Additional scan result of Farbar Recovery Scan Tool (x64) Version:11-07-2015 Ran by matesz at 2015-08-04 17:22:30 Running from C:\Users\matesz\Desktop\logi Boot Mode: Safe Mode (with Networking) ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3858547714-159695882-337848512-500 - Administrator - Disabled) Gość (S-1-5-21-3858547714-159695882-337848512-501 - Limited - Disabled) matesz (S-1-5-21-3858547714-159695882-337848512-1001 - Administrator - Enabled) => C:\Users\matesz ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton Internet Security (Disabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Disabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Reader X (10.1.3) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated) AIMP3 (HKLM-x32\...\AIMP3) (Version: v3.55.1345, 26.03.2014 - AIMP DevTeam) AMD Catalyst Install Manager (HKLM\...\{79AE0BD1-A930-B07C-C96D-E11FA9BB586F}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.3.26.0 - AppEx Networks) Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - ) ESDX4000_4050_CX3900 (HKLM-x32\...\ESDX4000_4050_CX3900) (Version: - ) FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden Gardenscapes: Mansion Makeover (x32 Version: 3.0.2.32 - WildTangent) Hidden GG 12 Packages (HKU\S-1-5-21-3858547714-159695882-337848512-1001\...\GG 12 Packages) (Version: - ) <==== ATTENTION Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.107 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden Malwarebytes Anti-Malware wersja 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Microsoft Office XP Web Components (HKLM-x32\...\{90260415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3858547714-159695882-337848512-1001\...\OneDriveSetup.exe) (Version: 17.0.4041.0512 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Mozilla Firefox 38.0.5 (x86 pl) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 pl)) (Version: 38.0.5 - Mozilla) Norton Anti-Theft (HKLM-x32\...\NAT) (Version: 1.10.0.9 - Symantec Corporation) Norton Internet Security (HKLM-x32\...\NIS) (Version: 20.1.0.24 - Symantec Corporation) Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.2.3.45 - Symantec Corporation) Norton Online Backup ARA (x32 Version: 4.1.0.11 - Symantec Corporation) Hidden Norton PC Checkup (HKLM-x32\...\NortonPCCheckup) (Version: 2.0.18.15 - Symantec Corporation) Norton Security Dashboard (HKLM-x32\...\NortonSD) (Version: 1.1.1.9 - Symantec Corporation) NVIDIA PhysX (HKLM-x32\...\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.0.15.60 - Electronic Arts, Inc.) Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden Photo! Editor 1.1 (HKLM-x32\...\PhotoToolkit_is1) (Version: - ) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Premium Sound HD (HKLM\...\{000A208E-1050-4181-AC37-E13DA9254B73}) (Version: 1.12.6000 - DTS, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6738 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.) Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0020 - REALTEK Semiconductor Corp.) Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.5 - Synaptics Incorporated) Toshiba App Place (HKLM-x32\...\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}) (Version: 1.0.6.3 - Toshiba) TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.4 - TOSHIBA) Toshiba Book Place (HKLM-x32\...\{24B45620-22B6-4E4A-B836-FF30A0B0404E}) (Version: 3.1.9534 - K-NFB Reading Technology, Inc.) TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.00.08.6402 - Toshiba Corporation) TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.0.0.6415 - Toshiba Corporation) TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.00.6626.6406 - Toshiba Corporation) TOSHIBA HDD Accelerator (HKLM\...\{DB4D9937-0B14-4EF1-BF9A-BB7E3B9DCB04}) (Version: 1.1.0001 - Toshiba Corporation) Toshiba Password Utility (HKLM-x32\...\InstallShield_{78931270-BC9E-441A-A52B-73ECD4ACFAB5}) (Version: 2.00.972 - Toshiba Corporation) TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.8.17.640104 - Toshiba Corporation) TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.8 - TOSHIBA) TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.2.1.54043006 - Toshiba Corporation) TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\...\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.2.2.00 - TOSHIBA Corporation) TOSHIBA Service Station (HKLM\...\{5B9D45BB-8930-4162-8B55-098A0DB98D64}) (Version: 2.6.8 - Toshiba Corporation) TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0015 - Toshiba Corporation) TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.00.0002.32002 - Toshiba Corporation) TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA) TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.1.0.12-A - Toshiba Corporation) TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.6 - TOSHIBA) Unity Web Player (HKU\S-1-5-21-3858547714-159695882-337848512-1001\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Vacation Quest™ - Australia (x32 Version: 3.0.2.32 - WildTangent) Hidden Virtual Villagers 5 - New Believers (x32 Version: 3.0.2.32 - WildTangent) Hidden WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent) WildTangent Games App (Toshiba Games) (x32 Version: 4.0.9.7 - WildTangent) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation) WinRAR 5.21 (32-bitowy) (HKLM-x32\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Youda Jewel Shop (x32 Version: 3.0.2.32 - WildTangent) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3858547714-159695882-337848512-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\matesz\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3858547714-159695882-337848512-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\matesz\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3858547714-159695882-337848512-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\matesz\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3858547714-159695882-337848512-1001_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\matesz\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll No File CustomCLSID: HKU\S-1-5-21-3858547714-159695882-337848512-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\matesz\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3858547714-159695882-337848512-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\matesz\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {2CCC3AF5-841C-4156-9BA6-7290BBA4B16B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2015-06-14] (Microsoft Corporation) Task: {464D008C-5144-4FE2-B30D-F8DA8058D2B8} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation) Task: {4974A4EC-8AC0-43BE-9336-1800B2D1291A} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation) Task: {68B3E191-50FC-4D1D-8D23-DB3A1CE53167} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\SymErr.exe [2012-08-17] (Symantec Corporation) Task: {68D62619-8151-4441-9DB2-06368B3F06EB} - System32\Tasks\{C371EF38-4187-4127-B3C5-D90F84370C75} => Firefox.exe http://ui.skype.com/ui/0/6.21.0.104/pl/abandoninstall?page=tsMain Task: {6AC46AE5-352D-4A5B-BADD-973CC4407F1E} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation) Task: {7218B830-108B-473B-9742-C654207E3DD3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-20] (Google Inc.) Task: {7C2CF997-12CD-45A6-9A26-BDA8EC4EEF76} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\SymErr.exe [2012-08-17] (Symantec Corporation) Task: {7E1D8158-1DED-44D2-8B77-09E32236642D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-20] (Google Inc.) Task: {8532D8EA-BB06-486C-90C2-F918D871EFAB} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3858547714-159695882-337848512-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {A728B2E4-FEB0-4E62-ACCD-C60591701FE7} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-27] (Adobe Systems Incorporated) Task: {C0595CE6-BF63-494F-8E68-3F59A5656748} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3858547714-159695882-337848512-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {DFB4ED0C-956C-4141-BD66-D4490882EA98} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.1.0.24\WSCStub.exe [2012-08-22] (Symantec Corporation) Task: {E0A7296F-CABD-4F97-AB41-E75F634C4D43} - System32\Tasks\{E35B481E-48E1-4A39-9A02-11A955ED4723} => Firefox.exe http://ui.skype.com/ui/0/6.21.0.104/pl/abandoninstall?page=tsMain Task: {EBD211F9-B4F5-436D-93ED-2EF7E861C267} - System32\Tasks\{9DFFDED5-58B9-4A56-A93A-024A4D9A7A33} => Firefox.exe http://ui.skype.com/ui/0/6.21.0.104/pl/eula Task: {FD0B5BBA-910C-4E7A-8634-29DC811B0C74} - System32\Tasks\{261F9D32-E8C3-466F-AB7E-A8EDA5BE5C2B} => pcalua.exe -a "C:\Program Files (x86)\EPSON\TPMANUAL\ESDX4000_4050_CX3900\USE_G\DOCUNINS.EXE" Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3858547714-159695882-337848512-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Innovation\Red.jpg DNS Servers: Media is not connected to internet. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{A940364C-3409-43FF-9495-326B93C603F2}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{B61E4E8F-7BDA-4AE9-9F89-5F75E596CF4C}] => (Allow) LPort=2869 FirewallRules: [{B2D4F161-8FAF-406B-86B5-D80D541DA1ED}] => (Allow) LPort=1900 FirewallRules: [{37DEDDAC-C341-4DA8-8ED5-C94A7054BD6C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{37C3C585-11F0-4B75-A542-09498B19B4EB}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe FirewallRules: [UDP Query User{39699DF8-E9AE-4E26-BD12-5E7EF252A1AB}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe FirewallRules: [TCP Query User{10B65E80-4196-4809-8E97-5E90DA290A86}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe FirewallRules: [UDP Query User{ED67F604-4F75-42FB-8BB3-66B535BAB1F0}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe FirewallRules: [{5D3A7166-8409-49CA-B178-768ADE5999BC}] => (Allow) C:\Program Files (x86)\cdp.pl\Farming Simulator 2013\FarmingSimulator2013.exe FirewallRules: [{438ACBB7-2A8E-47BA-9741-2CF57397A82B}] => (Allow) C:\Program Files (x86)\cdp.pl\Farming Simulator 2013\FarmingSimulator2013Game.exe FirewallRules: [TCP Query User{306DFB91-42CD-43A4-8DE0-FEFA5DA86DF4}C:\users\matesz\desktop\nowy folder\farming_simulator_2013_patch_2.0_i_wszystkie_dodatki\x86\farmingsimulator2013game.exe] => (Block) C:\users\matesz\desktop\nowy folder\farming_simulator_2013_patch_2.0_i_wszystkie_dodatki\x86\farmingsimulator2013game.exe FirewallRules: [UDP Query User{B55BD174-B45F-47CF-A9FD-9D4D99532D63}C:\users\matesz\desktop\nowy folder\farming_simulator_2013_patch_2.0_i_wszystkie_dodatki\x86\farmingsimulator2013game.exe] => (Block) C:\users\matesz\desktop\nowy folder\farming_simulator_2013_patch_2.0_i_wszystkie_dodatki\x86\farmingsimulator2013game.exe FirewallRules: [TCP Query User{708BC491-2D05-4242-992B-F5FE202DEEC9}C:\games\world_of_tanks\wotlauncher.exe] => (Block) C:\games\world_of_tanks\wotlauncher.exe FirewallRules: [UDP Query User{DE18E4C9-E34E-49DE-B8F1-C693F115EBAB}C:\games\world_of_tanks\wotlauncher.exe] => (Block) C:\games\world_of_tanks\wotlauncher.exe FirewallRules: [{9C7EA939-8505-4AA6-B743-1253583B3E63}] => (Allow) C:\Program Files (x86)\cdp.pl\Farming Simulator 2013\FarmingSimulator2013.exe FirewallRules: [{450D5754-E7EE-4701-89A8-B50888B98878}] => (Allow) C:\Program Files (x86)\cdp.pl\Farming Simulator 2013\FarmingSimulator2013Game.exe FirewallRules: [{A564E784-191E-4347-A418-9A0D18D96F0D}] => (Allow) C:\Users\matesz\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe FirewallRules: [{44208AD5-EDCB-4278-A930-A1FF7550105D}] => (Allow) C:\Program Files (x86)\Farming Simulator 2015\FarmingSimulator2015.exe FirewallRules: [{82BDC4EA-2EE2-444C-98FB-CF04DB2F3B43}] => (Allow) C:\Program Files (x86)\Farming Simulator 2015\FarmingSimulator2015.exe FirewallRules: [{126DDA63-D41A-490F-B1F9-BF1F8437D760}] => (Allow) C:\Program Files (x86)\Farming Simulator 2015\x86\FarmingSimulator2015Game.exe FirewallRules: [{1849DE4C-1B30-4CFD-9D6C-71B96F1CCA67}] => (Allow) C:\Program Files (x86)\Farming Simulator 2015\x86\FarmingSimulator2015Game.exe FirewallRules: [{7CEE53C5-1C5D-4F25-B556-883005F9954A}] => (Allow) C:\Program Files (x86)\Farming Simulator 2015\x64\FarmingSimulator2015Game.exe FirewallRules: [{AA37A9FB-A225-4156-8F43-CE046C75DB7F}] => (Allow) C:\Program Files (x86)\Farming Simulator 2015\x64\FarmingSimulator2015Game.exe FirewallRules: [{CD7E89EC-157D-4F73-A509-FB2C4D7D1DD8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3559A36B-33CF-4030-82AD-881ACF597F52}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{0FCA3C82-F348-4AF4-BE93-C3A7C3AFBD80}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3011AFA4-24F6-4BAA-ACB4-7FFDF8BE3EF3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{1C218F47-1335-4973-97B2-A9A834DB1AA3}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{05E11F4D-5634-448B-950F-8A88C2E87BC0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{E3EDBA0A-C440-4F8B-8106-7EB0715101F5}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{0A4C5767-90BF-4DD0-8350-3DB6531845AC}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{AE7E4144-122D-41CE-8531-68D90E44D509}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/04/2015 05:21:15 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: ZARZĄDZANIE NT) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (08/04/2015 05:21:15 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: ZARZĄDZANIE NT) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (08/04/2015 05:21:15 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: ZARZĄDZANIE NT) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (08/04/2015 05:20:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mateusz) Description: Aktywacja aplikacji microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe:Microsoft.WindowsLive.ModernPhotos.AppXsjk229593yvkhw8w13eans3t0eh9strp.wwa nie powiodła się. Błąd: -2144927149. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error: (08/04/2015 05:13:57 PM) (Source: Toshiba App Place) (EventID: 0) (User: ) Description: System.ArgumentOutOfRangeException: Liczba musi być nieujemna albo mniejsza od wartości Int32.MaxValue -1 lub jej równa. Nazwa parametru: dueTime Stack Trace: w System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period) w System.Timers.Timer.set_Enabled(Boolean value) w SnappCloud.ActivationReminder.AraClient.PostInit() w SnappCloud.ActivationReminder.Program.Main(String[] args) Error: (08/03/2015 10:46:29 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: ) Description: TSS Load: could not communicate with TMachInfo service Error: (08/03/2015 10:46:29 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: ) Description: Nie można uruchomić usługi TMachInfo na komputerze '.'. Error: (08/03/2015 06:22:52 PM) (Source: Toshiba App Place) (EventID: 0) (User: ) Description: System.ArgumentOutOfRangeException: Liczba musi być nieujemna albo mniejsza od wartości Int32.MaxValue -1 lub jej równa. Nazwa parametru: dueTime Stack Trace: w System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period) w System.Timers.Timer.set_Enabled(Boolean value) w SnappCloud.ActivationReminder.AraClient.PostInit() w SnappCloud.ActivationReminder.Program.Main(String[] args) Error: (07/27/2015 05:18:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: wwahost.exe, wersja: 6.2.9200.16420, sygnatura czasowa: 0x505a90d6 Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 6.2.9200.17366, sygnatura czasowa: 0x554d16f6 Kod wyjątku: 0x00000004 Przesunięcie błędu: 0x00010192 Identyfikator procesu powodującego błąd: 0x404 Godzina uruchomienia aplikacji powodującej błąd: 0xwwahost.exe0 Ścieżka aplikacji powodującej błąd: wwahost.exe1 Ścieżka modułu powodującego błąd: wwahost.exe2 Identyfikator raportu: wwahost.exe3 Pełna nazwa pakietu powodującego błąd: wwahost.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: wwahost.exe5 Error: (07/27/2015 05:03:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: wwahost.exe, wersja: 6.2.9200.16420, sygnatura czasowa: 0x505a90d6 Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 6.2.9200.17366, sygnatura czasowa: 0x554d16f6 Kod wyjątku: 0x00000004 Przesunięcie błędu: 0x00010192 Identyfikator procesu powodującego błąd: 0xfec Godzina uruchomienia aplikacji powodującej błąd: 0xwwahost.exe0 Ścieżka aplikacji powodującej błąd: wwahost.exe1 Ścieżka modułu powodującego błąd: wwahost.exe2 Identyfikator raportu: wwahost.exe3 Pełna nazwa pakietu powodującego błąd: wwahost.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: wwahost.exe5 System errors: ============= Error: (08/04/2015 05:21:33 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/04/2015 05:21:11 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/04/2015 05:21:08 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084WSearchNiedostępny{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (08/04/2015 05:21:06 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084WSearchNiedostępny{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (08/04/2015 05:21:06 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/04/2015 05:20:59 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/04/2015 05:20:54 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/04/2015 05:20:49 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/04/2015 05:20:44 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/04/2015 05:20:22 PM) (Source: DCOM) (EventID: 10005) (User: mateusz) Description: 1084ShellHWDetectionNiedostępny{DD522ACC-F821-461A-A407-50B198B896DC} Microsoft Office: ========================= Error: (08/04/2015 05:21:15 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: ZARZĄDZANIE NT) Description: WmiApRplWmiApRpl8F2030000E5050000 Error: (08/04/2015 05:21:15 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: ZARZĄDZANIE NT) Description: Performance163707000000000000000000008F020000 Error: (08/04/2015 05:21:15 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: ZARZĄDZANIE NT) Description: Performance163707000000000000000000008F020000 Error: (08/04/2015 05:20:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mateusz) Description: microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe:Microsoft.WindowsLive.ModernPhotos.AppXsjk229593yvkhw8w13eans3t0eh9strp.wwa-2144927149 Error: (08/04/2015 05:13:57 PM) (Source: Toshiba App Place) (EventID: 0) (User: ) Description: System.ArgumentOutOfRangeException: Liczba musi być nieujemna albo mniejsza od wartości Int32.MaxValue -1 lub jej równa. Nazwa parametru: dueTime Stack Trace: w System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period) w System.Timers.Timer.set_Enabled(Boolean value) w SnappCloud.ActivationReminder.AraClient.PostInit() w SnappCloud.ActivationReminder.Program.Main(String[] args) Error: (08/03/2015 10:46:29 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: ) Description: TSS Load: could not communicate with TMachInfo service Error: (08/03/2015 10:46:29 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: ) Description: Nie można uruchomić usługi TMachInfo na komputerze '.'. Error: (08/03/2015 06:22:52 PM) (Source: Toshiba App Place) (EventID: 0) (User: ) Description: System.ArgumentOutOfRangeException: Liczba musi być nieujemna albo mniejsza od wartości Int32.MaxValue -1 lub jej równa. Nazwa parametru: dueTime Stack Trace: w System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period) w System.Timers.Timer.set_Enabled(Boolean value) w SnappCloud.ActivationReminder.AraClient.PostInit() w SnappCloud.ActivationReminder.Program.Main(String[] args) Error: (07/27/2015 05:18:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: wwahost.exe6.2.9200.16420505a90d6KERNELBASE.dll6.2.9200.17366554d16f6000000040001019240401d0c87f78286f2dC:\windows\syswow64\wwahost.exeC:\windows\SYSTEM32\KERNELBASE.dllb63b556b-3472-11e5-8005-4c72b9a66f5eMicrosoft.SkypeApp_1.1.0.25_x86__kzf8qxf38zg5cApp Error: (07/27/2015 05:03:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: wwahost.exe6.2.9200.16420505a90d6KERNELBASE.dll6.2.9200.17366554d16f60000000400010192fec01d0c87d5f820c06C:\windows\syswow64\wwahost.exeC:\windows\SYSTEM32\KERNELBASE.dll9d9753dd-3470-11e5-8005-4c72b9a66f5eMicrosoft.SkypeApp_1.1.0.25_x86__kzf8qxf38zg5cApp ==================== Memory info =========================== Processor: AMD A6-4400M APU with Radeon(tm) HD Graphics Percentage of memory in use: 19% Total physical RAM: 5596.73 MB Available physical RAM: 4528.61 MB Total Virtual: 6492.73 MB Available Virtual: 5539.43 MB ==================== Drives ================================ Drive c: (TI10657700C) (Fixed) (Total:584.99 GB) (Free:520.99 GB) NTFS Drive f: (Label Iso) (Fixed) (Total:58.43 GB) (Free:39.62 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596.2 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 58.4 GB) (Disk ID: 0013EE1C) Partition 1: (Active) - (Size=58.4 GB) - (Type=07 NTFS) ==================== End of log ============================