Additional scan result of Farbar Recovery Scan Tool (x86) Version: 08-12-2014 Ran by darek at 2014-12-12 19:45:35 Running from C:\Documents and Settings\darek\Moje dokumenty Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) ABBYY FineReader 4.0 Sprint (HKLM\...\ABBYY FineReader 4.0 Sprint) (Version: - ) ABBYY PDF Transformer 1.0 (HKLM\...\{4837718C-5B6E-4496-B283-FFFB5A937825}) (Version: 1.00.847.4183 - ABBYY Software House) AC3Filter (remove only) (HKLM\...\AC3Filter) (Version: - ) ACE Mega CoDecS Pack (HKLM\...\{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1) (Version: 6.03.0911 - ACE DESIGN Software) Adobe Acrobat 4.0 (HKLM\...\Adobe Acrobat 4.0) (Version: 4.0 - Adobe Systems, Inc.) ADSL Modem (HKLM\...\StmAdsl) (Version: - ) Advanced Uninstaller 4.0 Special Edition (HKLM\...\AUSE4_is1) (Version: - Innovative Solutions) Any Video Converter 2.0.7 (HKLM\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com) Astariel version 1.7 (HKLM\...\Astariel_is1) (Version: - ) Athlon 64 Processor Driver (HKLM\...\{C151CE54-E7EA-4804-854B-F515368B0798}) (Version: 1.1.0.18 - ) Audacity 1.2.3 (HKLM\...\Audacity_is1) (Version: - ) avast! Free Antivirus (HKLM\...\avast) (Version: 8.0.1483.0 - AVAST Software) AviSynth 2.5 (HKLM\...\AviSynth) (Version: - ) CDCheck (HKLM\...\CDCheck) (Version: - ) ConvertXtoDVD 2.0.1 (HKLM\...\{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1) (Version: 2.0.1 - VSO-Software SARL) Disclib 1.0.4.36 (HKLM\...\Disclib_is1) (Version: - Lyrasoftware) DivX 5.0.3 Bundle (HKLM\...\DivX Codec) (Version: - ) Drive Rescue 1.9 (HKLM\...\Drive Rescue_is1) (Version: - Alexander Grau) DVD Solution (HKLM\...\{B97CF5C3-0487-11D8-A36E-0050BAE317E1}) (Version: - ) EasyCleaner (HKLM\...\{F5346614-B7C4-4E94-826A-E2363155233D}) (Version: 2.0.6.380 - ) eMule (HKLM\...\eMule) (Version: - ) English Translator 2 (HKLM\...\ET_2) (Version: - ) ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - ) ffdshow [rev 1738] [2008-01-01] (HKLM\...\ffdshow_is1) (Version: 1.0 - ) FlashGet(JetCar) (HKLM\...\FlashGet(JetCar)) (Version: - ) FM Screen Capture Codec (Remove Only) (HKLM\...\FMCODEC) (Version: - ) Garmin MapSource (HKLM\...\{CE428642-5112-49AC-B08F-D87DA8392FD2}) (Version: 6.12.2.0 - Garmin Ltd or its subsidiaries) GermaniXEncoder (HKLM\...\GermaniXEncoder) (Version: - ) GG (HKU\S-1-5-21-1606980848-1284227242-839522115-1003\...\GG) (Version: 12 - GG Network S.A.) GPMapa 5.0 (HKLM\...\{29A1F640-2AC5-443F-8987-C777A247A766}) (Version: 5.00 - Imagis Sp. z o.o.) HijackThis 2.0.2 (HKLM\...\HijackThis) (Version: 2.0.2 - TrendMicro) Image Eye v3.9 (HKLM\...\Image Eye) (Version: - ) KC Softwares VideoInspector (HKLM\...\KC Softwares VideoInspector_is1) (Version: - KC Softwares) MagicRotation (HKLM\...\{B5428E17-1886-4DBB-A148-DACBB60D7A3D}) (Version: 1.00.02 - ) MagicTune3.6 (HKLM\...\{1C04D433-2EDF-4AFB-B31B-C0B13065092F}) (Version: 1.00.0000 - ) Malwarebytes Anti-Malware wersja 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft Office FrontPage 2003 (HKLM\...\{90170415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.7969.0 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM\...\{90110415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Windows Media Video 9 VCM (HKLM\...\WMV9_VCM) (Version: - ) Mozilla Firefox 23.0.1 (x86 pl) (HKLM\...\Mozilla Firefox 23.0.1 (x86 pl)) (Version: 23.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 23.0.1 - Mozilla) Mp3tag v2.41a (HKLM\...\Mp3tag) (Version: v2.41a - Florian Heidenreich) Multimedia Launcher (HKLM\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: - ) Natural Color (HKLM\...\{F51D9393-BB14-4566-99BF-D6ED63AEFCD7}) (Version: - ) Neostrada TP (HKLM\...\NeostradaTP.exe) (Version: - ) Nero Suite (HKLM\...\NeroMultiInstaller!UninstallKey) (Version: - ) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) On2 VP7 Personal Edition (HKLM\...\{DD0DDC9E-2ED4-44DD-B461-0EFC126813A0}) (Version: - ) Panda ActiveScan (HKLM\...\Panda ActiveScan) (Version: - Panda Software S.L.) Panda ActiveScan 2.0 (HKLM\...\ActiveScan 2.0) (Version: 01.03.03.0000 - Panda Security) Panda Cloud Cleaner (HKLM\...\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.0.107 - Panda Security) Pazera Free 3GP to AVI Converter 1.4 (HKLM\...\{E39CFEE2-008E-459A-ADFD-60852A445D48}_is1) (Version: 1.4 - Jacek Pazera) PC Wizard 2007.1.72 (HKLM\...\PC Wizard 2007_is1) (Version: - Laurent KUTIL & Franck DELATTRE) PLAY ONLINE (HKLM\...\PLAY ONLINE) (Version: 11.302.09.06.264 - Huawei Technologies Co.,Ltd) PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - ) QuickTime (HKLM\...\QuickTime) (Version: - ) ratDVD 0.7.1235 (HKLM\...\ratDVD) (Version: 0.7.1235 - ratDVD) Real Alternative 1.7.5 Lite (HKLM\...\RealAlt_is1) (Version: 1.7.5 - ) Realtek AC'97 Audio (HKLM\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: - ) SnagIt 5 (HKLM\...\SnagIt5) (Version: 5.0 - TechSmith Corporation) SoulSeek 157 NS 13 (HKLM\...\Soulseek2) (Version: - ) SoulSeek Client 156c (HKLM\...\Soulseek) (Version: - ) Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: - ) V.R (HKLM\...\Rzeczpospolita - Angielski dla dzieci_is1) (Version: - ) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Winamp (remove only) (HKLM\...\Winamp) (Version: - ) WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - ) WinX Free DVD Ripper 4.5.11 (HKLM\...\WinX Free DVD Ripper_is1) (Version: - Digiarty Software,Inc.) xat.com JPEG Optimizer (HKLM\...\xat.com JPEG Optimizer) (Version: - ) ZD Soft Screen Video Decoder (HKLM\...\ZDSV) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1606980848-1284227242-839522115-1003_Classes\CLSID\{010833F3-751A-402F-9FCC-C365B6A12E41}\localserver32 -> C:\Downloads\BESTplayer.exe (Karol Winnicki) CustomCLSID: HKU\S-1-5-21-1606980848-1284227242-839522115-1003_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Documents and Settings\darek\Dane aplikacji\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.) ==================== Restore Points ========================= 10-12-2014 13:55:58 Punkt kontrolny systemu 12-12-2014 17:24:11 Removed Java 7 Update 17 12-12-2014 17:24:55 Removed Java(TM) 6 Update 5 12-12-2014 17:26:36 Removed Java 2 Runtime Environment, SE v1.4.0_03 12-12-2014 17:27:45 przed java- 12-12-2014 17:28:26 Removed J2SE Runtime Environment 5.0 Update 8 12-12-2014 17:45:09 Operacja przywracania 12-12-2014 18:16:42 Removed J2SE Runtime Environment 5.0 Update 8 12-12-2014 18:34:57 po fixie przed ffdshow ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2001-10-26 18:45 - 2014-12-12 19:24 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-1284227242-839522115-1004Core.job => C:\Documents and Settings\Adam\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-1284227242-839522115-1004UA.job => C:\Documents and Settings\Adam\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2006-10-23 09:50 - 2005-08-18 13:19 - 00032768 _____ () C:\Program Files\SEC\MagicTune3.6\Highlight.dll 2014-12-08 17:24 - 2014-12-08 09:28 - 02896896 _____ () C:\Program Files\Alwil Software\Avast5\defs\14120800\algo.dll 2010-11-16 14:37 - 2010-11-16 14:37 - 00264704 _____ () C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe 2006-10-23 09:50 - 2005-11-08 08:21 - 00040960 _____ () C:\Program Files\SEC\MagicTune3.6\I2CDll.dll 2006-10-23 09:50 - 2005-08-18 13:20 - 00032768 _____ () C:\Program Files\SEC\MagicTune3.6\HzZone.dll 2006-10-23 09:50 - 2005-11-08 07:57 - 09588736 _____ () C:\Program Files\SEC\MagicTune3.6\MTResEng.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1606980848-1284227242-839522115-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator darek (S-1-5-21-1606980848-1284227242-839522115-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\darek Gość (S-1-5-21-1606980848-1284227242-839522115-501 - Limited - Disabled) Pomocnik (S-1-5-21-1606980848-1284227242-839522115-1000 - Limited - Disabled) SUPPORT_388945a0 (S-1-5-21-1606980848-1284227242-839522115-1002 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/12/2014 07:16:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd javaws.exe, wersja 5.0.80.3, moduł powodujący błąd msvcrt.dll, wersja 7.0.2600.2180, adres błędu 0x000383b4. Przetwarzanie zdarzenia określonego nośnika dla [javaws.exe!ws!] Error: (12/11/2014 09:33:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd glzw.dll, wersja 1.0.1.0, adres błędu 0x0000200a. Przetwarzanie zdarzenia określonego nośnika dla [explorer.exe!ws!] Error: (12/07/2014 05:07:02 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Aplikacja zawieszająca EasyClea.exe, wersja 2.0.6.380, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error: (12/07/2014 01:18:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd glzw.dll, wersja 1.0.1.0, adres błędu 0x0000200a. Przetwarzanie zdarzenia określonego nośnika dla [explorer.exe!ws!] Error: (12/07/2014 01:17:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd glzw.dll, wersja 1.0.1.0, adres błędu 0x0000200a. Przetwarzanie zdarzenia określonego nośnika dla [explorer.exe!ws!] Error: (12/06/2014 09:53:44 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd glzw.dll, wersja 1.0.1.0, adres błędu 0x0000200a. Przetwarzanie zdarzenia określonego nośnika dla [explorer.exe!ws!] Error: (12/06/2014 09:53:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd glzw.dll, wersja 1.0.1.0, adres błędu 0x0000200a. Przetwarzanie zdarzenia określonego nośnika dla [explorer.exe!ws!] Error: (12/06/2014 09:52:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd glzw.dll, wersja 1.0.1.0, adres błędu 0x0000200a. Przetwarzanie zdarzenia określonego nośnika dla [explorer.exe!ws!] Error: (12/06/2014 00:17:36 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd glzw.dll, wersja 1.0.1.0, adres błędu 0x0000200a. Przetwarzanie zdarzenia określonego nośnika dla [explorer.exe!ws!] Error: (12/05/2014 10:53:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd nero.exe, wersja 6.3.1.26, moduł powodujący błąd unknown, wersja 0.0.0.0, adres błędu 0x0671bd60. Przetwarzanie zdarzenia określonego nośnika dla [nero.exe!ws!] System errors: ============= Error: (12/12/2014 07:23:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Bufor wydruku niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 60000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (12/12/2014 07:23:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Instalator Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (12/12/2014 07:23:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa HWDeviceService.exe niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (12/12/2014 07:00:00 PM) (Source: Schedule) (EventID: 7901) (User: ) Description: Uruchomienie polecenia At44.job nie powiodło się, ponieważ wystąpił następujący błąd: %%2147942402 Error: (12/12/2014 07:00:00 PM) (Source: Schedule) (EventID: 7901) (User: ) Description: Uruchomienie polecenia At20.job nie powiodło się, ponieważ wystąpił następujący błąd: %%2147942402 Error: (12/12/2014 06:18:38 PM) (Source: DCOM) (EventID: 10005) (User: ZARZĄDZANIE NT) Description: Model DCOM odebrał błąd „%%1084” podczas próby uruchomienia usługi EventSystem z argumentami „” w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (12/12/2014 06:14:37 PM) (Source: DCOM) (EventID: 10005) (User: ZAQ) Description: Model DCOM odebrał błąd „%%1084” podczas próby uruchomienia usługi netman z argumentami „” w celu uruchomienia serwera: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error: (12/12/2014 06:14:11 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: AFD AmdK8 aswRdr aswSnx aswSP aswTdi Fips IPSec magicpvt MRxSmb NetBIOS NetBT pavboot RasAcd Rdbss Tcpip Error: (12/12/2014 06:14:11 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Usługa Usługi IPSEC zależy od usługi Sterownik IPSEC, której nie można uruchomić z powodu następującego błędu: %%31 Error: (12/12/2014 06:14:11 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Usługa Pomoc TCP/IP NetBIOS zależy od usługi AFD, której nie można uruchomić z powodu następującego błędu: %%31 Microsoft Office Sessions: ========================= Error: (12/12/2014 07:16:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: javaws.exe5.0.80.3msvcrt.dll7.0.2600.2180000383b4 Error: (12/11/2014 09:33:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.2180glzw.dll1.0.1.00000200a Error: (12/07/2014 05:07:02 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: EasyClea.exe2.0.6.380hungapp0.0.0.000000000 Error: (12/07/2014 01:18:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.2180glzw.dll1.0.1.00000200a Error: (12/07/2014 01:17:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.2180glzw.dll1.0.1.00000200a Error: (12/06/2014 09:53:44 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.2180glzw.dll1.0.1.00000200a Error: (12/06/2014 09:53:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.2180glzw.dll1.0.1.00000200a Error: (12/06/2014 09:52:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.2180glzw.dll1.0.1.00000200a Error: (12/06/2014 00:17:36 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.0.2900.2180glzw.dll1.0.1.00000200a Error: (12/05/2014 10:53:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: nero.exe6.3.1.26unknown0.0.0.00671bd60 ==================== Memory info =========================== Processor: AMD Sempron(tm) Processor 2500+ Percentage of memory in use: 36% Total physical RAM: 1023.48 MB Available physical RAM: 654.19 MB Total Pagefile: 1693.34 MB Available Pagefile: 1473.43 MB Total Virtual: 2047.88 MB Available Virtual: 1949.27 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:29.29 GB) (Free:2.54 GB) NTFS ==>[Drive with boot components (Windows XP)] Drive d: (Nowy) (Fixed) (Total:119.75 GB) (Free:0.31 GB) NTFS Drive f: () (Fixed) (Total:3.8 GB) (Free:0.55 GB) FAT32 Drive g: (Nowy) (Fixed) (Total:33.5 GB) (Free:0.09 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 149 GB) (Disk ID: 23D87816) Partition 1: (Active) - (Size=29.3 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=119.7 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 37.3 GB) (Disk ID: 7F31552D) Partition 1: (Active) - (Size=3.8 GB) - (Type=0B) Partition 2: (Not Active) - (Size=33.5 GB) - (Type=OF Extended) ==================== End Of Log ============================