Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2014 Ran by Marta at 2014-12-04 19:32:35 Running from C:\Users\Marta\Desktop\Czyszczenie Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Reader 9.5.5 - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software) Cat Licking Screen Cleaner Screensaver (HKLM-x32\...\Cat Licking Screen Cleaner Screensaver) (Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform) Dropbox (HKU\S-1-5-21-421937301-649035308-745041611-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.) Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.1 - Lenovo) Energy Management (x32 Version: 6.0.2.1 - Lenovo) Hidden Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation) Foxy Secure (HKLM-x32\...\Foxy Secure) (Version: 6 - ) <==== ATTENTION Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel(R) Wireless Display (HKLM-x32\...\{F84906ED-BB54-4889-B131-FED9C9056FC8}) (Version: 2.0.27.0 - Intel Corporation) Internet Speed Checker (HKLM-x32\...\Internet Speed Checker) (Version: 1.35.9.29 - Speedchecker) <==== ATTENTION Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.8000 - Broadcom Corporation) Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.11.0209.1 - Lenovo EasyCamera) Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.5 - Lenovo) Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3603 - CyberLink Corp.) Lenovo YouCam (x32 Version: 3.1.3603 - CyberLink Corp.) Hidden LITTLEST PET SHOP (HKLM-x32\...\{75569133-FD58-4F54-B622-9193EC7B6000}) (Version: 2.0.1.0 - Electronic Arts) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.279 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.279 - LogMeIn, Inc.) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft PowerPoint 2013 Packages (HKU\S-1-5-21-421937301-649035308-745041611-1001\...\Microsoft PowerPoint 2013 Packages) (Version: - ) <==== ATTENTION Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0415-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) NewFreeScreensaver nfsDigitalClock03 (HKLM-x32\...\nfsDigitalClock03 New Free Screensaver_is1) (Version: - ) NVIDIA Sterownik graficzny 267.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA Corporation) Onekey Theater (HKLM-x32\...\InstallShield_{D4B060B9-AD4A-4152-9D99-28B93C615AFE}) (Version: 2.0.2.7 - Lenovo) Onekey Theater (x32 Version: 2.0.2.7 - Lenovo) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Oprogramowanie Intel(R) PROSet/Wireless WiFi (HKLM\...\{AF162E20-417F-4946-A06D-65734984957F}) (Version: 14.00.0000 - Intel Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.) Pakiet sterowników systemu Windows - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo) Panel sterowania NVIDIA 267.54 (Version: 267.54 - NVIDIA Corporation) Hidden PDF Creator (HKLM\...\PDF Creator) (Version: - ) PDF Creator Packages (HKU\S-1-5-21-421937301-649035308-745041611-1001\...\PDF Creator Packages) (Version: - ) <==== ATTENTION PennyBee (HKLM-x32\...\PennyBee) (Version: 1.0.4.2 - PennyBee) <==== ATTENTION PennyBeeUpdate (HKU\S-1-5-21-421937301-649035308-745041611-1001\...\PennyBee) (Version: - PennyBeeUpdate) <==== ATTENTION Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podręcznik użytkownika (x32 Version: 1.0.0.6 - Lenovo) Hidden Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.) Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.21.531.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6267 - Realtek Semiconductor Corp.) Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10008 - Realtek Semiconductor Corp.) RtLED (HKLM\...\{ACB6F4ED-835B-44EC-9EFD-AC8C83D28597}) (Version: 1.0.3 - Realtek Semiconductor Corp.) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.) Sony Ericsson Update Engine (HKLM-x32\...\Update Engine) (Version: 2.13.6.201305161305 - Sony Ericsson Communications AB) SPORE™ — śmieszne i straszne części stworów (HKLM-x32\...\{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}) (Version: 1.00.0000 - Electronic Arts) SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.02.0000 - Electronic Arts) SRS Premium Sound Control Panel (HKLM\...\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.18.0 - SRS Labs, Inc.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.7.0 - Synaptics Incorporated) The Sims 2: Ultimate Collection (HKLM-x32\...\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts) The Sims Średniowiecze (HKLM-x32\...\{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}) (Version: 2.0.113 - Electronic Arts) The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.63.5 - Electronic Arts) The Sims™ 3 Cztery pory roku (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts) The Sims™ 3 Diesel Akcesoria (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts) The Sims™ 3 Kariera (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts) The Sims™ 3 Nie z tego świata (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts) The Sims™ 3 Nowoczesny apartament Akcesoria (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts) The Sims™ 3 Po zmroku (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) The Sims™ 3 Pokolenia (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts) The Sims™ 3 Szybka jazda Akcesoria (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts) The Sims™ 3 Wymarzone Podróże (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.17.2 - Electronic Arts) The Sims™ 3 Zostań gwiazdą (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts) The Sims™ 3 Zwierzaki (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts) The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.2.24.20 - Electronic Arts Inc.) UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo) VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1206 - Lenovo) Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation) WinRAR 5.11 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-421937301-649035308-745041611-1001_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Marta\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) ==================== Restore Points ========================= 09-11-2014 17:22:56 avast! antivirus system restore point 09-11-2014 18:00:40 Kopia zapasowa systemu Windows 16-11-2014 10:42:15 Windows Update 16-11-2014 18:33:49 Installed Microsoft Office Professional Plus 2010 18-11-2014 05:57:14 Windows Update 19-11-2014 16:50:02 Windows Update 20-11-2014 17:29:01 Windows Update 23-11-2014 21:10:34 Kopia zapasowa systemu Windows 30-11-2014 18:19:58 Kopia zapasowa systemu Windows 03-12-2014 21:45:39 Usunięto: Moduł Szybka instalacja pakietu Microsoft Office 2010 03-12-2014 21:54:11 Removed Microsoft Office Professional Plus 2010 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {042E8582-3F25-4AED-B98D-2CC14FC8A42B} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-11 => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-11.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {109A3A62-5B17-4C9F-B18B-EFCB5E7AC721} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-421937301-649035308-745041611-1001Core => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-25] (Facebook Inc.) Task: {21DC0DAB-99F6-4312-9C76-8FF337D66529} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.) Task: {535CABD6-C3B8-487B-8BE0-FE6FBF4176DF} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-09] (AVAST Software) Task: {5C4F81A1-9E16-4FD3-9D7A-AA0A681B3480} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-12] (Adobe Systems Incorporated) Task: {8781D797-6E4E-498D-A0E0-744967BCA12C} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\windows\SysWOW64\FlashPlayerUpdateService.exe Task: {9260D919-6FF8-47C4-92E0-64178A84B5F5} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-5_user => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-5.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {A3996164-F0DA-44E4-9565-A3568DAD8749} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {A587E0F8-C0C9-41DC-BEBB-C48381A46206} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2010-12-05] (CyberLink) Task: {AF2BDC1B-D0E4-4B9F-87F1-A5F96B7D5767} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-7 => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-7.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {B7C80393-2807-4B87-B416-CD4F537D6C13} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-1 => C:\Program Files (x86)\Internet Speed Checker\Internet Speed Checker-codedownloader.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {B9BF867A-638F-4E39-BF3A-C8A9D52A8617} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-4 => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-4.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {BECBD2A3-B77E-4B8D-A51F-B0B33FCB970D} - System32\Tasks\AdobeFlashPlayerUpdate => C:\windows\SysWOW64\FlashPlayerUpdateService.exe Task: {CCE9D17C-8F16-4570-B3A9-8D39F0AA7B1E} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-5 => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-5.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {D73EF128-1367-4D7D-A7A3-01EF023F6B43} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-2 => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-2.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {E3BF9B99-FD58-45E5-9009-E873AD8B1CF4} - System32\Tasks\PennyBee => C:\Users\Marta\AppData\Roaming\PennyBee\UpdateProc\UpdateTask.exe [2014-08-11] () <==== ATTENTION Task: {FA36D863-0207-4E2D-9698-56FD59B3EC76} - System32\Tasks\61c99360-2be3-4593-806e-f395dc9af988-6 => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-6.exe [2014-11-02] (Speedchecker) <==== ATTENTION Task: {FB2CBEDD-F87C-4440-A933-3F4B40572D2E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-421937301-649035308-745041611-1001UA => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-25] (Facebook Inc.) Task: {FCFC96C7-1E23-48A4-A59A-F5B292113A80} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-25] (Google Inc.) Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-1.job => C:\Program Files (x86)\Internet Speed Checker\Internet Speed Checker-codedownloader.exe <==== ATTENTION Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-11.job => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-11.exe <==== ATTENTION Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-2.job => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-2.exe <==== ATTENTION Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-4.job => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-4.exe <==== ATTENTION Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-5.job => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-5.exe <==== ATTENTION Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-5_user.job => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-5.exe <==== ATTENTION Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-6.job => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-6.exe <==== ATTENTION Task: C:\windows\Tasks\61c99360-2be3-4593-806e-f395dc9af988-7.job => C:\Program Files (x86)\Internet Speed Checker\61c99360-2be3-4593-806e-f395dc9af988-7.exe <==== ATTENTION Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-421937301-649035308-745041611-1001Core.job => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-421937301-649035308-745041611-1001UA.job => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\PennyBee.job => C:\Users\Marta\AppData\Roaming\PennyBee\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2010-11-02 13:58 - 2010-11-02 13:58 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2010-11-11 11:42 - 2010-11-11 11:42 - 00202144 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect64.dll 2010-11-11 11:44 - 2010-11-11 11:44 - 00156576 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll64.dll 2011-10-13 17:35 - 2011-10-13 17:35 - 01502720 _____ () C:\windows\system32\IcnOvrly.dll 2011-10-13 17:35 - 2011-10-13 17:35 - 00622592 _____ () C:\windows\system32\SimpleExt.dll 2011-02-15 13:26 - 2011-02-15 13:26 - 00205088 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll 2013-04-02 13:03 - 2011-10-04 21:43 - 00087552 _____ () C:\windows\System32\custmon64i.dll 2014-09-17 08:54 - 2014-09-17 08:54 - 00054272 _____ () C:\Program Files (x86)\PennyBee\PennyBee.exe 2013-08-31 07:42 - 2013-08-31 07:42 - 03233806 _____ () C:\Program Files (x86)\Tor\tor.exe 2011-04-14 04:01 - 2011-03-25 10:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-11-02 13:58 - 2010-11-02 13:58 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2011-10-13 17:38 - 2011-10-13 17:38 - 00100256 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe 2008-12-20 04:20 - 2011-10-13 17:52 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll 2008-12-20 04:20 - 2011-10-13 17:52 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll 2014-08-11 12:55 - 2014-08-11 12:55 - 00136192 _____ () C:\Users\Marta\AppData\Roaming\PennyBee\UpdateProc\UpdateTask.exe 2014-12-03 22:28 - 2014-12-03 22:28 - 02904576 _____ () C:\Program Files\AVAST Software\Avast\defs\14120301\algo.dll 2010-11-11 11:38 - 2010-11-11 11:38 - 00161696 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll 2010-11-11 11:39 - 2010-11-11 11:39 - 00133024 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 01007104 _____ () C:\Program Files (x86)\Origin\platforms\qwindows.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 00023552 _____ () C:\Program Files (x86)\Origin\imageformats\qgif.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 00024576 _____ () C:\Program Files (x86)\Origin\imageformats\qico.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 00216576 _____ () C:\Program Files (x86)\Origin\imageformats\qjpeg.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 00261120 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 00019456 _____ () C:\Program Files (x86)\Origin\imageformats\qtga.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 00337408 _____ () C:\Program Files (x86)\Origin\imageformats\qtiff.dll 2014-09-06 16:10 - 2014-11-30 13:21 - 00018944 _____ () C:\Program Files (x86)\Origin\imageformats\qwbmp.dll 2011-10-13 17:35 - 2011-10-13 17:35 - 00013664 _____ () C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll 2014-11-09 18:25 - 2014-11-09 18:25 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-421937301-649035308-745041611-500 - Administrator - Disabled) Gość (S-1-5-21-421937301-649035308-745041611-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-421937301-649035308-745041611-1003 - Limited - Enabled) Marta (S-1-5-21-421937301-649035308-745041611-1001 - Administrator - Enabled) => C:\Users\Marta UpdatusUser (S-1-5-21-421937301-649035308-745041611-1000 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Faulty Device Manager Devices ============= Name: Zewnętrzne urządzenie Bluetooth Description: Zewnętrzne urządzenie Bluetooth Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Zewnętrzne urządzenie Bluetooth Description: Zewnętrzne urządzenie Bluetooth Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Zewnętrzne urządzenie Bluetooth Description: Zewnętrzne urządzenie Bluetooth Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Zewnętrzne urządzenie Bluetooth Description: Zewnętrzne urządzenie Bluetooth Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Realtek PCIe FE Family Controller Description: Realtek PCIe FE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: RTL8167 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (12/04/2014 06:38:55 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2014 10:50:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2014 10:41:16 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2014 10:26:55 PM) (Source: Google Update) (EventID: 20) (User: Marta-Komputer) Description: Network Request Error. Error: 0x80072ee7. Http status code: 0. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7 Error: (12/03/2014 10:23:26 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 09:25:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 07:38:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 07:27:22 PM) (Source: Windows Backup) (EventID: 4104) (User: ) Description: Wykonanie kopii zapasowej nie powiodło się. Błąd: Na tym dysku jest za mało miejsca, aby zapisać kopię zapasową. Zwolnij miejsce, usuwając starsze kopie zapasowe albo niepotrzebne dane, lub zmień ustawienia kopii zapasowej. (0x81000005). Error: (11/30/2014 07:08:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 06:57:06 PM) (Source: McLogEvent) (EventID: 5051) (User: ZARZĄDZANIE NT) Description: C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe900002304 (0x900)0x0000000076DC132A Build VSCORE.14.4.0.380 / 5400.1158 Object being scanned = \Device\HarddiskVolume2\ProgramData\AVAST Software\Avast\db1cc89bfc896f501-648872ef.dat by System 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0) System errors: ============= Error: (12/04/2014 07:27:20 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:42:55 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Usługa LogMeIn Hamachi Tunneling Engine jest oznaczona jako usługa interakcyjna. System jest jednak skonfigurowany tak, aby nie zezwalać na usługi interakcyjne, dlatego ta usługa może nie działać właściwie. Error: (12/03/2014 10:42:43 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:42:41 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:32:46 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:31:55 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:29:20 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:28:14 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:27:06 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (12/03/2014 10:27:04 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Microsoft Office Sessions: ========================= Error: (12/04/2014 06:38:55 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2014 10:50:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2014 10:41:16 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2014 10:26:55 PM) (Source: Google Update) (EventID: 20) (User: Marta-Komputer) Description: Network Request Error. Error: 0x80072ee7. Http status code: 0. Url=https://www.facebook.com/omaha/update.php Trying config: source=IE, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=IE, direct connection. trying CUP:WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying WinHTTP. Send request returned 0x80072ee7. Http status code 0. trying CUP:iexplore. Send request returned 0x80004005. Http status code 0. Trying config: source=auto, wpad=1, script=. trying CUP:WinHTTP. Send request returned 0x80072ee7 Error: (12/03/2014 10:23:26 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 09:25:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 07:38:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 07:27:22 PM) (Source: Windows Backup) (EventID: 4104) (User: ) Description: Na tym dysku jest za mało miejsca, aby zapisać kopię zapasową. Zwolnij miejsce, usuwając starsze kopie zapasowe albo niepotrzebne dane, lub zmień ustawienia kopii zapasowej. (0x81000005) Error: (11/30/2014 07:08:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2014 06:57:06 PM) (Source: McLogEvent) (EventID: 5051) (User: ZARZĄDZANIE NT) Description: C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe900002304 (0x900)0x0000000076DC132A Build VSCORE.14.4.0.380 / 5400.1158 Object being scanned = \Device\HarddiskVolume2\ProgramData\AVAST Software\Avast\db1cc89bfc896f501-648872ef.dat by System 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0) ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz Percentage of memory in use: 26% Total physical RAM: 8106.17 MB Available physical RAM: 5950.86 MB Total Pagefile: 16210.52 MB Available Pagefile: 14002.21 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:654.69 GB) (Free:484.23 GB) NTFS Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:0 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: A67A77D1) Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=654.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=14.7 GB) - (Type=12) ==================== End Of Log ============================