Additional scan result of Farbar Recovery Scan Tool (x64) Version:08-06-2015 Ran by User at 2015-06-13 13:59:10 Running from C:\Users\User\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-127472655-3634354632-1811636288-500 - Administrator - Disabled) Gość (S-1-5-21-127472655-3634354632-1811636288-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-127472655-3634354632-1811636288-1002 - Limited - Enabled) User (S-1-5-21-127472655-3634354632-1811636288-1000 - Administrator - Enabled) => C:\Users\User ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-127472655-3634354632-1811636288-1000\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Reader XI - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated) Autodesk DWF Viewer (HKLM-x32\...\Autodesk DWF Viewer) (Version: 4.1 - Autodesk, Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation) Borland Database Engine Setup (HKLM-x32\...\Borland Database Engine Setup) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0407 - Disc Soft Ltd) Eusing Free Registry Cleaner (HKLM-x32\...\Eusing Free Registry Cleaner) (Version: - Eusing Software) EWMAPA FB (HKLM-x32\...\EWMAPA10) (Version: 10.00.00.00 - Geobid sp. z o.o.) Geodeska 3D 2005 (HKLM-x32\...\{5783F2D7-0308-0415-0002-0060B0CE6BBA}) (Version: 16.319.10.92 - Autodesk) HP Deskjet 3520 series — badanie mające na celu poprawę produktów (HKLM\...\{EF04170D-0CE0-40E7-9F25-3A2BA2425C6E}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Deskjet 3520 series — podstawowe oprogramowanie urządzenia (HKLM\...\{2AF6DE35-EF82-42D5-86CA-9DE53EA29318}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Deskjet 3520 series Pomoc (HKLM-x32\...\{B15746C1-344B-40F8-A54E-85AD2AD8E81E}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation) K-Lite Codec Pack 10.0.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.0.5 - ) Malwarebytes Anti-Malware wersja 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Mozilla Firefox 38.0.5 (x86 pl) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 pl)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 36.0.4 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) PLAY ONLINE (HKLM-x32\...\PLAY ONLINE) (Version: 21.005.11.17.264 - Huawei Technologies Co.,Ltd) Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) WinKalk (HKLM-x32\...\WinKalk) (Version: - ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {48A4E475-6A23-498D-95EC-4C76F0EADAD3} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {5F2F5287-5302-47CD-9107-D6FA1A22F2DE} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {99F0728E-AE51-45AF-8599-095287937610} - \CCleanerSkipUAC No Task File <==== ATTENTION Task: {9E79BD00-675B-4F7D-821D-D187BD3E77CF} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {A055A3A0-D9C7-4406-979B-21429482EC0B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-10] (Adobe Systems Incorporated) Task: {BC52F102-95CF-46D6-8DD9-CABC0944AECA} - System32\Tasks\HPCustParticipation HP Deskjet 3520 series => C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {C3D22DE8-93FC-4C74-BE3B-5784AA4CFF16} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2015-04-03] (Microsoft Corporation) Task: {D0250F3F-6480-484F-B719-42F659AC64D5} - No Task path Task: {DDF2333F-1A28-4A76-A6E6-FB8009C6B3C5} - System32\Tasks\{A9FB9DBD-BED4-4425-93DF-B7A6359E2685} => pcalua.exe -a C:\Users\User\AppData\Roaming\do-search\UninstallManager.exe -c -ptid=cor Task: {EA0E62C7-743D-4616-911A-DCCB96457528} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-05-25] (Avast Software s.r.o.) Task: {FD5A7FBE-2F0A-4303-8B0C-2D61E46FE610} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (Whitelisted) ============== 2015-04-02 11:28 - 2014-03-20 06:34 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-03-13 15:54 - 2015-03-13 15:54 - 00050688 _____ () D:\Programy\CCleaner\lang\lang-1045.dll 2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2015-04-13 09:22 - 2015-04-13 09:21 - 00246112 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe 2015-05-25 15:41 - 2015-05-25 15:41 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-05-25 15:41 - 2015-05-25 15:41 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-06-13 10:30 - 2015-06-13 10:30 - 02954752 _____ () C:\Program Files\AVAST Software\Avast\defs\15061201\algo.dll 2015-04-02 11:42 - 2015-04-02 11:42 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-04-13 09:22 - 2015-04-13 09:21 - 00011362 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\mingwm10.dll 2015-04-13 09:22 - 2015-04-13 09:21 - 00043008 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\libgcc_s_dw2-1.dll 2015-04-13 09:22 - 2015-04-13 09:21 - 02415104 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtCore4.dll 2015-04-13 09:22 - 2015-04-13 09:21 - 01148416 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtNetwork4.dll 2015-04-13 09:22 - 2015-04-13 09:21 - 00384512 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QueryStrategy.dll 2015-04-13 09:22 - 2015-04-13 09:21 - 00398336 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtXml4.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:430C6D84 AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-127472655-3634354632-1811636288-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{1CF65B52-B6B9-4AAA-9331-FFAEFA8ED0CC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{0DF4F3E5-6491-4325-BA26-2E421337789F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{AB4CFE14-CA7C-4B8C-9076-7DB6B49DF058}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{389DDBCB-0804-416B-A8FF-D98DE68D006D}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{818A3694-77BD-4CE6-BDF7-C5C93A2B5C0F}] => (Allow) C:\Windows\System32\hasplms.exe FirewallRules: [{0C2BC5EE-12BE-4853-9E64-1F3B852F8F76}] => (Allow) C:\Windows\System32\hasplms.exe FirewallRules: [{B75FDC86-7ACB-4022-8269-F366750AB7CF}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{45E0A54E-50D0-47BA-B43B-8AF0985A89C2}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{A7BE1B1E-326A-4E6B-ADB5-FE40B3C557A7}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\DeviceSetup.exe FirewallRules: [{DB9483C8-2CF6-4FD4-8242-607A3A14F515}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe FirewallRules: [{09C1BFBA-2D10-4CE8-8BC1-73939C24239B}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{AAD5584C-7BED-4F3C-905C-71F8C7CE53F7}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{F713A1AD-929B-48E0-8295-13E6DD52AD5E}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{9085C16D-3E88-4188-AD7B-AA3BF6039AE5}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{0C5F41A5-0870-41EE-BE7F-2585C1E5E7E8}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{4B18408B-4668-4D99-ABD6-2C2BAECDE9C3}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe ==================== Faulty Device Manager Devices ============= Name: Generic Bluetooth Adapter Description: Generic Bluetooth Adapter Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: GenericAdapter Service: BTHUSB Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Event log errors: ========================= Application errors: ================== Error: (06/13/2015 01:58:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:25 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:18 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:18 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:13 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:08 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. Error: (06/13/2015 01:58:08 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4110) (User: ) Description: Nie można dodać certyfikatu do magazynu głównych urzędów certyfikacji innej firmy z powodu błędu: Odmowa dostępu. System errors: ============= Error: (06/13/2015 00:41:21 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: ) Description: WMPNetworkSvc0x80070006 Error: (06/13/2015 00:38:34 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: ZARZĄDZANIE NT) Description: Usługa Harmonogram zadań nie może załadować zadań podczas uruchamiania usługi. Dane dodatkowe: Wartość błędu: 2147942402. Error: (06/13/2015 00:38:31 PM) (Source: BTHUSB) (EventID: 17) (User: ) Description: W lokalnym adapterze Bluetooth wystąpił nieokreślony błąd. Adapter nie będzie używany. Sterownik został usunięty z pamięci. Error: (06/13/2015 00:38:20 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: ZARZĄDZANIE NT) Description: 0x8000002a36\SystemRoot\System32\Config\SOFTWARE Error: (06/13/2015 00:08:45 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: ) Description: WMPNetworkSvc0x80070006 Error: (06/13/2015 00:06:14 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: ZARZĄDZANIE NT) Description: Usługa Harmonogram zadań nie może załadować zadań podczas uruchamiania usługi. Dane dodatkowe: Wartość błędu: 2147942402. Error: (06/13/2015 00:06:12 PM) (Source: BTHUSB) (EventID: 17) (User: ) Description: W lokalnym adapterze Bluetooth wystąpił nieokreślony błąd. Adapter nie będzie używany. Sterownik został usunięty z pamięci. Error: (06/13/2015 00:06:00 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: ZARZĄDZANIE NT) Description: 0x8000002a36\SystemRoot\System32\Config\SOFTWARE Error: (06/13/2015 11:04:43 AM) (Source: WMPNetworkSvc) (EventID: 14329) (User: ) Description: WMPNetworkSvc0x80070006 Error: (06/13/2015 11:02:15 AM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: ZARZĄDZANIE NT) Description: Usługa Harmonogram zadań nie może załadować zadań podczas uruchamiania usługi. Dane dodatkowe: Wartość błędu: 2147942402. Microsoft Office: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz Percentage of memory in use: 57% Total physical RAM: 4007.77 MB Available physical RAM: 1687.79 MB Total Pagefile: 8013.74 MB Available Pagefile: 5865.77 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:146.39 GB) (Free:115.93 GB) NTFS Drive d: () (Fixed) (Total:319.28 GB) (Free:309.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 16401F0E) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=146.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=319.3 GB) - (Type=07 NTFS) ==================== End of log ============================