Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2015 Ran by XX at 2015-02-02 16:14:39 Running from C:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 32 Bit HP CIO Components Installer (Version: 6.1.1 - Hewlett-Packard) Hidden 4Media Video Editor 2 (HKLM\...\4Media Video Editor 2) (Version: 2.2.0.20120901 - 4Media) Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.4.0.2540 - Adobe Systems Incorporated) Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Reader XI - Polish (HKLM\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.) Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden Anki (HKLM\...\Anki) (Version: - ) AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5645 - AVG Technologies) AVG 2015 (Version: 15.0.4273 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.5645 - AVG Technologies) Hidden AVG Security Toolbar (HKLM\...\AVG Secure Search) (Version: 18.1.9.799 - AVG Technologies) Avi to Dvd Free Converter v6.4.0.48 (HKLM\...\Avi to Dvd Free Converter_is1) (Version: - AviToDvdFree.com Inc.) Avi2Dvd 0.6.4 (HKLM\...\Avi2Dvd) (Version: 0.6.4 - TrustFm) Avira (HKLM\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG) Avira (Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) AviSynth 2.5 (HKLM\...\AviSynth) (Version: - ) Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment) Bezpieczeństwo rodzinne usługi Windows Live (Version: 14.0.8052.1208 - Microsoft Corporation) Hidden BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden ccc-core-static (Version: 2009.1104.959.17837 - Nazwa firmy) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.09 - Piriform) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4214 - CDBurnerXP) Choice Guard (Version: 1.2.87.0 - Microsoft Corporation) Hidden Copy (Version: 130.0.428.000 - Hewlett-Packard) Hidden CoreAAC Audio Decoder (remove only) (HKLM\...\CoreAAC Audio Decoder) (Version: - ) Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 130.0.465.000 - Hewlett-Packard) Hidden DivX Plus DirectShow Filters (HKLM\...\DivX Plus DirectShow Filters) (Version: - DivX, Inc.) DivX Setup (HKLM\...\DivX Setup) (Version: 2.6.1.9 - DivX, LLC) DocProc (Version: 13.0.0.0 - Hewlett-Packard) Hidden Dual Package (HKLM\...\{37365259-9D37-4FBE-9204-08B4034623B6}) (Version: 2.8 - LG Soft India Pvt Ltd) Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden Firebird SQL Server - MAGIX Edition (HKLM\...\{3E6F0CAD-EE38-42A5-9EEA-AE17A55BF2D4}) (Version: 2.1.23.0 - MAGIX AG) Foxit Reader 5.0 (HKLM\...\Foxit Reader_is1) (Version: 5.0.2.718 - Foxit Corporation) Galeria fotografii usługi Windows Live (Version: 14.0.8051.1204 - Microsoft Corporation) Hidden Google Chrome (HKLM\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.) Google Drive (HKLM\...\{56D4499E-AC3E-4B8D-91C9-C700C148C44B}) (Version: 1.13.5782.599 - Google, Inc.) GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden Haali Media Splitter (HKLM\...\HaaliMkx) (Version: - ) Hearthstone (HKLM\...\Hearthstone) (Version: - Blizzard Entertainment) HP Update (HKLM\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard) HPPhotoSmartDiscLabelContent1 (Version: 2.04.0000 - Hewlett-Packard) Hidden HPPhotosmartEssential (Version: 2.04.0000 - Hewlett-Packard) Hidden HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden HTC Driver Installer (HKLM\...\{6D6664A9-3342-4948-9B7E-034EFE366F0F}) (Version: 3.0.0.018 - HTC Corporation) InterVideo DeviceService (HKLM\...\{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}) (Version: 1.0.0 - InterVideo) IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.36 - Irfan Skiljan) Junk Mail filter update (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Kies (HKLM\...\InstallShield_{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}) (Version: 1.4 - Nazwa firmy) Kies (Version: 1.4 - Nazwa firmy) Hidden League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (Version: 3.0.1 - Riot Games) Hidden LG United Mobile Driver (HKLM\...\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.10.1.0 - LG Electronics) LocK-A-FoLdeR (HKLM\...\LocK-A-FoLdeR) (Version: 3.9.2 - ) Malwarebytes Anti-Malware wersja 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden Math Problem Solver (HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\...\Math Problem Solver) (Version: - ) <==== ATTENTION Metin2 (HKLM\...\Metin2_is1) (Version: - Gameforge 4D GmbH) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Live Add-in 1.3 (HKLM\...\{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}) (Version: 2.0.2313.0 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (HKLM\...\{90850415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Virtual PC 2007 (HKLM\...\{8A7CAA24-7B23-410B-A7C3-F994B0944160}) (Version: 6.0.156.0 - Microsoft Corporation) Microsoft Virtual PC 2007 SP1 (HKLM\...\{AD483998-2E9A-4405-83FF-6E503AF49CBB}) (Version: 6.0.192.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) MK LOL (HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\...\MK LOL) (Version: - ) MKLOL (HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\...\MKLOL) (Version: - ) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) Narzędzie do przekazywania usługi Windows Live (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Nero 9 Essentials (HKLM\...\{1c7464ff-8eaa-474f-91a6-f2537056cdc8}) (Version: - Nero AG) Nexon Game Manager (HKLM\...\{289AC7E0-0AEE-4a7b-913C-709D9803D23E}) (Version: - ) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) OfferBLVDUpdate (HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\...\PennyBee) (Version: - OfferBLVDUpdate) <==== ATTENTION Poczta usługi Windows Live (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (Version: 14.0.8050.1202 - Microsoft Corporation) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden saveron (HKLM\...\{66951628-3E5A-9C96-37EA-490E187974D5}) (Version: - "") <==== ATTENTION Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype™ 6.21 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.) SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Sony PC Companion 2.10.188 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.188 - Sony) SpyHunter 4 (HKLM\...\SpyHunter) (Version: 4.18.9.4384 - Enigma Software Group, LLC) Status (Version: 130.0.469.000 - Hewlett-Packard) Hidden STOPzilla (HKLM\...\{AEA39A79-AFE1-4460-98D9-DFDBCAE21320}) (Version: 6.1.90.7 - iS3 Inc.) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH) TrayApp (Version: 130.0.422.000 - Hewlett-Packard) Hidden Unity Web Player (HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\...\UnityWebPlayer) (Version: 4.5.3f3 - Unity Technologies ApS) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - ) WordToPDF Packages (HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\...\WordToPDF Packages) (Version: - ) <==== ATTENTION YouTube Accelerator (HKLM\...\YouTube Accelerator) (Version: 3396(build_102) - Goobzo Ltd.) <==== ATTENTION ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 02-02-2015 14:32:42 Operacja przywracania ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2014-09-12 21:57 - 00000860 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {06924F4C-784E-4DFC-A78B-55CFD6CF17E2} - System32\Tasks\DLL-files.com Fixer_UPDATES => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: {12543C65-8A6D-401C-B87F-2D7189D0BFF1} - System32\Tasks\{58D2200F-DDCF-445E-BE0F-7FF74826830C} => pcalua.exe -a D:\Steam\steam.exe -c steam://uninstall/8770 Task: {13477BC6-7495-4923-A0A9-0D3C73496ACF} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe Task: {1851BD8D-1CD9-4021-9B2D-AFAE68B2552C} - System32\Tasks\{E8315CC3-04B0-426F-8A47-48141DDDAAFD} => pcalua.exe -a C:\Users\XX\Desktop\FrytkiBOT\HS_Blocker.exe -d C:\Users\XX\Desktop\FrytkiBOT Task: {22EC2BE5-E133-48C0-9CC6-BA319860DD79} - System32\Tasks\{DF5B99D9-8E73-4DE4-9159-70B61871B7FC} => pcalua.exe -a E:\setup.exe -d E:\ Task: {25BFAB60-C28A-4350-8C41-A698CA80CB38} - System32\Tasks\ygedzjm => C:\Users\XX\AppData\Local\Temp\ltuohkc.exe <==== ATTENTION Task: {295381B2-EB77-4598-B837-9D9C24DA9139} - System32\Tasks\{989EBDBD-62FC-4DB4-8DCB-543EC4D95931} => pcalua.exe -a "C:\Users\XX\Desktop\NAVI GUI 2012\NAVI GUI 2012\NAVI GUI 2012 (800x600).exe" -d "C:\Users\XX\Desktop\NAVI GUI 2012\NAVI GUI 2012" Task: {2D4F8C61-1477-4FA3-8D8A-27F47B01DEAD} - System32\Tasks\YTAUpdate => C:\PROGRA~1\YOUTUB~1\Updater.exe <==== ATTENTION Task: {32029460-E958-44A0-BA80-8221EA9FFD74} - System32\Tasks\{FED27A72-CD48-401E-B52B-A01C84B20AC8} => pcalua.exe -a C:\Users\XX\Desktop\6.86_nforce_win2kxp_international_whql.exe -d C:\Users\XX\Desktop Task: {3B6D2E55-39E6-48BD-8C8F-551E5E38292A} - System32\Tasks\DLL-files.com Fixer_MONTHLY => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: {3D1F88CB-451C-4D4E-B870-2159426E9796} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3848935919-3367533699-3990728495-1002 Task: {3DF51BBC-E6AB-470E-AA45-6992D9FBE4D6} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3848935919-3367533699-3990728495-1002 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-09-27] (RealNetworks, Inc.) Task: {3EA55B02-2834-42BB-A62F-2225C77994ED} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-02-02] (Enigma Software Group USA, LLC.) Task: {4021D99F-6698-4977-A474-FECD3128372F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-26] (Adobe Systems Incorporated) Task: {404D011E-2713-44EB-A64B-20A415347285} - System32\Tasks\RDReminder => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: {4CC0979E-EBF3-42B9-810F-6B61272D915B} - \YourFile Update No Task File <==== ATTENTION Task: {4DC82095-010D-460C-825D-92E2B531A548} - System32\Tasks\{54C3F4D1-5A52-4322-BB05-C58ACAE38103} => pcalua.exe -a C:\Users\XX\Desktop\Sims3_2.3.33.003002_from_2.0.86.002002.exe -d C:\Users\XX\Desktop Task: {523ABEBE-4550-49A1-85B6-05E6C8A53F94} - System32\Tasks\APSnotifierPP1 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {54483DCB-4108-4760-BE2F-93CA31181498} - System32\Tasks\{E169A21B-87F1-49EC-ABDF-25EF09604D5C} => pcalua.exe -a "C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe" -d "C:\Program Files\Common Files\Ahead\Nero Web" -c -ScParameter=8 MODE="update" Task: {570B6FE7-F4A1-48B1-A4BB-ABB7D1E13151} - System32\Tasks\{A2A3B52A-3ABC-4E3B-A91D-4F6DBBCDF0F4} => pcalua.exe -a C:\Windows\IsUn0415.exe -c -f"C:\Program Files\Gimnazjum klasa 1 - Fizyka\Uninst.isu" -c"C:\Program Files\Gimnazjum klasa 1 - Fizyka\UninstallProject.dll" Task: {575C1BC2-65F3-430A-BAA1-C3B940790CBA} - System32\Tasks\Math Problem Solver GPU => C:\Users\XX\AppData\Local\Math Problem Solver\gpu\dummysleep.exe <==== ATTENTION Task: {5BAAF458-EA78-4758-B398-6994CF39200F} - System32\Tasks\{4052535E-4CBB-46CE-88CE-FF3F7F2578E2} => Chrome.exe Task: {5D46EFF2-93A0-4F02-B23A-209859A96EA4} - System32\Tasks\{C32C989B-439E-4F8B-97BF-12911FE0BF77} => pcalua.exe -a "C:\Users\XX\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WKBOPGG\OggDS0995[1].exe" -d C:\Users\XX\Desktop Task: {6046192D-C0E1-4538-B720-7F5C8939F473} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3848935919-3367533699-3990728495-1002 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-09-27] (RealNetworks, Inc.) Task: {68A883B9-7843-4992-9095-486DCC2BD89D} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files\Protected Search\ProtectedSearch.exe <==== ATTENTION Task: {7284FFD2-64F8-4FEB-AA07-CA9D0022173C} - System32\Tasks\{F4035CFF-BFC2-4D32-9FF5-C4CDFACAF83D} => pcalua.exe -a "D:\Electronic Arts\Game\Bin\Sims3_2.3.33.003002_from_2.0.86.002002.exe" -d "D:\Electronic Arts\Game\Bin" Task: {75DEB202-D1C3-4C4F-A15F-EB439C1091E0} - System32\Tasks\{CD37BA95-3A2E-4907-BCAE-4B8B6C705602} => c:\program files\opera\opera.exe Task: {762CB282-0F27-4DAB-A67A-36FF61F21279} - System32\Tasks\Math Problem Solver CPU => C:\Users\XX\AppData\Local\Math Problem Solver\cpu\Solve.exe [2014-02-02] () <==== ATTENTION Task: {78808536-ACA4-4E4F-A7C1-1DFD81E158CA} - System32\Tasks\YTAUpdate_logon => C:\PROGRA~1\YOUTUB~1\Updater.exe <==== ATTENTION Task: {7E314B7E-8E4E-4A76-AFA5-DB1C64EC1FC0} - System32\Tasks\{2AFC76AB-09AA-472C-A27F-25BD5C7E0BC6} => pcalua.exe -a "C:\Program Files\YouTube Accelerator\YTAUninstall.exe" Task: {80D5E017-E192-4F38-B011-DC5DB2D8B49F} - System32\Tasks\{1C96B60C-FCFD-419A-BA77-10F9276C98F6} => pcalua.exe -a C:\Users\XX\Downloads\dotNetFx35setup(2).exe -d C:\Users\XX\Downloads Task: {8697C433-D4DF-49F6-A307-79E271D1CF96} - System32\Tasks\Math Problem Solver Optimize => C:\Users\XX\AppData\Local\Math Problem Solver\Optimize.exe [2014-01-20] () <==== ATTENTION Task: {892E0C77-F65F-42DF-B13A-4E44E40AB97C} - System32\Tasks\{88890589-C6E2-4BD2-B74A-DC9F2D89E870} => Chrome.exe Task: {9811EF5D-B8C1-4858-9FE6-62BF608D5DBD} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{BB5A512D-544A-4A1C-9B5A-B7A4AFC10F39}.exe Task: {A5134CAE-2604-44BD-BFE2-8DE663F9E3BF} - System32\Tasks\Norton Security Scan for XX => C:\PROGRA~1\NORTON~2\Engine\351~1.8\Nss.exe Task: {B6B8654D-E32F-4D4D-944F-04B8028AD5A7} - System32\Tasks\APSnotifierPP3 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {C04E7C3C-5167-418F-B1A2-0ADDB046C330} - System32\Tasks\{CEDCA9A4-CA14-4898-806A-951001CB2696} => pcalua.exe -a D:\CMR5.EXE -d D:\ Task: {C3965176-1194-4AFC-BAC0-EABF4580A064} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd) Task: {CA4EF24A-04C7-4085-99F4-1FAD95043CF9} - System32\Tasks\{9B087F2E-F6D4-419B-B4D7-7354C5C0E970} => pcalua.exe -a "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" Task: {CEA0A51F-AA11-463C-ADAC-769B8472C608} - System32\Tasks\{826D5F60-B62E-4C03-8A96-36BA93EB15BB} => pcalua.exe -a C:\Users\XX\Desktop\UniSpiker-2.6.exe -d C:\Users\XX\Desktop Task: {CFC7E1E8-97AE-4A89-A0B0-0DF0EB565419} - System32\Tasks\{6783762C-982D-497A-A37E-84E3E32719B0} => pcalua.exe -a "C:\Program Files\Steam\steam.exe" -c steam://uninstall/10 Task: {D0885CAB-62D1-4F32-8340-B5ACFD91DD1F} - System32\Tasks\{833EB77C-B397-4ABC-98C8-84A879989263} => pcalua.exe -a C:\Users\XX\Downloads\dziennik.exe -d C:\Users\XX\Downloads Task: {D5CAD9B4-3045-431D-BE45-B77677F838FF} - System32\Tasks\{17E4218E-C7C1-48EB-9827-4E3249531243} => pcalua.exe -a C:\Users\XX\AppData\Local\Temp\Temp1_AdobePhotoshop10pl_PL[www.INSTALKI.pl].zip\pl_PL\20070503.t4ce.089\Retail\Setup.exe Task: {DE0518D5-868B-4FEA-91C4-615E9AC0483F} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION Task: {E9B9C72B-2F33-4C06-BBEA-BDFC65D0FA77} - System32\Tasks\{AE041394-CEB8-4195-9334-B0E5CF6E0BCD} => C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe Task: {F519B37A-5D1B-41DD-9305-FDEAB358736D} - System32\Tasks\APSnotifierPP2 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {F89302F3-C51D-4FBC-943F-9C567F93ADAC} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe Task: {FF635474-C465-4FFD-B9B1-296C60F5D6EF} - System32\Tasks\{9A5426C8-494B-480C-88CF-13EB3DEE31CE} => pcalua.exe -a "C:\Program Files\4Media\Video Editor 2\Uninstall.exe" Task: {FFC8B55D-82F4-4FB8-B441-15E23716985B} - System32\Tasks\{A82B4408-EE86-437D-876E-374CE6D7D982} => pcalua.exe -a C:\Users\XX\Desktop\Expressivo_1_2_0_Jacek_Demo.exe -d C:\Users\XX\Desktop (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{BB5A512D-544A-4A1C-9B5A-B7A4AFC10F39}.exe Task: C:\Windows\Tasks\DLL-files.com Fixer_MONTHLY.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: C:\Windows\Tasks\DLL-files.com Fixer_UPDATES.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: C:\Windows\Tasks\Norton Security Scan for XX.job => C:\PROGRA~1\NORTON~2\Engine\351~1.8\Nss.exe ==================== Loaded Modules (whitelisted) ============= 2011-09-15 12:06 - 2011-09-15 12:06 - 00088576 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe 2014-11-09 12:02 - 2014-10-22 05:04 - 01042760 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.111\libglesv2.dll 2014-11-09 12:02 - 2014-10-22 05:04 - 00211272 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.111\libegl.dll 2014-11-09 12:02 - 2014-10-22 05:04 - 08910664 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.111\pdf.dll 2014-11-09 12:02 - 2014-10-22 05:04 - 01681224 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.111\ffmpegsumo.dll 2014-11-09 12:02 - 2014-10-22 05:05 - 14902600 _____ () C:\Program Files\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\Software\Classes\.exe: exefile => <===== ATTENTION! HKU\S-1-5-21-3848935919-3367533699-3990728495-1002\Software\Classes\exefile: <===== ATTENTION! ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: avgwd => 2 MSCONFIG\Services: FsUsbExService => 2 MSCONFIG\Services: Nero BackItUp Scheduler 4.0 => 2 MSCONFIG\Services: nkdytjtjsw32 => 2 MSCONFIG\Services: szserver => 2 MSCONFIG\Services: Update DigiHelp => 2 MSCONFIG\Services: Util DigiHelp => 2 MSCONFIG\Services: vToolbarUpdater18.1.9 => 2 MSCONFIG\Services: YouTubeAcceleratorService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dual Package.lnk => C:\Windows\pss\Dual Package.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupreg: Allworks => C:\Windows\System32\regsvr32.exe MSCONFIG\startupreg: avgnt => "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min MSCONFIG\startupreg: AVG_UI => "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY MSCONFIG\startupreg: Avira Systray => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe MSCONFIG\startupreg: Egftion => regsvr32.exe C:\Users\XX\AppData\Local\Egftion\CNBJOP99.DLL MSCONFIG\startupreg: FixCamera => C:\Windows\FixCamera.exe MSCONFIG\startupreg: hpqSRMon => C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe MSCONFIG\startupreg: MK LOL => "C:\Program Files\MKJogo\MK IM\Bin\MKIM.exe" -auto MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: TkBellExe => "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot MSCONFIG\startupreg: vProt => "C:\Program Files\AVG Secure Search\vprot.exe" ========================= Accounts: ========================== Administrator (S-1-5-21-3848935919-3367533699-3990728495-500 - Administrator - Disabled) Gość (S-1-5-21-3848935919-3367533699-3990728495-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3848935919-3367533699-3990728495-1683 - Limited - Enabled) XX (S-1-5-21-3848935919-3367533699-3990728495-1002 - Administrator - Enabled) => C:\Users\XX ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Urządzenie wejściowe USB Description: Urządzenie wejściowe USB Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da} Manufacturer: (Standardowe urządzenia systemowe) Service: HidUsb Problem: : Windows cannot initialize the device driver for this hardware. (Code 37) Resolution: The driver returned failure from its DriverEntry routine. Uninstall the driver, and then click "Scan for hardware changes" to reinstall or upgrade the driver. Name: Karta Microsoft Loopback Description: Karta Microsoft Loopback Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: msloop Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: AVGIDSShim Description: AVGIDSShim Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: AVGIDSShim Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Urządzenie wejściowe USB Description: Urządzenie wejściowe USB Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da} Manufacturer: (Standardowe urządzenia systemowe) Service: HidUsb Problem: : Windows cannot initialize the device driver for this hardware. (Code 37) Resolution: The driver returned failure from its DriverEntry routine. Uninstall the driver, and then click "Scan for hardware changes" to reinstall or upgrade the driver. Name: AVG Free Network Redirector Description: AVG Free Network Redirector Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: AvgTdiX Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (02/02/2015 03:08:42 PM) (Source: Wininit) (EventID: 1015) (User: ) Description: Błąd krytycznego procesu systemowego C:\Windows\system32\lsass.exe z kodem stanu 1. Komputer musi być ponownie uruchomiony. Error: (02/02/2015 02:59:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: csgo.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x5462bb74 Nazwa modułu powodującego błąd: tier0.dll, wersja: 0.0.0.0, sygnatura czasowa: 0x546ef9d7 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00009254 Identyfikator procesu powodującego błąd: 0x930 Godzina uruchomienia aplikacji powodującej błąd: 0xcsgo.exe0 Ścieżka aplikacji powodującej błąd: csgo.exe1 Ścieżka modułu powodującego błąd: csgo.exe2 Identyfikator raportu: csgo.exe3 Error: (02/02/2015 02:54:39 PM) (Source: MsiInstaller) (EventID: 11706) (User: MAJLOSZ) Description: Product: TrayApp -- Error 1706. An installation package for the product TrayApp cannot be found. Try the installation again using a valid copy of the installation package 'TrayApp.msi'. Error: (02/02/2015 02:49:22 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: Wystąpił nieokreślony błąd podczas przywracania systemu: (Kopia zapasowa systemu Windows). Informacje dodatkowe: 0x80070005. Error: (02/02/2015 02:45:37 PM) (Source: MsiInstaller) (EventID: 11706) (User: MAJLOSZ) Description: Product: TrayApp -- Error 1706. An installation package for the product TrayApp cannot be found. Try the installation again using a valid copy of the installation package 'TrayApp.msi'. Error: (02/02/2015 02:42:56 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: Wystąpił nieokreślony błąd podczas przywracania systemu: (Kopia zapasowa systemu Windows). Informacje dodatkowe: 0x80070005. Error: (02/02/2015 02:39:05 PM) (Source: MsiInstaller) (EventID: 11706) (User: MAJLOSZ) Description: Product: TrayApp -- Error 1706. An installation package for the product TrayApp cannot be found. Try the installation again using a valid copy of the installation package 'TrayApp.msi'. Error: (02/02/2015 02:38:24 PM) (Source: MsiInstaller) (EventID: 11706) (User: MAJLOSZ) Description: Product: TrayApp -- Error 1706. An installation package for the product TrayApp cannot be found. Try the installation again using a valid copy of the installation package 'TrayApp.msi'. Error: (02/02/2015 02:37:08 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: Wystąpił nieokreślony błąd podczas przywracania systemu: (Kopia zapasowa systemu Windows). Informacje dodatkowe: 0x80070005. Error: (02/02/2015 02:33:09 PM) (Source: MsiInstaller) (EventID: 11706) (User: MAJLOSZ) Description: Product: TrayApp -- Error 1706. An installation package for the product TrayApp cannot be found. Try the installation again using a valid copy of the installation package 'TrayApp.msi'. System errors: ============= Error: (02/02/2015 03:11:26 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Usługa Usługa nasłuchująca grup domowych zakończyła działanie; wystąpił specyficzny dla niej błąd %%-2147023143. Error: (02/02/2015 03:11:25 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: Avgdiskx AVGIDSDriver AVGIDSHX AVGIDSShim Avgldx86 Avglogx Avgmfx86 Avgrkx86 Avgtdix avipbb avkmgr is3srv netfilter prodrv06 prohlp02 prosync1 sfhlp01 ssmdrv szkgfs Error: (02/02/2015 03:10:35 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Usługa AVGIDSAgent zależy od usługi AVGIDSDriver, której nie można uruchomić z powodu następującego błędu: %%31 Error: (02/02/2015 03:10:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi avgntflt z powodu następującego błędu: %%31 Error: (02/02/2015 03:10:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi sbapifs z powodu następującego błędu: %%2 Error: (02/02/2015 03:10:24 PM) (Source: Application Popup) (EventID: 875) (User: ) Description: Sterownik prodrv06.sys został zablokowany dla ładowania. Error: (02/02/2015 03:10:31 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 15:09:33 na ‎2015-‎02-‎02 było nieoczekiwane. Error: (02/02/2015 03:10:22 PM) (Source: Application Popup) (EventID: 875) (User: ) Description: Sterownik prohlp02.sys został zablokowany dla ładowania. Error: (02/02/2015 03:10:22 PM) (Source: Application Popup) (EventID: 875) (User: ) Description: Sterownik prosync1.sys został zablokowany dla ładowania. Error: (02/02/2015 03:10:22 PM) (Source: Application Popup) (EventID: 875) (User: ) Description: Sterownik sfhlp01.sys został zablokowany dla ładowania. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz Percentage of memory in use: 86% Total physical RAM: 3579.49 MB Available physical RAM: 501.02 MB Total Pagefile: 7157.27 MB Available Pagefile: 3307.92 MB Total Virtual: 2799.88 MB Available Virtual: 2549.34 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:60 GB) (Free:8.54 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:622.64 GB) (Free:366.48 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================