Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-12-2013 Ran by Krzysztof at 2013-12-05 12:47:32 Running from C:\Users\Krzysztof\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== µTorrent (HKCU Version: 3.3.2.30180) 7-Zip 9.20 (x32) a2zLyrics-1 (x32 Version: 1.28.153.5) Adobe AIR (x32 Version: 3.9.0.1030) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader X MUI (x32 Version: 10.0.0) ASUS Live Update (x32 Version: 3.1.7) ASUS Power4Gear Hybrid (Version: 2.0.3) ASUS Smart Gesture (x32 Version: 1.0.35) ASUS Splendid Video Enhancement Technology (x32 Version: 1.03.0002) ASUS USB Charger Plus (x32 Version: 2.1.4) ATK Package (x32 Version: 1.0.0022) Babylon Chrome Toolbar (x32) Babylon toolbar (x32 Version: 1.8.24.6) Bonanza Deals (remove only) (x32 Version: 5.0.1.0) <==== ATTENTION Bundled software uninstaller (x32) Counter-Strike 1.6 v23 (x32 Version: v23) Delta Chrome Toolbar (x32) Delta toolbar (x32 Version: 1.8.24.6) <==== ATTENTION FilesFrog Update Checker (x32) Google Chrome (x32 Version: 65.143.49221) Google Update Helper (x32 Version: 1.3.21.165) Intel(R) Management Engine Components (x32 Version: 8.1.0.1252) Intel(R) Processor Graphics (x32 Version: 10.18.10.3308) Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Java 7 Update 40 (64-bit) (Version: 7.0.400) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) K-Lite Codec Pack 10.0.5 Full (x32 Version: 10.0.5) League of Legends (x32 Version: 3.0.1) Microsoft Office (x32 Version: 14.0.6120.5004) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MyPC Backup (Version: ) <==== ATTENTION NapiProjekt (2.2.0.2399) (x32) Opera Stable 18.0.1284.49 (x32 Version: 18.0.1284.49) Pakiet sterowników systemu Windows - ASUS (ATP) Mouse (10/29/2012 1.0.0.148) (Version: 10/29/2012 1.0.0.148) Qualcomm Atheros Client Installation Program (x32 Version: 10.0) Realtek Ethernet Controller Driver (x32 Version: 8.2.612.2012) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6685) Realtek PCIE Card Reader (x32 Version: 6.2.8400.27024) Search-Gol Chrome Toolbar (x32) searchgol toolbar (x32 Version: 1.8.16.19) Shared C Run-time for x64 (Version: 10.0.0) System Requirements Lab for Intel (x32 Version: 4.5.15.0) VLC media player 2.1.0 (x32 Version: 2.1.0) WinFlash (x32 Version: 2.41.1) WinRAR 4.20 (64-bitowy) (Version: 4.20.0) Wsys Control 10.2.1.2652 (x32 Version: 10.2.1.2652) Your Uninstaller! 7 (x32 Version: 7.5.2013.2) ==================== Restore Points ========================= 29-10-2013 09:38:56 Windows Update 01-11-2013 12:05:15 Windows Update 09-11-2013 12:10:40 Zaplanowany punkt kontrolny 13-11-2013 12:21:39 Windows Update 05-12-2013 10:29:48 Before uninstalling Avira Free Antivirus ==================== Hosts content: ========================== 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {035792A1-D4EF-4A78-BF9A-AA9628C281A3} - System32\Tasks\Microsoft\Windows\Setup\SetupCleanupTask Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0DCF0545-A62C-43B7-926B-9B795F395139} - System32\Tasks\a2zLyrics-1-codedownloader => C:\Program Files (x86)\a2zLyrics-1\a2zLyrics-1-codedownloader.exe [2013-10-10] (Lyrics) Task: {144E094E-A7DA-4BBD-A607-769FBEAA7285} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2012-10-31] (AsusTek) Task: {15A8973F-25EB-484A-845D-4822B189AC3F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-10] (Google Inc.) Task: {171DBBD9-CD0B-49AE-9C6F-4D5A0599D973} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-04] (ASUS) Task: {1FFF5965-FB13-4ED0-8063-0F5615D7893F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-14] (Adobe Systems Incorporated) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\System32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {40A31344-6C03-4064-ACE2-E613D0289B6B} - System32\Tasks\EPUpdater => C:\Users\Slawomir\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-09-01] () Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {811A65A1-617D-4E9B-9CE6-67D76FA49770} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\Windows\System32\oobe\setupsqm.exe [2013-08-22] (Microsoft Corporation) Task: {84BBC418-9DA2-4F69-BF4E-445161F6D7A7} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-10-10] (BonanzaDeals) <==== ATTENTION Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => C:\Windows\System32\AppXDeploymentClient.dll [2013-09-30] (Microsoft Corporation) Task: {960CDCDB-7C07-4571-A406-BC94B23B4BA6} - System32\Tasks\a2zLyrics-1-enabler => C:\Program Files (x86)\a2zLyrics-1\a2zLyrics-1-enabler.exe [2013-10-10] (Lyrics) Task: {9B62D363-E6AC-4A92-A235-1DEC04D0FCF0} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-10-10] (BonanzaDeals) <==== ATTENTION Task: {9C68C20C-F483-4B98-96B8-8F091979EC3B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\System32\MRT.exe [2013-11-13] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {B0512F5F-0DC0-4DDE-B239-01EB135CD0A5} - System32\Tasks\BonanzaDealsUpdate => C:\Program Task: {B13D777E-0ABF-4646-9CD7-0CB9335D3E5A} - System32\Tasks\a2zLyrics-1-updater => C:\Program Files (x86)\a2zLyrics-1\a2zLyrics-1-updater.exe [2013-10-10] (Lyrics) Task: {BF086ADC-9251-41FA-A8D7-58258CD2C8F3} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-06-21] (ASUSTeK Computer Inc.) Task: {C1843534-F669-418E-828D-216FEC593A4A} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-25] (ASUSTek Computer Inc.) Task: {CEA7A9BD-79BA-47C4-8E40-35B57EF3AA0D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-10] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: C:\WINDOWS\Tasks\a2zLyrics-1-codedownloader.job => C:\Program Files (x86)\a2zLyrics-1\a2zLyrics-1-codedownloader.exe Task: C:\WINDOWS\Tasks\a2zLyrics-1-enabler.job => C:\Program Files (x86)\a2zLyrics-1\a2zLyrics-1-enabler.exe Task: C:\WINDOWS\Tasks\a2zLyrics-1-updater.job => C:\Program Files (x86)\a2zLyrics-1\a2zLyrics-1-updater.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\WINDOWS\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-10-01 12:02 - 2013-10-01 12:02 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-06-07 23:12 - 2012-06-07 23:12 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2012-12-14 14:13 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-11-19 17:17 - 2013-11-15 15:23 - 00886624 _____ () C:\Program Files (x86)\Opera\18.0.1284.49\libglesv2.dll 2013-11-19 17:17 - 2013-11-15 15:23 - 00108896 _____ () C:\Program Files (x86)\Opera\18.0.1284.49\libegl.dll 2013-11-19 17:17 - 2013-11-15 15:23 - 00879968 _____ () C:\Program Files (x86)\Opera\18.0.1284.49\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:1CE11B51 AlternateDataStreams: C:\Users\Krzysztof\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/05/2013 00:47:22 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:47:22Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:46:52 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:46:52Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:46:22 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:46:22Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:45:52 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:45:52Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:45:22 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:45:22Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:44:52 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:44:52Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:44:22 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:44:22Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:43:52 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:43:52Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:43:22 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:43:22Z. Kod błędu: 0x80040154. Error: (12/05/2013 00:42:52 PM) (Source: Software Protection Platform Service) (User: ) Description: Nie można zaplanować restartu usługi ochrony oprogramowania o 2113-11-11T11:42:52Z. Kod błędu: 0x80040154. System errors: ============= Error: (12/05/2013 11:26:41 AM) (Source: Service Control Manager) (User: ) Description: Usługa BitGuard niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (12/05/2013 10:38:10 AM) (Source: BugCheck) (User: ) Description: 0x000000ef (0xffffe00004431080, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000)C:\WINDOWS\MEMORY.DMP120513-19468-01 Error: (12/05/2013 10:37:41 AM) (Source: EventLog) (User: ) Description: Poprzednie zamknięcie systemu przy 10:35:42 na ‎2013-‎12-‎05 było nieoczekiwane. Error: (12/05/2013 10:36:17 AM) (Source: Service Control Manager) (User: ) Description: Usługa Computer Backup (MyPC Backup) niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (12/05/2013 10:36:13 AM) (Source: Service Control Manager) (User: ) Description: Usługa Autokonfiguracja urządzeń podłączonych do sieci niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (12/05/2013 10:36:13 AM) (Source: Service Control Manager) (User: ) Description: Usługa Zapora systemu Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (12/05/2013 10:36:13 AM) (Source: Service Control Manager) (User: ) Description: Usługa Usługa zasad diagnostyki niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (12/05/2013 10:36:13 AM) (Source: Service Control Manager) (User: ) Description: Usługa Podstawowy aparat filtrowania niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (12/05/2013 10:36:09 AM) (Source: Service Control Manager) (User: ) Description: Usługa Broker czasu niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (12/05/2013 10:36:09 AM) (Source: Service Control Manager) (User: ) Description: Usługa Odnajdywanie SSDP niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 100 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Microsoft Office Sessions: ========================= Error: (12/05/2013 00:47:22 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:47:22Z Error: (12/05/2013 00:46:52 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:46:52Z Error: (12/05/2013 00:46:22 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:46:22Z Error: (12/05/2013 00:45:52 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:45:52Z Error: (12/05/2013 00:45:22 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:45:22Z Error: (12/05/2013 00:44:52 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:44:52Z Error: (12/05/2013 00:44:22 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:44:22Z Error: (12/05/2013 00:43:52 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:43:52Z Error: (12/05/2013 00:43:22 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:43:22Z Error: (12/05/2013 00:42:52 PM) (Source: Software Protection Platform Service)(User: ) Description: 0x800401542113-11-11T11:42:52Z ==================== Memory info =========================== Percentage of memory in use: 27% Total physical RAM: 8077.54 MB Available physical RAM: 5895.77 MB Total Pagefile: 16269.54 MB Available Pagefile: 14128.14 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:186.01 GB) (Free:141.88 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:258.51 GB) (Free:251.54 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 62911455) Partition: GPT Partition Type ==================== End Of Log ============================