Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-11-2014 Ran by Marysia at 2014-11-24 22:26:15 Running from C:\Documents and Settings\Marysia\My Documents\Pobrane Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Ashampoo WinOptimizer 2012 v.8.1.4 (HKLM\...\Ashampoo WinOptimizer 2012_is1) (Version: 8.1.4 - Ashampoo GmbH & Co. KG) Auslogics Disk Defrag (HKLM\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 3.5 - Auslogics Software Pty Ltd) avast! Free Antivirus (HKLM\...\avast) (Version: 9.0.2021 - AVAST Software) Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden K-Lite Codec Pack 7.7.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 7.7.0 - ) Lexmark X1100 Series (HKLM\...\Lexmark X1100 Series) (Version: - ) Localization Pack for Microsoft Windows XP Media Center Edition (Version: 1.0.0 - WIT) Hidden Media Player Classic - Home Cinema v1.5.2.3456 (HKLM\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.5.2.3456 - MPC-HC Team) Microsoft .NET Framework 1.0 Hotfix (KB2572066) (HKLM\...\KB2572066) (Version: - Microsoft Corporation) Microsoft .NET Framework 1.0 Hotfix (KB2604042) (HKLM\...\KB2604042) (Version: - Microsoft Corporation) Microsoft .NET Framework 1.0 Hotfix (KB2656378) (HKLM\...\KB2656378) (Version: - Microsoft Corporation) Microsoft .NET Framework 1.0 Security Update (KB2698035) (HKLM\...\KB2698035) (Version: - Microsoft Corporation) Microsoft .NET Framework 1.0 Security Update (KB2742607) (HKLM\...\KB2742607) (Version: - Microsoft Corporation) Microsoft .NET Framework 1.0 Security Update (KB2833951) (HKLM\...\KB2833951) (Version: - Microsoft Corporation) Microsoft .NET Framework 1.0 Security Update (KB2904878) (HKLM\...\KB2904878) (Version: - Microsoft Corporation) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 Polish Language Pack (HKLM\...\{64CB2553-C109-4132-AA51-1F421B515FD1}) (Version: 1.1.4322 - Microsoft) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 33.1 (x86 pl) (HKLM\...\Mozilla Firefox 33.1 (x86 pl)) (Version: 33.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 26.0 - Mozilla) MSN (HKLM\...\MSNINST) (Version: - ) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero Suite (HKLM\...\NeroMultiInstaller!UninstallKey) (Version: - ) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) OpenOffice.org 3.3 (HKLM\...\{EB87675F-5281-4767-A54B-31931794C23D}) (Version: 3.3.9567 - OpenOffice.org) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.8 - Google, Inc.) Revo Uninstaller 1.93 (HKLM\...\Revo Uninstaller) (Version: 1.93 - VS Revo Group) SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - ) Samsung Mobile phone USB driver Software (HKLM\...\Samsung Mobile phone USB driver) (Version: - ) SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - ) SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - ) Update Rollup 2 for Windows XP Media Center Edition 2005 (HKLM\...\KB900325) (Version: - Microsoft Corporation) VLC media player 2.0.8 (HKLM\...\VLC media player) (Version: 2.0.8 - VideoLAN) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (HKLM\...\KB952011) (Version: 1.0 - Microsoft Corporation) Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation) Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation) Windows Media Format Runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) Windows XP Media Center Edition 2005 KB2502898 (HKLM\...\KB2502898) (Version: - Microsoft Corporation) Windows XP Media Center Edition 2005 KB2619340 (HKLM\...\KB2619340) (Version: - Microsoft Corporation) Windows XP Media Center Edition 2005 KB2628259 (HKLM\...\KB2628259) (Version: - Microsoft Corporation) Windows XP Media Center Edition 2005 KB908250 (HKLM\...\KB908250) (Version: - Microsoft Corporation) Windows XP Media Center Edition 2005 KB973768 (HKLM\...\KB973768) (Version: - Microsoft Corporation) Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-602162358-842925246-839522115-1003_Classes\CLSID\{46CDD27D-E6F5-2EC0-6628-A966F43607EB}\InprocServer32 -> No File Path ==================== Restore Points ========================= 12-11-2014 17:19:27 Software Distribution Service 3.0 15-11-2014 10:31:22 Punkt kontrolny systemu 20-11-2014 13:01:19 Punkt kontrolny systemu 24-11-2014 21:15:08 Removed Adobe Reader X (10.1.9) - Polish. 24-11-2014 21:16:26 Removed Java 7 Update 25 24-11-2014 21:17:23 Removed Java(TM) 6 Update 27 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2004-08-10 13:00 - 2004-08-10 13:00 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-01 18:55 - 2014-07-04 21:05 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 2014-11-24 21:53 - 2014-11-24 21:53 - 02903552 _____ () C:\Program Files\AVAST Software\Avast\defs\14112401\algo.dll 2011-09-11 14:13 - 2003-07-29 17:27 - 00078336 _____ () C:\WINDOWS\System32\spool\PRTPROCS\W32X86\LXBKPP5C.dll 2004-08-10 13:00 - 2011-02-05 01:48 - 00291840 _____ () C:\WINDOWS\system32\sbe.dll 2004-08-10 13:00 - 2013-01-02 07:49 - 01292288 _____ () C:\WINDOWS\system32\quartz.dll 2004-08-10 13:00 - 2008-04-14 01:11 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll 2004-08-10 13:00 - 2008-04-14 01:11 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll 2014-11-11 16:25 - 2014-11-11 16:25 - 03649648 ____C () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup MSCONFIG\startupfolder: C:^Documents and Settings^Marysia^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk => C:\WINDOWS\pss\OpenOffice.org 3.3.lnkStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => MSCONFIG\startupreg: ehTray => C:\WINDOWS\ehome\ehtray.exe MSCONFIG\startupreg: FijkOrnex => regsvr32.exe "C:\Documents and Settings\All Users\Application Data\FijkOrnex\FijkOrnex.dat" MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background MSCONFIG\startupreg: NeroFilterCheck => C:\WINDOWS\system32\NeroCheck.exe MSCONFIG\startupreg: NvCplDaemon => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup MSCONFIG\startupreg: nwiz => nwiz.exe /install MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: ThreatFire => ========================= Accounts: ========================== Administrator (S-1-5-21-602162358-842925246-839522115-500 - Administrator - Enabled) ASPNET (S-1-5-21-602162358-842925246-839522115-1004 - Limited - Enabled) Guest (S-1-5-21-602162358-842925246-839522115-501 - Limited - Disabled) HelpAssistant (S-1-5-21-602162358-842925246-839522115-1000 - Limited - Disabled) Marysia (S-1-5-21-602162358-842925246-839522115-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Marysia SUPPORT_388945a0 (S-1-5-21-602162358-842925246-839522115-1002 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/05/2014 08:34:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Aplikacja zawieszająca firefox.exe, wersja 32.0.3.5379, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error: (10/01/2014 06:32:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd plugin-container.exe, wersja 32.0.3.5379, moduł powodujący błąd mozalloc.dll, wersja 32.0.3.5379, adres błędu 0x0000141b. Przetwarzanie zdarzenia określonego nośnika dla [plugin-container.exe!ws!] Error: (10/01/2014 06:32:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Aplikacja zawieszająca firefox.exe, wersja 32.0.3.5379, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error: (08/10/2014 03:07:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd skype.exe, wersja 6.11.0.102, moduł powodujący błąd skype.exe, wersja 6.11.0.102, adres błędu 0x002454e7. Przetwarzanie zdarzenia określonego nośnika dla [skype.exe!ws!] Error: (06/05/2014 04:59:04 PM) (Source: COM+) (EventID: 4689) (User: ) Description: Środowisko czasu wykonania wykryło niespójność swego stanu wewnętrznego. Wskazuje to na potencjalną niestabilność procesu, która mogła zostać spowodowana przez działające w aplikacji COM+ składniki użytkownika, używane przez nie składniki lub inne czynniki. Błąd w f:\xpsp3\com\com1x\src\comsvcs\package\cpackage.cpp(1184), hr = 8007041d: InitEventCollector failed Error: (10/27/2013 09:40:10 PM) (Source: MsiInstaller) (EventID: 11316) (User: ZARZĄDZANIE NT) Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files\Google\Update\1.3.21.165\BonanzaDealsLiveHelper.msi Error: (10/19/2013 08:33:42 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Aplikacja zawieszająca rundll32.exe, wersja 5.1.2600.5512, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error: (09/23/2013 06:12:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd drwtsn32.exe, wersja 5.1.2600.0, moduł powodujący błąd dbghelp.dll, wersja 5.1.2600.5512, adres błędu 0x0001295d. Przetwarzanie zdarzenia określonego nośnika dla [drwtsn32.exe!ws!] Error: (09/23/2013 06:12:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd nero.exe, wersja 6.6.0.15, moduł powodujący błąd newtrf.dll, wersja 6.6.0.15, adres błędu 0x0000a6a6. Przetwarzanie zdarzenia określonego nośnika dla [nero.exe!ws!] Error: (09/22/2013 02:45:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd istudio.exe, wersja 3.1.36.6, moduł powodujący błąd unknown, wersja 0.0.0.0, adres błędu 0x4c494146. Przetwarzanie zdarzenia określonego nośnika dla [istudio.exe!ws!] System errors: ============= Error: (11/24/2014 10:17:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Java Quick Starter niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (11/24/2014 09:50:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Media Center Extender Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/24/2014 09:50:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa COM+ System Application niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/24/2014 09:50:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Usługa Odbiornik Media Center niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/24/2014 09:50:30 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa Media Center Extender Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 5000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/24/2014 09:50:30 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa NVIDIA Display Driver Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (11/24/2014 09:50:30 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa COM+ System Application niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 1000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (11/24/2014 09:50:30 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Application Layer Gateway Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (11/24/2014 09:50:30 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Windows User Mode Driver Framework niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (11/24/2014 09:50:30 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Usługa Planowanie nagrywania niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Microsoft Office Sessions: ========================= Error: (10/05/2014 08:34:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: firefox.exe32.0.3.5379hungapp0.0.0.000000000 Error: (10/01/2014 06:32:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe32.0.3.5379mozalloc.dll32.0.3.53790000141b Error: (10/01/2014 06:32:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: firefox.exe32.0.3.5379hungapp0.0.0.000000000 Error: (08/10/2014 03:07:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: skype.exe6.11.0.102skype.exe6.11.0.102002454e7 Error: (06/05/2014 04:59:04 PM) (Source: COM+) (EventID: 4689) (User: ) Description: Błąd w f:\xpsp3\com\com1x\src\comsvcs\package\cpackage.cpp(1184), hr = 8007041d: InitEventCollector failed Error: (10/27/2013 09:40:10 PM) (Source: MsiInstaller) (EventID: 11316) (User: ZARZĄDZANIE NT) Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files\Google\Update\1.3.21.165\BonanzaDealsLiveHelper.msi(NULL)(NULL)(NULL) Error: (10/19/2013 08:33:42 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: rundll32.exe5.1.2600.5512hungapp0.0.0.000000000 Error: (09/23/2013 06:12:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: drwtsn32.exe5.1.2600.0dbghelp.dll5.1.2600.55120001295d Error: (09/23/2013 06:12:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: nero.exe6.6.0.15newtrf.dll6.6.0.150000a6a6 Error: (09/22/2013 02:45:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: istudio.exe3.1.36.6unknown0.0.0.04c494146 ==================== Memory info =========================== Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz Percentage of memory in use: 87% Total physical RAM: 510.42 MB Available physical RAM: 61.37 MB Total Pagefile: 1243.06 MB Available Pagefile: 760.77 MB Total Virtual: 2047.88 MB Available Virtual: 1950.1 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:20 GB) (Free:13.5 GB) NTFS ==>[Drive with boot components (Windows XP)] Drive d: (Dysk lokalny) (Fixed) (Total:91.78 GB) (Free:51.63 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 111.8 GB) (Disk ID: 9A0B9A0B) Partition 1: (Active) - (Size=20 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=91.8 GB) - (Type=OF Extended) ==================== End Of Log ============================