Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-10-2014 01 Ran by Michal at 2014-10-10 12:30:38 Running from C:\Users\Michal\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} FW: Zapora osobista ESET (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Aktualizacje NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) ESET Smart Security (HKLM\...\{B00F3D06-90CA-4388-8622-FD018675C29A}) (Version: 7.0.317.4 - ESET, spol s r. o.) Google Chrome (HKCU\...\Google Chrome) (Version: 38.0.2125.101 - Google Inc.) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) NVIDIA Install Application (Version: 2.1002.154.1150 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden NVIDIA Sterownik 3D Vision 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation) NVIDIA Sterownik graficzny 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation) NVIDIA Update Core (Version: 10.4.0 - NVIDIA Corporation) Hidden Panel sterowania NVIDIA 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3917850209-3315541947-2670492561-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Michal\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3917850209-3315541947-2670492561-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Michal\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.) ==================== Restore Points ========================= 10-10-2014 08:07:06 Zainstalowano ESET Smart Security ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {AB96B97B-39C2-46A2-876A-EEB6AE199033} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup => C:\Windows\system32\dism.exe [2012-07-26] (Microsoft Corporation) Task: {B6BE724C-54A3-46F7-9B63-53053E62A6E0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3917850209-3315541947-2670492561-1001UA => C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-10] (Google Inc.) Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {CD2C7806-58B8-408C-B280-189FC5118178} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3917850209-3315541947-2670492561-1001Core => C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-10] (Google Inc.) Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3917850209-3315541947-2670492561-1001Core.job => C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3917850209-3315541947-2670492561-1001UA.job => C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-07-26 11:56 - 2012-07-26 11:54 - 00170864 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll 2014-10-10 10:07 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-10-10 10:01 - 2014-10-01 07:54 - 08911176 _____ () C:\Users\Michal\AppData\Local\Google\Chrome\Application\38.0.2125.101\pdf.dll 2014-10-10 10:01 - 2014-10-01 07:54 - 01681224 _____ () C:\Users\Michal\AppData\Local\Google\Chrome\Application\38.0.2125.101\ffmpegsumo.dll 2014-10-10 11:14 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Michal\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll 2014-10-10 11:14 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Michal\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-3917850209-3315541947-2670492561-500 - Administrator - Disabled) Gość (S-1-5-21-3917850209-3315541947-2670492561-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3917850209-3315541947-2670492561-1003 - Limited - Enabled) Michal (S-1-5-21-3917850209-3315541947-2670492561-1001 - Administrator - Enabled) => C:\Users\Michal ==================== Faulty Device Manager Devices ============= Name: MEDIA Description: MEDIA Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: MEDIA Description: MEDIA Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: MEDIA Description: MEDIA Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: MEDIA Description: MEDIA Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/10/2014 11:26:28 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: stacjonarny) Description: Aplikacja Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo nie została uruchomiona w wyznaczonym czasie. Error: (10/10/2014 11:26:14 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: stacjonarny) Description: Aktywacja aplikacji Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo nie powiodła się. Błąd: -2147023170. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (10/10/2014 11:26:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: wwahost.exe, wersja: 6.2.9200.16384, sygnatura czasowa: 0x50107c6e Nazwa modułu powodującego błąd: EntPlat.dll, wersja: 1.0.927.0, sygnatura czasowa: 0x4ffcd52b Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000008ad7 Identyfikator procesu powodującego błąd: 0x794 Godzina uruchomienia aplikacji powodującej błąd: 0xwwahost.exe0 Ścieżka aplikacji powodującej błąd: wwahost.exe1 Ścieżka modułu powodującego błąd: wwahost.exe2 Identyfikator raportu: wwahost.exe3 Pełna nazwa pakietu powodującego błąd: wwahost.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: wwahost.exe5 Error: (10/10/2014 10:09:49 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004C003 Argumenty wiersza polecenia: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=9e473b6d-b591-4c46-9c44-90a865f22e76;NotificationInterval=1440;Trigger=NetworkAvailable Error: (10/10/2014 10:09:49 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: Pozyskanie licencji użytkowania nie powiodło się. hr=0xC004C003 Identyfikator SKU=9e473b6d-b591-4c46-9c44-90a865f22e76 Error: (10/10/2014 10:09:49 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Szczegóły błędu pozyskiwania licencji. hr=0xC004C003 Error: (10/10/2014 10:09:48 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: Pozyskanie licencji użytkowania nie powiodło się. hr=0xC004C003 Identyfikator SKU=9e473b6d-b591-4c46-9c44-90a865f22e76 Error: (10/10/2014 10:09:48 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Szczegóły błędu pozyskiwania licencji. hr=0xC004C003 Error: (10/10/2014 09:59:01 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004C003 Argumenty wiersza polecenia: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=9e473b6d-b591-4c46-9c44-90a865f22e76;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (10/10/2014 09:59:00 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: Pozyskanie licencji użytkowania nie powiodło się. hr=0xC004C003 Identyfikator SKU=9e473b6d-b591-4c46-9c44-90a865f22e76 System errors: ============= Error: (10/10/2014 10:09:36 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Usługa ESET Service jest oznaczona jako usługa interakcyjna. System jest jednak skonfigurowany tak, aby nie zezwalać na usługi interakcyjne, dlatego ta usługa może nie działać właściwie. Error: (10/10/2014 09:57:57 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: ZARZĄDZANIE NT) Description: 0x8000002a31\SystemRoot\System32\Config\SAM Error: (10/10/2014 09:56:42 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Usługa listy sieci zakończyła działanie; wystąpił następujący błąd: %%21 Error: (10/10/2014 09:56:41 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Pomoc IP zakończyła działanie; wystąpił następujący błąd: %%1058 Error: (10/10/2014 09:56:08 AM) (Source: volmgr) (EventID: 46) (User: ) Description: Inicjowanie zrzutu awaryjnego nie powiodło się! Microsoft Office Sessions: ========================= Error: (10/10/2014 11:26:28 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: stacjonarny) Description: Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo Error: (10/10/2014 11:26:14 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: stacjonarny) Description: Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo-2147023170 Error: (10/10/2014 11:26:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: wwahost.exe6.2.9200.1638450107c6eEntPlat.dll1.0.927.04ffcd52bc00000050000000000008ad779401cfe46c0f36313aC:\Windows\system32\wwahost.exeC:\Program Files\WindowsApps\Microsoft.ZuneVideo_1.0.927.0_x64__8wekyb3d8bbwe\EntPlat.dll79b91d99-505f-11e4-be67-10bf48bd2099Microsoft.ZuneVideo_1.0.927.0_x64__8wekyb3d8bbweMicrosoft.ZuneVideo Error: (10/10/2014 10:09:49 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: hr=0xC004C003RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=9e473b6d-b591-4c46-9c44-90a865f22e76;NotificationInterval=1440;Trigger=NetworkAvailable Error: (10/10/2014 10:09:49 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: hr=0xC004C0039e473b6d-b591-4c46-9c44-90a865f22e76 Error: (10/10/2014 10:09:49 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: hr=0xC004C00300010001(0x00000000, 10:09:48:309 - https://activation.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail) 00020001(0x00000000, 10:09:48:309) 00030001(0x00000000, 10:09:48:309 - https://activation.sls.microsoft.com) 00030002(0x00000000, 10:09:48:309 - 0) 00040001(0x00000000, 10:09:48:309 - https://activation.sls.microsoft.com) 00040002(0x00000000, 10:09:48:309 - 1, , , ) 00050002(0x80072F94, 10:09:48:309 - 0, 1) 00040006(0x00000001, 10:09:48:309 - 0, https://activation.sls.microsoft.com, , ) 00020005(0x00000000, 10:09:48:309 - 0) 0002000C(0x00000000, 10:09:49:543 - 500) 00010002(0x8004FC01, 10:09:49:543 - soap:ServerSoapException0xC004C003103 (Activation) - [PA Product key blocked. ---> Product key blocked]) 00010003(0x8004FC01, 10:09:49:543) Error: (10/10/2014 10:09:48 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: hr=0xC004C0039e473b6d-b591-4c46-9c44-90a865f22e76 Error: (10/10/2014 10:09:48 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: hr=0xC004C00300010001(0x00000000, 10:09:46:731 - https://activation.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail) 00020001(0x00000000, 10:09:46:731) 00030001(0x00000000, 10:09:46:731 - https://activation.sls.microsoft.com) 00030002(0x00000000, 10:09:46:731 - 0) 00040001(0x00000000, 10:09:46:731 - https://activation.sls.microsoft.com) 00040002(0x00000000, 10:09:46:731 - 1, , , ) 00050002(0x80072F94, 10:09:46:731 - 0, 1) 00040006(0x00000001, 10:09:46:731 - 0, https://activation.sls.microsoft.com, , ) 00020005(0x00000000, 10:09:46:731 - 0) 0002000C(0x00000000, 10:09:48:215 - 500) 00010002(0x8004FC01, 10:09:48:215 - soap:ServerSoapException0xC004C003103 (Activation) - [PA Product key blocked. ---> Product key blocked]) 00010003(0x8004FC01, 10:09:48:215) Error: (10/10/2014 09:59:01 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: hr=0xC004C003RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=9e473b6d-b591-4c46-9c44-90a865f22e76;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (10/10/2014 09:59:00 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: hr=0xC004C0039e473b6d-b591-4c46-9c44-90a865f22e76 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3570 CPU @ 3.40GHz Percentage of memory in use: 19% Total physical RAM: 8143.79 MB Available physical RAM: 6547.28 MB Total Pagefile: 12751.79 MB Available Pagefile: 11005.14 MB Total Virtual: 8192 MB Available Virtual: 8191.77 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:97.56 GB) (Free:74.7 GB) NTFS Drive d: (Nowy) (Fixed) (Total:465.76 GB) (Free:57.76 GB) NTFS Drive e: () (Fixed) (Total:833.85 GB) (Free:0.19 GB) NTFS Drive g: (KINGSTON) (Removable) (Total:29.31 GB) (Free:29.22 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 3D9373E2) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=97.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=833.9 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5559A0D3) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 29.3 GB) (Disk ID: C3072E18) Partition 1: (Not Active) - (Size=29.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================