Additional scan result of Farbar Recovery Scan Tool (x86) Version:09-01-2015 Ran by Martyna (2016-01-10 12:58:31) Running from C:\Users\Martyna\Desktop Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2015-11-11 12:37:04) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-946734987-201425966-3322790820-500 - Administrator - Disabled) Guest (S-1-5-21-946734987-201425966-3322790820-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-946734987-201425966-3322790820-1002 - Limited - Enabled) Martyna (S-1-5-21-946734987-201425966-3322790820-1000 - Administrator - Enabled) => C:\Users\Martyna ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET NOD32 Antivirus 9.0.349.14 (Enabled - Out of date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET NOD32 Antivirus 9.0.349.14 (Enabled - Out of date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 20 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.111.0.63 - Conexant) ESET NOD32 Antivirus (HKLM\...\{5F652F0B-BBC7-46E9-8825-BE9930D37B0B}) (Version: 9.0.349.14 - ESET, spol. s r.o.) ETDWare PS/2-x86 7.0.5.12_WHQL (HKLM\...\Elantech) (Version: 7.0.5.12 - ELAN Microelectronics Corp.) Intel(R) Control Center (HKLM\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2125 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) JMicron Ethernet Adapter NDIS Driver (HKLM\...\{96DCEE2F-98EE-4F80-8C0F-7C04D1FB9D7F}) (Version: 6.0.17.1 - JMicron Technology Corp.) JMicron Flash Media Controller Driver (HKLM\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.33.2 - JMicron Technology Corp.) LibreOffice 5.0.3.2 (HKLM\...\{D61E7AA0-0380-49B9-8DDD-7685E2306176}) (Version: 5.0.3.2 - The Document Foundation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 43.0.4 (x86 pl) (HKLM\...\Mozilla Firefox 43.0.4 (x86 pl)) (Version: 43.0.4 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 43.0.4.5848 - Mozilla) NVIDIA PhysX (HKLM\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) PhotoScape (HKLM\...\PhotoScape) (Version: - ) Rocket League (HKLM\...\Steam App 252950) (Version: - Psyonix) Skype™ 7.14 (HKLM\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.14.104 - Skype Technologies S.A.) Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation) USB 2.0 VGA UVC WebCam (HKLM\...\USB 2.0 VGA UVC WebCam) (Version: - ) WinRAR 5.30 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {2D4E9CA5-C04B-45F1-B1AE-292F2194C523} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {6AEF0C98-2CB4-4B67-8C70-4C977C7355CC} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc Task: {D622195C-D680-4FEA-9C56-59660C7C9E94} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Martyna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452245337&z=3b9ef33f1eaa2af68c90265gdzcwfofo0z6wccezbg&from=wpm01073&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50P6733P6733 ShortcutWithArgument: C:\Users\Martyna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452245337&z=3b9ef33f1eaa2af68c90265gdzcwfofo0z6wccezbg&from=wpm01073&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50P6733P6733 ShortcutWithArgument: C:\Users\Martyna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452245337&z=3b9ef33f1eaa2af68c90265gdzcwfofo0z6wccezbg&from=wpm01073&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50P6733P6733 ShortcutWithArgument: C:\Users\Martyna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452245337&z=3b9ef33f1eaa2af68c90265gdzcwfofo0z6wccezbg&from=wpm01073&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50P6733P6733 ShortcutWithArgument: C:\Users\Martyna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452245337&z=3b9ef33f1eaa2af68c90265gdzcwfofo0z6wccezbg&from=wpm01073&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50P6733P6733 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452245337&z=3b9ef33f1eaa2af68c90265gdzcwfofo0z6wccezbg&from=wpm01073&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50P6733P6733 ==================== Loaded Modules (Whitelisted) ============== 2015-11-11 14:20 - 2007-11-30 11:20 - 00051768 _____ () C:\Program Files\ASUS\ASUS Live Update\ALU.exe ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-946734987-201425966-3322790820-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Martyna\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 62.179.1.61 - 62.179.1.63 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{88C174CD-C4C5-4873-A417-3ECBC345F6F6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{C9D4AFA4-EBEF-418E-ADA1-3DC7751688FD}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{2CBF627B-25DB-4F8A-BAA3-1F557A35254A}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{58D7F046-CA90-4CFF-8136-74F597536BBF}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{9412CFA5-599A-4DA5-8E35-38A813D04053}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{3AE6A545-A505-477C-8807-30846141DFCA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{C3A39A11-E109-4CD9-91AA-774D9E9F3A5C}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{A92419F9-85CF-4718-B01F-A76C2D7C5EA8}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{45E83E5C-A1B6-42B5-8E95-5DA536EB854E}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [{00B753FE-8E5A-4772-8FC6-49DD8543CDC8}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [{8CC51384-DF8B-4D1E-A911-8541CED7C57F}] => (Allow) C:\Program Files\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{DFD2E356-910A-43D9-9540-EA9BB64E789A}] => (Allow) C:\Program Files\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe ==================== Restore Points ========================= 23-12-2015 11:59:49 Windows Update 27-12-2015 09:46:05 Windows Update 29-12-2015 17:27:59 Zainstalowany program DirectX 01-01-2016 19:26:19 Windows Update 06-01-2016 17:49:02 Windows Update ==================== Faulty Device Manager Devices ============= Name: wfdrvr_vt_1_10_0_28 Description: wfdrvr_vt_1_10_0_28 Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: wfdrvr_vt_1_10_0_28 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (01/10/2016 12:51:38 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/10/2016 12:50:00 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005. Error: (01/09/2016 07:09:22 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/09/2016 07:07:55 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005. Error: (01/09/2016 06:48:46 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 Error: (01/09/2016 06:05:07 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/09/2016 06:03:25 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005. Error: (01/09/2016 05:38:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/09/2016 05:37:17 PM) (Source: Winlogon) (EventID: 4103) (User: ) Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005. Error: (01/09/2016 02:20:23 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: ) Description: Wystąpił błąd harmonogramu aktywacji licencji (sppuinotify.dll), kod błędu: 0x80070005 System errors: ============= Error: (01/10/2016 12:50:52 PM) (Source: DCOM) (EventID: 10001) (User: ) Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} Error: (01/10/2016 12:50:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: wfdrvr_vt_1_10_0_28 Error: (01/09/2016 07:09:12 PM) (Source: DCOM) (EventID: 10001) (User: ) Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} Error: (01/09/2016 07:07:58 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: wfdrvr_vt_1_10_0_28 Error: (01/09/2016 06:48:46 PM) (Source: DCOM) (EventID: 10001) (User: ) Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} Error: (01/09/2016 06:11:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa WdMan Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (01/09/2016 06:11:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi SSFK z powodu następującego błędu: %%5 Error: (01/09/2016 06:11:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa SSFK niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 0 milisekund zostanie podjęta następująca czynność korekcyjna: Restart the service. Error: (01/09/2016 06:11:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa IhPul niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (01/09/2016 06:10:52 PM) (Source: DCOM) (EventID: 10001) (User: ) Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU P6100 @ 2.00GHz Percentage of memory in use: 41% Total physical RAM: 1900.57 MB Available physical RAM: 1112.6 MB Total Virtual: 3801.13 MB Available Virtual: 2823.28 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:78.03 GB) (Free:51.42 GB) NTFS Drive d: () (Fixed) (Total:219.96 GB) (Free:117.94 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 5D92E179) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=78 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=220 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================