Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-12-2014 03 Ran by Mariola at 2014-12-12 21:28:45 Running from C:\Users\Mariola\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Photoshop Elements 11 (HKLM-x32\...\Adobe Photoshop Elements 11) (Version: 11.0 - Adobe Systems Incorporated) Adobe Reader X (10.1.3) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.3 - Adobe Systems Incorporated) Archiwizator WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - ) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software) Bitcasa version 0.9.20.4135 (HKLM\...\{EDA09459-AD7D-4434-BA0C-647F6703EA12}_is1) (Version: 0.9.20.4135 - Bitcasa Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.00 - Piriform) Classic Shell (HKLM\...\{2368907C-E8F6-4750-A023-254C3E2B5E8D}) (Version: 4.0.4 - IvoSoft) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.1912 - CyberLink Corp.) CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4421.02 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Easy File Share (HKLM-x32\...\{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}) (Version: 1.3.6 - Samsung Electronics CO.,LTD.) Elements 11 Organizer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.) Fotogalleri (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Fotogalleriet (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.120 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Help Desk (HKLM\...\{22B32087-797D-4A1B-AFA7-072C87580ADC}) (Version: 1.0.9 - Samsung Electronics CO., LTD.) Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33070) (Version: 3.6.1.33070.11 - Intel) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36843 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2875 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.7.0.1013 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Malwarebytes Anti-Malware wersja 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden MSVCRT110_amd64 (Version: 16.4.1108.0727 - Microsoft) Hidden Multimedia mobilNET (HKLM-x32\...\Multimedia mobilNET) (Version: 21.005.11.01.576 - Huawei Technologies Co.,Ltd) Opera Stable 26.0.1656.32 (HKLM-x32\...\Opera 26.0.1656.32) (Version: 26.0.1656.32 - Opera Software ASA) Phone Screen Sharing (HKLM-x32\...\{DF02C515-40B5-45AC-A601-5DC69D03885C}) (Version: 1.0.0.1 - RSUPPORT) Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden PSE11 STI Installer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.220 - Qualcomm Atheros Communications) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.4.907.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6818 - Realtek Semiconductor Corp.) Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.9.5 - Samsung Electronics CO., LTD.) S Agent (Version: 1.1.30 - Samsung Electronics CO., LTD.) Hidden Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.2.13021_11 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.5.2.13021_11 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.16.0 - SAMSUNG Electronics Co., Ltd.) Sense (HKLM-x32\...\Sense) (Version: 1.34.2.13 - Object Browser) <==== ATTENTION Settings (HKLM-x32\...\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.) Side Sync (HKLM-x32\...\{34BEB782-66B1-4772-8E3E-71B758BA848B}) (Version: 1.0.2 - Samsung Electronics CO., LTD.) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Support Center (HKLM\...\{25B191F6-A277-478F-90CA-88B76D5A08BD}) (Version: 2.1.70 - Samsung Electronics CO., LTD.) Support Center FAQ (x32 Version: 1.0.8 - Samsung Electronics CO., LTD.) Hidden SW Update (HKLM-x32\...\{DC4F83F3-CAF0-4347-97A4-D6B43D7E34F0}) (Version: 2.1.7 - Samsung Electronics CO., LTD.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.14.2 - Synaptics Incorporated) User Guide (HKLM-x32\...\{A6C17C20-4464-4A2A-968D-684C083B9424}) (Version: 1.0.00 - Samsung Electronics CO., LTD.) Valokuvavalikoima (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 21-11-2014 17:55:46 Windows Update 30-11-2014 17:09:37 Removed Norton Online Backup 12-12-2014 16:13:49 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 06:26 - 2014-12-12 18:40 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {09B8C298-1448-4454-8D60-34B27CF0442B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-12] (Google Inc.) Task: {163D1A83-26C0-4B19-8B59-6D3E483F79F8} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-12-12] (AVAST Software) Task: {1CE1CAF8-B073-46B1-A482-0BAD5B740E62} - System32\Tasks\{28B123DB-0563-4657-9CB4-5E1642AA4F5C} => pcalua.exe -a "C:\Program Files (x86)\PopCap Games\Plants vs. Zombies\PopUninstall.exe" -c "C:\Program Files (x86)\PopCap Games\Plants vs. Zombies\Install.log" Task: {2ACDC6D4-7082-47C1-9173-C7224A0F2844} - \SPDriver No Task File <==== ATTENTION Task: {3A3F18D0-16EB-4F9A-9EC8-2DF462F2C0C9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-12] (Google Inc.) Task: {4D2C145E-D059-4521-B4DB-EDEDDE2699AC} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-10-16] (Synaptics Incorporated) Task: {600AE852-E36A-4FF2-81EE-8DC1DBF856A5} - \bench-sys No Task File <==== ATTENTION Task: {7872A90B-AB2F-4254-B471-E8D10E0C10F2} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-09-13] (Intel Corporation) Task: {9CC57E81-3703-44C3-BAAB-1C9CB8F9481C} - \SPBIW_UpdateTask_Time_323238343032363735322d2350785732325b6c342a2d45 No Task File <==== ATTENTION Task: {9D9EF338-7E80-4332-93D6-B8A189230070} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2013-02-13] (SEC) Task: {9DBD80A7-846F-4CA2-BB55-DB33716E41EB} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2013-02-13] (Samsung Electronics CO., LTD.) Task: {9EE987E6-95FB-48C9-9E7A-4C7E8AAC009E} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2013-02-01] (Samsung Electronics CO., LTD.) Task: {C67DC3B4-15B2-4414-AAB0-6B93AEACBC67} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-09-13] (Intel Corporation) Task: {D8BBBE6E-ABF5-464E-89C6-1CD7E1EB1862} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-12-12] (Microsoft Corporation) Task: {E31418D0-D41E-4A39-9F9E-E18BE2121545} - System32\Tasks\Opera scheduled Autoupdate 1414264561 => C:\Program Files (x86)\Opera\launcher.exe [2014-11-25] (Opera Software) Task: {FD349E48-9273-432C-813B-3E7982B0E72A} - System32\Tasks\SideSyncAutoRun => C:\Program Files (x86)\Samsung\Side Sync\SideSync.exe [2013-03-09] (Samsung Electronics CO., LTD.) Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\NDFNWE.job => C:\Users\Mariola\AppData\Roaming\NDFNWE.exe <==== ATTENTION Task: C:\windows\Tasks\PZBSD.job => C:\Users\Mariola\AppData\Roaming\PZBSD.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2010-11-16 14:38 - 2010-11-16 14:38 - 00339456 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2013-02-01 02:52 - 2013-02-01 02:52 - 00085040 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe 2014-03-15 14:25 - 2014-03-15 14:24 - 00218624 _____ () C:\ProgramData\Multimedia mobilNET\OnlineUpdate\ouc.exe 2014-12-12 21:24 - 2014-12-12 21:24 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll 2014-12-12 21:24 - 2014-12-12 21:24 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll 2013-02-13 06:16 - 2013-02-13 06:16 - 00022528 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll 2014-11-22 01:03 - 2014-11-22 01:03 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll 2014-12-13 08:42 - 2014-12-13 08:42 - 02905600 _____ () C:\Program Files\AVAST Software\Avast\defs\14121100\algo.dll 2014-12-12 21:24 - 2014-12-12 21:24 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00029232 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 01106480 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00111152 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00027184 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00111152 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00060976 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll 2013-02-01 02:52 - 2013-02-01 02:52 - 00103472 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll 2014-03-15 14:25 - 2014-03-15 14:24 - 00011362 _____ () C:\ProgramData\Multimedia mobilNET\OnlineUpdate\mingwm10.dll 2014-03-15 14:25 - 2014-03-15 14:24 - 00043008 _____ () C:\ProgramData\Multimedia mobilNET\OnlineUpdate\libgcc_s_dw2-1.dll 2014-03-15 14:25 - 2014-03-15 14:24 - 02415104 _____ () C:\ProgramData\Multimedia mobilNET\OnlineUpdate\QtCore4.dll 2014-03-15 14:25 - 2014-03-15 14:24 - 01148416 _____ () C:\ProgramData\Multimedia mobilNET\OnlineUpdate\QtNetwork4.dll 2013-03-09 20:58 - 2013-03-09 20:58 - 00192048 _____ () C:\Program Files (x86)\Samsung\Side Sync\SideSyncNetworkFramework.dll 2014-12-12 21:25 - 2014-12-12 21:25 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-09-15 19:48 - 2014-09-04 04:01 - 01098056 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\libglesv2.dll 2014-09-15 19:48 - 2014-09-04 04:01 - 00174408 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\libegl.dll 2014-09-15 19:48 - 2014-09-04 04:01 - 08577864 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll 2014-09-15 19:48 - 2014-09-04 04:01 - 00331592 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll 2014-09-15 19:48 - 2014-09-04 04:01 - 01660232 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ffmpegsumo.dll 2013-03-11 08:34 - 2013-01-14 19:25 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:56E2E879 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "Bitcasa" HKLM\...\StartupApproved\Run: => "HotKeysCmds" HKLM\...\StartupApproved\Run: => "Persistence" HKLM\...\StartupApproved\Run32: => "Adobe Reader Speed Launcher" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8" HKLM\...\StartupApproved\Run32: => "CLVirtualDrive" HKLM\...\StartupApproved\Run32: => "fst_pl_78" HKLM\...\StartupApproved\Run32: => "Intel AppUp(SM) center" HKLM\...\StartupApproved\Run32: => "SPDriver" HKLM\...\StartupApproved\Run32: => "KiesTrayAgent" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKLM\...\StartupApproved\Run32: => "fst_pl_211" HKLM\...\StartupApproved\Run32: => "fst_pl_79" HKLM\...\StartupApproved\Run32: => "fst_pl_99" HKU\S-1-5-21-1389066822-2107305290-2761972221-1001\...\StartupApproved\Run: => "SPDriver" HKU\S-1-5-21-1389066822-2107305290-2761972221-1001\...\StartupApproved\Run: => "GoobzoYouTubeAccelerator" HKU\S-1-5-21-1389066822-2107305290-2761972221-1001\...\StartupApproved\Run: => "Super Optimizer" ========================= Accounts: ========================== Administrator (S-1-5-21-1389066822-2107305290-2761972221-500 - Administrator - Disabled) Guest (S-1-5-21-1389066822-2107305290-2761972221-501 - Limited - Disabled) Mariola (S-1-5-21-1389066822-2107305290-2761972221-1001 - Administrator - Enabled) => C:\Users\Mariola ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Karta tunelowania Teredo firmy Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/12/2014 09:17:44 PM) (Source: VSS) (EventID: 12294) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: Błąd wywołania procedury w Dostawcy kopii w tle {b5946137-7b9f-4925-af80-51abd60b20d5}. Procedura zwróciła wartość E_INVALIDARG. Szczegóły procedury: GetSnapshot({00000000-0000-0000-0000-000000000000},00000021A0EF7FB0). Operacja: Pobierz właściwości kopii w tle Kontekst: Kontekst wykonywania: Coordinator Error: (12/12/2014 02:53:37 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury RegOpenKeyExW(-2147483646,SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl,...). hr = 0x80070005, Odmowa dostępu. . Operacja: Zainicjuj w celu wykonania kopii zapasowej Error: (12/12/2014 02:51:38 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury RegOpenKeyExW(-2147483646,SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl,...). hr = 0x80070005, Odmowa dostępu. . Operacja: Zainicjuj w celu wykonania kopii zapasowej Error: (12/12/2014 02:51:37 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury RegOpenKeyExW(-2147483646,SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl,...). hr = 0x80070005, Odmowa dostępu. . Operacja: Zainicjuj w celu wykonania kopii zapasowej Error: (12/13/2014 09:52:32 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program OTL.com w wersji 3.2.69.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 1770 Godzina rozpoczęcia: 01d016ad93ccf47b Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Users\Mariola\Downloads\OTL.com Identyfikator raportu: 5d65087b-82a5-11e4-be9f-1867b078d0b4 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (12/13/2014 06:25:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: GoogleUpdate.exe, wersja: 1.3.25.0, sygnatura czasowa: 0x53592941 Nazwa modułu powodującego błąd: urlmon.dll_unloaded, wersja: 0.0.0.0, sygnatura czasowa: 0x541ccfa4 Kod wyjątku: 0xc00001a5 Przesunięcie błędu: 0x76fcb131 Identyfikator procesu powodującego błąd: 0x4a8 Godzina uruchomienia aplikacji powodującej błąd: 0xGoogleUpdate.exe0 Ścieżka aplikacji powodującej błąd: GoogleUpdate.exe1 Ścieżka modułu powodującego błąd: GoogleUpdate.exe2 Identyfikator raportu: GoogleUpdate.exe3 Pełna nazwa pakietu powodującego błąd: GoogleUpdate.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: GoogleUpdate.exe5 Error: (12/13/2014 00:17:01 AM) (Source: VSS) (EventID: 12294) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: Błąd wywołania procedury w Dostawcy kopii w tle {b5946137-7b9f-4925-af80-51abd60b20d5}. Procedura zwróciła wartość E_INVALIDARG. Szczegóły procedury: GetSnapshot({00000000-0000-0000-0000-000000000000},0000008A898D5BB0). Operacja: Pobierz właściwości kopii w tle Kontekst: Kontekst wykonywania: Coordinator Error: (12/13/2014 00:15:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: spbia.exe, wersja: 1.0.0.4, sygnatura czasowa: 0x53ce1754 Nazwa modułu powodującego błąd: spbia.exe, wersja: 1.0.0.4, sygnatura czasowa: 0x53ce1754 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000000000000a746 Identyfikator procesu powodującego błąd: 0x44c Godzina uruchomienia aplikacji powodującej błąd: 0xspbia.exe0 Ścieżka aplikacji powodującej błąd: spbia.exe1 Ścieżka modułu powodującego błąd: spbia.exe2 Identyfikator raportu: spbia.exe3 Pełna nazwa pakietu powodującego błąd: spbia.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: spbia.exe5 Error: (12/12/2014 09:40:43 PM) (Source: globalUpdate Update) (EventID: 1) (User: ZARZĄDZANIE NT) Description: globalUpdate Update has encountered a fatal error. ver=1.3.25.0.private;lang=en;id=;is_machine=1;upload=0;minidump=C:\Program Files (x86)\globalUpdate\CrashReports\7a3784f5-50a3-433b-bbb2-c445a7544ee5.dmp Error: (12/12/2014 09:35:27 PM) (Source: VSS) (EventID: 12294) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: Błąd wywołania procedury w Dostawcy kopii w tle {b5946137-7b9f-4925-af80-51abd60b20d5}. Procedura zwróciła wartość E_INVALIDARG. Szczegóły procedury: GetSnapshot({00000000-0000-0000-0000-000000000000},000000641D165770). Operacja: Pobierz właściwości kopii w tle Kontekst: Kontekst wykonywania: Coordinator System errors: ============= Error: (12/12/2014 09:14:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Multimedia mobilNET. OUC z powodu następującego błędu: %%1053 Error: (12/12/2014 09:14:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Multimedia mobilNET. OUC. Error: (12/12/2014 09:13:15 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 6) (User: ZARZĄDZANIE NT) Description: 0xc000014d0 Error: (12/12/2014 08:35:42 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: ) Description: 4 Error: (12/12/2014 03:28:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Multimedia mobilNET. OUC z powodu następującego błędu: %%1053 Error: (12/12/2014 03:28:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Multimedia mobilNET. OUC. Error: (12/12/2014 03:26:16 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 6) (User: ZARZĄDZANIE NT) Description: 0xc000014d0 Error: (12/12/2014 03:25:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Klient DNS z powodu następującego błędu: %%3 Error: (12/12/2014 03:25:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Klient zasad grupy z powodu następującego błędu: %%3 Error: (12/12/2014 03:25:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Klient zasad grupy z powodu następującego błędu: %%3 Microsoft Office Sessions: ========================= Error: (12/12/2014 09:17:44 PM) (Source: VSS) (EventID: 12294) (User: ) Description: {b5946137-7b9f-4925-af80-51abd60b20d5}GetSnapshot({00000000-0000-0000-0000-000000000000},00000021A0EF7FB0) Operacja: Pobierz właściwości kopii w tle Kontekst: Kontekst wykonywania: Coordinator Error: (12/12/2014 02:53:37 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegOpenKeyExW(-2147483646,SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl,...)0x80070005, Odmowa dostępu. Operacja: Zainicjuj w celu wykonania kopii zapasowej Error: (12/12/2014 02:51:38 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegOpenKeyExW(-2147483646,SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl,...)0x80070005, Odmowa dostępu. Operacja: Zainicjuj w celu wykonania kopii zapasowej Error: (12/12/2014 02:51:37 PM) (Source: VSS) (EventID: 8193) (User: ) Description: RegOpenKeyExW(-2147483646,SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl,...)0x80070005, Odmowa dostępu. Operacja: Zainicjuj w celu wykonania kopii zapasowej Error: (12/13/2014 09:52:32 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: OTL.com3.2.69.0177001d016ad93ccf47b4294967295C:\Users\Mariola\Downloads\OTL.com5d65087b-82a5-11e4-be9f-1867b078d0b4 Error: (12/13/2014 06:25:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: GoogleUpdate.exe1.3.25.053592941urlmon.dll_unloaded0.0.0.0541ccfa4c00001a576fcb1314a801d016953a5be389C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exeurlmon.dll7c7f01a1-8288-11e4-be9f-1867b078d0b4 Error: (12/13/2014 00:17:01 AM) (Source: VSS) (EventID: 12294) (User: ) Description: {b5946137-7b9f-4925-af80-51abd60b20d5}GetSnapshot({00000000-0000-0000-0000-000000000000},0000008A898D5BB0) Operacja: Pobierz właściwości kopii w tle Kontekst: Kontekst wykonywania: Coordinator Error: (12/13/2014 00:15:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: spbia.exe1.0.0.453ce1754spbia.exe1.0.0.453ce1754c0000005000000000000a74644c01d01661705730c1C:\Program Files\Common Files\ShopperPro\spbia.exeC:\Program Files\Common Files\ShopperPro\spbia.exed34c35c1-8254-11e4-be9f-1867b078d0b4 Error: (12/12/2014 09:40:43 PM) (Source: globalUpdate Update) (EventID: 1) (User: ZARZĄDZANIE NT) Description: globalUpdate Update has encountered a fatal error. ver=1.3.25.0.private;lang=en;id=;is_machine=1;upload=0;minidump=C:\Program Files (x86)\globalUpdate\CrashReports\7a3784f5-50a3-433b-bbb2-c445a7544ee5.dmp Error: (12/12/2014 09:35:27 PM) (Source: VSS) (EventID: 12294) (User: ) Description: {b5946137-7b9f-4925-af80-51abd60b20d5}GetSnapshot({00000000-0000-0000-0000-000000000000},000000641D165770) Operacja: Pobierz właściwości kopii w tle Kontekst: Kontekst wykonywania: Coordinator CodeIntegrity Errors: =================================== Date: 2014-12-12 18:32:34.821 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-12-12 18:32:34.258 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-03-12 12:06:13.445 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU 847 @ 1.10GHz Percentage of memory in use: 49% Total physical RAM: 3795.48 MB Available physical RAM: 1920.14 MB Total Pagefile: 5971.48 MB Available Pagefile: 3719.26 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:441.73 GB) (Free:372.71 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================