Additional scan result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01 Ran by DOM at 2015-06-29 19:29:40 Running from C:\Users\DOM\Desktop\FRST64 Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1757415873-2226878437-4207686015-500 - Administrator - Disabled) DOM (S-1-5-21-1757415873-2226878437-4207686015-1000 - Administrator - Enabled) => C:\Users\DOM Gość (S-1-5-21-1757415873-2226878437-4207686015-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1757415873-2226878437-4207686015-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) "Nero SoundTrax Help (x32 Version: 4.0.15.0 - Nero AG) Hidden µTorrent (HKU\S-1-5-21-1757415873-2226878437-4207686015-1000\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) ACE Mega CoDecS Pack (HKLM-x32\...\{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1) (Version: 6.03.0911 - ACE DESIGN Software) Adobe Flash Player 17 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 17.0.0.190 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.194 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden Aktualizacje NVIDIA 2.4.3.22 (Version: 2.4.3.22 - NVIDIA Corporation) Hidden 'Âĺäüěŕę. Çîëîňîĺ Čçäŕíčĺ' (v.1.5) (HKLM-x32\...\'Âĺäüěŕę. Çîëîňîĺ Čçäŕíčĺ'_is1) (Version: - ) ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS) Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0008 - ASUS) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.2.0.65 - Atheros Communications) calibre 64bit (HKLM\...\{170BA998-F98B-47E6-A70E-8AE7B6F9E156}) (Version: 2.1.0 - Kovid Goyal) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Counter-Strike (HKLM-x32\...\Steam App 10) (Version: - Valve) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform) DolbyFiles (x32 Version: 2.0 - Nero AG) Hidden ETDWare PS/2-X64 8.0.5.0_WHQL (HKLM\...\Elantech) (Version: 8.0.5.0 - ELAN Microelectronic Corp.) Football Manager 2014 wersja 14.1.4 (HKLM-x32\...\Football Manager 2014_is1) (Version: 14.1.4 - Sega) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.242 - SurfRight B.V.) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Lightshot-5.2.1.1 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.1.1 - Skillbrains) Menu Templates - Starter Kit (x32 Version: 9.0.4.0 - Nero AG) Hidden Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (Polski) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1757415873-2226878437-4207686015-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft Outlook Hotmail Connector (wersja 64-bitowa) (HKLM\...\{95140000-007A-0415-1000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Outlook Hotmail Connector 64-bit (HKLM\...\{95140000-007A-0409-1000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Outlook Social Connector Provider for Windows Live Messenger 64-bit (HKLM\...\{95140000-007D-0409-1000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MoorHunt 2.1.14 (HKLM-x32\...\MoorHunt_is1) (Version: - http://moorhunt.pl) Movie Templates - Starter Kit (x32 Version: 9.0.4.0 - Nero AG) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NapiProjekt (2.2.0.2399) (HKLM-x32\...\NapiProjekt_is1) (Version: - ) Nero 9 (HKLM-x32\...\{ea8121c9-dad5-4f96-a575-88edf52caa81}) (Version: - Nero AG) NetCut 2.1.4 (HKLM-x32\...\NetCut_is1) (Version: - arcai.com) NVIDIA GeForce Experience 2.4.3.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.3.22 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) NVIDIA Sterownik graficzny 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation) OpenFM (HKU\S-1-5-21-1757415873-2226878437-4207686015-1000\...\OpenFM) (Version: 2 - GG Network S.A.) Panel sterowania NVIDIA 337.88 (Version: 337.88 - NVIDIA Corporation) Hidden Path of Exile (HKLM-x32\...\Steam App 238960) (Version: - Grinding Gear Games) Polski pakiet językowy dla narzędzi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PLK) (Version: 10.0.50903 - Microsoft Corporation) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.86.508.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.) Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10001 - Realtek Semiconductor Corp.) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_16 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.3.14044_16 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.43.0 - SAMSUNG Electronics Co., Ltd.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.3.22 - NVIDIA Corporation) Hidden Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys ) SopCast 3.9.3 (HKLM-x32\...\SopCast) (Version: 3.9.3 - www.sopcast.com) SoundTrax (x32 Version: 4.2.5.0 - Nero AG) Hidden Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Testy B 2015 (HKLM-x32\...\{51c8ad09-d9b5-478f-8dfe-6a5e040d7e7c}_is1) (Version: 6.1.5.92 - Grupa IMAGE Sp. z o.o.) The Witcher 2 - Assassins of Kings Enhanced Edition (HKLM-x32\...\The Witcher 2 - Assassins of Kings Enhanced Edition_is1) (Version: - GOG.com) Tombraider (HKLM-x32\...\Tombraider_is1) (Version: - ) VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.0 - ASUS) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 5.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1757415873-2226878437-4207686015-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\DOM\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1757415873-2226878437-4207686015-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\DOM\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1757415873-2226878437-4207686015-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\DOM\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1757415873-2226878437-4207686015-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\DOM\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1757415873-2226878437-4207686015-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\DOM\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 28-06-2015 15:00:25 Avira System Speedup 1.6.10 28-06-2015 15:17:16 Removed Avira Browser Safety 28-06-2015 15:29:16 Punkt przywracania stworzony przez HitmanPro 28-06-2015 15:29:59 Punkt przywracania stworzony przez HitmanPro 28-06-2015 20:41:09 Windows Update 28-06-2015 21:04:51 Windows Update 28-06-2015 21:10:16 Kopia zapasowa systemu Windows 28-06-2015 21:10:56 Instalator modułów systemu Windows 29-06-2015 15:16:17 Windows Update ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {105B5137-20C9-4146-9D30-AA66F2039F91} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2014-06-16] (Microsoft Corporation) Task: {1D2C950E-989B-40D8-919A-27066E3CF677} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-27] (Google Inc.) Task: {5E2021B3-6ED8-41A6-A65B-33E216BB3FD2} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {5F64EE55-B8C6-471B-9C41-6AC3EF750ACA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-27] (Google Inc.) Task: {6149EA97-12F2-47A6-AE6C-352C3326FB35} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-06-15] () Task: {6A883529-5833-45F9-A894-8424F546B59A} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {9CE40160-F996-49F8-B875-F789129A754E} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-01] (ASUS) Task: {C38ABFFC-6B55-4468-9ABD-DE670B704FF2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {F687C7BC-F030-4762-9CB6-5D71C2FDECF2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-27] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Acrobat Update Task.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0b0b4a3fb8ff2.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0b0b6ec96676d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2014-06-08 18:48 - 2014-05-20 03:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-07-14 16:11 - 2010-07-14 16:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2014-11-28 19:37 - 2014-11-28 19:37 - 00066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-06-08 17:20 - 2014-05-20 04:44 - 00012120 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2015-05-24 15:52 - 2015-05-01 18:52 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-06-27 10:39 - 2015-06-20 07:46 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll 2015-06-27 10:39 - 2015-06-20 07:46 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll 2015-06-29 17:11 - 2015-06-29 17:11 - 00380416 _____ () C:\Users\DOM\Desktop\huoliejh.exe ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1757415873-2226878437-4207686015-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Windows\SysWOW64\qttask.exe" -atboottime MSCONFIG\startupreg: SonicMasterTray => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{EA8BB312-4AAE-4826-BEC8-B2E52A1DB53A}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{4B2A5716-942E-4F82-A6F3-71BBF0428ED6}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{8F2BC90F-1D25-4163-AB33-BA227F7E9F71}] => (Allow) C:\Users\DOM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{82C2BB03-D979-40FC-AFF5-58445C59E6F1}] => (Allow) C:\Users\DOM\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{0B16FA1D-08EF-482B-AFE3-E9FC09C7B91C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{7DE15204-D270-492D-89FB-F38E50AFE6B1}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{0DDD9F78-F80C-4ED0-871E-628B04FB2C6B}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe FirewallRules: [{466F0C8A-3D87-460F-BAF1-DA9BF60DFA68}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe FirewallRules: [{340B1F9B-B654-4B54-B1E3-F262F874B268}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{7CF2A1FF-4B61-4145-A3B6-F619A5730370}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{DC937293-9D7C-4D52-9766-538BBD6333FC}] => (Allow) E:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{32B1DF7A-CD97-4DAB-B0F7-449A2AFE41E9}] => (Allow) E:\Program Files (x86)\NapiProjekt\napisy.exe FirewallRules: [{6264AD7C-2B7D-4A8D-AE78-8A9C12A55C5B}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{86DCC42B-CF42-45EC-A292-092A9CBE364F}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{019F3B87-EA37-47A3-A5D0-D1EB7A39EF17}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Path of Exile\PathOfExileSteam.exe FirewallRules: [{9EABBD4A-C2D1-402A-B611-C615510E9A29}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Path of Exile\PathOfExileSteam.exe FirewallRules: [{01F82C60-F7C5-43D9-A6B4-85A9BC530CD4}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{B29C2090-A669-4783-B37A-54A0E007689D}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{A27C2A8C-A48C-4DAF-BBCA-3D7406B15FD4}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe FirewallRules: [{E7714742-1172-4B98-B539-22CAC16615B2}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe FirewallRules: [{58E2A5FF-1ABA-4286-8BE2-6AD1DAA4F15A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{921E985A-EBDE-4307-8F4D-8CF7CF2C593D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{65BEA8A1-BE2D-4F99-B0F9-060E7DE227B7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{D20F6CF6-5217-47AE-89AB-BA8F008EF2FF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{A8B34773-EFC8-4409-8561-FB3EF293626C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{F7DAB96B-7124-4DB9-A252-FC1F5616DD06}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{A2C33487-9468-4943-B8D7-635BFCC0414D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{562B3A21-4E86-46A8-8498-C363CCBEC937}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{DFA5C347-4E59-487C-8CC1-C16F133FAF92}] => (Allow) C:\Users\DOM\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{8C99EFCF-BFEB-488E-8BBF-C7560065C825}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Bluetooth Module Description: Bluetooth Module Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Atheros Communications Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/29/2015 03:16:27 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service WN 1.10.0.19 Client Service since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (06/29/2015 03:16:26 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service Emsisoft Anti-Malware 8.0 - Service since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . Error: (06/29/2015 02:39:16 PM) (Source: MsiInstaller) (EventID: 11723) (User: DOM-Komputer) Description: SA_Error1709: StandardAction(0xC00706AD): Produkt: AVG 2015 — Error 1723. SA_Error1723: StandardAction(0xC00706BB): Wystąpił problem z tym pakietem Instalatora Windows. Nie udało się uruchomić biblioteki DLL wymaganej do ukończenia tej instalacji. Skontaktuj się z zespołem pomocy technicznej lub dostawcą pakietu. Akcja CA_InitInstallation, wpis: CA_InitInstallation, biblioteka: C:\Windows\system32\config\SYSTEM~1\AppData\Local\Temp\MSI5AB8.tmp Error: (06/28/2015 11:38:36 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (06/28/2015 03:32:17 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (06/28/2015 03:32:17 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (06/28/2015 03:32:17 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (06/28/2015 03:30:55 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (06/28/2015 03:30:23 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury RegSetValueExW(0x000002f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000000002FCEEC0.72). hr = 0x80070005, Odmowa dostępu. . Error: (06/28/2015 03:30:23 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury RegSetValueExW(0x000001bc,SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer,0,REG_BINARY,0000000001BBEA70.72). hr = 0x80070005, Odmowa dostępu. . Operacja: Zdarzenie BackupShutdown Kontekst: Kontekst wykonywania: Writer Identyfikator klasy modułu zapisującego: {afbab4a2-367d-4d15-a586-71dbb18f8485} Nazwa modułu zapisującego: Registry Writer Identyfikator wystąpienia modułu zapisującego: {c2590d12-b548-4c82-b622-7a5bf62ea133} System errors: ============= Error: (06/29/2015 07:23:24 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa Windows Defender zakończyła działanie; wystąpił następujący błąd: %%-2147024891 Error: (06/29/2015 07:13:33 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Uruchom usługę ponownie) po nieoczekiwanym zakończeniu usługi Windows Search, ale ta akcja nie powiodła się przy następującym błędzie: %%1056. Error: (06/29/2015 07:13:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Nero BackItUp Scheduler 4.0 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 500 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (06/29/2015 07:13:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa NVIDIA Network Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (06/29/2015 07:13:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa NVIDIA Streamer Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (06/29/2015 07:13:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Office Software Protection Platform niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (06/29/2015 07:13:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa PnkBstrA niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (06/29/2015 07:13:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Intel(R) Turbo Boost Technology Monitor niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 1000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (06/29/2015 07:13:03 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Atheros Bt&Wlan Coex Agent niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (06/29/2015 07:13:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Microsoft Office: ========================= Error: (06/29/2015 03:16:27 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service WN 1.10.0.19 Client Service since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. Error: (06/29/2015 03:16:26 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service Emsisoft Anti-Malware 8.0 - Service since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. Error: (06/29/2015 02:39:16 PM) (Source: MsiInstaller) (EventID: 11723) (User: DOM-Komputer) Description: SA_Error1709: StandardAction(0xC00706AD): Produkt: AVG 2015 — Error 1723. SA_Error1723: StandardAction(0xC00706BB): Wystąpił problem z tym pakietem Instalatora Windows. Nie udało się uruchomić biblioteki DLL wymaganej do ukończenia tej instalacji. Skontaktuj się z zespołem pomocy technicznej lub dostawcą pakietu. Akcja CA_InitInstallation, wpis: CA_InitInstallation, biblioteka: C:\Windows\system32\config\SYSTEM~1\AppData\Local\Temp\MSI5AB8.tmp (NULL)(NULL)(NULL)(NULL)(NULL) Error: (06/28/2015 11:38:36 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (06/28/2015 03:32:17 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (06/28/2015 03:32:17 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (06/28/2015 03:32:17 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (06/28/2015 03:30:55 PM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0] Error: (06/28/2015 03:30:23 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000002f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000000002FCEEC0.72)0x80070005, Odmowa dostępu. Error: (06/28/2015 03:30:23 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000001bc,SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer,0,REG_BINARY,0000000001BBEA70.72)0x80070005, Odmowa dostępu. Operacja: Zdarzenie BackupShutdown Kontekst: Kontekst wykonywania: Writer Identyfikator klasy modułu zapisującego: {afbab4a2-367d-4d15-a586-71dbb18f8485} Nazwa modułu zapisującego: Registry Writer Identyfikator wystąpienia modułu zapisującego: {c2590d12-b548-4c82-b622-7a5bf62ea133} ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz Percentage of memory in use: 66% Total physical RAM: 4007.77 MB Available physical RAM: 1323.09 MB Total Pagefile: 8013.75 MB Available Pagefile: 5198.38 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:112.6 GB) (Free:41.32 GB) NTFS Drive d: (Nowy) (Fixed) (Total:390.62 GB) (Free:213.11 GB) NTFS Drive e: (Nowy) (Fixed) (Total:195.31 GB) (Free:72.83 GB) NTFS Drive j: (Zastrzeżone przez system) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 4535C2A3) Partition 1: (Active) - (Size=99 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=195.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=112.6 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=390.6 GB) - (Type=OF Extended) ==================== End of log ============================