Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-02-2015 Ran by Fabian at 2015-03-03 15:08:27 Running from C:\Users\Fabian\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 16.2.1 - Hewlett-Packard) Hidden Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Aktualizacje NVIDIA 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden BookScan&Whiteboard Suite (HKLM-x32\...\{F4933D9F-89CC-4CA9-B5B0-CF32968890C7}) (Version: 1.0 - Reallusion) Brother MFL-Pro Suite DCP-J152W (HKLM-x32\...\{B742757A-7658-4E09-A51A-085CF0F7F4D3}) (Version: 1.0.0.0 - Brother Industries, Ltd.) CRM (HKLM-x32\...\CRM) (Version: - ) Dell Data Vault (Version: 4.1.9.0 - Dell Inc.) Hidden Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.0.6584.52 - Dell) Dell SupportAssistAgent (HKLM-x32\...\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.0.1.56462 - Dell) Dell System Detect - 1 (HKU\S-1-5-21-4113954769-2473987496-1411739572-1001\...\73f463568823ebbe) (Version: 5.14.0.9 - Dell) Dell System Detect (HKU\S-1-5-21-4113954769-2473987496-1411739572-1001\...\9204f5692a8faf3b) (Version: 5.9.0.5 - Dell) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Homepage Print 2 (HKLM-x32\...\{57008A17-E76A-4832-A195-FE6A94DC8A66}) (Version: 1.0.0.0 - CORPUS CORPORATION) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.7.3.1001 - Intel Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office 2013 dla Użytkowników Domowych i Małych Firm - pl-pl (HKLM\...\HomeBusinessRetail - pl-pl) (Version: 15.0.4693.1002 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-4113954769-2473987496-1411739572-1001\...\OneDriveSetup.exe) (Version: 17.3.4713.0209 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MobileWiFi (HKLM-x32\...\MobileWiFi) (Version: 1.12.01.159 - Huawei Technologies Co.,Ltd) Mozilla Firefox 35.0.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 pl)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) NOVUS DVR NET (HKLM-x32\...\InstallShield_{9480A7FC-C476-4881-A92C-2E415DD362AE}) (Version: 7.00.0000 - NOVUS SECURITY) NOVUS DVR NET (x32 Version: 7.00.0000 - NOVUS SECURITY) Hidden NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) NVIDIA Sterownik 3D Vision 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.52 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation) NVIDIA Sterownik graficzny 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.52 - NVIDIA Corporation) NVIDIA Sterownik kontrolera 3D Vision 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation) Odinstaluj AutoControl 2.0 (HKLM-x32\...\{B57A8359-3C91-45A7-B9BE-F4C46F201F10}_is1}_is1) (Version: - AutoGuard S.A.) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4693.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4693.1002 - Microsoft Corporation) Hidden Oprogramowanie mikroukładu Intel® (x32 Version: 10.0.13 - Intel(R) Corporation) Hidden Panel sterowania NVIDIA 347.52 (Version: 347.52 - NVIDIA Corporation) Hidden PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge) PolkaSQL (HKLM-x32\...\PolkaSQL) (Version: - ) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.15.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden SQL Anywhere 9 for Windows x64 (HKLM-x32\...\{88A74695-D9B6-4F26-9252-40DCD3A6659E}) (Version: 9.0.2.3924 - iAnywhere Solutions, Inc.) SUNIX Multi-IO Controller (HKLM-x32\...\{A8D5B39E-815D-44BC-AC52-657FE3D2E21D}) (Version: 8.1.0.0 - SUNIX Co., Ltd.) Vademecum Haccp (P) wer. 96.64.2.864 (HKLM-x32\...\VHCC_SG_01_is1) (Version: - ) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 5.10 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4113954769-2473987496-1411739572-1001_Classes\CLSID\{C4FB9EEC-5B29-486B-ACD1-D93A4396E567}\InprocServer32 -> C:\Program Files (x86)\Homepage Print 2\pl\HPPrint.resources.dll (CORPUS CORPORATION) CustomCLSID: HKU\S-1-5-21-4113954769-2473987496-1411739572-1001_Classes\CLSID\{EFC91ACA-519F-428D-8472-81E158609D25}\InprocServer32 -> C:\Program Files (x86)\Homepage Print 2\pl\HPPrint.resources.dll (CORPUS CORPORATION) CustomCLSID: HKU\S-1-5-21-4113954769-2473987496-1411739572-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Fabian\AppData\Local\Microsoft\OneDrive\17.3.4713.0209\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 12-02-2015 06:48:58 Windows Update 17-02-2015 09:28:54 Windows Update 25-02-2015 07:14:35 Windows Update 27-02-2015 15:00:29 Operacja przywracania 03-03-2015 09:50:46 Restore Point Created by FRST 03-03-2015 09:58:06 Restore Point Created by FRST ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {14B33112-8F59-471B-98FC-324F262DEDDE} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-02-03] (PC-Doctor, Inc.) Task: {1AC46A0A-7CEA-4763-9E27-771589628E44} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated) Task: {1B1C4503-DB22-46E4-9A13-08B2FC2FBCD0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-17] (Google Inc.) Task: {2D7C87CB-7B16-42E4-8485-76BE9D9F166E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {3B2A8F02-D4E2-417F-ACF3-EE40773D64E4} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {6169D641-5A4A-4621-8FAE-68DBFDDE7DD8} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-02-03] (PC-Doctor, Inc.) Task: {80935368-E0F3-4FEF-83C1-F384DED3A375} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-02-19] (Microsoft) Task: {8F1B7DA8-373F-4943-9C9C-E495F88439FE} - System32\Tasks\Microsoft Office 15 Sync Maintenance for MAGAZYN-Fabian Magazyn => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-01-06] (Microsoft Corporation) Task: {BEB6FAED-D029-4E7F-9BB2-03616DFC67A0} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation) Task: {DD78C53E-BDDB-4A7E-875E-06CEDC60C76F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation) Task: {EB4AD923-8A74-49A9-BFFE-9DAAE620FE22} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-17] (Google Inc.) Task: {EEDC1FB9-251A-4015-9341-D57B2C25C86D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-02-12] (Microsoft Corporation) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\Dell SupportAssistAgent AutoUpdate.job => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-07-29 20:48 - 2015-02-05 20:07 - 00117576 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-07-31 09:57 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-02-06 07:10 - 2013-02-06 07:10 - 00351824 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2014-11-24 07:42 - 2014-11-24 07:42 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll 2014-11-24 07:40 - 2014-11-24 07:40 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll 2014-08-04 12:40 - 2013-12-09 22:27 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\Fabian\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Fabian\Downloads\Fwd_ Nowe oferty 19-12-2014.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4113954769-2473987496-1411739572-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Fabian\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\3albylaran-bluewaterdrop mój.jpg DNS Servers: 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run: => "RtHDVBg" HKU\S-1-5-21-4113954769-2473987496-1411739572-1001\...\StartupApproved\Run: => "swg" ==================== Accounts: ============================= Administrator (S-1-5-21-4113954769-2473987496-1411739572-500 - Administrator - Disabled) Fabian (S-1-5-21-4113954769-2473987496-1411739572-1001 - Administrator - Enabled) => C:\Users\Fabian Guest (S-1-5-21-4113954769-2473987496-1411739572-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-4113954769-2473987496-1411739572-1006 - Limited - Enabled) Jarosław (S-1-5-21-4113954769-2473987496-1411739572-1007 - Limited - Enabled) => C:\Users\Jarosław ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/03/2015 03:06:28 PM) (Source: PostgreSQL) (EventID: 0) (User: ) Description: Is server running? Error: (03/03/2015 03:06:28 PM) (Source: PostgreSQL) (EventID: 0) (User: ) Description: pg_ctl: PID file "../pg/data/postmaster.pid" does not exist Error: (03/03/2015 03:04:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.3.9600.17415, sygnatura czasowa: 0x54503a3a Nazwa modułu powodującego błąd: twinui.dll, wersja: 6.3.9600.17415, sygnatura czasowa: 0x54503c45 Kod wyjątku: 0x80270249 Przesunięcie błędu: 0x00000000002f497f Identyfikator procesu powodującego błąd: 0xd80 Godzina uruchomienia aplikacji powodującej błąd: 0xExplorer.EXE0 Ścieżka aplikacji powodującej błąd: Explorer.EXE1 Ścieżka modułu powodującego błąd: Explorer.EXE2 Identyfikator raportu: Explorer.EXE3 Pełna nazwa pakietu powodującego błąd: Explorer.EXE4 Identyfikator aplikacji względem pakietu powodującego błąd: Explorer.EXE5 Error: (03/03/2015 03:02:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.3.9600.17415, sygnatura czasowa: 0x54503a3a Nazwa modułu powodującego błąd: twinui.dll, wersja: 6.3.9600.17415, sygnatura czasowa: 0x54503c45 Kod wyjątku: 0x80270249 Przesunięcie błędu: 0x00000000002f497f Identyfikator procesu powodującego błąd: 0xf80 Godzina uruchomienia aplikacji powodującej błąd: 0xExplorer.EXE0 Ścieżka aplikacji powodującej błąd: Explorer.EXE1 Ścieżka modułu powodującego błąd: Explorer.EXE2 Identyfikator raportu: Explorer.EXE3 Pełna nazwa pakietu powodującego błąd: Explorer.EXE4 Identyfikator aplikacji względem pakietu powodującego błąd: Explorer.EXE5 Error: (03/03/2015 09:59:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.3.9600.17415, sygnatura czasowa: 0x54503a3a Nazwa modułu powodującego błąd: twinui.dll, wersja: 6.3.9600.17415, sygnatura czasowa: 0x54503c45 Kod wyjątku: 0x80270249 Przesunięcie błędu: 0x00000000002f497f Identyfikator procesu powodującego błąd: 0x88c Godzina uruchomienia aplikacji powodującej błąd: 0xExplorer.EXE0 Ścieżka aplikacji powodującej błąd: Explorer.EXE1 Ścieżka modułu powodującego błąd: Explorer.EXE2 Identyfikator raportu: Explorer.EXE3 Pełna nazwa pakietu powodującego błąd: Explorer.EXE4 Identyfikator aplikacji względem pakietu powodującego błąd: Explorer.EXE5 Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service Wire Brightness since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service Typewriter Contract since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Eraser Control driver. System Error: The system cannot find the file specified. . Error: (03/03/2015 09:52:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: FRST64.exe, wersja: 29.2.2015.0, sygnatura czasowa: 0x54f24e5d Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.3.9600.17630, sygnatura czasowa: 0x54b0e17a Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000045d4a Identyfikator procesu powodującego błąd: 0x133c Godzina uruchomienia aplikacji powodującej błąd: 0xFRST64.exe0 Ścieżka aplikacji powodującej błąd: FRST64.exe1 Ścieżka modułu powodującego błąd: FRST64.exe2 Identyfikator raportu: FRST64.exe3 Pełna nazwa pakietu powodującego błąd: FRST64.exe4 Identyfikator aplikacji względem pakietu powodującego błąd: FRST64.exe5 System errors: ============= Error: (03/03/2015 03:04:29 PM) (Source: DCOM) (EventID: 10010) (User: MAGAZYN) Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca Error: (03/03/2015 03:03:12 PM) (Source: DCOM) (EventID: 10010) (User: MAGAZYN) Description: {BC4ABC58-1BD7-57E8-B3D4-6850C60D87FD} Error: (03/03/2015 03:03:11 PM) (Source: DCOM) (EventID: 10010) (User: MAGAZYN) Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca Error: (03/03/2015 03:03:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (03/03/2015 03:02:18 PM) (Source: DCOM) (EventID: 10010) (User: MAGAZYN) Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca Error: (03/03/2015 02:51:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (03/03/2015 01:10:37 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: Wygenerowano alert krytyczny, który został wysłany do zdalnego punktu końcowego. W efekcie połączenie może zostać zakończone. Kod błędu krytycznego zdefiniowany przez protokół TLS to 40. Kod stanu błędu SChannel w systemie Windows to 252. Error: (03/03/2015 09:59:53 AM) (Source: DCOM) (EventID: 10010) (User: MAGAZYN) Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca Error: (03/03/2015 09:59:53 AM) (Source: DCOM) (EventID: 10010) (User: MAGAZYN) Description: Windows.Networking.BackgroundTransfer.Internal.NetworkChangeTask.ClassId.4 Error: (03/03/2015 09:58:57 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Microsoft Office Sessions: ========================= Error: (03/03/2015 03:06:28 PM) (Source: PostgreSQL) (EventID: 0) (User: ) Description: Is server running? Error: (03/03/2015 03:06:28 PM) (Source: PostgreSQL) (EventID: 0) (User: ) Description: pg_ctl: PID file "../pg/data/postmaster.pid" does not exist Error: (03/03/2015 03:04:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.3.9600.1741554503a3atwinui.dll6.3.9600.1741554503c458027024900000000002f497fd8001d055baf52b2072C:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\twinui.dll33ec3bd5-c1ae-11e4-827d-c81f66483531 Error: (03/03/2015 03:02:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.3.9600.1741554503a3atwinui.dll6.3.9600.1741554503c458027024900000000002f497ff8001d055baa7d9601bC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\twinui.dlle65a1de9-c1ad-11e4-827c-c81f66483531 Error: (03/03/2015 09:59:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.3.9600.1741554503a3atwinui.dll6.3.9600.1741554503c458027024900000000002f497f88c01d055906464a129C:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\twinui.dlla6ad5bbd-c183-11e4-827a-c81f66483531 Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service Wire Brightness since QueryServiceConfig API failed System Error: The system cannot find the file specified. Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddWin32ServiceFiles: Unable to back up image of service Typewriter Contract since QueryServiceConfig API failed System Error: The system cannot find the file specified. Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. Error: (03/03/2015 09:58:07 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Symantec Eraser Control driver. System Error: The system cannot find the file specified. Error: (03/03/2015 09:52:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: FRST64.exe29.2.2015.054f24e5dntdll.dll6.3.9600.1763054b0e17ac00000050000000000045d4a133c01d0558f107d219dC:\Users\Fabian\Desktop\FRST64.exeC:\WINDOWS\SYSTEM32\ntdll.dlla9721c78-c182-11e4-8279-c81f66483531 CodeIntegrity Errors: =================================== Date: 2015-03-03 15:01:27.903 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:27.262 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:25.043 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:24.559 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:23.809 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:23.481 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:23.090 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:22.840 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:22.449 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-03 15:01:22.231 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4440 CPU @ 3.10GHz Percentage of memory in use: 9% Total physical RAM: 16334.95 MB Available physical RAM: 14813.66 MB Total Pagefile: 18766.95 MB Available Pagefile: 17180.82 MB Total Virtual: 131072 MB Available Virtual: 131071.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:915.81 GB) (Free:857.01 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: A860F0D9) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=15.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=915.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================