Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-09-2014 Ran by Okurwiencze at 2014-10-01 11:54:17 Running from D:\Instalki nowe\FRST Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Aktualizacje NVIDIA 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden ASUS Power4Gear Hybrid (HKLM\...\{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}) (Version: 1.1.24 - ASUS) avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software) Detektor Winampa (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden ipla 2.8 (HKLM-x32\...\ipla) (Version: 2.8 - Redefine Sp z o.o.) Java 7 Update 67 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417067FF}) (Version: 7.0.670 - Oracle) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837B34E3-7C30-493C-8F6A-2B0F04E2912C}) (Version: - ) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Minecraft1.7.8 (HKLM-x32\...\Minecraft1.7.8) (Version: - ) Mozilla Firefox 29.0.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 pl)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Oprogramowanie systemu PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Sterownik graficzny 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation) NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA) Panel sterowania NVIDIA 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden PDF Creator (HKLM\...\PDF Creator) (Version: - ) SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - ) Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - ) SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - ) SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - ) SavingsbullFilter (Version: 1.0.0.0 - SavingsBull Filter) Hidden <==== ATTENTION SharkManCoupon (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - SharkManCoupon) <==== ATTENTION SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden Skype™ 6.3 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: - ) SmartFTP Client (HKLM\...\{D07D3212-B67A-45EE-A5B7-A5942CC2785B}) (Version: 5.0.1351.0 - SmartSoft Ltd.) SmartSaver+ 8 (HKLM-x32\...\SmartSaver+ 8) (Version: 1.34.4.10 - smart-saverplus) <==== ATTENTION SRS Premium Sound Control Panel (HKLM\...\{D42F84B6-3709-4A50-8502-6719D16AE6C8}) (Version: 1.07.0300 - Ihr Firmenname) Update for PDF Creator (HKCU\...\DSite) (Version: - ) <==== ATTENTION Update for Zip Extractor (HKCU\...\Digital Sites) (Version: - Update for Zip Extractor) <==== ATTENTION Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 19-08-2014 08:35:19 Windows-Sicherung 19-08-2014 09:25:05 Windows Update 24-08-2014 19:23:38 Windows-Sicherung 30-08-2014 20:07:19 Windows Update 01-09-2014 10:17:48 Windows-Sicherung 13-09-2014 12:43:37 Windows Update 19-09-2014 11:31:25 Windows Update 21-09-2014 20:10:55 avast! antivirus system restore point 29-09-2014 10:53:12 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2014-01-15 15:39 - 00000864 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 validation.sls.microsoft.com ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {2BADBFC0-4DA5-4DCD-9D2E-F0E07BA5BB87} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-09-21] (AVAST Software) Task: {3AA119B0-E79F-473A-A4F6-566822487BD2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated) Task: {6DAABE86-7052-4270-967C-42ED18BAC781} - System32\Tasks\P4G Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation) Task: {788DE199-3670-48FB-BA98-15D9E2A4F2AB} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2009-09-08] (ATK) Task: {7D4E147D-AF76-452C-B228-D69761840A99} - System32\Tasks\P4GIntlCtrl => C:\Program Files\P4G\IntlCtrl.exe [2009-08-11] (TODO: ) Task: {8CA72D19-DCC4-4041-99F1-5493B1B7062A} - System32\Tasks\{C5A01B16-0726-44DD-9255-BC3343DFCD79} => c:\program files (x86)\opera\opera.exe [2014-04-25] (Opera Software) Task: {92E4AFD4-CF69-4674-B65D-A9C36033A5B8} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-16 14:42 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-01-26 13:05 - 2011-10-04 23:43 - 00087552 _____ () C:\Windows\System32\custmon64i.dll 2009-09-10 17:42 - 2009-09-10 17:42 - 00041984 _____ () C:\Program Files\P4G\DevMng.dll 2009-09-11 13:27 - 2009-09-11 13:27 - 00029184 _____ () C:\Program Files\P4G\OvrClk.dll 2014-01-17 00:49 - 2007-08-03 13:24 - 00125496 _____ () C:\Program Files (x86)\ASUS\NB Probe\SPM\spmgr.exe 2014-09-21 22:13 - 2014-09-21 22:13 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 2014-10-01 10:31 - 2014-10-01 10:31 - 02867712 _____ () C:\Program Files\AVAST Software\Avast\defs\14100100\algo.dll 2014-01-17 00:49 - 2007-09-14 11:00 - 00147456 _____ () C:\Program Files (x86)\ASUS\NB Probe\SPM\spdiskex.dll 2014-01-17 00:49 - 2003-11-28 03:11 - 00135168 _____ () C:\Program Files (x86)\ASUS\NB Probe\SPM\spos.dll 2014-01-17 00:49 - 2005-08-29 16:24 - 00081920 _____ () C:\Program Files (x86)\ASUS\NB Probe\SPM\spnbacpi.dll 2014-01-17 00:49 - 2003-09-09 17:08 - 00049152 _____ () C:\Program Files (x86)\ASUS\NB Probe\SPM\spdmi.dll 2014-01-17 00:49 - 2006-04-04 11:24 - 00036864 _____ () C:\Program Files (x86)\ASUS\NB Probe\SPM\ghadmi.dll 2014-01-17 00:49 - 2005-04-07 20:25 - 00077824 _____ () C:\Program Files (x86)\ASUS\NB Probe\SPM\spmemory.dll 2014-09-21 22:13 - 2014-09-21 22:13 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-09-09 23:25 - 2014-09-09 23:25 - 16825520 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-3825525903-336485760-839643112-500 - Administrator - Disabled) Gast (S-1-5-21-3825525903-336485760-839643112-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3825525903-336485760-839643112-1002 - Limited - Enabled) Okurwiencze (S-1-5-21-3825525903-336485760-839643112-1000 - Administrator - Enabled) => C:\Users\Okurwiencze ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/01/2014 11:43:20 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/01/2014 11:42:06 AM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005. Error: (10/01/2014 10:42:34 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 Error: (10/01/2014 10:02:47 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/01/2014 09:56:49 AM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005. Error: (09/30/2014 11:28:22 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 Error: (09/30/2014 10:28:21 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 Error: (09/30/2014 09:28:21 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 Error: (09/30/2014 08:28:20 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 Error: (09/30/2014 07:28:20 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 System errors: ============= Error: (10/01/2014 11:45:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Google Update-Dienst (gupdate) z powodu następującego błędu: %%2 Error: (10/01/2014 11:19:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Update Surftastic z powodu następującego błędu: %%3 Error: (10/01/2014 11:19:42 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Software Protection niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Neustart des Diensts. Error: (10/01/2014 11:19:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Neustart des Diensts. Error: (10/01/2014 11:19:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Druckwarteschlange niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 60000 milisekund zostanie podjęta następująca czynność korekcyjna: Neustart des Diensts. Error: (10/01/2014 11:19:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Media Player-Netzwerkfreigabedienst niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Neustart des Diensts. Error: (10/01/2014 11:19:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa WinZiper service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (10/01/2014 11:19:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Adobe Acrobat Update Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (10/01/2014 11:19:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa spmgr niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (10/01/2014 11:19:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa WajamUpdaterV3 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Microsoft Office Sessions: ========================= Error: (10/01/2014 11:43:20 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/01/2014 11:42:06 AM) (Source: Winlogon) (EventID: 4103) (User: ) Description: 0x800700050x00000000 Error: (10/01/2014 10:42:34 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: 0x80070005 Error: (10/01/2014 10:02:47 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/01/2014 09:56:49 AM) (Source: Winlogon) (EventID: 4103) (User: ) Description: 0x800700050x00000000 Error: (09/30/2014 11:28:22 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: 0x80070005 Error: (09/30/2014 10:28:21 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: 0x80070005 Error: (09/30/2014 09:28:21 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: 0x80070005 Error: (09/30/2014 08:28:20 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: 0x80070005 Error: (09/30/2014 07:28:20 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: 0x80070005 ==================== Memory info =========================== Processor: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz Percentage of memory in use: 44% Total physical RAM: 3071.34 MB Available physical RAM: 1691.77 MB Total Pagefile: 6140.86 MB Available Pagefile: 4516.91 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:171.82 GB) (Free:24.09 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:114.55 GB) (Free:36.56 GB) NTFS Drive f: () (Removable) (Total:14.81 GB) (Free:5.69 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 97646C29) Partition 1: (Not Active) - (Size=11.7 GB) - (Type=1C) Partition 2: (Active) - (Size=171.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=114.5 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 14.8 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================