Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-08-2015 Ran by Pawel.Zawadzki (2015-08-24 11:18:06) Running from C:\Users\pawel.zawadzki\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-645245218-766633011-3774407696-500 - Administrator - Enabled) => C:\Users\Administrator.YAPP-DLG10 Gość (S-1-5-21-645245218-766633011-3774407696-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Trend Micro OfficeScan Antivirus (Disabled - Up to date) {B7599298-8445-728A-A5C7-A26A082C8BDA} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Trend Micro OfficeScan Anti-spyware (Disabled - Up to date) {0C38737C-A27F-7D04-9F77-991873ABC167} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: Trend Micro Personal Firewall (Enabled) {49A8346C-6900-54B6-B1B3-5F678736DDE9} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1860 - Adobe Systems Incorporated) Adobe Flash Player 10 ActiveX (HKLM-x32\...\{B7B3E9B3-FB14-4927-894B-E9124509AF5A}) (Version: 10.0.32.18 - Adobe Systems, Inc.) Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.42.34 - Adobe Systems Incorporated) Adobe Reader X (10.1.15) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.15 - Adobe Systems Incorporated) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.3.2225 - AVAST Software) Burn.Now 4.5 (x32 Version: 4.5.0 - Corel Corporation) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform) Corel Burn.Now Lenovo Edition (HKLM-x32\...\InstallShield_{A3BE3F1E-2472-4211-8735-E8239BE49D9F}) (Version: 4.5.0 - Corel Corporation) Corel DVD MovieFactory 7 (x32 Version: 7.0.0 - Corel Corporation) Hidden Corel DVD MovieFactory Lenovo Edition (HKLM-x32\...\InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}) (Version: 7.0.0 - Corel Corporation) Create Recovery Media (HKLM-x32\...\{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}) (Version: 1.20.0.00 - Lenovo Group Limited) cwbin64a (Version: 05.04.0000 - IBM) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Direct DiscRecorder (x32 Version: 1.00.0000 - Corel Corporation) Hidden D-Link DWA-525 (HKLM-x32\...\{1DEB8A37-56C9-4E41-9102-171D8EC91DF0}) (Version: - D-Link) Engineering Client Viewer 7.0 (HKLM-x32\...\SAP_Engineering Client Viewer 7.0) (Version: - SAP AG) Evernote v. 4.2.3 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.3.15 - Evernote Corp.) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation) Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden GG (HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\GG) (Version: 12 - GG Network S.A.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden Huawei E3272 (HKLM-x32\...\Huawei E3272) (Version: 22.001.22.00.1202 - Huawei Technologies Co.,Ltd) IBM iSeries Access for Windows (HKLM-x32\...\ClientAccessExpress) (Version: - ) Intel AppUp(R) center (HKLM-x32\...\Intel AppUp(SM) center 33057) (Version: 41651 - Intel) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation) Intel(R) Network Connections 16.8.46.0 (HKLM\...\PROSetDX) (Version: 16.8.46.0 - Intel) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2696 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}) (Version: 1.23.216.0 - Intel Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LBAI (HKLM-x32\...\{C5C91B7B-38A6-40B7-84D6-E44885E44B13}) (Version: 1.0.0.6 - Lenovo) Lenovo Patch Utility 64 bit (HKLM\...\{0369F866-2CE0-4EB9-B426-88FA122C6E82}) (Version: 1.3.0.9 - Lenovo Group Limited) Lenovo Registration (HKLM-x32\...\{6707C034-ED6B-4B6A-B21F-969B3606FBDE}) (Version: 1.0.4 - Lenovo Inc.) Lenovo SimpleTap (HKLM\...\{BF601122-9F0A-41A9-BA06-3158D9FB4B80}) (Version: 3.2.0004.00 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{4041B18B-DE30-4D78-9D60-6ADC586C5E00}) (Version: 2.1.003.00 - Lenovo Group Limited) Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.02.0018 - Lenovo) Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0009.00 - Lenovo Group Limited) Lenovo Welcome (HKLM-x32\...\{2DC26D10-CC6A-494F-BEA3-B5BC21126D5E}) (Version: 3.1.0020.00 - Lenovo Group Limited) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Message Center Plus (HKLM\...\{3849486C-FF09-4F5D-B491-3E179D58EE15}) (Version: 3.1.0004.00 - Lenovo Group Limited) MetaFrame Presentation Server Client (HKLM-x32\...\{D989BCC0-757C-4FB6-893C-512DF4382656}) (Version: 9.200.44376 - Citrix Systems, Inc.) Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft Lync 2010 (HKLM\...\{11849FBC-C416-4742-8279-17C3A2C85F72}) (Version: 4.0.7577.0 - Microsoft Corporation) Microsoft Lync Web App Plug-in (HKLM\...\{D8228565-6CD7-40EF-B2EA-C7C95183EDEB}) (Version: 15.8.8308.577 - Microsoft Corporation) Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft redistributable runtime DLLs VS2005 SP1(x86) (HKLM-x32\...\{CEC7A786-A9C8-4EF7-BB59-6518E3B3C878}) (Version: 8.0.50727.4053 - SAP) Microsoft redistributable runtime DLLs VS2008 SP1(x86) (HKLM-x32\...\{A47A9101-6EB5-4314-BDA1-297880FBB908}) (Version: 9.0 - SAP AG) Microsoft redistributable runtime DLLs VS2010 SP1 (x86) (HKLM-x32\...\{2385C070-EC26-4AB9-8718-E605C977C0ED}) (Version: 10.0.40219.1 - SAP) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50826.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) mp (x32 Version: 05.03.0000 - IBM) Hidden mpmri (x32 Version: 05.03.0000 - IBM) Hidden OpenFM (HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\OpenFM) (Version: 2 - GG Network S.A.) Pakiet sterowników systemu Windows - Intel (e1cexpress) Net (01/11/2012 11.15.16.0) (HKLM\...\E6D02BAF356D0EEE96DE70D352026CE420321A16) (Version: 01/11/2012 11.15.16.0 - Intel) Pakiet sterowników systemu Windows - Intel Corporation (igfx) Display (03/19/2012 8.15.10.2696) (HKLM\...\6AF882A8E50505CE490495746E271C3F586F9110) (Version: 03/19/2012 8.15.10.2696 - Intel Corporation) Pakiet sterowników systemu Windows - Intel hdc (08/26/2011 9.3.0.1011) (HKLM\...\A7E82C89A6D6643325B95A4FEDAB3DB18640208F) (Version: 08/26/2011 9.3.0.1011 - Intel) Pakiet sterowników systemu Windows - Intel System (01/11/2012 9.3.0.1020) (HKLM\...\09839A9B5EDA69DA2DCC34637B5140AAF8A53B44) (Version: 01/11/2012 9.3.0.1020 - Intel) Pakiet sterowników systemu Windows - Intel System (08/26/2011 9.3.0.1011) (HKLM\...\9D7CD466F7FC8B18FF1B84943B7BB8648D17FCE8) (Version: 08/26/2011 9.3.0.1011 - Intel) Pakiet sterowników systemu Windows - Intel System (08/26/2011 9.3.0.1011) (HKLM\...\D8EF6CACF49BD33CC1FACD124C8CC2B1A8E8AE35) (Version: 08/26/2011 9.3.0.1011 - Intel) Pakiet sterowników systemu Windows - Intel USB (08/26/2011 9.3.0.1011) (HKLM\...\97EE1802A0385A37DE6323FA39EC76BEB2D73E41) (Version: 08/26/2011 9.3.0.1011 - Intel) Pakiet sterowników systemu Windows - Intel(R) Corporation (IntcDAud) MEDIA (12/06/2011 6.14.00.3090) (HKLM\...\8384654D490AA4CB537BE669DA59242CA3D85FF0) (Version: 12/06/2011 6.14.00.3090 - Intel(R) Corporation) Pakiet sterowników systemu Windows - Realtek Semiconductor Corp. HD Audio Driver (01/03/2012 6.0.1.6543) (HKLM\...\5DE3700033F94FCFD8726BE46A6727E460254CD5) (Version: 01/03/2012 6.0.1.6543 - Realtek Semiconductor Corp.) PDF reDirect (remove only) (HKLM-x32\...\PDF reDirect) (Version: v2.5.2 - EXP Systems LLC) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 1.00.0802 - Lenovo) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6543 - Realtek Semiconductor Corp.) SAP Business Explorer (HKLM-x32\...\SAPBI) (Version: 7.30 - SAP AG) SAP Console 7.10 (HKLM-x32\...\SAPConsole) (Version: - SAP AG) SAP GUI for Windows 7.30 (HKLM-x32\...\SAPGUI710) (Version: 7.30 Compilation 1 - SAP) SAPSetup Automatic Workstation Update Service (HKLM-x32\...\SAP_WUS) (Version: - SAP AG) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) TeamViewer 6 (HKLM-x32\...\TeamViewer 6) (Version: 6.0.12879 - TeamViewer GmbH) ThinkVantage Communications Utility (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 3.0.30.0 - Lenovo) ThinkVantage Power Manager (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}) (Version: 2.10.0007 - Lenovo Group Limited) Trend Micro OfficeScan Client (HKLM-x32\...\OfficeScanNT) (Version: 10.6.3205 - Trend Micro Inc.) View Management Utility (HKLM-x32\...\InstallShield_{C6254514-DD94-45E5-87C0-B9CB90A34C89}) (Version: 3.0.12.0329 - Lenovo) View Management Utility (Version: 3.0.12.0329 - Lenovo) Hidden VIP Access (HKLM-x32\...\{E8D46836-CD55-453C-A107-A59EC51CB8DC}) (Version: 2.0.5.13 - VeriSign) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-449068364-4053775113-1626773979-97692_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\pawel.zawadzki\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) ==================== Restore Points ========================= 23-06-2015 12:34:39 Zaplanowany punkt kontrolny 06-07-2015 11:59:14 Zaplanowany punkt kontrolny 15-07-2015 09:22:33 Windows Update 29-07-2015 12:23:02 Zaplanowany punkt kontrolny 21-08-2015 12:53:50 avast! antivirus system restore point ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0A0FB219-213D-43E3-860C-46A5718D06DE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated) Task: {18B1D21B-8DD1-4511-9240-1BD4F873F490} - System32\Tasks\Lenovo\SimpleTap\Start SimpleTap for LAN.Administrator => C:\Program Files\Lenovo\SimpleTap\SimpleTap.exe [2012-05-15] (Lenovo) Task: {28CE7835-ECE5-49C9-BC66-67FFE988997D} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-05-17] (Lenovo) Task: {4A561EB0-14FD-4690-BC80-A297BE56E20D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.) Task: {78FE38B9-9D49-4FF0-837E-23472D41DCB7} - System32\Tasks\Lenovo\Message Center Plus Launcher => C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe [2012-05-15] (Lenovo) Task: {7F553253-26D2-46F2-83DF-03AE91673B90} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-21] (AVAST Software) Task: {8537CF33-DAE6-40E9-A6DA-3DFB603C4DEA} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-06-26] () Task: {9E9E40BF-49BF-46DF-804F-E27BA0AE72D3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-17] (Piriform Ltd) Task: {B50A8921-22DB-42AA-A09A-82EA92BA7684} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-05-17] (Lenovo) Task: {CDC369FF-CD8B-4250-8C50-953E2053EC9D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.) Task: {D4DE543C-AE0E-45F1-8993-AA91E620B57E} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-05-17] () Task: {D54649EB-C55B-449A-86CC-1BDED2584C6E} - System32\Tasks\PMTask => C:\Program Files (x86)\Lenovo\PowerMgr\PWMIDTSV.EXE [2012-02-22] (Lenovo Group Limited) Task: {F7C3C051-3948-4A62-A9F4-672338D71F02} - System32\Tasks\Lenovo\SimpleTap\Start SimpleTap for a-THINK.a => C:\Program Files\Lenovo\SimpleTap\SimpleTap.exe [2012-05-15] (Lenovo) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2010-06-06 16:20 - 2010-06-06 16:20 - 00065344 _____ () C:\Windows\System32\PDFreDirectMon64.dll 2013-06-17 12:03 - 2010-07-12 14:39 - 00053248 _____ () C:\Program Files (x86)\D-Link\DWA-525 revA\ANIWConnService.exe 2015-07-03 11:40 - 2013-12-03 08:09 - 00240720 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe 2013-03-27 14:25 - 2011-04-01 14:16 - 00801792 _____ () C:\Program Files (x86)\Trend Micro\OfficeScan Client\sqlite3.dll 2013-03-27 14:25 - 2007-05-16 12:42 - 00089088 _____ () C:\Program Files (x86)\Trend Micro\OfficeScan Client\zlibwapi.dll 2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2013-04-05 08:16 - 2012-03-19 09:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-06-28 12:55 - 2012-06-02 15:28 - 00534397 _____ () D:\Datum Memory Booster\memBoost.exe 2015-07-17 19:34 - 2015-07-17 19:34 - 00061440 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll 2013-04-04 22:34 - 2012-02-12 20:10 - 00029184 ____N () C:\Program Files (x86)\Lenovo\PowerMgr\US\PWMRT64V.DLL 2015-08-21 12:55 - 2015-08-21 12:55 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-08-21 12:55 - 2015-08-21 12:55 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-08-24 10:33 - 2015-08-24 10:33 - 02960896 _____ () C:\Program Files\AVAST Software\Avast\defs\15082400\algo.dll 2013-04-04 22:38 - 2012-01-17 08:29 - 00030512 ____N () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00322048 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\log4cplus.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00400384 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\sqlite3.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00016896 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\featureController.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\osEvents.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00195584 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\libgsoap.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00062464 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\zlib1.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00020480 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\eventsSender.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00446976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\deviceProfile.dll 2013-04-04 22:42 - 2012-12-14 19:55 - 00064512 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\serviceManagerStarter.dll 2013-06-17 12:04 - 2013-06-17 12:04 - 00315392 _____ () C:\Program Files (x86)\D-Link\DWA-525 revA\ANPDApi.dll 2013-06-17 12:03 - 2010-05-13 10:58 - 00294912 _____ () C:\Program Files (x86)\D-Link\DWA-525 revA\WlanApp.dll 2015-08-21 12:55 - 2015-08-21 12:55 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-06-07 09:55 - 2013-06-07 09:55 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\3346874287dfbb81c2925cafea362cf0\IsdiInterop.ni.dll 2013-04-04 22:30 - 2011-11-29 20:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2015-08-21 09:34 - 2015-08-18 07:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll 2015-08-21 09:34 - 2015-08-18 07:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll 2013-04-04 22:31 - 2011-12-16 04:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\localhost -> hxxps://localhost IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\pfn.vwg -> hxxps://kvspfv1.pfn.vwg IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\systech.local -> hxxp://systech.local IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\systech.local -> hxxps://systech.local IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\yazaki-europe.com -> hxxps://autodiscover.yazaki-europe.com IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\yazaki.com -> hxxps://autodiscover.eu.yazaki.com IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\yazaki.local -> *.yel.yazaki.local IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\yelblrd01 -> hxxps://yelblrd01 IE trusted site: HKU\S-1-5-21-449068364-4053775113-1626773979-97692\...\yelk-dc01 -> hxxps://yelk-dc01 ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-449068364-4053775113-1626773979-97692\Control Panel\Desktop\\Wallpaper -> C:\Users\pawel.zawadzki\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 10.42.250.1 - 10.42.251.201 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Client Access Help Update => "C:\Program Files (x86)\IBM\Client Access\cwbinhlp.exe" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{88D4A504-3BAB-4625-B57C-73B6A0FC04C3}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{26E540F8-50BC-4493-8BDF-C14240140A69}] => (Allow) LPort=2869 FirewallRules: [{F7CD1352-2E28-4AB1-A5CC-C80B538A6A59}] => (Allow) LPort=1900 FirewallRules: [{54C65F3B-7417-4165-91F3-6CB742333A69}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{FB3B4F57-F6D9-42A5-A80A-1696B01A5473}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [{D4A32985-AF02-4DC7-BAF9-99FA138C39FC}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [{3C0CF3B0-8F35-42C4-8543-D02D192D9E65}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [TCP Query User{E7F8096D-CBDC-4830-BF71-40FC37C6CFBF}C:\program files (x86)\intel\intelappstore\bin\ismagent.exe] => (Allow) C:\program files (x86)\intel\intelappstore\bin\ismagent.exe FirewallRules: [UDP Query User{5D67E635-8C61-4416-97C3-863B874F7376}C:\program files (x86)\intel\intelappstore\bin\ismagent.exe] => (Allow) C:\program files (x86)\intel\intelappstore\bin\ismagent.exe FirewallRules: [{157E978B-B9CF-4075-A3CE-8704E01E0597}] => (Allow) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe FirewallRules: [TCP Query User{05A2A221-2A57-4CF6-87F3-991F9D0283C7}C:\program files (x86)\gadu-gadu 10\gg.exe] => (Allow) C:\program files (x86)\gadu-gadu 10\gg.exe FirewallRules: [UDP Query User{E230EDF9-FFAE-431E-9BFB-C57BF2105A89}C:\program files (x86)\gadu-gadu 10\gg.exe] => (Allow) C:\program files (x86)\gadu-gadu 10\gg.exe FirewallRules: [{381FB66F-062D-4C8A-89BC-8436F7EA10F7}] => (Allow) C:\Program Files (x86)\Microsoft Lync\communicator.exe FirewallRules: [{874D635D-29A9-4A05-A8C9-BE445BEDFCFF}] => (Allow) C:\Program Files (x86)\Microsoft Lync\UcMapi.exe FirewallRules: [{67C74572-24C6-4C49-83B4-C1347C1BD6C9}] => (Allow) C:\Program Files\Microsoft Lync\UcMapi64.exe FirewallRules: [{2F7B091D-F56B-45B0-A9FA-DE24CF19666A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe FirewallRules: [{45F2E32F-EF26-421A-9696-576A9B60539A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe FirewallRules: [{3B7A7DEE-5423-419E-A3CA-4D4FCD5C041A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe FirewallRules: [{0F729767-0332-4037-B8CA-4D8C282C0A44}] => (Allow) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe FirewallRules: [TCP Query User{DC0E7573-9751-411F-ABAB-916E5CFC6194}C:\program files (x86)\sap\frontend\sapgui\saplpd\saplpd.exe] => (Allow) C:\program files (x86)\sap\frontend\sapgui\saplpd\saplpd.exe FirewallRules: [UDP Query User{647C2C59-A3AB-4EB6-AF5C-E98AAD31B4C4}C:\program files (x86)\sap\frontend\sapgui\saplpd\saplpd.exe] => (Allow) C:\program files (x86)\sap\frontend\sapgui\saplpd\saplpd.exe FirewallRules: [{63CA6548-1340-4500-AB64-A009BC864003}] => (Allow) C:\Program Files (x86)\Microsoft Lync\communicator.exe FirewallRules: [{F672B54F-86D5-478A-ABCF-DBD13CEC8368}] => (Allow) C:\Program Files (x86)\Microsoft Lync\communicator.exe FirewallRules: [{0275156A-E52D-4CDD-B4B3-FF8BC588AFAD}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [{85EA0F90-CE52-41B1-A04C-CE8FDFDEDD3F}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [{061EB03D-5641-49EB-AC8A-26A85BE01AAA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{82B4AFFE-0FD7-4EB0-A1D3-968604B87D30}] => (Allow) LPort=44096 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/24/2015 11:10:05 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 10:33:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 09:50:44 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 09:05:24 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/21/2015 11:48:24 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/21/2015 09:04:55 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 01:09:22 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 01:06:33 PM) (Source: Windows Search Service) (EventID: 3100) (User: ) Description: Nie można zainicjować procesu hosta filtru. Kończenie. Szczegóły: Operacja została zwrócona, ponieważ przekroczono limit czasu. (HRESULT : 0x800705b4) (0x800705b4) Error: (08/20/2015 10:56:13 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 10:53:26 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program Explorer.EXE w wersji 6.1.7601.17567 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 898 Godzina rozpoczęcia: 01d0db13020d755b Godzina zakończenia: 14 Ścieżka aplikacji: C:\Windows\Explorer.EXE Identyfikator raportu: 99a0100c-4718-11e5-a630-fc4dd434709c System errors: ============= Error: (08/24/2015 11:09:52 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 11:09:15 na ‎2015-‎08-‎24 było nieoczekiwane. Error: (08/24/2015 10:33:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Power Manager DBC Service z powodu następującego błędu: %%1053 Error: (08/24/2015 10:33:01 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Power Manager DBC Service. Error: (08/24/2015 10:32:16 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 10:31:13 na ‎2015-‎08-‎24 było nieoczekiwane. Error: (08/24/2015 09:49:20 AM) (Source: NETLOGON) (EventID: 5719) (User: ) Description: Ten komputer nie może skonfigurować zabezpieczonej sesji z kontrolerem domeny w domenie YEL z następującego powodu: %%1311 To może powodować problemy z uwierzytelnianiem. Upewnij się, że ten komputer jest podłączony do sieci. Jeżeli problem się nie rozwiąże, skontaktuj się z administratorem domeny. INFORMACJE DODATKOWE Jeżeli ten komputer jest kontrolerem domeny dla określonej domeny, konfiguruje zabezpieczoną sesję z emulatorem podstawowego kontrolera domeny w określonej domenie. W przeciwnym przypadku komputer może skonfigurować zabezpieczoną sesję z dowolnym kontrolerem domeny w określonej domenie. Error: (08/24/2015 09:49:14 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 09:47:58 na ‎2015-‎08-‎24 było nieoczekiwane. Error: (08/24/2015 09:05:04 AM) (Source: NETLOGON) (EventID: 5719) (User: ) Description: Ten komputer nie może skonfigurować zabezpieczonej sesji z kontrolerem domeny w domenie YEL z następującego powodu: %%1311 To może powodować problemy z uwierzytelnianiem. Upewnij się, że ten komputer jest podłączony do sieci. Jeżeli problem się nie rozwiąże, skontaktuj się z administratorem domeny. INFORMACJE DODATKOWE Jeżeli ten komputer jest kontrolerem domeny dla określonej domeny, konfiguruje zabezpieczoną sesję z emulatorem podstawowego kontrolera domeny w określonej domenie. W przeciwnym przypadku komputer może skonfigurować zabezpieczoną sesję z dowolnym kontrolerem domeny w określonej domenie. Error: (08/21/2015 11:48:10 AM) (Source: NETLOGON) (EventID: 5719) (User: ) Description: Ten komputer nie może skonfigurować zabezpieczonej sesji z kontrolerem domeny w domenie YEL z następującego powodu: %%1311 To może powodować problemy z uwierzytelnianiem. Upewnij się, że ten komputer jest podłączony do sieci. Jeżeli problem się nie rozwiąże, skontaktuj się z administratorem domeny. INFORMACJE DODATKOWE Jeżeli ten komputer jest kontrolerem domeny dla określonej domeny, konfiguruje zabezpieczoną sesję z emulatorem podstawowego kontrolera domeny w określonej domenie. W przeciwnym przypadku komputer może skonfigurować zabezpieczoną sesję z dowolnym kontrolerem domeny w określonej domenie. Error: (08/21/2015 11:48:08 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Poprzednie zamknięcie systemu przy 11:46:39 na ‎2015-‎08-‎21 było nieoczekiwane. Error: (08/21/2015 09:24:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa TeamViewer 6 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 2000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Microsoft Office: ========================= Error: (08/24/2015 11:10:05 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 10:33:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 09:50:44 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/24/2015 09:05:24 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/21/2015 11:48:24 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/21/2015 09:04:55 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 01:09:22 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 01:06:33 PM) (Source: Windows Search Service) (EventID: 3100) (User: ) Description: Szczegóły: Operacja została zwrócona, ponieważ przekroczono limit czasu. (HRESULT : 0x800705b4) (0x800705b4) Error: (08/20/2015 10:56:13 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/20/2015 10:53:26 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Explorer.EXE6.1.7601.1756789801d0db13020d755b14C:\Windows\Explorer.EXE99a0100c-4718-11e5-a630-fc4dd434709c ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3550 CPU @ 3.30GHz Percentage of memory in use: 40% Total physical RAM: 3891.85 MB Available physical RAM: 2331.56 MB Total Virtual: 11673.73 MB Available Virtual: 9438.62 MB ==================== Drives ================================ Drive c: (Windows7_OS) (Fixed) (Total:226.42 GB) (Free:165.18 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive d: (Dane) (Fixed) (Total:224.2 GB) (Free:213.87 GB) NTFS Drive q: (Lenovo_Recovery) (Fixed) (Total:13.67 GB) (Free:3.86 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 04D23473) Partition 1: (Active) - (Size=1.5 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=226.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=224.2 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=13.7 GB) - (Type=07 NTFS) ==================== End of log ============================