ADVERTISEMENT

Addition.txt

Laptop Acer - Pojawiające się okienka z reklamami.

Log Addiition w załączniku.


Download file - link to post

Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-06-2015
Ran by tereska at 2015-06-17 16:54:27
Running from C:\Users\tereska\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4006550626-1204394080-3215568820-500 - Administrator - Disabled)
Gość (S-1-5-21-4006550626-1204394080-3215568820-501 - Limited - Disabled) = & gt; C:\Users\Gość
Olee (S-1-5-21-4006550626-1204394080-3215568820-1001 - Administrator - Enabled) = & gt; C:\Users\Olee
tereska (S-1-5-21-4006550626-1204394080-3215568820-1000 - Administrator - Enabled) = & gt; C:\Users\tereska

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Lavasoft Ad-Watch Live! Anti-Virus (Enabled - Up to date) {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Lavasoft Ad-Watch Live! (Enabled - Up to date) {24938260-56EE-C1E5-047B-DC2BDD234BAB}

==================== Installed Programs ======================

(Only the adware programs with " hidden " flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Ad-Aware (HKLM-x32\...\{D0046F17-A170-4E07-A349-F1BCB3A8A8EB}) (Version: 9.0.7 - Lavasoft Limited)
Adobe Acrobat Reader DC - Polish (HKLM-x32\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.160 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.160 - Adobe Systems Incorporated)
Broadcom Card Reader Driver Installer (HKLM\...\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 15.0.7.2 - Broadcom Corporation)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.35 - Irfan Skiljan)
K-Lite Codec Pack 10.4.0 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.4.0 - )
Malwarebytes Anti-Malware wersja 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 38.0.6 (x86 pl) (HKLM-x32\...\Mozilla Firefox 38.0.6 (x86 pl)) (Version: 38.0.6 - Mozilla)
PLAY ONLINE (HKLM-x32\...\PLAY ONLINE) (Version: 21.005.11.17.264 - Huawei Technologies Co.,Ltd)
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
WinRAR 5.20 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

14-06-2015 23:06:04 Removed Firebird SQL Server - MAGIX Edition
14-06-2015 23:06:32 Removed Google Drive
15-06-2015 22:14:56 avast! antivirus system restore point
16-06-2015 08:43:02 Removed Google Drive
16-06-2015 21:13:41 avast! antivirus system restore point
16-06-2015 21:32:43 Removed MSXML 4.0 SP3 Parser
16-06-2015 21:50:22 Installed Ad-Aware
16-06-2015 21:50:58 Installed Ad-Aware

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {058C2DBF-A9CB-4CDC-889F-09FC4FA88201} - System32\Tasks\GoogleUpdateTaskMachineUA = & gt; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-13] (Google Inc.)
Task: {192E0CC9-C69D-430C-891A-AC42EA49B9B1} - System32\Tasks\Ad-Aware Update (Weekly) = & gt; C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2015-06-16] (Lavasoft Limited )
Task: {21ECCA37-BDDD-451E-924D-325C978BE7EE} - System32\Tasks\GoogleUpdateTaskMachineCore = & gt; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-13] (Google Inc.)
Task: {3B45A8EC-FBC7-4FBA-B7E3-8582B95B75C0} - System32\Tasks\Adobe Acrobat Update Task = & gt; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job = & gt; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job = & gt; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2014-12-11 18:17 - 2014-12-11 18:17 - 00019720 _____ () C:\Program Files (x86)\Infigo\InfigoOperator.exe
2015-06-13 16:05 - 2015-06-13 16:04 - 00246112 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe
2012-03-20 13:41 - 2015-06-16 23:26 - 00591232 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\RPAPI.dll
2012-03-20 13:41 - 2015-06-16 23:26 - 00430568 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\viprebridge.dll
2012-03-20 13:41 - 2012-03-20 13:41 - 00308560 _____ () C:\Program Files (x86)\Lavasoft\Ad-Aware\Vipre.dll
2015-06-13 16:05 - 2015-06-13 16:04 - 00011362 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\mingwm10.dll
2015-06-13 16:05 - 2015-06-13 16:04 - 00043008 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\libgcc_s_dw2-1.dll
2015-06-13 16:05 - 2015-06-13 16:04 - 02415104 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtCore4.dll
2015-06-13 16:05 - 2015-06-13 16:04 - 01148416 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtNetwork4.dll
2015-06-13 16:05 - 2015-06-13 16:04 - 00384512 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QueryStrategy.dll
2015-06-13 16:05 - 2015-06-13 16:04 - 00398336 _____ () C:\ProgramData\PLAY ONLINE\OnlineUpdate\QtXml4.dll
2014-04-18 11:19 - 2014-04-18 11:19 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\c1ef8189e658c07001049b7e7d83a2aa\IsdiInterop.ni.dll
2014-04-18 11:18 - 2012-02-01 16:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2015-06-15 08:24 - 2015-06-15 08:24 - 17321648 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_160.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The " AlternateShell " will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service = & gt; " " = " Service "
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Lavasoft Ad-Aware Service = & gt; " " = " Service "

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4006550626-1204394080-3215568820-1000\Control Panel\Desktop\\Wallpaper - & gt; C:\Users\tereska\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.100.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{8ACB9BF4-3BD0-4D67-A4FD-F217E42F1BDB}] = & gt; (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Karta tunelowania Teredo firmy Microsoft
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click " Update Driver " to update the drivers for this device.
On the " General Properties " tab of the device, click " Troubleshoot " to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/16/2015 09:50:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary avast! VM Monitor.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary aswStm.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary aswSP.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary aswSnx.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary avast! Revert.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary aswRdr.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary aswMonFlt.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary avast! VM Monitor.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary aswStm.

System Error:
Nie można odnaleźć określonego pliku.
.

Error: (06/16/2015 09:50:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.


Details:
AddLegacyDriverFiles: Unable to back up image of binary aswSP.

System Error:
Nie można odnaleźć określonego pliku.
.


System errors:
=============
Error: (06/17/2015 01:35:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi PLAY ONLINE. OUC z powodu następującego błędu:
%%1053

Error: (06/17/2015 01:35:50 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą PLAY ONLINE. OUC.

Error: (06/17/2015 00:16:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi PLAY ONLINE. OUC z powodu następującego błędu:
%%1053

Error: (06/17/2015 00:16:50 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą PLAY ONLINE. OUC.

Error: (06/17/2015 00:13:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie.

Error: (06/17/2015 00:12:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie.

Error: (06/17/2015 00:12:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa Intel(R) Rapid Storage Technology niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.

Error: (06/17/2015 00:12:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa MaintainerSvc2.49.6826863 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.

Error: (06/17/2015 00:12:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Usługa ServiceEverything niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 0 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie.

Error: (06/17/2015 00:12:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa Infigo Operator niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.


Microsoft Office:
=========================

==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU B960 @ 2.20GHz
Percentage of memory in use: 72%
Total physical RAM: 3912.36 MB
Available physical RAM: 1087.98 MB
Total Pagefile: 7822.87 MB
Available Pagefile: 4455.71 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:118.24 GB) (Free:77.19 GB) NTFS
Drive d: (Nowy) (Fixed) (Total:347.42 GB) (Free:338 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: BECE9220)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=118.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=347.4 GB) - (Type=07 NTFS)

==================== End of log ============================