Additional scan result of Farbar Recovery Scan Tool (x64) Version:08-06-2015 Ran by Duda at 2015-06-08 21:16:53 Running from C:\Users\Duda\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2435897020-3182320802-3336853129-500 - Administrator - Disabled) Duda (S-1-5-21-2435897020-3182320802-3336853129-1001 - Administrator - Enabled) => C:\Users\Duda Gość (S-1-5-21-2435897020-3182320802-3336853129-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton Internet Security (Disabled - Out of date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Disabled - Out of date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Norton Internet Security (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-2435897020-3182320802-3336853129-1001\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.) AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden Aktualizacja produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{04E205D6-88B1-4652-B162-42DF2C3B1228}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{442ECBCF-94A7-48CC-8CD9-D31FFFD5FA86}) (Version: - Microsoft) Aktualizacja produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{128A36ED-21BE-4547-9FFE-5B85AEC735DD}) (Version: - Microsoft) AMD Catalyst Install Manager (HKLM\...\{49F51ACB-7CDD-3728-1E9E-49398FF8BA95}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) Angry Birds Seasons (HKLM-x32\...\{9E4F7DD0-C596-4501-AE16-77F18F7EE694}) (Version: 1.5.1 - Rovio) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB) Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.66.1075 - AB Team, d.o.o.) BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) Centrum obsługi urządzeń z systemem Windows Mobile (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Connected Music powered by Universal Music Group version 1.0 (HKLM-x32\...\{46037DC7-F927-46DF-935F-D6F122BDD34B}_is1) (Version: 1.0 - Snowite) Copy (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2.5712 - CyberLink Corp.) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.2.2114 - CyberLink Corp.) CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.2.2110 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.) CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.7.4528 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden Diablo II (HKLM-x32\...\Diablo II) (Version: - ) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) DJ_AIO_NS_LP_DocCD (x32 Version: 90.0.222.000 - Hewlett-Packard) Hidden DJ_AIO_ProductContext (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden DJ_AIO_Software (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden DJ_AIO_Software_min (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden DocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) Hidden Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) F4100 (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden F4100_Help (x32 Version: 90.0.222.000 - Hewlett-Packard) Hidden Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Galeria fotografii (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP 3D DriveGuard (HKLM\...\{9F92182D-24EB-4A4E-A318-E3E8011EF638}) (Version: 4.2.9.1 - Hewlett-Packard Company) HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd) HP Connected Remote (HKLM-x32\...\{F243A34B-AB7F-4065-B770-B85B767C247C}) (Version: 1.0.1218 - Hewlett-Packard) HP CoolSense (HKLM-x32\...\{59F8C5AA-91BD-423D-BF05-09A80F39898F}) (Version: 2.10.62 - Hewlett-Packard Company) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Deskjet All-In-One Software (HKLM\...\{2CB8566A-8EA6-417A-BAB1-1B10A88C79BB}) (Version: 14.0 - HP) HP Documentation (HKLM-x32\...\{23C74C03-680C-455D-933F-5BC8683CAE52}) (Version: 1.2.0.0 - Hewlett-Packard) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Quick Launch (HKLM-x32\...\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company) HP Registration Service (HKLM\...\{C2E428EB-116E-41C0-9E84-B22DE9CCA42F}) (Version: 1.1.6232.4245 - Hewlett-Packard) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Support Solutions Framework (HKLM-x32\...\{C43602FE-988C-47BA-9F9F-B95FDDAFB624}) (Version: 11.50.0031 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.8 - Hewlett-Packard) HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company) HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.9.1002 - Intel Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MarketResearch (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-2435897020-3182320802-3336853129-1001\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 38.0.5 (x86 pl) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 pl)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MyDriveConnect 4.0.0.2117 (HKLM-x32\...\MyDriveConnect) (Version: 4.0.0.2117 - TomTom) Norton Internet Security (HKLM-x32\...\NIS) (Version: 20.6.0.27 - Symantec Corporation) NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation) OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP) Origin (HKLM-x32\...\Origin) (Version: 9.4.7.2799 - Electronic Arts, Inc.) Poczta usługi Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Ralink Bluetooth Stack64 (HKLM\...\{95DF815D-BE2D-9118-F549-39794C5869CF}) (Version: 9.0.725.0 - Nazwa firmy) Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.5.0 - Ralink) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.) SAMSUNG PC Share Manager (HKLM-x32\...\InstallShield_{2A2E822B-3B0E-46C1-9E3B-ACD7D1E95139}) (Version: 4.0 - SAMSUNG) SAMSUNG PC Share Manager (x32 Version: 4.0 - SAMSUNG) Hidden Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) Software Informer 1.2 (HKLM\...\Software Informer_is1) (Version: - Informer Technologies, Inc.) SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.5.3.3 - Synaptics Incorporated) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.65 - Nullsoft, Inc) WinRAR 5.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Worms Revolution (HKLM-x32\...\Worms Revolution_is1) (Version: - ) Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2435897020-3182320802-3336853129-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-2435897020-3182320802-3336853129-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Duda\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2435897020-3182320802-3336853129-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Duda\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2435897020-3182320802-3336853129-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Duda\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2435897020-3182320802-3336853129-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Duda\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2435897020-3182320802-3336853129-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Duda\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 19-04-2015 18:04:46 Windows Update 12-05-2015 11:09:27 Zaplanowany punkt kontrolny 17-05-2015 16:58:39 Windows Update 25-05-2015 10:36:24 Zaplanowany punkt kontrolny 07-06-2015 19:21:12 Windows Update ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2014-08-22 15:14 - 2014-08-22 15:14 - 00000035 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {00991AB5-6C92-4200-A0DA-55167D5A4A07} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink) Task: {0A9997EA-58FE-43E3-B580-8E1DF4970612} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {0F04096B-7721-4DBF-B1A5-0A61C7267718} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {1398A86A-3E35-48AE-B56F-3F822130D878} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {1614702A-2710-47D8-B74B-DD6D40ED0676} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink) Task: {170DF191-5DEF-4E40-812A-D94EF3C16EDD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {197688E4-24D0-4A5D-A560-1482EFD691E3} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\WSCStub.exe [2014-12-06] (Symantec Corporation) Task: {250BFC7D-A5FE-4FD2-8BCF-0E61EA488ED5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {2FE2B83D-BD40-4F63-9943-627617857CE5} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {3DA5D261-24D0-474F-A63E-C91FFD0232B2} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation) Task: {426EBC03-2932-4BCA-A753-C7B4EC9680E5} - System32\Tasks\SoftwareInformerService => C:\Program Files\Software Informer\softinfo.exe [2013-11-26] (Informer Technologies, Inc.) Task: {438BE109-C87B-4B62-ABE9-AB6C24643CDF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-20] (Google Inc.) Task: {451B9320-26BF-467C-BA5D-CF8FB71C4DF5} - System32\Tasks\{A0FA0018-CF7F-479E-AE71-3BEE62F3B91F} => pcalua.exe -a F:\DirectX\dxsetup.exe -d F:\DirectX Task: {49B4337A-F4E4-4CC4-B935-F68FA6853830} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2435897020-3182320802-3336853129-1001UA => C:\Users\Duda\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-18] (Facebook Inc.) Task: {57DEF215-3B31-4255-8890-12E033DD6DDD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {606143B0-859E-41B5-A26C-AC60971DB053} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {642AD54F-8B60-4098-B366-E5634B1B5CFA} - System32\Tasks\HPCeeScheduleForDuda => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) Task: {80A92481-290D-48C4-8559-A649E6B07D6B} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-06-07] (Hewlett-Packard Development Company, L.P.) Task: {83B7CB7C-F03C-4E62-ABB2-1A2E74EACCC0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {A1FB4559-7B7C-49AA-8075-779C5D555A49} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-04-14] (Hewlett-Packard) Task: {AF4AEE2C-1328-4287-B0C7-9E960636A93E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-27] (Adobe Systems Incorporated) Task: {D1D4A399-3030-4DF6-BA31-0AB36129CBDF} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {E44F17EA-553D-49D1-8023-325B7449CC57} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-04-14] (Hewlett-Packard) Task: {E7D80C32-D11D-4D97-8ADE-3704046A3E20} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-05-17] (Microsoft Corporation) Task: {F061B595-536D-4220-A101-6804C82BF1A4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2435897020-3182320802-3336853129-1001Core => C:\Users\Duda\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-18] (Facebook Inc.) Task: {F8704644-A112-4EFF-8B6D-970ACC60A834} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-20] (Google Inc.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2435897020-3182320802-3336853129-1001Core.job => C:\Users\Duda\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2435897020-3182320802-3336853129-1001UA.job => C:\Users\Duda\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForDuda.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Loaded Modules (Whitelisted) ============== 2014-05-31 08:32 - 2014-08-17 14:13 - 00076152 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2012-09-19 19:37 - 2012-09-19 19:37 - 00017160 _____ () C:\Windows\system32\BsHelpCSps.dll 2012-10-12 18:22 - 2012-10-12 18:22 - 00120224 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPItunesModule.dll 2012-10-12 18:22 - 2012-10-12 18:22 - 00048544 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPItunesProxy.dll 2012-10-12 18:22 - 2012-10-12 18:22 - 00180224 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\zxing.dll 2012-09-19 19:37 - 2012-09-19 19:37 - 00029960 _____ () C:\Windows\system32\BsTrace.dll 2015-02-23 15:55 - 2015-02-23 15:55 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\952624f5942fdcd80e5cbd9dfdfdf257\PSIClient.ni.dll 2012-09-19 19:37 - 2012-09-19 19:37 - 00029960 _____ () C:\Windows\SYSTEM32\BsTrace.dll 2012-12-28 03:25 - 2012-06-25 20:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2012-09-19 19:37 - 2012-09-19 19:37 - 00029960 _____ () C:\WINDOWS\SYSTEM32\BsTrace.dll 2012-09-19 19:37 - 2012-09-19 19:37 - 00062216 _____ () C:\Windows\SYSTEM32\BlueSoleilCSps.dll 2012-09-19 19:37 - 2012-09-19 19:37 - 00017160 _____ () C:\Windows\SYSTEM32\BsHelpCSps.dll 2012-09-24 15:27 - 2012-09-24 15:27 - 00335176 _____ () C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\Driver\USB\tl_filter.dll 2012-05-02 18:28 - 2012-05-02 18:28 - 00012800 _____ () C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\Driver\AMP\IVTAMPRL.dll 2014-03-31 21:35 - 2014-03-31 21:35 - 00286400 _____ () C:\Program Files (x86)\Windows Live\Writer\pl\WindowsLive.Writer.Localization.resources.dll 2014-04-17 22:13 - 2014-04-17 22:13 - 00080896 _____ () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraPlk.dll 2012-12-28 03:45 - 2012-06-08 05:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2435897020-3182320802-3336853129-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Duda\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk" HKLM\...\StartupApproved\Run: => "Zune Launcher" HKLM\...\StartupApproved\Run32: => "CLVirtualDrive" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKLM\...\StartupApproved\Run32: => "HP Quick Launch" HKLM\...\StartupApproved\Run32: => "NCPluginUpdater" HKLM\...\StartupApproved\Run32: => "Windows Mobile Device Center" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKU\S-1-5-21-2435897020-3182320802-3336853129-1001\...\StartupApproved\Run: => "SkyDrive" HKU\S-1-5-21-2435897020-3182320802-3336853129-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{C4345E20-BE51-45A5-B585-895665090B45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{9813551B-8283-43DC-A748-7339696479E5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [UDP Query User{968E7E2D-86E2-4915-AEBA-17849E900E78}C:\users\duda\downloads\utorrent.exe] => (Block) C:\users\duda\downloads\utorrent.exe FirewallRules: [TCP Query User{86146B2C-1F8B-4E35-A976-4B5FD827DA3E}C:\users\duda\downloads\utorrent.exe] => (Block) C:\users\duda\downloads\utorrent.exe FirewallRules: [{BC9F18AA-01AA-453F-BFA0-2ABF7C47D909}] => (Allow) C:\Users\Duda\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{AF157090-A441-4852-8CF3-4CFB23541592}] => (Allow) C:\Users\Duda\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{F0F60146-8DBF-4078-AF33-AF51212F1888}] => (Allow) C:\Users\Duda\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe FirewallRules: [{F6CFA0CD-18CA-4732-9EBF-AE3353BA441F}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{FECFDBC4-86D7-4DF1-AB06-FD51DB7BD13E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{1919531B-EF18-4C82-955C-B3E21A31F761}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{91ED034F-5232-4F6F-BCC4-58D71362FAEA}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{E66319CC-F53E-485B-81AA-D326B9C06B8F}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{21459304-CC35-41DB-B43C-8D29E46A6BA1}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{91C06438-A336-4C1A-B617-1A82BD9A3D66}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{8713CC4D-10AF-45B7-92D6-BF773B5CC49D}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{47DDEE03-F0E8-4097-A291-26C667D15859}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{A99C2025-7627-4861-A287-0B7FBF0C51CC}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{46E940EC-B698-46FE-86C3-812E999414D5}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPPSdr\HPDiagnosticCoreUI.exe FirewallRules: [{6ED33F9D-19BB-4485-8115-70C4436C0825}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPPSdr\HPDiagnosticCoreUI.exe FirewallRules: [{B9A69687-2E97-44D4-8320-AD67A3EF29D8}] => (Allow) LPort=1900 FirewallRules: [{3A65E69C-FF9D-4FCD-A443-852E1F473AC0}] => (Allow) LPort=2869 FirewallRules: [{21F90AAC-AF05-46A6-9A53-E4272CE76ED9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{8468E8EF-DB66-4987-AA9F-ED879778D47B}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{D48D94B2-7784-4414-8E8E-561E33ECED12}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{B205175F-B74B-4CDC-8726-150B73EDCAE5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{377E2FD0-0DE2-45F5-B8AF-C0C390083428}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{CFA00776-01C9-4F8F-AC72-5D7B8C50D10F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{615472C2-105C-48E3-9FAA-D840478509FB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [UDP Query User{A06D088A-1433-479E-AE7A-564E9E24E455}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{462D5E45-6D8F-4626-9BEC-FD37CBA51C9B}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [{EEF1831C-37BD-4533-B866-A83B34580A56}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{4D46ED47-36FC-4401-AC0B-04EB7788B72A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{45BAB7E4-1192-4545-8757-172602896C63}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{47D2B787-2B14-4E69-A360-D6726BE96B0A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{B05B706F-3982-470F-AFA6-831A7204811C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{93DF4921-65B4-4F83-B6E0-1178811B24AC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{489F2A00-45B4-4127-AC0A-3E125608128C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe FirewallRules: [{02796E91-1057-4EF0-AAB2-28378F0A185F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{6DE73CD6-600A-4043-921F-FFB09C1119BB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{B6E73221-B4F7-4884-A4B9-F06139842A08}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{CB73CE75-ADA8-4BE3-BAD8-24F1B057604F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{CB1928AB-918B-44D3-B3D2-F9182C3D81FD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{CD314033-EFCD-4487-89E7-3952A90B84E0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [UDP Query User{7D495A08-35BC-44A6-8377-A54FA261EC6F}C:\program files (x86)\worms revolution\wormsrevolution.exe] => (Block) C:\program files (x86)\worms revolution\wormsrevolution.exe FirewallRules: [TCP Query User{29056062-5879-4611-A1D5-712495F1B009}C:\program files (x86)\worms revolution\wormsrevolution.exe] => (Block) C:\program files (x86)\worms revolution\wormsrevolution.exe FirewallRules: [UDP Query User{40A883FE-0F90-4FFF-8C5F-BC28DDCF157A}C:\windows\syswow64\svchost.exe] => (Block) C:\windows\syswow64\svchost.exe FirewallRules: [TCP Query User{DB33C91A-3BEE-4560-A413-97B831E4806D}C:\windows\syswow64\svchost.exe] => (Block) C:\windows\syswow64\svchost.exe FirewallRules: [UDP Query User{3EA18976-48B7-4708-BCDC-75C7283D3A26}C:\program files (x86)\ea games\need for speed most wanted\nfs13.exe] => (Allow) C:\program files (x86)\ea games\need for speed most wanted\nfs13.exe FirewallRules: [TCP Query User{21757D0E-C115-4DBA-9335-CBE47DA83F7E}C:\program files (x86)\ea games\need for speed most wanted\nfs13.exe] => (Allow) C:\program files (x86)\ea games\need for speed most wanted\nfs13.exe FirewallRules: [{47E3937E-765F-4269-B445-A0C27E8E95CF}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{CCAD6EEC-0EC0-419E-8559-1AE81134FFDF}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{4D4B03C1-BDE7-424A-8FF5-150F2505A3E2}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{66F4C29D-DEF2-416D-ACA6-770C91961183}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{5B07ADA7-28C7-4748-AE35-C034933AC5DF}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{ACA4C3D8-A272-4906-B59E-071BC52F828E}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{F260A5A6-7220-479B-9E60-1437B0954F81}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{C096AB44-4DAF-4797-9932-266CEE69E768}] => (Allow) %ProgramFiles%\Zune\ZuneNSS.exe FirewallRules: [{DAEB98A4-FE6E-4435-BFAE-819B1B80A96E}] => (Allow) %ProgramFiles%\Zune\Zune.exe FirewallRules: [{8332744E-F0B8-4333-862C-26CCC4A322C9}] => (Allow) C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe FirewallRules: [{32EDC5AC-C1A3-4AA4-82D0-8596BEC9F96E}] => (Allow) C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe FirewallRules: [{05C246E6-B1A0-4381-B9AD-55F0D9355100}] => (Allow) C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe FirewallRules: [{4B4CF6E2-2FED-4E48-88AA-EABD0706CE2D}] => (Allow) C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe FirewallRules: [{3AFCD7B5-76E5-4947-8847-2DDA74160056}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{E7224157-0417-48AF-A1C9-70CA0204B890}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [UDP Query User{47B29980-C18E-4041-B592-88C13329B33F}C:\windows\syswow64\svchost.exe] => (Block) C:\windows\syswow64\svchost.exe FirewallRules: [TCP Query User{E58A2DA5-F62D-446D-B20B-E35480C6BE65}C:\windows\syswow64\svchost.exe] => (Block) C:\windows\syswow64\svchost.exe FirewallRules: [{7D514CB6-5CE4-41F8-8ACE-99AAEC9C69AD}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [{3B149B1E-F5F3-4045-8FDF-72A82EE449B9}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [{CFFBE7F7-60BB-4FA4-AEEA-03F3C4A245C6}] => (Allow) C:\Users\Duda\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{F68A79ED-44E7-444B-874E-3A4B3281953A}] => (Allow) C:\Users\Duda\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{2746C8CF-E79A-4474-BE5C-F9FC0E95A79D}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{E7F979B8-26BA-43ED-B721-E968226A2C94}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{6C4C0577-BB73-47F4-81E1-BA39D2A24AAD}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{55A195A0-E968-40FB-9889-652010DEDA80}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{ACB0D9EE-A8CD-4D12-BB87-FEADC592143B}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [{566913F0-D7DB-4858-9049-7554CF2CC0ED}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [{CEBD78F8-455A-43BB-8008-0CDD27DD262B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{51B1B655-F390-4A10-BB74-357E5A6DE3F3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{371F668D-030A-45A9-903B-BC073DEE3F4E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7534428D-9BA5-4FA7-BF30-3EFE5354C3D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{BE80F010-1744-4499-99D7-9158F902168A}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe FirewallRules: [{E05E4295-5362-4A66-9380-FA52B6220714}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe FirewallRules: [{5E6056D5-1890-4F7D-AB84-17E3E6506847}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [{5BBFC1F4-24F0-4191-8703-BC3DDC6C6007}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [TCP Query User{D82286A1-E07E-4AFA-ACE1-2212E27E9D60}C:\program files (x86)\origin games\fifa world\fifaworld.exe] => (Allow) C:\program files (x86)\origin games\fifa world\fifaworld.exe FirewallRules: [UDP Query User{63FED418-311C-4AC7-BB7D-C7116ED9678D}C:\program files (x86)\origin games\fifa world\fifaworld.exe] => (Allow) C:\program files (x86)\origin games\fifa world\fifaworld.exe FirewallRules: [{EC9B19DF-2C69-475D-81C6-B7A30CEDA354}] => (Allow) LPort=53000 FirewallRules: [{79F430BC-37CF-4572-B3B2-BE74A647EBC1}] => (Allow) LPort=52000 FirewallRules: [{9489130E-B6B1-42FB-B0AB-BEC055424466}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/07/2015 08:16:39 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest1”. Błąd w pliku manifestu lub w pliku zasad „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest2” w wierszu C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest3. Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna. Składniki powodujące konflikt: Składnik 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest. Składnik 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_624760d1ecb7236e.manifest. Error: (06/07/2015 08:16:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program backgroundTaskHost.exe w wersji 6.3.9600.17415 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 113c Godzina rozpoczęcia: 01d0a14d5d2ebfb5 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\WINDOWS\system32\backgroundTaskHost.exe Identyfikator raportu: 512e699a-0d41-11e5-bed3-f4b7e2051e5e Pełna nazwa pakietu powodującego błąd: 12199Asparion.AsparionClock_3.5.1.53_neutral__f89vgcf3qm37t Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (06/07/2015 08:08:49 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest1”. Błąd w pliku manifestu lub w pliku zasad „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest2” w wierszu C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest3. Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna. Składniki powodujące konflikt: Składnik 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest. Składnik 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_624760d1ecb7236e.manifest. Error: (06/07/2015 07:45:44 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program LiveComm.exe w wersji 17.5.9600.20856 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: abc Godzina rozpoczęcia: 01d0a14713d9ab31 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\LiveComm.exe Identyfikator raportu: 07e8d30a-0d3b-11e5-bed3-f4b7e2051e5e Pełna nazwa pakietu powodującego błąd: microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe Identyfikator aplikacji względem pakietu powodującego błąd: ppleae38af2e007f4358a809ac99a64a67c1 Error: (06/07/2015 07:31:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program backgroundTaskHost.exe w wersji 6.3.9600.17415 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 11ac Godzina rozpoczęcia: 01d0a14713d9ab31 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\WINDOWS\system32\backgroundTaskHost.exe Identyfikator raportu: 07e8fa1a-0d3b-11e5-bed3-f4b7e2051e5e Pełna nazwa pakietu powodującego błąd: 12199Asparion.AsparionClock_3.5.1.53_neutral__f89vgcf3qm37t Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (06/07/2015 07:30:23 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest1”. Błąd w pliku manifestu lub w pliku zasad „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest2” w wierszu C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest3. Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna. Składniki powodujące konflikt: Składnik 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest. Składnik 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_624760d1ecb7236e.manifest. Error: (06/01/2015 08:11:04 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Nie można wygenerować kontekstu aktywacji dla „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest1”. Błąd w pliku manifestu lub w pliku zasad „C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest2” w wierszu C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest3. Wersja składnika wymagana przez aplikację powoduje konflikt z inną wersją składnika, która jest już aktywna. Składniki powodujące konflikt: Składnik 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_a9f497a901334c74.manifest. Składnik 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17784_none_624760d1ecb7236e.manifest. Error: (05/30/2015 06:26:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2759282 Error: (05/30/2015 06:26:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2759282 Error: (05/30/2015 06:26:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (06/07/2015 07:21:45 PM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (06/07/2015 07:21:13 PM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (06/03/2015 07:28:02 AM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/03/2015 07:28:02 AM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/03/2015 07:28:00 AM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/03/2015 07:28:00 AM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/02/2015 07:30:45 PM) (Source: BTHUSB) (EventID: 17) (User: ) Description: W lokalnym adapterze Bluetooth wystąpił nieokreślony błąd. Adapter nie będzie używany. Sterownik został usunięty z pamięci. Error: (06/01/2015 09:58:02 AM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/01/2015 09:58:02 AM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (06/01/2015 09:58:00 AM) (Source: DCOM) (EventID: 10010) (User: Dud) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Microsoft Office: ========================= Error: (06/05/2014 02:51:34 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1010 seconds with 420 seconds of active time. This session ended with a crash. Error: (06/05/2014 02:17:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/04/2014 09:38:38 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 5482 seconds with 0 seconds of active time. This session ended with a crash. Error: (04/04/2014 09:18:47 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 493 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-06-07 21:19:44.139 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:43.967 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:43.827 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:43.702 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:43.467 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:43.342 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:43.217 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:43.092 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:42.905 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-07 21:19:42.780 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz Percentage of memory in use: 37% Total physical RAM: 6036.27 MB Available physical RAM: 3768.23 MB Total Pagefile: 6996.27 MB Available Pagefile: 4240.71 MB Total Virtual: 131072 MB Available Virtual: 131071.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:913.6 GB) (Free:703.05 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:16.7 GB) (Free:2.15 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 873B541F) Partition: GPT Partition Type. ==================== End of log ============================