Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015 Ran by ZOOZKA at 2015-01-29 23:15:24 Running from E:\instalki\frst logi Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: STOPzilla (Disabled - Up to date) {17032AB1-6644-0721-EEB5-A39B8B646009} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG Internet Security 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: STOPzilla (Enabled - Up to date) {AC62CB55-407E-08AF-D405-98E9F0E32AB4} AS: AVG Internet Security 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} FW: AVG Internet Security 2015 (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) clear.fi SDK - Video 2 (x32 Version: 2.1.1925 - CyberLink Corp.) Hidden clear.fi SDK- Movie 2 (x32 Version: 2.1.2008 - CyberLink Corp.) Hidden 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Acer Backup Manager (HKLM-x32\...\InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}) (Version: 4.0.0.0059 - NTI Corporation) Acer Device Fast-lane (HKLM\...\{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}) (Version: 1.00.3007 - Acer Incorporated) Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3006 - Acer Incorporated) Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3011 - Acer Incorporated) AcerCloud Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.00.3201 - Acer Incorporated) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5646 - AVG Technologies) AVG 2015 (Version: 15.0.4273 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.5646 - AVG Technologies) Hidden AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.0.0.19 - AVG Technologies) Backup Manager v4 (x32 Version: 4.0.0.0059 - NTI Corporation) Hidden Broadcom Card Reader Driver Installer (HKLM\...\{F0A7DF2F-0BE0-470F-B137-D7A19F977189}) (Version: 15.4.7.1 - Broadcom Corporation) ChomikBox (HKLM-x32\...\{26050F54-3928-4D9C-849A-C48A9E831E6F}) (Version: 2.0.5.0 - Chomikuj.pl) Classic Shell (HKLM\...\{FEA1590B-540A-41FC-A95C-664493C82A21}) (Version: 3.6.8 - IvoSoft) clear.fi Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.01.3108 - Acer Incorporated) clear.fi Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.01.3108 - Acer Incorporated) doPDF 8 (HKLM-x32\...\{c61b55b1-0524-4fc7-a4d2-6896ae2a2edb}) (Version: 8.1.923 - Softland) Dritek Radio Controller (HKLM-x32\...\RadioController) (Version: 2.02.2001.0803 - Dritek System Inc.) FormatFactory 3.0.1 (HKLM-x32\...\FormatFactory) (Version: 3.0.1 - Free Time) Foxit PDF Editor (HKLM-x32\...\Foxit PDF Editor) (Version: - ) GeekBuddy (HKLM\...\{EC4E385C-4B7D-4FDD-9F0C-C91B116AD243}) (Version: 4.10.79 - Comodo Security Solutions Inc) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.4.1001 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) iVMS-4200(v2.00) (HKLM-x32\...\{7697245D-2E00-4B83-AD27-C051DE314D1F}) (Version: 2.00.02.50 - company) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Karaoke Dziecięce Przeboje 2 (HKLM-x32\...\{562A94F6-8267-4772-AD2D-8E24C933987B}_is1) (Version: 2 - Techland) Launch Manager (HKLM-x32\...\LManager) (Version: 7.0.7 - Acer Inc.) Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3004 - Acer Incorporated) Malwarebytes Anti-Malware wersja 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0415-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 (HKLM-x32\...\Microsoft SQL Server 2005) (Version: - Microsoft Corporation) Microsoft SQL Server Native Client (HKLM\...\{79BF7CB8-1E09-489F-9547-DB3EE8EA3F16}) (Version: 9.00.4035.00 - Microsoft Corporation) Microsoft SQL Server Setup Support Files (English) (HKLM-x32\...\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.4035.00 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{86177DAE-38B1-49DD-912E-35CB703AB779}) (Version: 9.00.4035.00 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 33.0.2 (x86 pl) (HKLM-x32\...\Mozilla Firefox 33.0.2 (x86 pl)) (Version: 33.0.2 - Mozilla) Mozilla Firefox 35.0 (x86 pl) (HKU\S-1-5-21-417449669-2771163209-2432074822-1002\...\Mozilla Firefox 35.0 (x86 pl)) (Version: 35.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.2 - Mozilla) MyWinLocker (Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.35 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.24 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.24 - Egis Technology Inc.) Hidden Nero 9 Essentials (HKLM-x32\...\{d72a2d6f-a993-40ea-bd8c-dfd8df9fc3de}) (Version: - Nero AG) novaPDF 8 add-in for Microsoft Office (x64) (HKLM\...\{9F3FFB12-258E-4BB1-8576-FB5F1F1E039E}) (Version: 8.1.923 - Softland) novaPDF 8 add-in for Microsoft Office (x86) (HKLM-x32\...\{7C972E62-BC1F-4D1C-BB95-FDB648EF6213}) (Version: 8.1.923 - Softland) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9008 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.9008 - NTI Corporation) Hidden NVIDIA PhysX System Software 9.12.0613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation) NVIDIA Sterownik graficzny 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation) NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation) OpenVPN 2.3.2-I003 (HKLM\...\OpenVPN) (Version: 2.3.2-I003 - ) Opera Stable 26.0.1656.60 (HKLM-x32\...\Opera 26.0.1656.60) (Version: 26.0.1656.60 - Opera Software ASA) Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC) Pakiet zgodności dla systemu Office 2007 (HKLM-x32\...\{90120000-0020-0415-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Panel sterowania NVIDIA 327.02 (Version: 327.02 - NVIDIA Corporation) Hidden PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) PIT Projekt 2013 (HKLM-x32\...\{9DC72E7A-ED60-49C9-845F-3022B7A5BB8C}}_is1) (Version: 2.0.0 - GP SOFT) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.220 - Qualcomm Atheros Communications) Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.41 - Qualcomm Atheros) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Sales Partner (HKLM-x32\...\Sales Partner) (Version: - ) Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden STOPzilla (HKLM-x32\...\{9DECA4F0-64C8-4520-9AFA-8E3AA125AA59}) (Version: 6.1.100.3 - iS3 Inc.) TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - ) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) XnView 2.22 (HKLM-x32\...\XnView_is1) (Version: 2.22 - Gougelet Pierre-e) Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-417449669-2771163209-2432074822-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) ==================== Restore Points ========================= 24-01-2015 21:21:36 STOPzilla Restore Point. 28-01-2015 08:43:58 Windows Update 29-01-2015 09:40:24 STOPzilla Restore Point. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 06:26 - 2015-01-10 12:48 - 00000882 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost 192.168.1.110 serwer ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1C56FD5E-D85C-41E5-9224-C897114D1757} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2012-07-12] (Egis Technology Inc.) Task: {26C4C360-9CE8-4FA9-97D1-0801FC2A5F72} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2012-08-23] (Acer Incorporated) Task: {275D5333-7A4C-4DB9-9697-5C38637F58D6} - System32\Tasks\Opera scheduled Autoupdate 1415193460 => C:\Program Files (x86)\Opera\launcher.exe [2014-12-17] (Opera Software) Task: {52EF4DF8-76E9-4CC4-AA1D-F6AE1AB61497} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2012-06-22] () Task: {5C8D408E-B0F2-4FCC-BD0D-0C269C54C08F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-06] (Google Inc.) Task: {7621FA10-EF89-48A9-96E4-E759CA11F7CC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-06] (Google Inc.) Task: {864523AE-FEC3-4A2F-99EE-640EFFF4AA56} - System32\Tasks\{46792F03-8174-4687-9447-6C85D7E0A35E} => pcalua.exe -a "C:\Program Files (x86)\WildGames\uninstall.exe" -d "C:\Program Files (x86)\WildGames" Task: {93347DF4-5F18-4248-AEE6-D871894B8294} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2012-08-30] () Task: {F0DBFE3F-2A5D-4E19-A89D-CAC61EA34DB0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-01-15] (Microsoft Corporation) Task: {FBA71317-EB0D-4719-A075-715EE0EA0F86} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2012-07-12] (Egis Technology Inc.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 02:36 - 2013-09-05 02:36 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-01-28 13:45 - 2013-01-28 13:45 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll 2013-01-28 13:42 - 2013-01-28 13:42 - 00084992 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll 2013-01-28 13:47 - 2013-01-28 13:47 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe 2015-01-10 17:50 - 2014-12-19 05:01 - 00192376 _____ () C:\ProgramData\STOPzilla!\VIPRE\libBase64.dll 2015-01-10 17:50 - 2014-12-19 05:01 - 00180088 _____ () C:\ProgramData\STOPzilla!\VIPRE\libMachoUniv.dll 2012-08-23 07:26 - 2012-08-23 07:26 - 00465384 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2012-08-23 07:25 - 2012-08-23 07:25 - 00125504 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2012-08-23 07:26 - 2012-08-23 07:26 - 00155712 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\VolumeSnapshot.dll 2012-08-23 07:25 - 2012-08-23 07:25 - 00118336 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\Online.dll 2012-08-23 07:25 - 2012-08-23 07:25 - 01081408 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2012-08-23 07:25 - 2012-08-23 07:25 - 00052288 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OsSettingPort.dll 2012-08-23 07:26 - 2012-08-23 07:26 - 00727616 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OutlookShadow.dll 2014-11-17 14:35 - 2014-11-17 14:34 - 01685528 _____ () C:\Program Files (x86)\AVG Web TuneUp\TBAPI.dll 2015-01-27 15:32 - 2015-01-25 07:08 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libglesv2.dll 2015-01-27 15:32 - 2015-01-25 07:08 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libegl.dll 2015-01-27 15:32 - 2015-01-25 07:08 - 09170760 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\pdf.dll 2012-12-26 06:26 - 2012-06-25 18:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:430C6D84 AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) HKU\S-1-5-21-417449669-2771163209-2432074822-1002\Software\Classes\.exe: exefile => <===== ATTENTION! HKU\S-1-5-21-417449669-2771163209-2432074822-1002\Software\Classes\exefile: <===== ATTENTION! ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "Start GeekBuddy.lnk" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "BtPreLoad" HKLM\...\StartupApproved\Run: => "ETDCtrl" HKLM\...\StartupApproved\Run: => "HotKeysCmds" HKLM\...\StartupApproved\Run: => "IgfxTray" HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run: => "Persistence" HKLM\...\StartupApproved\Run: => "Zune Launcher" HKLM\...\StartupApproved\Run: => "CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "RadioController" HKLM\...\StartupApproved\Run32: => "tvncontrol" HKLM\...\StartupApproved\Run32: => "PrivDogService" HKLM\...\StartupApproved\Run32: => "CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}" HKLM\...\StartupApproved\Run32: => "ETDCtrl" HKLM\...\StartupApproved\Run32: => "LManager" HKU\S-1-5-21-417449669-2771163209-2432074822-1002\...\StartupApproved\Run: => "NTRedirect" HKU\S-1-5-21-417449669-2771163209-2432074822-1002\...\StartupApproved\Run: => "ChomikBox" HKU\S-1-5-21-417449669-2771163209-2432074822-1002\...\StartupApproved\Run: => "CCleaner" ========================= Accounts: ========================== Administrator (S-1-5-21-417449669-2771163209-2432074822-500 - Administrator - Disabled) Gość (S-1-5-21-417449669-2771163209-2432074822-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-417449669-2771163209-2432074822-1012 - Limited - Enabled) UpdatusUser (S-1-5-21-417449669-2771163209-2432074822-1001 - Limited - Enabled) => C:\Users\UpdatusUser ZOOZKA (S-1-5-21-417449669-2771163209-2432074822-1002 - Administrator - Enabled) => C:\Users\ZOOZKA ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/29/2015 08:57:13 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program backgroundTaskHost.exe w wersji 6.3.9600.16384 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 2654 Godzina rozpoczęcia: 01d03bfd0ff0bc8e Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\WINDOWS\syswow64\backgroundTaskHost.exe Identyfikator raportu: 02a5eb5a-a7f1-11e4-bf03-20898452d391 Pełna nazwa pakietu powodującego błąd: Microsoft.MicrosoftMahjong_2.4.1408.2503_x86__8wekyb3d8bbwe Identyfikator aplikacji względem pakietu powodującego błąd: MicrosoftMahjong Error: (01/29/2015 09:41:40 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: OUTLOOK.EXE, wersja: 11.0.8326.0, sygnatura czasowa: 0x4c1c2372 Nazwa modułu powodującego błąd: OUTLLIB.dll, wersja: 11.0.8330.0, sygnatura czasowa: 0x4cb60a62 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x002769b5 Identyfikator procesu powodującego błąd: 0x2080 Godzina uruchomienia aplikacji powodującej błąd: 0xOUTLOOK.EXE0 Ścieżka aplikacji powodującej błąd: OUTLOOK.EXE1 Ścieżka modułu powodującego błąd: OUTLOOK.EXE2 Identyfikator raportu: OUTLOOK.EXE3 Pełna nazwa pakietu powodującego błąd: OUTLOOK.EXE4 Identyfikator aplikacji względem pakietu powodującego błąd: OUTLOOK.EXE5 Error: (01/28/2015 10:35:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: OUTLOOK.EXE, wersja: 11.0.8326.0, sygnatura czasowa: 0x4c1c2372 Nazwa modułu powodującego błąd: OUTLLIB.dll, wersja: 11.0.8330.0, sygnatura czasowa: 0x4cb60a62 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x002769b5 Identyfikator procesu powodującego błąd: 0x1d24 Godzina uruchomienia aplikacji powodującej błąd: 0xOUTLOOK.EXE0 Ścieżka aplikacji powodującej błąd: OUTLOOK.EXE1 Ścieżka modułu powodującego błąd: OUTLOOK.EXE2 Identyfikator raportu: OUTLOOK.EXE3 Pełna nazwa pakietu powodującego błąd: OUTLOOK.EXE4 Identyfikator aplikacji względem pakietu powodującego błąd: OUTLOOK.EXE5 Error: (01/28/2015 08:09:14 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: MSSQL$SALESPARTNER8 Error: (01/28/2015 07:57:00 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program Explorer.EXE w wersji 6.3.9600.17284 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 1d60 Godzina rozpoczęcia: 01d03b2679273388 Godzina zakończenia: 651 Ścieżka aplikacji: C:\WINDOWS\Explorer.EXE Identyfikator raportu: 6f040b60-a71f-11e4-bf02-20898452d391 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (01/28/2015 07:39:43 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 1110 Godzina rozpoczęcia: 01d03b2910ab1293 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe Identyfikator raportu: 03fed0af-a71d-11e4-bf02-20898452d391 Pełna nazwa pakietu powodującego błąd: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (01/28/2015 05:53:25 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 1d40 Godzina rozpoczęcia: 01d03b1a2ff2fccd Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe Identyfikator raportu: 296105e4-a70e-11e4-bf02-20898452d391 Pełna nazwa pakietu powodującego błąd: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (01/28/2015 05:38:17 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: f94 Godzina rozpoczęcia: 01d03b1817a0359a Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe Identyfikator raportu: 0ddc0e2a-a70c-11e4-bf02-20898452d391 Pełna nazwa pakietu powodującego błąd: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (01/28/2015 05:26:09 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program wwahost.exe w wersji 6.3.9600.17031 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 18d0 Godzina rozpoczęcia: 01d03b16e9dd5b25 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\WINDOWS\syswow64\wwahost.exe Identyfikator raportu: 556eb856-a70a-11e4-bf02-20898452d391 Pełna nazwa pakietu powodującego błąd: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c Identyfikator aplikacji względem pakietu powodującego błąd: App Error: (01/28/2015 05:25:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ANETA) Description: Działanie pakietu Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c+App zostało zakończone, ponieważ operacja wstrzymywania pakietu trwała zbyt długo. System errors: ============= Error: (01/29/2015 11:08:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi NVIDIA Update Service Daemon z powodu następującego błędu: %%1069 Error: (01/29/2015 11:08:17 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Usługa nvUpdatusService nie może zalogować się jako .\UpdatusUser za pomocą obecnie skonfigurowanego hasła z powodu następującego błędu: %%1326 Aby upewnić się, że usługa jest skonfigurowana prawidłowo, użyj przystawki Usługi w programie Microsoft Management Console (MMC). Error: (01/29/2015 11:06:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Usługa Windows Defender z powodu następującego błędu: %%577 Error: (01/29/2015 10:26:47 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: ANETA) Description: 0x8000002a116\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-417449669-2771163209-2432074822-1002-0-ntuser.dat Error: (01/29/2015 10:26:38 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: ANETA) Description: 0x8000002a116\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-417449669-2771163209-2432074822-1002-0-ntuser.dat Error: (01/29/2015 02:37:56 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: ZARZĄDZANIE NT) Description: Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Definition Update for Windows Defender - KB2267602 (Definition 1.191.3536.0). Error: (01/29/2015 02:00:12 PM) (Source: DCOM) (EventID: 10010) (User: ANETA) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (01/29/2015 01:59:34 PM) (Source: DCOM) (EventID: 10010) (User: ANETA) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (01/29/2015 01:41:18 PM) (Source: DCOM) (EventID: 10010) (User: ANETA) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (01/29/2015 01:40:48 PM) (Source: DCOM) (EventID: 10010) (User: ANETA) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Microsoft Office Sessions: ========================= Error: (01/29/2015 08:57:13 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: backgroundTaskHost.exe6.3.9600.16384265401d03bfd0ff0bc8e4294967295C:\WINDOWS\syswow64\backgroundTaskHost.exe02a5eb5a-a7f1-11e4-bf03-20898452d391Microsoft.MicrosoftMahjong_2.4.1408.2503_x86__8wekyb3d8bbweMicrosoftMahjong Error: (01/29/2015 09:41:40 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: OUTLOOK.EXE11.0.8326.04c1c2372OUTLLIB.dll11.0.8330.04cb60a62c0000005002769b5208001d03b9f3e146d1bE:\programy\Microsoft Office\OFFICE11\OUTLOOK.EXEE:\programy\Microsoft Office\OFFICE11\OUTLLIB.dlla449f666-a792-11e4-bf02-20898452d391 Error: (01/28/2015 10:35:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: OUTLOOK.EXE11.0.8326.04c1c2372OUTLLIB.dll11.0.8330.04cb60a62c0000005002769b51d2401d03b415bded627E:\programy\Microsoft Office\OFFICE11\OUTLOOK.EXEE:\programy\Microsoft Office\OFFICE11\OUTLLIB.dll982c13a1-a735-11e4-bf02-20898452d391 Error: (01/28/2015 08:09:14 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: MSSQL$SALESPARTNER8 Error: (01/28/2015 07:57:00 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Explorer.EXE6.3.9600.172841d6001d03b2679273388651C:\WINDOWS\Explorer.EXE6f040b60-a71f-11e4-bf02-20898452d391 Error: (01/28/2015 07:39:43 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.17031111001d03b2910ab12934294967295C:\WINDOWS\syswow64\wwahost.exe03fed0af-a71d-11e4-bf02-20898452d391Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp Error: (01/28/2015 05:53:25 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.170311d4001d03b1a2ff2fccd4294967295C:\WINDOWS\syswow64\wwahost.exe296105e4-a70e-11e4-bf02-20898452d391Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp Error: (01/28/2015 05:38:17 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.17031f9401d03b1817a0359a4294967295C:\WINDOWS\syswow64\wwahost.exe0ddc0e2a-a70c-11e4-bf02-20898452d391Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp Error: (01/28/2015 05:26:09 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.1703118d001d03b16e9dd5b254294967295C:\WINDOWS\syswow64\wwahost.exe556eb856-a70a-11e4-bf02-20898452d391Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp Error: (01/28/2015 05:25:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ANETA) Description: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c+App CodeIntegrity Errors: =================================== Date: 2015-01-29 23:06:13.421 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-29 10:32:29.713 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-28 17:20:58.067 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-26 11:02:53.608 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-25 13:28:48.892 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-25 00:19:01.114 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-25 00:05:11.113 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-24 22:35:43.355 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-24 21:54:02.584 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-01-24 19:04:47.009 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz Percentage of memory in use: 51% Total physical RAM: 3911.27 MB Available physical RAM: 1892.35 MB Total Pagefile: 6343.27 MB Available Pagefile: 3692.04 MB Total Virtual: 131072 MB Available Virtual: 131071.78 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:227.96 GB) (Free:163.01 GB) NTFS Drive e: (Nowy) (Fixed) (Total:219.73 GB) (Free:167.92 GB) NTFS Drive f: (KODAK) (Removable) (Total:0.48 GB) (Free:0.19 GB) FAT ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 316343A1) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 488.5 MB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================