Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by woint at 2015-06-25 17:39:33 Running from C:\Users\woint\Desktop\naprawa komputera Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3379811810-2905435290-2568296203-500 - Administrator - Disabled) Guest (S-1-5-21-3379811810-2905435290-2568296203-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3379811810-2905435290-2568296203-1002 - Limited - Enabled) woint (S-1-5-21-3379811810-2905435290-2568296203-1001 - Administrator - Enabled) => C:\Users\woint ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3379811810-2905435290-2568296203-1001\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.) Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.190 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.190 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Aslain's WoT Modpack wersja 4.4.8 (HKLM-x32\...\ZRwTINhSZfduKONYrSCTiCiGPggQZdcLRvoAVxyCOXXpkHeC~1DC3968F_is1) (Version: 4.4.8 - Aslain) AVG 2015 (Version: 15.0.4365 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.5961 - AVG Technologies) Hidden Avira (HKLM-x32\...\{8467e01f-0496-42ce-b247-88ef205b4880}) (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG) Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 1.6.10.1246 - Avira Operations GmbH & Co. KG) CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform) Cities Skylines (HKLM-x32\...\Cities Skylines_is1) (Version: 1.0 - Релиз от R.G. Steamgames) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) EA SPORTS Game Face Browser Plugin 1.8.0.0 (HKU\S-1-5-21-3379811810-2905435290-2568296203-1001\...\EA SPORTS Game Face Browser Plugin) (Version: 1.8.0.0 - Electronic Arts) FTL - Advanced Edition (HKLM-x32\...\GOGPACKFTL_is1) (Version: 2.1.0.11 - GOG.com) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 38.0.5 (x86 pl) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 pl)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) NapiProjekt (2.2.0.2399) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Nosgoth (HKLM-x32\...\Steam App 200110) (Version: 150114.100101 - Square Enix Ltd) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge) Pillars of Eternity (HKLM-x32\...\1207666813_is1) (Version: 2.0.0.1 - GOG.com) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation) Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.101 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) SteelSeries Engine (HKLM\...\SteelSeries Engine) (Version: 2.9.2014.1 - SteelSeries) SteelSeries Engine 3.3.2 (HKLM\...\SteelSeries Engine 3) (Version: 3.3.2 - SteelSeries ApS) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.0.632 - Electronic Arts) This War of Mine (HKLM-x32\...\{5FD7B6B3-08C7-4FEE-9C37-A2134C699885}}_is1) (Version: 1 - 11 bit studios) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) WinRAR 5.01 (32-bitowy) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {01A1BA28-21A7-4655-897F-0860F8451F4F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-25] (Adobe Systems Incorporated) Task: {0B149BF8-46DA-4A2A-88DF-C72124C719EA} - System32\Tasks\AviraSpeedup => C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe [2015-06-17] (Avira Operations GmbH & Co. KG) Task: {0F7519C7-4BBB-4D01-8B2F-4AFCD1EE3A26} - System32\Tasks\{325E77B6-CBC1-4448-AC8E-87C74177DD6A} => pcalua.exe -a "C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe" -c /AppMode=SETUP /Uninstall /UDS=1 Task: {12D0215A-86D6-41B7-BD5F-25196866EBD9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd) Task: {40B4AF06-AE5A-46D6-B324-D10F8CD78632} - System32\Tasks\{08131310-980E-4A7E-8663-E8FAF1A3A52B} => Firefox.exe http://ui.skype.com/ui/0/6.14.59.104/pl/abandoninstall?page=tsBing Task: {4C477156-51A2-4762-B739-E14B9F142371} - System32\Tasks\{B0BD1CC9-7BFA-4DE0-9CB8-0DA9597D0CB4} => pcalua.exe -a C:\Users\woint\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=smt Task: {A79BE1B3-A049-4CC8-A9FB-FB96B868C2BD} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2014-03-26] (Microsoft Corporation) Task: {C782A205-BE92-4D0B-8F6F-FC20910E236C} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {CF43F35A-50E9-4652-AD1C-3F72E246585D} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {D23AD63D-C2B2-4F46-AA12-3A01F0998E0A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated) Task: {FC4696CA-1264-4E41-87AD-F24ED2774E37} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (Whitelisted) ============== 2010-01-09 21:17 - 2010-01-09 21:17 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 02:40 - 2010-01-21 02:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00504832 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SSEngineLib.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 09315328 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SSEngineWinGui.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00015872 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\Localization.dll 2014-10-09 21:43 - 2014-10-09 21:43 - 00011264 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\ISSPlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00011264 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\Utilities.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00115200 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\DriverCommunication.dll 2014-10-08 17:30 - 2014-10-08 17:30 - 00047616 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesDrivers\x2api.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00034304 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\DBUtils.dll 2014-10-08 17:30 - 2014-10-08 17:30 - 01102336 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\System.Data.SQLite.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00189440 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\MousePlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00030720 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\D3MousePlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00031744 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\KKMousePlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00030720 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SRawPlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00159744 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\MLGSenseiPlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00020992 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\WoWGoldPlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00030720 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\GW2MousePlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00029696 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\CSGOMousePlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00030208 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\DOTA2MousePlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00023040 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\WoWWirelessPlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00030720 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\CODMousePlugin.dll 2014-10-09 21:44 - 2014-10-09 21:44 - 00030208 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\WoTMousePlugin.dll 2015-01-08 23:37 - 2015-01-08 23:37 - 17833984 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe 2015-01-03 19:28 - 2015-01-03 19:28 - 00047616 _____ () C:\Program Files\SteelSeries\SteelSeries Engine 3\x2api.dll 2010-01-09 21:18 - 2010-01-09 21:18 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 02:34 - 2010-01-21 02:34 - 08793952 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2015-06-25 09:24 - 2015-06-25 09:24 - 16867504 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3379811810-2905435290-2568296203-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\woint\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 8.8.8.8 - 8.8.4.4 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{4C5A5100-1384-476A-97E5-F62FE0F10941}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3C603C66-98D1-4609-9A7C-EEE335CB26DE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{4B780665-1820-4394-9654-69AF202D1C8C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{C78B0E21-8ABF-4E61-A8F9-CFACCC146932}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{DB090738-6017-40AE-A6D5-8AFBA0A473D4}] => (Allow) C:\Users\woint\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{FF37D836-9F66-4F4D-B223-AAE9942C715D}] => (Allow) C:\Users\woint\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{55A4112C-3664-40D6-9533-C9B93E39D1B8}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{F64BC11C-7D0B-4E68-8CCE-3948B49CEAAA}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [TCP Query User{3E1A12FC-07F4-4E12-A059-990DF086E537}C:\games\wotlauncher.exe] => (Allow) C:\games\wotlauncher.exe FirewallRules: [UDP Query User{C01C6419-FBDE-45A5-AD5D-AF1EA3D292B3}C:\games\wotlauncher.exe] => (Allow) C:\games\wotlauncher.exe FirewallRules: [TCP Query User{EFF1F436-C1C9-4A9D-BC65-498920B05B25}C:\games\worldoftanks.exe] => (Allow) C:\games\worldoftanks.exe FirewallRules: [UDP Query User{0074A6B8-CDCA-47A3-9D47-063F28788BEC}C:\games\worldoftanks.exe] => (Allow) C:\games\worldoftanks.exe FirewallRules: [{E0B5B6FF-ABD3-4285-B3B0-3D0F5B6E45C0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{6413F636-FE1B-4769-A6A4-5385D97D6682}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{F86FC1B6-7B14-4291-8D82-5B11F75E2429}] => (Allow) C:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{8881DD00-0084-469E-8A8D-6EFBF4B0AF38}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{6DB09998-A788-472F-8CE5-065979EC55B2}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{CC701326-39FB-43F4-9B03-AD9808E1F11D}] => (Allow) D:\GRY\stimowe\SteamApps\common\nosgoth\Binaries\Win32\Nosgoth.exe FirewallRules: [{8913DEEC-F16A-4F96-B569-2A77BE38D33B}] => (Allow) D:\GRY\stimowe\SteamApps\common\nosgoth\Binaries\Win32\Nosgoth.exe FirewallRules: [{D0748159-6547-4464-AB89-BDA07C01F6B1}] => (Allow) D:\GRY\stimowe\SteamApps\common\nosgoth\Binaries\Win32\Nosgoth.exe FirewallRules: [{7581FF6E-16EA-4A63-8BC4-2EC0E3D8C868}] => (Allow) D:\GRY\stimowe\SteamApps\common\nosgoth\Binaries\Win32\Nosgoth.exe FirewallRules: [TCP Query User{5D4714E5-70DF-4E11-ADF4-03CBD5B05587}C:\games\wotlauncher.exe] => (Allow) C:\games\wotlauncher.exe FirewallRules: [UDP Query User{64417E00-E5BA-4520-AD4E-A0FDB17D8943}C:\games\wotlauncher.exe] => (Allow) C:\games\wotlauncher.exe FirewallRules: [TCP Query User{73E29C2B-F2D0-4F88-8FFD-CBF75FA0FDC8}C:\games\worldoftanks.exe] => (Allow) C:\games\worldoftanks.exe FirewallRules: [UDP Query User{FCEE375C-D441-4CC6-A8C7-BE0F9E12F8EE}C:\games\worldoftanks.exe] => (Allow) C:\games\worldoftanks.exe FirewallRules: [{B86889A6-76D3-45DC-8EE8-9802EC06721A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{4C0B17D5-F4B7-4B6F-8E4F-78E75006F2A1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3BBBBF17-A934-4E12-8A67-4DFCD93C7B29}] => (Allow) D:\GRY\stimowe\SteamApps\common\nosgoth\Binaries\Win32\Nosgoth.exe FirewallRules: [{DFDEF5CC-C2C3-4D75-A2EE-504AE57D1395}] => (Allow) D:\GRY\stimowe\SteamApps\common\nosgoth\Binaries\Win32\Nosgoth.exe FirewallRules: [TCP Query User{CD010014-E101-4B3E-A810-3EB4E8C58A9D}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{04F6E043-8542-4F2E-B8FB-4497058BA069}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{1C2AB207-58F2-43F5-BC47-2968EC7AC81E}C:\users\woint\appdata\roaming\utorrent\updates\3.4.3_40298.exe] => (Allow) C:\users\woint\appdata\roaming\utorrent\updates\3.4.3_40298.exe FirewallRules: [UDP Query User{2CD2CF50-427F-4A0F-8968-F527D27525D1}C:\users\woint\appdata\roaming\utorrent\updates\3.4.3_40298.exe] => (Allow) C:\users\woint\appdata\roaming\utorrent\updates\3.4.3_40298.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/24/2015 05:17:00 PM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost (1404) WebCacheLocal: Error -1811 occurred while opening logfile C:\Users\woint\AppData\Local\Microsoft\Windows\WebCache\V010016F.log. Error: (06/24/2015 05:11:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: avgsea.dll_unloaded, version: 0.0.0.0, time stamp: 0x5559b4ed Exception code: 0xc0000005 Fault offset: 0x000007feeaaa5500 Faulting process id: 0x65c Faulting application start time: 0xExplorer.EXE0 Faulting application path: Explorer.EXE1 Faulting module path: Explorer.EXE2 Report Id: Explorer.EXE3 Error: (06/19/2015 09:38:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17813, time stamp: 0x554a15f3 Faulting module name: ntdll.dll, version: 6.1.7601.18869, time stamp: 0x556366f2 Exception code: 0xc0000005 Fault offset: 0x000000000004ada4 Faulting process id: 0xbfc Faulting application start time: 0xGWXUX.exe0 Faulting application path: GWXUX.exe1 Faulting module path: GWXUX.exe2 Report Id: GWXUX.exe3 Error: (05/16/2015 01:51:11 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: worldoftanks.exe, version: 0.9.7.0, time stamp: 0x552cf39e Faulting module name: worldoftanks.exe, version: 0.9.7.0, time stamp: 0x552cf39e Exception code: 0xc0000005 Fault offset: 0x002affdf Faulting process id: 0x1058 Faulting application start time: 0xworldoftanks.exe0 Faulting application path: worldoftanks.exe1 Faulting module path: worldoftanks.exe2 Report Id: worldoftanks.exe3 Error: (05/16/2015 00:31:52 AM) (Source: MsiInstaller) (EventID: 1024) (User: EFBECE) Description: Product: Adobe Reader XI (11.0.10) - Polish - Update '{AC76BA86-7AD7-0000-2550-7A8C40011011}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127 Error: (05/14/2015 11:39:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7601.18839, time stamp: 0x553e8bfa Exception code: 0xc000000d Fault offset: 0x000000000006ec12 Faulting process id: 0x530 Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Error: (05/14/2015 02:36:59 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7601.18839, time stamp: 0x553e8bfa Exception code: 0xc000000d Fault offset: 0x000000000006ec12 Faulting process id: 0x72c Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Error: (05/12/2015 11:23:17 PM) (Source: MsiInstaller) (EventID: 1024) (User: EFBECE) Description: Product: Adobe Reader XI (11.0.11) - Polish - Update 'Adobe Reader XI (11.0.11)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127 Error: (05/12/2015 11:23:14 PM) (Source: MsiInstaller) (EventID: 11321) (User: EFBECE) Description: Produkt: Adobe Reader XI (11.0.11) - Polish -- Błąd 1321.Instalator posiada niewystarczające przywileje, aby modyfikować plik C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\Annots.api. Error: (05/12/2015 11:22:54 PM) (Source: MsiInstaller) (EventID: 1024) (User: EFBECE) Description: Product: Adobe Reader XI (11.0.10) - Polish - Update '{AC76BA86-7AD7-0000-2550-7A8C40011011}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127 System errors: ============= Error: (06/25/2015 05:36:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Volume Shadow Copy Service service failed to start due to the following error: %%2 Error: (06/25/2015 05:36:51 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa8005e075d0, 0xfffffa8005e078b0, 0xfffff80002f7ae20)C:\Windows\MEMORY.DMP062515-10764-01 Error: (06/25/2015 05:36:49 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 17:34:55 on ‎2015-‎06-‎25 was unexpected. Error: (06/25/2015 05:32:18 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for DeleteFlag with the following error: %%5 Error: (06/25/2015 05:32:18 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for DeleteFlag with the following error: %%5 Error: (06/25/2015 05:32:18 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Avira Real-Time Protection service, but this action failed with the following error: %%1058 Error: (06/25/2015 05:32:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Avira Real-Time Protection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error: (06/25/2015 05:32:18 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for DeleteFlag with the following error: %%5 Error: (06/25/2015 05:32:18 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Avira Scheduler service, but this action failed with the following error: %%1058 Error: (06/25/2015 05:32:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Avira Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Microsoft Office: ========================= Error: (06/24/2015 05:17:00 PM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost1404WebCacheLocal: C:\Users\woint\AppData\Local\Microsoft\Windows\WebCache\V010016F.log-1811 Error: (06/24/2015 05:11:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175674d672ee4avgsea.dll_unloaded0.0.0.05559b4edc0000005000007feeaaa550065c01d0ae8a64599240C:\Windows\Explorer.EXEavgsea.dll58257d30-1a83-11e5-93d1-20cf3080dbdd Error: (06/19/2015 09:38:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: GWXUX.exe6.3.9600.17813554a15f3ntdll.dll6.1.7601.18869556366f2c0000005000000000004ada4bfc01d0aac784fc9540C:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dllc3aa9a30-16ba-11e5-9083-20cf3080dbdd Error: (05/16/2015 01:51:11 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: worldoftanks.exe0.9.7.0552cf39eworldoftanks.exe0.9.7.0552cf39ec0000005002affdf105801d08f5de3993700C:\Games\worldoftanks.exeC:\Games\worldoftanks.exe434f3c10-fb5d-11e4-82aa-20cf3080dbdd Error: (05/16/2015 00:31:52 AM) (Source: MsiInstaller) (EventID: 1024) (User: EFBECE) Description: Adobe Reader XI (11.0.10) - Polish{AC76BA86-7AD7-0000-2550-7A8C40011011}1625(NULL)(NULL)(NULL) Error: (05/14/2015 11:39:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe_DiagTrack6.1.7600.163854a5bc3c1ntdll.dll6.1.7601.18839553e8bfac000000d000000000006ec1253001d08e2abea88c40C:\Windows\System32\svchost.exeC:\Windows\SYSTEM32\ntdll.dllaf50ba10-fa81-11e4-ab8f-20cf3080dbdd Error: (05/14/2015 02:36:59 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe_DiagTrack6.1.7600.163854a5bc3c1ntdll.dll6.1.7601.18839553e8bfac000000d000000000006ec1272c01d08dabe1b66740C:\Windows\System32\svchost.exeC:\Windows\SYSTEM32\ntdll.dll5465bc00-f9d1-11e4-878c-20cf3080dbdd Error: (05/12/2015 11:23:17 PM) (Source: MsiInstaller) (EventID: 1024) (User: EFBECE) Description: Adobe Reader XI (11.0.11) - PolishAdobe Reader XI (11.0.11)1603(NULL)(NULL)(NULL) Error: (05/12/2015 11:23:14 PM) (Source: MsiInstaller) (EventID: 11321) (User: EFBECE) Description: Produkt: Adobe Reader XI (11.0.11) - Polish -- Błąd 1321.Instalator posiada niewystarczające przywileje, aby modyfikować plik C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\Annots.api.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (05/12/2015 11:22:54 PM) (Source: MsiInstaller) (EventID: 1024) (User: EFBECE) Description: Adobe Reader XI (11.0.10) - Polish{AC76BA86-7AD7-0000-2550-7A8C40011011}1625(NULL)(NULL)(NULL) ==================== Memory info =========================== Processor: AMD Athlon(tm) II X3 445 Processor Percentage of memory in use: 39% Total physical RAM: 4095.23 MB Available physical RAM: 2482.54 MB Total Pagefile: 8188.66 MB Available Pagefile: 6050.6 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.79 GB) (Free:47.55 GB) NTFS Drive d: (j K s) (Fixed) (Total:134.39 GB) (Free:6.42 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 0CAE0CAE) Partition 1: (Active) - (Size=14.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=134.4 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: A5E45308) Partition 1: (Not Active) - (Size=111.8 GB) - (Type=07 NTFS) ==================== End of log ============================