1-461C-82CC-458074808C2F}:  DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DDBC8F60-2C00-4B27-AE25-90C7E62A9F62}:  DhcpNameServer = 192.168.1.1
O18: [b]64bit: [/b] - Protocol\Handler\skype4com - No CLSID value found
O18: [b]64bit: [/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C: \PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20: [b]64bit: [/b] - HKLM Winlogon:  Shell - (explorer.exe) - C: \Windows\explorer.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - HKLM Winlogon:  UserInit - (C: \Windows\system32\userinit.exe) - C: \Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon:  Shell - (explorer.exe) - C: \Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon:  UserInit - (userinit.exe) - C: \Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21: [b]64bit: [/b] - SSODL:  WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL:  WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28: [b]64bit: [/b] - HKLM ShellExecuteHooks:  {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D: \Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks:  {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C: \PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom:  AutoRun - 1
O32 - AutoRun File - [2013-10-28 12: 34: 19 | 000,000,000 | ---D | M] - C: \Autodesk -- [ NTFS ]
O33 - MountPoints2\{224f0dc5-9de4-11e1-b097-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{224f0dc5-9de4-11e1-b097-c860000527e3}\Shell\AutoRun\command - "" = F: \Setup.exe
O33 - MountPoints2\{3cff2020-d3f3-11e1-a05f-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{3cff2020-d3f3-11e1-a05f-c860000527e3}\Shell\AutoRun\command - "" = F: \Install.exe
O33 - MountPoints2\{6552aa80-9a32-11e1-8704-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{6552aa80-9a32-11e1-8704-806e6f6e6963}\Shell\AutoRun\command - "" = E: \CheckID.exe
O33 - MountPoints2\{7a79fa2d-fc10-11e1-923b-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{7a79fa2d-fc10-11e1-923b-c860000527e3}\Shell\AutoRun\command - "" = F: \AutoRun.exe
O33 - MountPoints2\{af856866-c466-11e2-b288-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{af856866-c466-11e2-b288-c860000527e3}\Shell\AutoRun\command - "" = G: \LaunchU3.exe -a
O33 - MountPoints2\{cfcc9b63-3311-11e3-b7db-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{cfcc9b63-3311-11e3-b7db-c860000527e3}\Shell\AutoRun\command - "" = G: \iLinker.exe
O34 - HKLM BootExecute:  (autocheck autochk *)
O35: [b]64bit: [/b] - HKLM\..comfile [open] -- "%1" %*
O35: [b]64bit: [/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows:  (ServerDll=winsrv: UserServerDllInitialization,3)
O38 - SubSystems\\Windows:  (ServerDll=winsrv: ConServerDllInitialization,2)
O38 - SubSystems\\Windows:  (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015-04-09 02: 43: 38 | 000,000,000 | ---D | C] -- C: \AdwCleaner
[2015-03-31 16: 04: 14 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2015-03-31 16: 04: 10 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\LogMeIn Hamachi
[2015-03-24 23: 25: 09 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\XAMPP
[2015-03-24 23: 22: 14 | 000,000,000 | ---D | C] -- C: \xampp
[2015-03-24 14: 20: 17 | 000,136,408 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015-03-24 14: 20: 09 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015-03-24 14: 20: 07 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbamchameleon.sys
[2015-03-24 14: 20: 07 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mwac.sys
[2015-03-24 14: 20: 07 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbam.sys
[2015-03-24 14: 20: 07 | 000,000,000 | ---D | C] -- C: \ProgramData\Malwarebytes
[2015-03-24 14: 16: 26 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\trend micro
[2015-03-24 14: 16: 25 | 000,000,000 | ---D | C] -- C: \rsit
[2015-03-18 21: 27: 46 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2015-03-18 21: 26: 30 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Dropbox
[2015-03-17 09: 58: 23 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Just Aion Launcher
[2015-03-17 09: 58: 23 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Just Aion Launcher
[1 C: \Windows\*.tmp files -> C: \Windows\*.tmp -> ]
[1 C: \Users\Remik\Desktop\*.tmp files -> C: \Users\Remik\Desktop\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015-04-09 13: 57: 52 | 000,021,280 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015-04-09 13: 57: 52 | 000,021,280 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015-04-09 13: 56: 04 | 001,662,064 | ---- | M] () -- C: \Windows\SysNative\PerfStringBackup.INI
[2015-04-09 13: 56: 04 | 000,737,616 | ---- | M] () -- C: \Windows\SysNative\perfh015.dat
[2015-04-09 13: 56: 04 | 000,651,824 | ---- | M] () -- C: \Windows\SysNative\perfh009.dat
[2015-04-09 13: 56: 04 | 000,154,304 | ---- | M] () -- C: \Windows\SysNative\perfc015.dat
[2015-04-09 13: 56: 04 | 000,120,756 | ---- | M] () -- C: \Windows\SysNative\perfc009.dat
[2015-04-09 13: 50: 59 | 000,000,532 | ---- | M] () -- C: \Windows\tasks\Norton Product Installer.job
[2015-04-09 13: 37: 47 | 000,067,584 | --S- | M] () -- C: \Windows\bootstat.dat
[2015-04-09 13: 37: 31 | 2117,951,487 | -HS- | M] () -- C: \hiberfil.sys
[2015-04-09 02: 59: 20 | 000,002,194 | ---- | M] () -- C: \Users\Remik\Desktop\Norton Product Installer.lnk
[2015-04-09 00: 11: 07 | 000,000,898 | ---- | M] () -- C: \Users\Public\Desktop\Hearthstone.lnk
[2015-03-30 15: 25: 00 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) -- C: \Windows\SysNative\hamachi.sys
[2015-03-29 19: 01: 19 | 616,736,130 | ---- | M] () -- C: \Windows\MEMORY.DMP
[2015-03-24 14: 20: 35 | 000,136,408 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015-03-24 02: 36: 12 | 000,000,540 | -H-- | M] () -- C: \Windows\tasks\Norton Product InstallerIdle.job
[2015-03-17 23: 47: 10 | 000,000,770 | ---- | M] () -- C: \Users\Remik\Documents\aionmemo_fa48d296.dat
[2015-03-17 23: 42: 55 | 000,648,704 | ---- | M] () -- C: \Users\Remik\Desktop\Just Aion Launcher.exe
[2015-03-17 07: 15: 38 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mwac.sys
[2015-03-17 07: 15: 28 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbamchameleon.sys
[2015-03-17 07: 15: 24 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbam.sys
[2015-03-16 21: 24: 26 | 000,344,064 | ---- | M] () -- C: \Users\Remik\Documents\Database4.accdb
[2015-03-16 21: 21: 24 | 000,753,664 | ---- | M] () -- C: \Users\Remik\Documents\Database3.accdb
[2015-03-16 21: 19: 06 | 001,052,672 | ---- | M] () -- C: \Users\Remik\Documents\Database1.accdb
[1 C: \Windows\*.tmp files -> C: \Windows\*.tmp -> ]
[1 C: \Users\Remik\Desktop\*.tmp files -> C: \Users\Remik\Desktop\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015-04-09 02: 59: 19 | 000,002,194 | ---- | C] () -- C: \Users\Remik\Desktop\Norton Product Installer.lnk
[2015-03-24 13: 02: 06 | 000,002,224 | ---- | C] () -- C: \Users\Remik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton Product Installer.lnk
[2015-03-17 09: 58: 17 | 000,648,704 | ---- | C] () -- C: \Users\Remik\Desktop\Just Aion Launcher.exe
[2015-03-16 21: 24: 23 | 000,344,064 | ---- | C] () -- C: \Users\Remik\Documents\Database4.accdb
[2015-03-16 20: 44: 02 | 000,753,664 | ---- | C] () -- C: \Users\Remik\Documents\Database3.accdb
[2014-06-19 20: 49: 31 | 000,421,888 | ---- | C] () -- C: \Windows\SysWow64\lame_enc.dll
[2014-01-03 22: 00: 01 | 000,007,594 | ---- | C] () -- C: \Users\Remik\AppData\Local\Resmon.ResmonCfg
[2013-05-03 00: 21: 19 | 000,001,313 | ---- | C] () -- C: \Users\Remik\trelis
[2013-05-03 00: 20: 54 | 000,000,111 | ---- | C] () -- C: \Users\Remik\dle trelis
[2013-02-04 23: 22: 57 | 000,000,600 | ---- | C] () -- C: \Users\Remik\PUTTY.RND
[2012-12-28 14: 27: 26 | 000,001,024 | ---- | C] () -- C: \Users\Remik\.rnd
[2012-10-10 18: 46: 32 | 000,000,037 | -HS- | C] () -- C: \Users\Remik\AppData\Local\1754111884ee9ab5277ca00.95260103
[2012-09-18 17: 52: 50 | 060,898,540 | ---- | C] () -- C: \Users\Remik\AppData\Roaming\.minecraft.rar
[2012-09-17 16: 56: 42 | 000,000,054 | ---- | C] () -- C: \Users\Remik\AppData\Roaming\updater.cfg
[2012-05-13 03: 00: 36 | 000,003,072 | ---- | C] () -- C: \Users\Remik\AppData\Local\file__0.localstorage

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009-07-14 06: 55: 00 | 000,000,227 | RHS- | M] () -- C: \Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C: \Windows\SysNative\shell32.dll -- [2010-11-21 05: 23: 55 | 014,174,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010-11-21 05: 24: 02 | 012,872,192 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03: 40: 51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05: 24: 25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03: 41: 56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 3996 bytes -> C: \Users\Remik\Desktop\Just Aion Launcher.exe: config
@Alternate Data Stream - 231 bytes -> C: \ProgramData\TEMP: 6BE50C2B
@Alternate Data Stream - 1138 bytes -> C: \Users\Remik\Desktop\Just Aion Launcher.exe: status

< End of report >

Przy autostarcie włącza mi się tylko system operacyjny i avast, bo tego drugiego nie mogłem wyłączyć z autostartu. Zastanawiam się nad odinstalowaniem tego, i instalacją jakiegoś innego antywirusa, albo nawet żyć bez niego, tylko korzystać z komputera z głową Zacieszacz


Nie mogę wrzucić extras, bo jest za dużo znaków w poście, a jak robię drugi to i tak pojawia mi się jak w jednym, wrzucę jak ktoś mi tutaj odpisze Uśmiechnięty
(Ten post był ostatnio modyfikowany: 09.04.2015 20:27 przez Remciol.)

09.04.2015 20:24

Znajdź wszystkie posty użytkownika
LadyInBlue
Pani SuperMod

Liczba postów: 19.072
Post: #7

RE: Komputer włącza się 10-20 minut.


Daj zawartość i logu i extras na np. wklej.org i daj tu linki.

Żyj tak, aby twoim znajomym zrobiło się nudno, kiedy umrzesz.
[Obrazek: Lady_In_Blue.gif]
[Obrazek: sygnaasia.png]

Windows ❼ Forum

09.04.2015 20:30

Odwiedź stronę użytkownika Znajdź wszystkie posty użytkownika
Glover
Młodszy user systemu

Liczba postów: 83
Post: #8

RE: Komputer włącza się 10-20 minut.


Remciol
Sprawdź Moją diagnozę. Jeżeli dysk hdd jest jako ESP - czyli sata przełącza się w napęd "wyjmowalny", który można odłączyć "w traju" może być powodem czarnego ekranu podczas logowania, co skutkuje lagiem od kilku, do kilkunastu minut.

09.04.2015 21:52

Znajdź wszystkie posty użytkownika
Remciol
Nowy
Liczba postów: 7
Post: #9

RE: Komputer włącza się 10-20 minut.


Kod:
OTL Extras logfile created on:  2015-04-09 21: 11: 21 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = D: \Pobieranie z Chrome
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale:  00000415 | Country:  Polska | Language:  PLK | Date Format:  yyyy-MM-dd

7,96 Gb Total Physical Memory | 3,84 Gb Available Physical Memory | 48,27% Memory free
15,92 Gb Paging File | 10,91 Gb Available in Paging File | 68,49% Paging File free
Paging file location(s):  ?: \pagefile.sys [binary data]

%SystemDrive% = C:  | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C:  | 68,26 Gb Total Space | 7,67 Gb Free Space | 11,24% Space Free | Partition Type:  NTFS
Drive D:  | 397,40 Gb Total Space | 194,31 Gb Free Space | 48,89% Space Free | Partition Type:  NTFS

Computer Name:  AMD-DRAGON | User Name:  Remik | Logged in as Administrator.
Boot Mode:  Normal | Scan Mode:  Current user | Include 64bit Scans
Company Name Whitelist:  Off | Skip Microsoft Files:  Off | No Company Name Whitelist:  On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C: \Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C: \Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error:  Key error. File not found

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error:  Key error.
htmlfile [edit] -- Reg Error:  Key error.
htmlfile [print] -- "C: \Windows\system32\rundll32.exe" "C: \Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C: \Windows\System32\rundll32.exe" "C: \Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C: \Windows\System32\rundll32.exe" "C: \Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error:  Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error:  Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ChomikBox.Upload] -- "C: \Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( )
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error:  Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error:  Key error.
htmlfile [edit] -- Reg Error:  Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error:  Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error:  Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ChomikBox.Upload] -- "C: \Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( )
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error:  Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit: [/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainPr​ofile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Standard​Profile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicPr​ofile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Firewall​Rules]

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Firewall​Rules]
"{6249B381-FA82-4508-98A4-190C59A5D766}" = protocol=6 | dir=in | app=d: \gry\steam\steam.exe |
"{CE856633-4961-4AFA-8DC0-6D80164A9351}" = protocol=17 | dir=in | app=d: \gry\steam\steam.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit:  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0CC4F67D-D41D-8C1A-C605-39154DDEAC63}" = AMD Fuel
"{119B2F5A-2A06-DB96-FF28-992EC2A10BDF}" = AMD Accelerated Video Transcoding
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{2180B33F-3225-423E-BBC1-7798CFD3CD1F}" = Microsoft SQL Server 2008 R2 Native Client
"{2E8D6204-D656-8355-1ED3-2988AC52EB0F}" = ccc-utility64
"{3ABFAF33-D6EE-9348-CE96-AF51E9D6D2FF}" = AMD Drag and Drop Transcoding
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5783F2D7-B001-0000-0102-0060B0CE6BBA}" = AutoCAD 2013 – Polski (Polish)
"{5783F2D7-B001-0415-1102-0060B0CE6BBA}" = AutoCAD 2013 Language Pack – Polski (Polish)
"{5783F2D7-B001-0415-2102-0060B0CE6BBA}" = AutoCAD 2013 – Polski (Polish)
"{5783F2D7-B002-0415-0102-0060B0CE6BBA}" = AutoCAD Map 3D 2013 – Polski (Polish)
"{5783F2D7-B002-0415-1102-0060B0CE6BBA}" = AutoCAD Map 3D 2013 Language Pack
"{5783F2D7-B002-0415-2102-0060B0CE6BBA}" = AutoCAD Map 3D 2013
"{5831C6D6-309D-DBB5-14F7-FEE57086CEE7}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{63CE6C32-1EB3-4C51-89FC-9FD96A661A9C}" = AMD Media Foundation Decoders
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0415-1000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010
"{90140000-0016-0415-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010
"{90140000-0018-0415-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010
"{90140000-0019-0415-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010
"{90140000-001A-0415-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010
"{90140000-001B-0415-1000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0415-1000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010
"{90140000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2010
"{90140000-0044-0415-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010
"{90140000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010
"{90140000-00A1-0415-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010
"{90140000-00BA-0415-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}" = Apple Mobile Device Support
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{EE5F74BC-5CD5-4EF2-86BA-81E6CF46A18F}" = Autodesk Sync
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AutoCAD 2013 – Polski (Polish)" = AutoCAD 2013 – Polski (Polish)
"AutoCAD Map 3D 2013 – Polski (Polish)" = AutoCAD Map 3D 2013 – Polski (Polish)
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR 4.11 (64-bitowy)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}" = Windows Live UX Platform
"{03D4C700-2BFE-43E0-A0B4-9512B43C5B9F}" = Catalyst Control Center - Branding
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07AAB66E-4718-422D-9218-4AFB3C922A71}" = Photo Gallery
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{117EBEEB-5DB0-43C8-9FD6-DD583DB152DD}" = Autodesk Material Library 2013
"{19D614EB-D62A-AEE7-2391-E74126601D59}" = CCC Help Italian
"{1C373820-B9C8-0F7F-8F84-FC1B76A85F27}" = CCC Help Portuguese
"{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}" = Windows Live Photo Common
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{2D35BC33-7D08-D529-DF91-8A15FBF2600E}" = CCC Help Polish
"{337788D1-43D1-9A0F-9787-DD00DB512D41}" = Catalyst Control Center Localization All
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3EEF6B1E-38AA-4F22-BA70-30A73BB06AAE}" = Photo Common
"{41C61308-6CFD-4D54-AB6A-7136ED08A18E}" = Windows Live Communications Platform
"{4725833D-4325-5C34-57D4-1FE23E5AE578}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B271648-43CB-DD31-FF24-E7B06D3EE72A}" = Catalyst Control Center InstallProxy
"{4DC37F33-7AEC-A4CB-56B1-69A402828763}" = CCC Help Japanese
"{4F7B7598-88EA-4442-A54E-65EADCF06D97}" = ChomikBox
"{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5710DAC2-8F2A-503C-CFC2-A973ADE0EA4C}" = CCC Help Czech
"{5AD315BE-2E3E-446D-8FF9-75A73445DC47}" = Bentley MicroStation V8i 08.11.05.17
"{5C763682-4C40-86DA-9C46-31924D7D2C34}" = CCC Help Thai
"{606E12B9-641F-4644-A22A-FF38AE980AFD}" = Autodesk Material Library Base Resolution Image Library 2013
"{60E5022D-FA4B-C6A2-1E80-B46EC39096F3}" = CCC Help Chinese Traditional
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{60F34FDF-267C-408F-290E-EC90D841C8CB}" = CCC Help German
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{62F029AB-85F2-0000-866A-9FC0DD99DDBC}" = Autodesk Content Service
"{62F029AB-85F2-0001-866A-9FC0DD99DDBC}" = Autodesk Content Service Language Pack
"{659CB81C-B54E-4DF1-B618-F35777393A54}" = Windows Live Installer
"{660787DD-68B3-4E67-9073-4A66DD7AD193}" = ASUS VGA Driver
"{66B79AE1-C6E2-B958-689C-D0812DE86BAB}" = CCC Help Greek
"{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}" = AION Free-To-Play
"{6B39BE0F-0F5E-A8FA-33E4-8481AE39D96C}" = CCC Help Russian
"{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1" = Gyazo 1.2.1
"{70CB6C40-8DF1-11E1-BDCF-F04DA23A5C58}" = MSVCRT Redists
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{77655DF6-A143-4A25-A5F8-127C8CE63EDA}" = Galeria fotografii
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.18
"{80EE9168-BB59-4F87-BF1A-57C137EAF714}" = LogMeIn Hamachi
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{887868A2-D6DE-3255-AA92-AA0B5A59B874}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8E19F2AF-7145-51DE-E395-7729A9374973}" = Catalyst Control Center Graphics Previews Common
"{8FFD72FC-4FFA-472D-9F76-AEC85F602F9D}" = Podstawowe programy Windows Live
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{91CB5B8B-4EC8-DBA1-A88D-99FD480567B0}" = CCC Help English
"{924FBAC4-60D2-7981-3C3E-979DF9CBB346}" = CCC Help Finnish
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1" = Gameforge Live 2.0.6
"{9DC939DC-B7A4-D0E2-C582-A442DF1B3EBE}" = CCC Help Spanish
"{A13D16C5-38A9-4D96-9647-59FCCAB12A85}" = Visual Basic for Applications (R) Core - English
"{A1BD938B-F006-6E6D-70B2-47E1DD56F7DE}" = CCC Help Swedish
"{A1C962E2-2426-49C6-A38B-9A07E40D607C}" = Microsoft Games for Windows - LIVE
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = blueconnect
"{AC57543E-EC54-4AB7-A18C-4B04BB1CF09A}" = Windows Live UX Platform Language Pack
"{AC76BA86-7AD7-1045-7B44-A95000000001}" = Adobe Reader 9.5.5 - Polish
"{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
"{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}" = Windows Live PIMT Platform
"{B5373BA3-BAD7-4EAC-A9D2-B66B41B82C57}" = OpenOffice 4.1.1
"{BABF7852-C2DD-6A8A-9956-101720C715C7}" = CCC Help Turkish
"{BB7C2A56-9706-43B8-5A8C-210AF5816106}" = CCC Help French
"{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}" = Windows Live SOXE
"{CFC2CB60-5654-05A7-4D30-C661800A3A92}" = CCC Help Korean
"{D04CE005-D1D2-80F3-84C8-B3524FCD39C3}" = CCC Help Norwegian
"{D1893000-EA77-493C-8DDD-E262436E959B}" = Windows Live SOXE Definitions
"{D544AE4C-4152-225B-A897-6756C8986B14}" = AMD VISION Engine Control Center
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D81E9069-3CCC-4405-3751-71E4AFEACC52}" = CCC Help Hungarian
"{DAE8CC57-EBF5-4D46-8572-9A0C769D6F16}" = Movie Maker
"{DD67BE4B-7E62-4215-AFA3-F123A800A389}" = Movie Maker
"{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}" = Curse
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E68EADA6-63A4-F6D3-FE12-968B879F7AD6}" = Adobe Download Assistant
"{E93FF166-DF14-2537-8FB4-96BB5810A96C}" = CCC Help Danish
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA9827E1-8A8E-C176-4923-0840A67ED4DE}" = CCC Help Dutch
"{FB97C283-1F3C-42D4-AE01-ADC1DC12F774}" = Visual Basic for Applications (R) Core
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.1
"Autodesk Content Service" = Autodesk Content Service
"avast" = avast! Free Antivirus
"AVI ReComp" = AVI ReComp 1.5.5
"Battle.net" = Battle.net
"C-GEO V8_is1" = C-GEO 8.0
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Cool Edit Pro 2.1" = Cool Edit Pro 2.1
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dll-Files.com Fixer_is1" = Dll-Files.com Fixer wersja 3.0.81.2643
"Google Chrome" = Google Chrome
"Hearthstone" = Hearthstone
"InstallShield_{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}" = AION Free-To-Play
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"LogMeIn Hamachi" = LogMeIn Hamachi
"LOLReplay" = LOLReplay
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 2.1.4.1018
"Mozilla Firefox 18.0.1 (x86 pl)" = Mozilla Firefox 18.0.1 (x86 pl)
"NCLauncher_GameForge" = NC Launcher (GameForge)
"Picasa 3" = Picasa 3
"Steam App 202990" = Call of Duty:  Black Ops II - Multiplayer
"Steam App 205790" = Dota 2 Test
"Steam App 212910" = Call of Duty:  Black Ops II - Zombies
"Steam App 218620" = PAYDAY 2
"Steam App 55230" = Saints Row:  The Third
"Steam App 570" = Dota 2
"Steam App 730" = Counter-Strike:  Global Offensive
"Tibia Preview_is1" = Tibia Preview
"Tibia_is1" = Tibia
"TMIPC" = Tibia MULTI-ip changer
"WinLiveSuite" = Podstawowe programy Windows Live
"xampp" = XAMPP

[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Dropbox" = Dropbox

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2015-04-07 08: 43: 55 | Computer Name = AMD-Dragon | Source = Steam Client Service | ID = 1
Description = Error:  Failed to add firewall exception for D: \Gry\Steam\steam.exe

Error - 2015-04-07 14: 28: 00 | Computer Name = AMD-Dragon | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd:  Fuel.Service.exe, wersja:  1.0.0.0,
sygnatura czasowa:  0x4f7e4d8c  Nazwa modułu powodującego błąd:  Device.dll, wersja:
4.1.0.0, sygnatura czasowa:  0x4f55e10b  Kod wyjątku:  0xc0000005  Przesunięcie błędu:
0x00000000000033c1  Identyfikator procesu powodującego błąd:  0x330  Godzina uruchomienia
aplikacji powodującej błąd:  0x01d0712d37195c22  Ścieżka aplikacji powodującej błąd:
C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe  Ścieżka modułu powodującego
błąd:  C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll  Identyfikator raportu:
d1868f0b-dd53-11e4-a367-c860000527e3

Error - 2015-04-07 16: 04: 32 | Computer Name = AMD-Dragon | Source = WinMgmt | ID = 10
Description =

Error - 2015-04-07 16: 14: 15 | Computer Name = AMD-Dragon | Source = Steam Client Service | ID = 1
Description = Error:  Failed to add firewall exception for D: \Gry\Steam\steam.exe

Error - 2015-04-07 16: 29: 30 | Computer Name = AMD-Dragon | Source = Steam Client Service | ID = 1
Description = Error:  Failed to add firewall exception for D: \Gry\Steam\steam.exe

Error - 2015-04-07 22: 16: 30 | Computer Name = AMD-Dragon | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd:  Fuel.Service.exe, wersja:  1.0.0.0,
sygnatura czasowa:  0x4f7e4d8c  Nazwa modułu powodującego błąd:  Device.dll, wersja:
4.1.0.0, sygnatura czasowa:  0x4f55e10b  Kod wyjątku:  0xc0000005  Przesunięcie błędu:
0x00000000000033c1  Identyfikator procesu powodującego błąd:  0x7f4  Godzina uruchomienia
aplikacji powodującej błąd:  0x01d0716df0535829  Ścieżka aplikacji powodującej błąd:
C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe  Ścieżka modułu powodującego
błąd:  C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll  Identyfikator raportu:
4453653e-dd95-11e4-88c9-c860000527e3

Error - 2015-04-08 05: 54: 41 | Computer Name = AMD-Dragon | Source = WinMgmt | ID = 10
Description =

Error - 2015-04-08 20: 58: 20 | Computer Name = AMD-Dragon | Source = WinMgmt | ID = 10
Description =

Error - 2015-04-08 21: 05: 59 | Computer Name = AMD-Dragon | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd:  Fuel.Service.exe, wersja:  1.0.0.0,
sygnatura czasowa:  0x4f7e4d8c  Nazwa modułu powodującego błąd:  Device.dll, wersja:
4.1.0.0, sygnatura czasowa:  0x4f55e10b  Kod wyjątku:  0xc0000005  Przesunięcie błędu:
0x00000000000033c1  Identyfikator procesu powodującego błąd:  0x7f0  Godzina uruchomienia
aplikacji powodującej błąd:  0x01d0726027f32072  Ścieżka aplikacji powodującej błąd:
C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe  Ścieżka modułu powodującego
błąd:  C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll  Identyfikator raportu:
94eeee41-de54-11e4-875f-c860000527e3

Error - 2015-04-09 07: 49: 53 | Computer Name = AMD-Dragon | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2015-04-08 20: 57: 22 | Computer Name = AMD-Dragon | Source = Microsoft-Windows-Eventlog | ID = 23
Description = Usługa rejestrowania zdarzeń napotkała błąd (zasób=1117) podczas inicjowania
zasobów rejestrowana dla kanału Microsoft-Windows-GroupPolicy/Operational.

Error - 2015-04-08 20: 57: 37 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7009
Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się
z usługą Apple Mobile Device.

Error - 2015-04-08 20: 57: 37 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi Apple Mobile Device z powodu następującego
błędu:    %%1053

Error - 2015-04-08 20: 59: 49 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7024
Description = Usługa Usługa nasłuchująca grup domowych zakończyła działanie; wystąpił
specyficzny dla niej błąd %%-2147023143.

Error - 2015-04-08 21: 05: 59 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7034
Description = Usługa AMD FUEL Service niespodziewanie zakończyła pracę. Wystąpiło
to razy:  1.

Error - 2015-04-09 07: 39: 16 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7022
Description = Usługa Autokonfiguracja sieci WLAN zawiesiła się podczas uruchamiania.

Error - 2015-04-09 07: 48: 54 | Computer Name = AMD-Dragon | Source = Microsoft-Windows-Eventlog | ID = 23
Description = Usługa rejestrowania zdarzeń napotkała błąd (zasób=1117) podczas inicjowania
zasobów rejestrowana dla kanału Microsoft-Windows-GroupPolicy/Operational.

Error - 2015-04-09 07: 49: 08 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7009
Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się
z usługą Apple Mobile Device.

Error - 2015-04-09 07: 49: 08 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi Apple Mobile Device z powodu następującego
błędu:    %%1053

Error - 2015-04-09 07: 51: 38 | Computer Name = AMD-Dragon | Source = Service Control Manager | ID = 7024
Description = Usługa Usługa nasłuchująca grup domowych zakończyła działanie; wystąpił
specyficzny dla niej błąd %%-2147023143.


< End of report >

LadyInBlue, mózg mi się na chwilę wyłączył i zapomniałem że tak też można Zacieszacz

Glover, jest gdzies jakas instrukcja jak to sprawdzić w biosie? W sumie nie znam się aż tak na komputerach, a nie chcę czegoś zepsuć Uśmiechnięty

09.04.2015 21:55

Znajdź wszystkie posty użytkownika
LadyInBlue
Pani SuperMod

Liczba postów: 19.072
Post: #10

RE: Komputer włącza się 10-20 minut.


To może dasz linki do tych logów? Bo w [code] potrafi ścinać zawartość? Zadowolony

Żyj tak, aby twoim znajomym zrobiło się nudno, kiedy umrzesz.
[Obrazek: Lady_In_Blue.gif]
[Obrazek: sygnaasia.png]

Windows ❼ Forum

09.04.2015 21:58

Odwiedź stronę użytkownika Znajdź wszystkie posty użytkownika
Glover
Młodszy user systemu

Liczba postów: 83
Post: #11

RE: Komputer włącza się 10-20 minut.


Po prostu wejdź do biosu i szukaj ustawień od Sata. Powinno być blisko tego Sata as ESP jeśli jest "enabled" to daj na disabled"
To wszystko.
Jeśli ustawienia sata jako AHCI, a ESP wyłączone, to masz dobrze ustawione, to wtedy trzeba szukać gdzie indziej usterki.

09.04.2015 22:01

Znajdź wszystkie posty użytkownika
Remciol
Nowy
Liczba postów: 7
Post: #12

RE: Komputer włącza się 10-20 minut.


LadyInBlue

http://wklej.org/id/1684390/

Dobra, zrobię to jak będę kompa wyłączał za kilka godzin i jutro wrzucę log Uśmiechnięty

09.04.2015 23:05

Znajdź wszystkie posty użytkownika
Illidan
Ekspert

Liczba postów: 1.024
Post: #13

RE: Komputer włącza się 10-20 minut.


Pokaż Screen z "CrystalDiskInfo" i uruchom "OTL",wklej do niego w pole "Własne opcje skanowania/Skrypt":
Cytat::OTL
@Alternate Data Stream - 3996 bytes -> C: \Users\Remik\Desktop\Just Aion Launcher.exe: config
@Alternate Data Stream - 231 bytes -> C: \ProgramData\TEMP: 6BE50C2B
@Alternate Data Stream - 1138 bytes -> C: \Users\Remik\Desktop\Just Aion Launcher.exe: status

:Commands
[emptytemp]
Wykonaj skrypt i pokaż raport z usuwania po restarcie jaki otrzymasz.

Uaktualnij jeszcze sterowniki,bo system raportuje problemy,prawdopodobnie z sterownikiem do karty graficznej:
http://forum.komputerswiat.pl/topic/2058...imdrivers/


(Ten post był ostatnio modyfikowany: 09.04.2015 23:36 przez Illidan.)

09.04.2015 23:32

Znajdź wszystkie posty użytkownika
thermalfake
Ostatni Mohikanin

Liczba postów: 13.580
Post: #14

RE: Komputer włącza się 10-20 minut.


Cytat:Glover, jest gdzies jakas instrukcja jak to sprawdzić w biosie? W sumie nie znam się aż tak na komputerach, a nie chcę czegoś zepsuć

Podałeś bardzo ubogo specyfikację sprzętu a bez modelu płyty głównej (softu do identyfikacji jest multum albo otworzyć bok obudowy i spojrzeć) nikt wróżyć nie będzie. Poza tym nie każdy bios/uefi posiada taką opcję.
Prostym sposobem na sprawdzenie co się dzieje jest odpalenie systemu w trybie awaryjnym - ładowane są tylko podstawowe usługi systemowe, bez sterowników i usług oprogramowania które zainstalował użytkownik. Jeśli załaduje się szybciutko to wiadomo, że to nie jest żadna usterka/konfiguracja sprzętowa.

[Obrazek: 2089620800_1406976151.png]

W zamian za pomoc oczekuję poprawnej pisowni. Stop niechlujstwu.
Jak mądrze zadawać pytania? - przejrzyj poradnik na forum.
Nie udzielam porad via PW.
(Ten post był ostatnio modyfikowany: 10.04.2015 00:51 przez thermalfake.)

10.04.2015 00:51

Znajdź wszystkie posty użytkownika
Remciol
Nowy
Liczba postów: 7
Post: #15

RE: Komputer włącza się 10-20 minut.


Z OTL:

Kod:
All processes killed
========== OTL ==========
Unable to delete ADS C:  \Users\Remik\Desktop\Just Aion Launcher.exe:  config .
Unable to delete ADS C:  \ProgramData\TEMP:  6BE50C2B .
Unable to delete ADS C:  \Users\Remik\Desktop\Just Aion Launcher.exe:  status .
========== COMMANDS ==========

[EMPTYTEMP]

User:  All Users

User:  Default
->Temp folder emptied:  0 bytes
->Temporary Internet Files folder emptied:  0 bytes
->Flash cache emptied:  56475 bytes

User:  Default User
->Temp folder emptied:  0 bytes
->Temporary Internet Files folder emptied:  0 bytes
->Flash cache emptied:  0 bytes

User:  Public

User:  Remik
->Temp folder emptied:  103216042 bytes
->Temporary Internet Files folder emptied:  46420139 bytes
->Java cache emptied:  13641084 bytes
->FireFox cache emptied:  1623130 bytes
->Google Chrome cache emptied:  259359762 bytes
->Flash cache emptied:  64598 bytes

%systemdrive% .tmp files removed:  0 bytes
%systemroot% .tmp files removed:  200704 bytes
%systemroot%\System32 .tmp files removed:  0 bytes
%systemroot%\System32 (64bit) .tmp files removed:  0 bytes
%systemroot%\System32\drivers .tmp files removed:  0 bytes
Windows Temp folder emptied:  104618456 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied:  18231514 bytes
RecycleBin emptied:  0 bytes

Total Files Cleaned = 522,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 04102015_023142

Files\Folders moved on Reboot...
C: \Users\Remik\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C: \Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Screen z crystaldiskinfo:
RE: Komputer włącza się 10-20 minut.

10.04.2015 12:31

Znajdź wszystkie posty użytkownika
LadyInBlue
Pani SuperMod

Liczba postów: 19.072
Post: #16

RE: Komputer włącza się 10-20 minut.


Po tym screenie widać, że dysk zaczyna się sypać. Zrób profilaktycznie back up ważnych danych.

Żyj tak, aby twoim znajomym zrobiło się nudno, kiedy umrzesz.
[Obrazek: Lady_In_Blue.gif]
[Obrazek: sygnaasia.png]

Windows ❼ Forum

10.04.2015 12:40

Odwiedź stronę użytkownika Znajdź wszystkie posty użytkownika
thermalfake
Ostatni Mohikanin

Liczba postów: 13.580
Post: #17

RE: Komputer włącza się 10-20 minut.


To nie jest pełna diagnostyka dysku i ponadto stwierdzenie iż zaczyna się sypać jest na razie niczym nieuzasadnione.
Nie wiadomo od kiedy jest ten jeden jedyny niestabilny i nienaprawialny sektor - nie będzie przeniesiona jego zawartość na pulę rezerwową bo nic się nie da z tego sektora odczytać. Widziałem realnie sporo dysków, ba nawet sam miałem jedną sztukę samsunga (przepracowane około 30k godzin - kilka lat bezustannej pracy) który miał taki babol i zupełnie nic z dyskiem/dyskami się nie działo. Dlatego nie ma od razu co straszyć. Trzeba tylko powziąć środki ostrożności i od czasu do czasu sprawdzać smart i obserwować jego wyniki. Można to zrobić instalując jedną z aplikacji do monitoringu smart'a, część płyt głównych potrafi podczas procedury post wyświetlić informację o problemach ze smart'em bądź też sama siódemka ma mechanizm monitoringu stanu dysku i wyświetla stosowne monity o wykonanie kopii.
Ze smart'a czyli technologii która aproksymuje ryzyko na podstawie zebranych informacji przyszłą awarię nie da się nigdy jednoznacznie określić czy coś się sypnie i kiedy. Warto zrobić kopię ponieważ dysk już przepracował ponad 10k godzin.

[Obrazek: 2089620800_1406976151.png]

W zamian za pomoc oczekuję poprawnej pisowni. Stop niechlujstwu.
Jak mądrze zadawać pytania? - przejrzyj poradnik na forum.
Nie udzielam porad via PW.
(Ten post był ostatnio modyfikowany: 10.04.2015 22:00 przez thermalfake.)

10.04.2015 21:59

Znajdź wszystkie posty użytkownika
Illidan
Ekspert

Liczba postów: 1.024
Post: #18

RE: Komputer włącza się 10-20 minut.


Usuwanie wykonane, możesz kontrolnie nowy log zrobić. Co do dysku to nie jest dobrze. Ja ze swojegomdoświadczeniampowiem że dyski tylko z jednym barem powodować potrafią problemy, jak i odwrotnie, czasem nic nie wskazuje w danych na uszkodzenie a dysk chodzi fatalnie, nawet czasem słychać. SMART jest skuteczne w ocenie w 60%,także moim zdaniem stwierdzenie że dysk zaczyna się sypać jest bardzo trafne. Także... Możesz jak na razie chcesz dokonać naprawy w MHDD, zerwanie i Remap, może to coś pomoże, ale wiąże się to ze stratą danych na dysku. Także wykonanie kopii jak najbardziej zalecane jak i w ogóle ze względu na fakt że zyskiem coś się zaczyna dziać niedobrego.

Aaaa, no i nowe logi z FRST zrób.


(Ten post był ostatnio modyfikowany: 11.04.2015 10:29 przez Illidan.)

11.04.2015 10:20

Znajdź wszystkie posty użytkownika
thermalfake
Ostatni Mohikanin

Liczba postów: 13.580
Post: #19

RE: Komputer włącza się 10-20 minut.


Nie ma zrobionego testu odczytu uruchomionego z livecd i nie wiadomo na jego bazie czy są jakiekolwiek chwilowe drastyczne spadki transferów więc na jakiej nieudowodnionej podstawie tylko po samym jednym nie do odratowania sektorze i to nie wiadomo od kiedy istniejącym już siejecie czarne chmury ? Ba, nie ma nawet zrobionego skanu powierzchni talerzy ze statystyką czasów dostępu. Była prośba prosta jak drut uruchomienia trybu awaryjnego i sprawdzeniu czy problem jest ten a jak nie to w msconfig włączyć uruchamianie diagnostyczne i porównać to sobie.

[Obrazek: 2089620800_1406976151.png]

W zamian za pomoc oczekuję poprawnej pisowni. Stop niechlujstwu.
Jak mądrze zadawać pytania? - przejrzyj poradnik na forum.
Nie udzielam porad via PW.
(Ten post był ostatnio modyfikowany: 11.04.2015 12:15 przez thermalfake.)

11.04.2015 12:14

Znajdź wszystkie posty użytkownika
Illidan
Ekspert

Liczba postów: 1.024
Post: #20

RE: Komputer włącza się 10-20 minut.


Nie chce się z tobą sprzeczać w olejnym temacie,ale...zresztą napisałem swoje ,ty swoje i nie wiem po co dalej rozwijasz ten wątek.Autor tematu wie co robić,jak by po prostu najlepszą diagnostykę wykonał klonując system na zdrowy dysk i podmieniając go,bez zbędnych pierdół które mogą zabrać niepotrzebnie czas i nerwy.Tak jak pisałem bez innego dysku użył bym "MHDD" i potem reinstalował system czy przywrócił z backupu.
Jeśli chodzi o system to jest praktycznie czysty,nie ma tam się czego doszukiwać,ale chcę raz jeszcze dla pewności nowe logi zobaczyć z FRST,które są pełniejsze i pokazują dokładniej błędy systemu.Co do diagnostyki twojej,to ja bym sobie jeszcze tak zrobił log z "Monitora niezawodności" i sprawdził,czyli:
Panel Sterowania >>System i zabezpieczenia >> Centrum akcji >> monitor niezawodności(na dole okna).
Wyeksportuj ten log nam do wglądu "Zapisz historię niezawodności" i otrzymany plik "xml" pokaż na forum jak da się go tu wgrać,lub wgraj gdzieś w na serwer w sieci a tu podaj linka.


12.04.2015 00:01

Znajdź wszystkie posty użytkownika
Wątek zamknięty

Podobne wątki
Wątek: Autor Odpowiedzi: Wyświetleń: Ostatni post
Windows 7 - Menadżer Zadań nie włącza się. SpeedSeconds 0 947 18.08.2016 13:12
Ostatni post: SpeedSeconds
Rozwiązany Win7 uruchamia się 7 minut pomocy GregPl 4 2.728 15.05.2016 09:50
Ostatni post: GregPl
problem,przy włączeniu blue screen i komputer się włącza od nowa(Windows 7) Kowalski19 3 2.121 22.07.2015 15:51
Ostatni post: thermalfake
Zatrzymanie systemu zaraz po starcie na około 15 minut psg 2 1.444 22.07.2015 15:33
Ostatni post: Bartixxx
Zatrzymanie (zamrożenie) systemu zaraz po starcie na około 10 minut psg 4 1.677 07.05.2015 17:28
Ostatni post: psg
Asus N71JQ włącza się szybciej, gdy działa tylko na baterii. QooCis 2 1.593 24.02.2015 19:57
Ostatni post: QooCis
« Starszy wątek | Nowszy wątek »

Temat został oceniony na 0 w skali 1-5 gwiazdek.
Zebrano 1 głosów.

Najszybszy światłowód w Polsce dostarczany przez operatora Airmax na terenie południowo zachodniej Polski, opinie klientów https://opiniuj24.comsolution for cleaning dpf
Regulamin for | Polityka Prywatności | Oznacz wszystkie działy jako przeczytane | Ekipa forum | Statystyki | Wersja mobilna | Użytkownicy | Wersja Lo-Fi | Mapa strony | RSS