Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-04-2015 01 Ran by Juleczka at 2015-05-01 12:18:17 Running from C:\Users\Juleczka\Desktop\fix Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3676795516-2390992231-3671279854-500 - Administrator - Disabled) Gość (S-1-5-21-3676795516-2390992231-3671279854-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3676795516-2390992231-3671279854-1003 - Limited - Enabled) Juleczka (S-1-5-21-3676795516-2390992231-3671279854-1000 - Administrator - Enabled) => C:\Users\Juleczka ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} FW: Zapora osobista ESET (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated) Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.206 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden Aktualizacje NVIDIA 2.4.1.21 (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version: - ) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - ) CD-LabelPrint (HKLM-x32\...\MediaNavigation.CDLabelPrint) (Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Easy Settings (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.1 - Samsung Electronics CO., LTD.) Easy Support Center (HKLM\...\{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}) (Version: 1.2.33 - Samsung Electronics CO., LTD.) ESET Smart Security (HKLM\...\{A9550052-52AD-414B-AB58-74F0D7DC8188}) (Version: 8.0.304.2 - ESET, spol s r. o.) Galeria fotografii (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden GG (HKU\S-1-5-21-3676795516-2390992231-3671279854-1000\...\GG) (Version: 12 - GG Network S.A.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.135 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2712 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{F0932859-AA60-459E-B843-0BDECA34E2C7}) (Version: 2.0.0.0086 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.1.209 - Intel Corporation) Intel(R) WiDi (HKLM\...\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) ipla 2.8.4 (HKLM-x32\...\ipla) (Version: 2.8.4 - Redefine Sp z o.o.) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3676795516-2390992231-3671279854-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Nero 9 Essentials (HKLM-x32\...\{70af18d2-aa2c-4c37-a352-79dc3e5b6922}) (Version: - Nero AG) NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.15.0324 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0324 - NVIDIA Corporation) NVIDIA Sterownik graficzny 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation) OFICJALNE TESTY EGZAMINACYJNE PWPW (HKLM-x32\...\OFICJALNE TESTY EGZAMINACYJNE PWPW) (Version: - ) OpenFM (HKU\S-1-5-21-3676795516-2390992231-3671279854-1000\...\OpenFM) (Version: 2 - GG Network S.A.) Oprogramowanie Intel® PROSet/Wireless (HKLM-x32\...\{ae509f68-6982-4506-befc-f2218d72cd5e}) (Version: 15.8.0 - Intel Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.) Panel sterowania NVIDIA 350.12 (Version: 350.12 - NVIDIA Corporation) Hidden PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) Poczta usługi Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Polski pakiet językowy dla narzędzi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PLK) (Version: 10.0.50903 - Microsoft Corporation) Prawo Jazdy 5.1.3.66 (HKLM-x32\...\{85522F30-E2AD-4D87-948D-4654FF3CADEC}_is1) (Version: 5.1.3.66 - Grupa IMAGE sp. z o.o.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6716 - Realtek Semiconductor Corp.) Rejestracja użytkownika drukarki Canon MG5200 series (HKLM-x32\...\Rejestracja użytkownika drukarki Canon MG5200 series) (Version: - ) S Agent (Version: 1.1.45 - Samsung Electronics CO., LTD.) Hidden Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.) Smart View 2.0 (HKLM-x32\...\{FBAAAFAE-08A8-4C63-87EA-4AEA9DEE53E1}) (Version: 1.0.0.0 - Samsung) SW Update (HKLM-x32\...\{DA06101F-FD76-4BF0-88BD-B26A197005E3}) (Version: 2.1.21 - Samsung Electronics CO., LTD.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.40.0 - Synaptics Incorporated) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.41459 - TeamViewer) The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.42.130 - Electronic Arts) Unity Web Player (HKU\S-1-5-21-3676795516-2390992231-3671279854-1000\...\UnityWebPlayer) (Version: 4.5.5f1 - Unity Technologies ApS) Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0415-1000-0000000FF1CE}_Office15.PROPLUS_{CF394926-359E-48E1-AA25-E56B32FCB335}) (Version: - Microsoft) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3676795516-2390992231-3671279854-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Juleczka\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3676795516-2390992231-3671279854-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Juleczka\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3676795516-2390992231-3671279854-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Juleczka\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3676795516-2390992231-3671279854-1000_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Juleczka\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) CustomCLSID: HKU\S-1-5-21-3676795516-2390992231-3671279854-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Juleczka\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3676795516-2390992231-3671279854-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Juleczka\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= ATTENTION: System Restore is disabled. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {04B7C703-B910-4A78-97E8-4C71FC5955B6} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-01-15] () Task: {05CD7182-99A6-417F-B4A8-ECA68A21F2F5} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {0BC0B3DE-93C3-4EE5-AE90-63E3A3480FF1} - System32\Tasks\{CE89B7B2-909A-40F7-868B-7E8660E7B808} => pcalua.exe -a "C:\Users\Juleczka\Downloads\wlsetup-web (2).exe" -d C:\Users\Juleczka\Downloads Task: {1CBD5F00-334B-487C-AFF8-4AB681BC0053} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics) Task: {238D3DB8-DFF3-4954-A343-AE67DDBC4D1B} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-05-02] (Samsung Electronics Co., Ltd.) Task: {245138B2-4FF7-4000-86B1-E266A496CB41} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {28FD8792-3645-4439-804C-2250C2C96DB4} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {2B49FFF3-5BC4-4C5A-B65C-E9830B25BFD3} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\SymErr.exe Task: {2CC488B4-BBEC-4D6C-BAAE-DCE4FD84AE29} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {30011D72-2588-4E3B-8B7F-D2F7CB5B1E72} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [2013-01-31] (Samsung Electronics CO., LTD.) Task: {38B576E5-A8D6-4165-A34D-C29E4AE112D8} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe [2012-01-31] (Samsung Electronics) Task: {464C15C8-64EA-4552-B443-71CCDE787C54} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-04-25] (Samsung Electronics Co., Ltd.) Task: {59E9FE9B-9720-4953-A4E4-FB379E1299B5} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.) Task: {62692435-C045-46AB-BB21-DEE7699F3E46} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-03] (Adobe Systems Incorporated) Task: {6B17117E-5331-47AB-ADE7-93839BCB2464} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {79F2029F-B7AF-4C67-8F17-8A38826CF3AC} - System32\Tasks\{9DC21278-363B-4CDD-84AB-32847C27BBFB} => pcalua.exe -a "C:\Users\Juleczka\Downloads\Shockwave_Installer_Slim (1).exe" -d C:\Users\Juleczka\Downloads Task: {7D9BEF53-3BA5-4168-82C8-FE7CFD3EF49E} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\WSCStub.exe Task: {8BA67676-92E2-45F0-A01E-5A02D9A26F29} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {8FCD7688-BF7A-446D-8AD5-972F2BC04C46} - System32\Tasks\GoogleUpdateTaskMachineCore1cf2aaccd0ff270 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-14] (Google Inc.) Task: {984DA026-9DA2-477D-BB55-D1310D76DE9A} - System32\Tasks\GoogleUpdateTaskMachineUA1cf90948f04922a => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-14] (Google Inc.) Task: {9B8C146B-1F4E-4F39-BE87-713A5FF5DB1D} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-05-30] (Samsung Electronics Co., Ltd.) Task: {A56C1ACA-A6B3-44A6-9478-F9C91E3B60EE} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {A7AB860B-5761-4F91-AEC4-4FA51A1CA145} - System32\Tasks\{16787399-11FF-4B00-A91F-D5FBB5CF4860} => Chrome.exe http://ui.skype.com/ui/0/6.16.0.105/pl/abandoninstall?source=lightinstaller&page=tsMain Task: {B5322265-ACE8-4F29-B835-C46F0303DE81} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2013-10-16] (Samsung Electronics CO., LTD.) Task: {CA998441-84A7-430D-B8CC-C5ECFF00EA23} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\SymErr.exe Task: {D48D9777-DEFC-45AF-88E7-931236043E61} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {DC32588B-FE6D-4427-B823-C55D4BCFE2BE} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.) Task: {E2BBCEF7-DFE5-40AB-A8E9-3A00A63FCEFF} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {E78C2322-B219-45B1-85C7-0DB367C32A0E} - System32\Tasks\{89A2373E-5DF0-44B8-B332-8D14454B55F4} => pcalua.exe -a C:\Users\Juleczka\Desktop\wlsetup-web.exe -d C:\Users\Juleczka\Desktop Task: {EE916BAE-AB78-4BD9-8BC4-063F881A6BDC} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {F1E66BA9-3B7D-4743-A928-FE8205A237C8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {F23B3ED5-2BB5-489D-9D4C-D673502F26B1} - System32\Tasks\{6E1A3841-5FF4-45F7-BE68-3D7CA3A8D99A} => pcalua.exe -a "C:\Program Files (x86)\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe" -c REMOVESERIALNUMBER="XM02-508X-MHAT-19WU-9Z3Z-0CH0-3U6E-85W5-MMHH-6647-1Z5L-7M8C-0U45-758P-0000" Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf2aaccd0ff270.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf90948f04922a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============== 2014-01-14 23:50 - 2012-02-07 19:03 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2014-01-15 07:27 - 2012-02-13 16:02 - 00031624 _____ () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe 2012-03-26 18:33 - 2012-03-26 18:33 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll 2014-01-15 07:28 - 2006-08-12 13:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll 2015-04-30 22:35 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-05-01 09:52 - 2015-04-28 04:07 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libglesv2.dll 2015-05-01 09:52 - 2015-04-28 04:07 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libegl.dll 2014-01-14 23:50 - 2012-02-07 18:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3676795516-2390992231-3671279854-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Juleczka\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 8.8.8.8 - 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (whitelisted) =============== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) FirewallRules: [{6D122482-FB8A-47C1-A249-33533686BCDC}] => (Allow) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe FirewallRules: [{B2FDA29B-4074-479F-BB62-5C11A4F6140C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{3F3F20B0-DF79-45E6-9DF1-739467511DDE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{262BEC30-4CB7-43BB-AF51-FB7BA163DB83}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{F2AFD8EB-7113-42A4-ADD8-4594C7C98386}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{2EA2AAE5-2A0B-4C1F-B234-64A9E2CE6E1D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{167B1894-D9D2-4501-8158-A5170768DAA5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{87E8D54F-0E12-42D8-8218-641AEFB444E2}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe FirewallRules: [{3D71ED59-7192-4C65-BC15-FFAA7BAD4574}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{D775AB80-52C9-4A0F-AF63-500DA84F2912}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{3E37B7B0-2606-4502-9135-4901A82C72EE}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{750B0274-9727-48E1-8476-03088304102E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{5FB3E693-8C5B-4DCD-AEA4-1C7221111855}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{6EAC4242-F38F-41F2-B104-4AC8D73F5B7B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{01083803-E466-4AC8-8A4E-98E7745276C0}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{07ED23CD-B4BA-4CED-8839-3D3D0ABA3C5C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{E3CD5947-CD7D-48CF-9185-DC20FAF4B5F7}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{24C05AAB-2D9E-4044-A386-8344E3246736}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{D1672B0B-016C-4455-80E7-5E43A8D1720A}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe FirewallRules: [{C471B5BB-1238-4050-86CD-75AE308C1041}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe FirewallRules: [{1997B968-9AAD-4401-B74F-00A6D593A232}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe FirewallRules: [{21F3C424-CA94-4CCA-99F6-C1723EFC8EE1}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe FirewallRules: [{BCD04760-2305-46D7-A667-CF5526DB8440}] => (Allow) C:\Users\Juleczka\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{95E57E35-7D28-4A9A-A923-89E2F15EEBF7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{069C96E7-B253-499C-AF3F-E845F97BA344}] => (Allow) LPort=2869 FirewallRules: [{58DACB32-0A2F-4A3C-BFAF-9FCAB1F71A4F}] => (Allow) LPort=1900 FirewallRules: [{D530E434-ACEB-4DAC-A07B-6CC6985CE874}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{E9334F37-5DC8-4941-AA41-8D3935EA1DEF}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{3FE6FA7D-8974-4F2A-8E12-9688254FC0B8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{F5DBDAD6-01C6-4AA6-AA8A-D4FBF65290EE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{FA2BDA59-351B-49F5-857C-50BD8F9C35BE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{F2A661DE-4513-474E-ADA9-E2E7E445E83F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (05/01/2015 00:00:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: NvStreamNetworkService.exe, wersja: 4.1.1943.6202, sygnatura czasowa: 0x551399be Nazwa modułu powodującego błąd: NvStreamNetworkService.exe, wersja: 4.1.1943.6202, sygnatura czasowa: 0x551399be Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000004e920f Identyfikator procesu powodującego błąd: 0xb28 Godzina uruchomienia aplikacji powodującej błąd: 0xNvStreamNetworkService.exe0 Ścieżka aplikacji powodującej błąd: NvStreamNetworkService.exe1 Ścieżka modułu powodującego błąd: NvStreamNetworkService.exe2 Identyfikator raportu: NvStreamNetworkService.exe3 Error: (05/01/2015 11:59:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: CommonAgent.exe, wersja: 1.1.4.5, sygnatura czasowa: 0x525e671b Nazwa modułu powodującego błąd: CommonAgent.exe, wersja: 1.1.4.5, sygnatura czasowa: 0x525e671b Kod wyjątku: 0x40000015 Przesunięcie błędu: 0x0000000000186865 Identyfikator procesu powodującego błąd: 0xc58 Godzina uruchomienia aplikacji powodującej błąd: 0xCommonAgent.exe0 Ścieżka aplikacji powodującej błąd: CommonAgent.exe1 Ścieżka modułu powodującego błąd: CommonAgent.exe2 Identyfikator raportu: CommonAgent.exe3 Error: (05/01/2015 11:59:50 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: MovieColorEnhancer.exe, wersja: 1.0.5.7, sygnatura czasowa: 0x4f9788e7 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000 Identyfikator procesu powodującego błąd: 0x960 Godzina uruchomienia aplikacji powodującej błąd: 0xMovieColorEnhancer.exe0 Ścieżka aplikacji powodującej błąd: MovieColorEnhancer.exe1 Ścieżka modułu powodującego błąd: MovieColorEnhancer.exe2 Identyfikator raportu: MovieColorEnhancer.exe3 Error: (05/01/2015 11:59:06 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2015 11:56:12 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (05/01/2015 11:11:59 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (05/01/2015 10:50:42 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (05/01/2015 09:45:43 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [0] Error: (05/01/2015 06:25:54 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [0] Error: (05/01/2015 00:06:39 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: CommonAgent.exe, wersja: 1.1.4.5, sygnatura czasowa: 0x525e671b Nazwa modułu powodującego błąd: CommonAgent.exe, wersja: 1.1.4.5, sygnatura czasowa: 0x525e671b Kod wyjątku: 0x40000015 Przesunięcie błędu: 0x0000000000186865 Identyfikator procesu powodującego błąd: 0xb4c Godzina uruchomienia aplikacji powodującej błąd: 0xCommonAgent.exe0 Ścieżka aplikacji powodującej błąd: CommonAgent.exe1 Ścieżka modułu powodującego błąd: CommonAgent.exe2 Identyfikator raportu: CommonAgent.exe3 System errors: ============= Error: (05/01/2015 11:58:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Update Mgr RollAround z powodu następującego błędu: %%2 Error: (05/01/2015 11:58:16 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Usługa InCD Helper zakończyła działanie; wystąpił specyficzny dla niej błąd %%1. Error: (05/01/2015 11:56:53 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Ładowanie sterownika \SystemRoot\SysWow64\Drivers\InCDrec.SYS zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Error: (05/01/2015 09:50:12 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Usługa ESET Service jest oznaczona jako usługa interakcyjna. System jest jednak skonfigurowany tak, aby nie zezwalać na usługi interakcyjne, dlatego ta usługa może nie działać właściwie. Error: (05/01/2015 00:05:31 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Intel(R) PROSet/Wireless Zero Configuration Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (05/01/2015 00:03:27 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Update Mgr RollAround z powodu następującego błędu: %%2 Error: (05/01/2015 00:02:48 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Usługa InCD Helper zakończyła działanie; wystąpił specyficzny dla niej błąd %%1. Error: (05/01/2015 00:02:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Intel(R) PROSet/Wireless Event Log z powodu następującego błędu: %%1053 Error: (05/01/2015 00:02:36 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Intel(R) PROSet/Wireless Event Log. Error: (05/01/2015 00:00:40 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Ładowanie sterownika \SystemRoot\SysWow64\Drivers\InCDrec.SYS zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Microsoft Office Sessions: ========================= Error: (05/01/2015 00:00:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1943.6202551399beNvStreamNetworkService.exe4.1.1943.6202551399bec000000500000000004e920fb2801d083f564139e54C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exedc19040b-efe8-11e4-bdda-c48508131711 Error: (05/01/2015 11:59:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: CommonAgent.exe1.1.4.5525e671bCommonAgent.exe1.1.4.5525e671b400000150000000000186865c5801d083f56eb6c48dC:\Program Files\Samsung\S Agent\CommonAgent.exeC:\Program Files\Samsung\S Agent\CommonAgent.exed2109744-efe8-11e4-bdda-c48508131711 Error: (05/01/2015 11:59:50 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: MovieColorEnhancer.exe1.0.5.74f9788e7unknown0.0.0.000000000c00000050000000096001d083f55a0ff44dC:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exeunknowncdf939cb-efe8-11e4-bdda-c48508131711 Error: (05/01/2015 11:59:06 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2015 11:56:12 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (05/01/2015 11:11:59 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (05/01/2015 10:50:42 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [6] Error: (05/01/2015 09:45:43 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [0] Error: (05/01/2015 06:25:54 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [0] Error: (05/01/2015 00:06:39 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: CommonAgent.exe1.1.4.5525e671bCommonAgent.exe1.1.4.5525e671b400000150000000000186865b4c01d083915f9c84f8C:\Program Files\Samsung\S Agent\CommonAgent.exeC:\Program Files\Samsung\S Agent\CommonAgent.exe2c72d8dd-ef85-11e4-b666-c48508131711 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz Percentage of memory in use: 49% Total physical RAM: 6041.27 MB Available physical RAM: 3037.25 MB Total Pagefile: 12080.74 MB Available Pagefile: 8648.72 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:390.62 GB) (Free:322.35 GB) NTFS Drive d: () (Fixed) (Total:540.79 GB) (Free:540.68 GB) NTFS Drive e: (Sylwia Wiesenberg) (CDROM) (Total:4.2 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 342B3C67) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=390.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=540.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================