Additional scan result of Farbar Recovery Scan Tool (x86) Version:21-08-2015 03 Ran by Alex (2015-08-22 03:20:31) Running from C:\Users\Alex\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3050552178-2778190213-2786081387-500 - Administrator - Disabled) Alex (S-1-5-21-3050552178-2778190213-2786081387-1000 - Administrator - Enabled) => C:\Users\Alex Gość (S-1-5-21-3050552178-2778190213-2786081387-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3050552178-2778190213-2786081387-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: 电脑管家系统防护 (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5} AV: ESET Smart Security 8.0 (Enabled - Out of date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: 电脑管家系统防护 (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48} AS: ESET Smart Security 8.0 (Enabled - Out of date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} FW: Zapora osobista ESET (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3050552178-2778190213-2786081387-1000\...\uTorrent) (Version: 3.4.2.39744 - BitTorrent Inc.) ACP Application (Version: 2.15.30.0019 - Advanced Micro Devices, Inc.) Hidden Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.45.2 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.) AdVenture Capitalist (HKLM\...\Steam App 346900) (Version: - Hyper Hippo Games) AMD Catalyst Install Manager (HKLM\...\{FC550040-B62D-FAAC-C46A-8435C9D8EE20}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AutoHotkey 1.1.22.03 (HKLM\...\AutoHotkey) (Version: 1.1.22.03 - Lexikos) Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 3.18 - Piriform) Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve) Entity Framework Designer for Visual Studio 2012 - enu (HKLM\...\{32136776-FE3F-453D-80DA-CDD993BDB2A3}) (Version: 11.1.20810.00 - Microsoft Corporation) ESET Smart Security (HKLM\...\{92454C96-C162-47E6-8806-B64224BACEF4}) (Version: 8.0.304.2 - ESET, spol s r. o.) GIGABYTE OC_GURU II (HKLM\...\InstallShield_{5588D686-D23B-4C9D-BDFA-2A7875CD3722}) (Version: 1.52.0000 - GIGABYTE Technology Co.,Ltd.) GIGABYTE OC_GURU II (Version: 1.52.0000 - GIGABYTE Technology Co.,Ltd.) Hidden GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) globalupdate Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.0 - globalupdate Inc.) <==== ATTENTION Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.) Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden GS Auto Clicker (HKLM\...\GS Auto Clicker_is1) (Version: V3.1.3 - goldensoft.org) Heroes of the Storm (HKLM\...\Heroes of the Storm) (Version: - Blizzard Entertainment) Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (Version: 3.0.1 - Riot Games) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM\...\{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM\...\{1948E039-EC79-4591-951D-9867A8C14C90}) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.51209 - Microsoft Corporation) Microsoft DirectX SDK (June 2010) (HKLM\...\Microsoft DirectX SDK (June 2010)) (Version: 9.29.1962.0 - Microsoft Corporation) Microsoft Help Viewer 2.0 (HKLM\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{45A8F8FF-ED9B-40B2-B923-94F46FCF6135}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{D9DA2981-3298-4F1A-9192-F2CF5BD91145}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{83C7F964-AC58-4104-B613-B4D0F61DA8CD}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL Compiler Service (HKLM\...\{79B49428-E9B0-4479-A0FA-3EFF8AFA9F07}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{CD920828-2B95-49A4-8BFD-1D34BCBF5A27}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL Language Service (HKLM\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 ENU (HKLM\...\{773AC1E4-5F27-4DF6-A932-7FDDE35C069D}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (11.1.20828.01) (HKLM\...\{4F2B8233-35EE-4197-8C3B-EACCBF712029}) (Version: 11.1.20828.01 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20828.01) (HKLM\...\{FAE0523E-08A4-4717-8E8E-6EC6F32CBE88}) (Version: 11.1.20828.01 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2012 (HKLM\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio Express 2012 for Windows Desktop - ENU (HKLM\...\{e0efdce9-a486-4676-8aa5-65bb08cbf34c}) (Version: 11.0.50727.42 - Microsoft Corporation) Minecraft (HKLM\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) MK LOL (HKU\S-1-5-21-3050552178-2778190213-2786081387-1000\...\MK LOL) (Version: - ) Open Broadcaster Software (HKLM\...\Open Broadcaster Software) (Version: - ) OpenVPN 2.3.4-I001 (HKLM\...\OpenVPN) (Version: 2.3.4-I001 - ) PingBuster version 2 (HKLM\...\{2E297026-529F-42C7-8FCA-8EE9540585DF}_is1) (Version: 2 - PingBuster) Prerequisites for SSDT (HKLM\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation) Raptr (HKLM\...\Raptr) (Version: - ) Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek) Realtek Ethernet Diagnostic Utility (HKLM\...\{DADC7AB0-E554-4705-9F6A-83EA82ED708E}) (Version: 1.006 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6767 - Realtek Semiconductor Corp.) screenSHU - the fastest screen capture ever. (HKLM\...\screenSHU) (Version: - ) Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation) Skype™ 7.6 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.) SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - ) Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - ) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TeamViewer 10 (HKLM\...\TeamViewer) (Version: 10.0.45862 - TeamViewer) The Enigma Protector v3.70 Build 20120504 (HKLM\...\The Enigma Protector_is1) (Version: - The Enigma Protector Developers Team) Time Clickers (HKLM\...\Steam App 385770) (Version: - Proton Studio Inc) Trove (HKLM\...\Steam App 304050) (Version: - Trion Worlds) Update for (KB2504637) (HKLM\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version: - ) Winamp (HKLM\...\Winamp) (Version: 5.56 - Nullsoft, Inc) WinRAR 5.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) Wise Care 365 wersja 3.14 (HKLM\...\Wise Care 365_is1) (Version: 3.14 - ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 19-08-2015 13:58:14 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2014-12-20 18:55 - 00000864 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 validation.sls.microsoft.com ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {4D536F16-1731-4E9F-AECD-E24961E33D42} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated) Task: {7ABB6894-4338-4DDB-8AB2-BD25C9A82E48} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser Task: {F0662788-D5BB-44FB-B72D-4E1FE1F42AAA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-29] (Google Inc.) Task: {F0F1B4E5-631F-4371-B2CE-71155BD2CE81} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-29] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d09a038b4810b3.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-08-04 10:06 - 2015-08-04 10:06 - 00481632 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\sqlite.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00100704 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\tinyxml.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00088416 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\zlib.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00203104 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QQFileFlt.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00063840 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\plugins\qmiemalrtpplugin\qmiemalrtpplugin.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00051552 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\plugins\sysspeeduprtpplugin\SysSpeedupRtpPlugin.dll 2015-08-04 10:51 - 2015-04-17 12:02 - 00018784 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\oDayProtect.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00137568 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\libexpatw.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00092184 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\xGraphic32.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00342040 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\arkGraphic.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00045920 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\jgImage.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00158048 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\libpng.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00285024 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\libjpegturbo.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00014176 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\jgIOStub.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00194912 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\xImage.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00076128 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\MemDefrag.dll 2015-08-04 10:06 - 2015-08-04 10:06 - 00268640 _____ () C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\plugins\StartupMgr\SoftMon.dll 2009-07-01 18:37 - 2009-07-01 18:37 - 00037888 _____ () C:\Program Files\Winamp\winampa.exe 2015-08-21 00:45 - 2015-08-18 07:23 - 01405768 _____ () C:\Program Files\Google\Chrome\Application\44.0.2403.157\libglesv2.dll 2015-08-21 00:45 - 2015-08-18 07:23 - 00081224 _____ () C:\Program Files\Google\Chrome\Application\44.0.2403.157\libegl.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00087040 _____ () C:\Program Files\Raptr\_ctypes.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00043008 _____ () C:\Program Files\Raptr\_socket.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00805376 _____ () C:\Program Files\Raptr\_ssl.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 05812736 _____ () C:\Program Files\Raptr\PyQt4.QtGui.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00067584 _____ () C:\Program Files\Raptr\sip.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 01662464 _____ () C:\Program Files\Raptr\PyQt4.QtCore.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00494592 _____ () C:\Program Files\Raptr\PyQt4.QtNetwork.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00096256 _____ () C:\Program Files\Raptr\win32api.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00110592 _____ () C:\Program Files\Raptr\pywintypes26.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00010240 _____ () C:\Program Files\Raptr\select.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00356864 _____ () C:\Program Files\Raptr\_hashlib.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00036352 _____ () C:\Program Files\Raptr\win32process.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00111104 _____ () C:\Program Files\Raptr\win32file.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00044544 _____ () C:\Program Files\Raptr\_sqlite3.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 00417501 _____ () C:\Program Files\Raptr\sqlite3.dll 2010-11-23 00:57 - 2010-11-23 00:57 - 00167936 _____ () C:\Program Files\Raptr\win32gui.pyd 2014-05-14 01:26 - 2014-05-14 01:26 - 00313856 _____ () C:\Program Files\Raptr\PyQt4.QtWebKit.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00127488 _____ () C:\Program Files\Raptr\pyexpat.pyd 2010-11-23 00:56 - 2010-11-23 00:56 - 00009216 _____ () C:\Program Files\Raptr\winsound.pyd 2014-08-14 02:37 - 2014-08-14 02:37 - 00113171 _____ () C:\Program Files\Raptr\libvlc.dll 2014-08-14 02:37 - 2014-08-14 02:37 - 02396691 _____ () C:\Program Files\Raptr\libvlccore.dll 2013-11-21 02:05 - 2013-11-21 02:05 - 00256000 _____ () C:\Program Files\Raptr\amd_ags.dll 2010-11-23 00:56 - 2010-11-23 00:56 - 00583680 _____ () C:\Program Files\Raptr\unicodedata.pyd 2010-11-23 00:57 - 2010-11-23 00:57 - 00141312 _____ () C:\Program Files\Raptr\gobject._gobject.pyd 2014-06-18 02:56 - 2014-06-18 02:56 - 02717595 _____ () C:\Program Files\Raptr\heliotrope._purple.pyd 2011-02-15 20:17 - 2011-02-15 20:17 - 01213633 _____ () C:\Program Files\Raptr\libxml2-2.dll 2010-11-23 01:06 - 2010-11-23 01:06 - 00055808 _____ () C:\Program Files\Raptr\zlib1.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00495680 _____ () C:\Program Files\Raptr\plugins\libaim.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 01183699 _____ () C:\Program Files\Raptr\liboscar.dll 2013-05-10 01:52 - 2013-05-10 01:52 - 00483306 _____ () C:\Program Files\Raptr\plugins\libicq.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00655356 _____ () C:\Program Files\Raptr\plugins\libirc.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 01306387 _____ () C:\Program Files\Raptr\plugins\libmsn.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00565461 _____ () C:\Program Files\Raptr\plugins\libxmpp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01640221 _____ () C:\Program Files\Raptr\libjabber.dll 2013-05-03 20:56 - 2013-05-03 20:56 - 00506276 _____ () C:\Program Files\Raptr\plugins\libyahoo.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 01053730 _____ () C:\Program Files\Raptr\libymsg.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00497782 _____ () C:\Program Files\Raptr\plugins\libyahoojp.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00603326 _____ () C:\Program Files\Raptr\plugins\ssl-nss.dll 2013-05-03 20:57 - 2013-05-03 20:57 - 00474199 _____ () C:\Program Files\Raptr\plugins\ssl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:6BE50C2B ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3050552178-2778190213-2786081387-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{003AE472-CE17-45B7-841E-9F8CBA7069F9}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{BF653582-3EDA-4BD9-B30C-065709B95DC1}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{BCD465FD-4BCA-4D80-A821-D4049F7E1CA0}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{D635F363-1DF5-4E63-9F92-C2596A9D997C}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{EB2A7917-4AFE-44BD-BF99-14B0E51DD0DC}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [{A7653E8F-3DF8-4A78-8B62-6CDC5E037F22}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [{A783D897-BD78-4824-A30E-A3826165EA27}] => (Allow) C:\Users\Alex\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{2B34F67E-C966-4784-9FC2-22A46260E67A}] => (Allow) C:\Users\Alex\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{9F292850-0F59-4721-B5B5-F0A850C3F9C5}] => (Allow) C:\Users\Alex\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{9997CF41-74E1-463E-A19E-D5734E2DCEF2}] => (Allow) C:\Users\Alex\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{9613A1E4-B030-4FE2-8E4D-43427B7A0E85}] => (Allow) C:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\WDExpress.exe FirewallRules: [{4035F1D2-438F-4D07-BCA1-F122F0616EB6}] => (Allow) C:\Program Files\Battle.net\Battle.net.exe FirewallRules: [{D994266E-1207-4032-8987-40BFDB7A96B2}] => (Allow) C:\Program Files\Battle.net\Battle.net.exe FirewallRules: [{739B9277-F14D-4366-8919-F5CDD9F5CE6B}] => (Allow) C:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{667BB490-F615-42C4-BBDF-6B0864C03152}] => (Allow) C:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{6F9E8C82-1BBB-49F9-90AC-28B9A5BB80FF}] => (Allow) C:\Program Files\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe FirewallRules: [{19D2240A-81B7-48CC-ABE5-8EE29FF8415F}] => (Allow) C:\Program Files\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe FirewallRules: [{40F79116-EC96-404A-95B8-991DB90A24B5}] => (Allow) C:\Program Files\Steam\steamapps\common\Trove\GlyphClient.exe FirewallRules: [{509A1730-5975-4350-AB1B-8E6357E4C315}] => (Allow) C:\Program Files\Steam\steamapps\common\Trove\GlyphClient.exe FirewallRules: [{80A8A50B-9595-4D94-A8A5-A8B62A8D4E15}] => (Allow) C:\Program Files\Steam\steamapps\common\TimeClickers\TimeClickers.exe FirewallRules: [{58FC6303-46E7-4102-B7EC-1727DFE144EF}] => (Allow) C:\Program Files\Steam\steamapps\common\TimeClickers\TimeClickers.exe FirewallRules: [{108984AC-F609-4847-9248-4E8CD85A199E}] => (Allow) C:\Program Files\Raptr\raptr.exe FirewallRules: [{946E5551-577F-4192-B8CF-7420D977AC19}] => (Allow) C:\Program Files\Raptr\raptr_im.exe FirewallRules: [{BAFA5E46-F7F3-406F-80A6-585A5DC75831}] => (Allow) C:\Program Files\Raptr\raptr_im.exe FirewallRules: [{524FE873-4CE0-4A1F-95D1-DC6E796619FE}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe FirewallRules: [{E44AB9BA-88F4-4BFB-8568-8DC6E0E5D96C}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe FirewallRules: [{3AEF875C-450D-4A56-8821-C07F03DC6C5F}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe FirewallRules: [{BC6AAFA6-F648-464F-8D0B-BDF0E6AE18B9}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe FirewallRules: [{0EECD6DA-C155-4B22-8A96-EF6F6E8BC1A4}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe ==================== Faulty Device Manager Devices ============= Name: Karta Microsoft 6to4 Description: Karta Microsoft 6to4 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Karta Microsoft ISATAP Description: Karta Microsoft ISATAP Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Karta Microsoft ISATAP #2 Description: Karta Microsoft ISATAP Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/22/2015 03:18:02 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/21/2015 03:50:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: nbaex.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x545a04c8 Nazwa modułu powodującego błąd: nbaex.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x545a04c8 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00092aee Identyfikator procesu powodującego błąd: 0x2420 Godzina uruchomienia aplikacji powodującej błąd: 0xnbaex.exe0 Ścieżka aplikacji powodującej błąd: nbaex.exe1 Ścieżka modułu powodującego błąd: nbaex.exe2 Identyfikator raportu: nbaex.exe3 Error: (08/20/2015 04:19:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: steamwebhelper.exe, wersja: 2.91.71.80, sygnatura czasowa: 0x55cb7c96 Nazwa modułu powodującego błąd: libcef.dll, wersja: 3.2357.1273.0, sygnatura czasowa: 0x5581d4e8 Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x000894f9 Identyfikator procesu powodującego błąd: 0x1a8 Godzina uruchomienia aplikacji powodującej błąd: 0xsteamwebhelper.exe0 Ścieżka aplikacji powodującej błąd: steamwebhelper.exe1 Ścieżka modułu powodującego błąd: steamwebhelper.exe2 Identyfikator raportu: steamwebhelper.exe3 Error: (08/20/2015 11:57:37 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 08:30:41 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/19/2015 06:50:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: steamwebhelper.exe, wersja: 2.91.71.80, sygnatura czasowa: 0x55cb7c96 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0xc0140998 Identyfikator procesu powodującego błąd: 0x109c Godzina uruchomienia aplikacji powodującej błąd: 0xsteamwebhelper.exe0 Ścieżka aplikacji powodującej błąd: steamwebhelper.exe1 Ścieżka modułu powodującego błąd: steamwebhelper.exe2 Identyfikator raportu: steamwebhelper.exe3 Error: (08/19/2015 02:52:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/19/2015 08:22:53 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/18/2015 05:15:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: ekrn.exe, wersja: 8.0.304.0, sygnatura czasowa: 0x542bf4a4 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x091673f3 Identyfikator procesu powodującego błąd: 0x7c8 Godzina uruchomienia aplikacji powodującej błąd: 0xekrn.exe0 Ścieżka aplikacji powodującej błąd: ekrn.exe1 Ścieżka modułu powodującego błąd: ekrn.exe2 Identyfikator raportu: ekrn.exe3 Error: (08/18/2015 01:43:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/22/2015 03:12:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi TAOFrame z powodu następującego błędu: %%3 Error: (08/22/2015 03:12:06 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: 3TAOFrame{88260EA6-BC91-42DF-ABEF-4A683E8A3C23} Error: (08/21/2015 06:32:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Steam Client Service z powodu następującego błędu: %%1053 Error: (08/21/2015 06:32:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Steam Client Service. Error: (08/20/2015 02:48:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa TAOFrame niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. Error: (08/20/2015 02:25:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa TAOFrame niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (08/20/2015 11:56:21 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: sysmon Error: (08/20/2015 11:55:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Rav Service z powodu następującego błędu: %%2 Error: (08/20/2015 11:55:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Rsd Service z powodu następującego błędu: %%2 Error: (08/20/2015 09:21:25 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa TAOFrame niespodziewanie zakończyła pracę. Wystąpiło to razy: 3. Microsoft Office: ========================= Error: (08/22/2015 03:18:02 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/21/2015 03:50:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: nbaex.exe0.0.0.0545a04c8nbaex.exe0.0.0.0545a04c8c000000500092aee242001d0dc17c02fcfa5C:\Program Files\MKJogo\MK IM\Bin\nbaex.exeC:\Program Files\MKJogo\MK IM\Bin\nbaex.exe890d675f-480b-11e5-89a4-00304f170966 Error: (08/20/2015 04:19:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: steamwebhelper.exe2.91.71.8055cb7c96libcef.dll3.2357.1273.05581d4e880000003000894f91a801d0db4465037696C:\Program Files\Steam\bin\steamwebhelper.exeC:\Program Files\Steam\bin\libcef.dll7629332d-4746-11e5-89a4-00304f170966 Error: (08/20/2015 11:57:37 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 08:30:41 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/19/2015 06:50:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: steamwebhelper.exe2.91.71.8055cb7c96unknown0.0.0.000000000c0000005c0140998109c01d0da9dadfec58eC:\Program Files\Steam\bin\steamwebhelper.exeunknown6996033f-4692-11e5-9165-00304f170966 Error: (08/19/2015 02:52:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/19/2015 08:22:53 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/18/2015 05:15:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: ekrn.exe8.0.304.0542bf4a4unknown0.0.0.000000000c0000005091673f37c801d0d9aae08ef158C:\Program Files\ESET\ESET Smart Security\ekrn.exeunknowne713395e-45bb-11e5-910d-00304f170966 Error: (08/18/2015 01:43:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3 CPU 540 @ 3.07GHz Percentage of memory in use: 71% Total physical RAM: 3319.49 MB Available physical RAM: 945.39 MB Total Virtual: 6637.3 MB Available Virtual: 3890.2 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:104.33 GB) (Free:21.77 GB) NTFS Drive d: () (Fixed) (Total:361.33 GB) (Free:360.48 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: F9D4F9D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=104.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=361.3 GB) - (Type=07 NTFS) ==================== End of log ============================