OTL Extras logfile created on: 2013-09-08 20:35:13 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = d:\Users\T9\Desktop\logs 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,96 Gb Total Physical Memory | 5,66 Gb Available Physical Memory | 71,15% Memory free 9,96 Gb Paging File | 7,63 Gb Available in Paging File | 76,59% Paging File free Paging file location(s): c:\pagefile.sys 2048 4096 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 50,00 Gb Total Space | 19,54 Gb Free Space | 39,09% Space Free | Partition Type: NTFS Drive D: | 188,37 Gb Total Space | 33,68 Gb Free Space | 17,88% Space Free | Partition Type: NTFS Drive F: | 931,51 Gb Total Space | 626,10 Gb Free Space | 67,21% Space Free | Partition Type: NTFS Computer Name: T9K | User Name: T9 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = Notepad++_file] -- D:\PProgram Files\Notepad++\unicode\notepad++.exe (Don HO don.h@free.fr) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .js [@ = Notepad++_file] -- D:\PProgram Files\Notepad++\unicode\notepad++.exe (Don HO don.h@free.fr) [HKEY_USERS\S-1-5-21-3195291957-1564524796-3624665937-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- D:\PProgram Files\FirefoxPortable\App\Firefox 4 rc\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{2235E6CD-17E2-41F4-A30B-03901BF1DA45}" = lport=139 | protocol=6 | dir=in | app=system | "{48B4CED6-ECB5-4CF7-886B-C273FD5A5D8D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{5AC5D6F3-42CC-4577-BF0E-1D03E959BB56}" = rport=445 | protocol=6 | dir=out | app=system | "{6B677D5B-10DE-42DE-8253-6BCA4A1DEAE2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{71C958D0-4915-4AE5-AFF5-FD1A410A9C0E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7E99299E-8CA4-4814-ABFB-60E45EA3220D}" = lport=138 | protocol=17 | dir=in | app=system | "{7FED688E-7A0D-497E-808A-20D9320B65E1}" = rport=139 | protocol=6 | dir=out | app=system | "{89A4C603-7890-4ACE-8EDA-875247491419}" = rport=137 | protocol=17 | dir=out | app=system | "{9D730326-B6DB-488C-BF63-50820EEE97B9}" = lport=137 | protocol=17 | dir=in | app=system | "{A3C4E10D-2321-45B2-A3ED-F1F27112F74A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C91D7873-D901-4973-9658-96AC3994EFD9}" = lport=445 | protocol=6 | dir=in | app=system | "{E293563A-1485-416E-A629-0DF2F72851BF}" = rport=138 | protocol=17 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{027D07A5-0309-4C04-9336-7E7BDB2D46D9}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\shadow warrior original\bin\dosbox.exe | "{033CB0B3-302D-4A95-9C96-A266463B39FB}" = protocol=6 | dir=in | app=d:\games\diablo iii\diablo iii.exe | "{0F8065BE-A05B-47D3-9EFE-CDF8E704F56C}" = protocol=6 | dir=in | app=d:\pprogram files\wtw\wtw.exe | "{1DF1475B-C7EF-4B3F-8AF4-366790E44DAE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2560DAC0-BDCD-47A0-BD81-5F694C64E2AE}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2000\agent.exe | "{3CFFBAC4-E0F0-444A-8E50-15917C816208}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\shadow warrior original\bin\dosbox.exe | "{489347B7-2462-4E6E-8926-AB9BE5308280}" = protocol=17 | dir=in | app=d:\pprogram files\wtw\wtw.exe | "{52EB6959-A11B-4264-9322-10C8B78DAF12}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{55298104-2198-48DE-9B40-496B81ECFB89}" = protocol=17 | dir=in | app=d:\games\battle.net\battle.net.exe | "{60ABE805-7249-4997-8403-84DA19CF3242}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2096\agent.exe | "{624999F0-6936-4DDC-8C40-8858692C3BC5}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2000\agent.exe | "{70E0FAE0-1055-4444-A7CF-9321874AA55F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{74F44D0A-80B2-47FE-901B-E4430B0D678E}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\shadow warrior original\bin\launcher.exe | "{77139489-3EA5-4D0A-A0C8-15520D6A63E8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{77700BE4-D3EA-47C6-A23B-77C8BCC51450}" = protocol=17 | dir=in | app=d:\games\steam\steam.exe | "{7C83E581-7DC7-47F0-986C-324C216B9C7D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{84046F01-B047-4F18-9AEA-B54C33FBC307}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2launcher.exe | "{8E2C5E3D-2C6A-4CAC-BDF9-61D98D67D30F}" = protocol=17 | dir=in | app=d:\users\t9\appdata\roaming\dropbox\bin\dropbox.exe | "{8FE77C73-3C92-4B18-843F-94D5378D80F6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{91CF34B8-92B5-47DB-98E5-E620EF2A1E09}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2110\agent.exe | "{92C5CBB0-CF57-45EB-AF62-242F2A77397C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | "{9359514A-D8C0-466B-BA48-89CA87747798}" = protocol=17 | dir=in | app=d:\games\diablo iii\diablo iii.exe | "{9AA8AAF6-8F73-4280-B1D5-4D64F3778F7C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{A1BF1906-52DC-4B2E-B08D-95C8649B6F5F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2110\agent.exe | "{A330E501-0875-4E1C-AE5E-96C37BA57078}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{A9CD5560-4ED8-48FA-B172-FDE32FB7717C}" = protocol=6 | dir=in | app=d:\games\steam\steam.exe | "{AD3F6C29-ACFC-4BD3-9D9C-75F066F62458}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{B49FF142-D52E-4D43-A110-CD64E15D0848}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2096\agent.exe | "{B85B8731-A7B8-4281-98E2-11EE5AF7A7DA}" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2launcher.exe | "{B890FC12-0A63-4630-B11E-40F08AF8AC26}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C4194FFB-9A93-4438-BABE-213478D5A9C8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{CB0DB5C2-3EB5-4F2A-810B-08F1361C9B84}" = protocol=6 | dir=in | app=d:\users\t9\appdata\roaming\dropbox\bin\dropbox.exe | "{CDEBFCEA-FB5B-45C8-9457-B84E80204F06}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D0B53E64-8FFF-4DAC-A852-5B2840C893FC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{D0F90E25-E724-42F4-9696-461FE92AAFB2}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D3A7AD54-7378-46A2-9F19-1C3812676431}" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\shadow warrior original\bin\launcher.exe | "{DDDFB068-6A61-4A30-B1EF-ACDD765D17D3}" = protocol=6 | dir=in | app=d:\games\battle.net\battle.net.exe | "{E61353B6-E118-4AF7-A322-7A56E720C3E3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | "{F5ABCB20-C5AE-45DA-8297-065D5DA5DE7F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "TCP Query User{0BBF63E6-C331-4BFA-B961-44D963924C30}D:\games\nwo\neverwinter\live\gameclient.exe" = protocol=6 | dir=in | app=d:\games\nwo\neverwinter\live\gameclient.exe | "TCP Query User{38AAD1D2-DE73-4B19-8BE0-7B5485BB0D85}D:\users\t9\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=d:\users\t9\appdata\roaming\dropbox\bin\dropbox.exe | "TCP Query User{74DCE24B-27CA-40A4-8AE8-87FC81FCDEB9}D:\games\kraven manor\binaries\win32\udk.exe" = protocol=6 | dir=in | app=d:\games\kraven manor\binaries\win32\udk.exe | "TCP Query User{7B45E352-1205-4EAE-9A8C-8E3DB5AE0D26}D:\pprogram files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=d:\pprogram files\utorrent\utorrent.exe | "TCP Query User{8368D081-A12D-4C36-BFA5-4F79C3C457AF}C:\programdata\battle.net\agent\agent.beta.2110\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2110\agent.exe | "TCP Query User{880FA531-FB17-4B7F-BB87-F1BECDCA094C}D:\games\openra\openra.game.exe" = protocol=6 | dir=in | app=d:\games\openra\openra.game.exe | "TCP Query User{8D181713-4522-4424-B052-BFBAAAF77000}D:\pprogram files\total-cmd\totalcmd.exe" = protocol=6 | dir=in | app=d:\pprogram files\total-cmd\totalcmd.exe | "TCP Query User{B15B9A47-74FA-4568-86DA-16A007744EC0}D:\games\ddo\dndclient.exe" = protocol=6 | dir=in | app=d:\games\ddo\dndclient.exe | "TCP Query User{C31FE679-12BA-48A0-84AE-ADCB50EE501B}D:\pprogram files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=d:\pprogram files\utorrent\utorrent.exe | "TCP Query User{C55ED3B2-83BB-40A2-9AC1-7C9D219C92B9}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "TCP Query User{D2A71B89-F5AA-4F8D-9D7D-F5B94D7E1F3A}D:\games\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe" = protocol=6 | dir=in | app=d:\games\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe | "TCP Query User{E47F00EE-D1DB-4EE8-9D35-8D2457C61C29}D:\games\wiedzmin 2\bin\witcher2.exe" = protocol=6 | dir=in | app=d:\games\wiedzmin 2\bin\witcher2.exe | "UDP Query User{1BCA524B-6338-42DA-A048-58E8175E1EE2}D:\games\openra\openra.game.exe" = protocol=17 | dir=in | app=d:\games\openra\openra.game.exe | "UDP Query User{21615D78-E917-4DA5-B0BA-6AAC1EEDC6E6}D:\games\ddo\dndclient.exe" = protocol=17 | dir=in | app=d:\games\ddo\dndclient.exe | "UDP Query User{36DD98A5-6114-4F02-8161-D078730EC9BB}D:\pprogram files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=d:\pprogram files\utorrent\utorrent.exe | "UDP Query User{58CE9DF4-00F4-400F-9CAC-FC43F99E16E4}D:\users\t9\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=d:\users\t9\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{97CE3C4D-4294-44AB-AE6F-A77B96E63EC1}D:\games\nwo\neverwinter\live\gameclient.exe" = protocol=17 | dir=in | app=d:\games\nwo\neverwinter\live\gameclient.exe | "UDP Query User{9CA0B253-CD98-464D-819B-BDB1AF9C4912}D:\games\kraven manor\binaries\win32\udk.exe" = protocol=17 | dir=in | app=d:\games\kraven manor\binaries\win32\udk.exe | "UDP Query User{A246122A-226B-4D35-86B7-381D5F7E46B7}D:\games\wiedzmin 2\bin\witcher2.exe" = protocol=17 | dir=in | app=d:\games\wiedzmin 2\bin\witcher2.exe | "UDP Query User{A9A5E883-8594-428C-93C2-172E155CD820}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "UDP Query User{AAA38FBE-2418-47B8-83BC-86E3D49CD343}D:\games\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe" = protocol=17 | dir=in | app=d:\games\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2.exe | "UDP Query User{B373DAC3-8F07-4244-9A36-2167E107563E}D:\pprogram files\total-cmd\totalcmd.exe" = protocol=17 | dir=in | app=d:\pprogram files\total-cmd\totalcmd.exe | "UDP Query User{B8BB0695-6D7D-4331-B40F-30ECD1060BE7}C:\programdata\battle.net\agent\agent.beta.2110\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2110\agent.exe | "UDP Query User{D91AC24A-BD7C-442B-AEB9-93574E5B9B52}D:\pprogram files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=d:\pprogram files\utorrent\utorrent.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{26A24AE4-039D-4CA4-87B4-2F86417003FF}" = Java(TM) 7 Update 3 (64-bit) "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{55E79447-F6B0-46CB-9F58-F82DAC9C2286}" = Dell ControlVault Host Components Installer 64 bit "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{9CC89928-4787-4ED5-9942-4EBF6C2468E6}" = Dell System Manager "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Sterownik dźwięku HD 1.3.23.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "CCleaner" = CCleaner "CrystalDiskMark_is1" = CrystalDiskMark 3.0.2e "Find and Mount_is1" = Find and Mount 2.32 "HWiNFO64_is1" = HWiNFO64 Version 4.18 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "PROSet" = Intel(R) Network Connections Drivers "Puran Defrag Free Edition_is1" = Puran Defrag Free Edition 7.3 "sp6" = Logitech SetPoint 6.32 "TeamSpeak 3 Client" = TeamSpeak 3 Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07A540AB-D785-11D5-8E89-0090275862A0}" = Corel Graphics Suite 11 "{0CB3B7EE-52C7-4136-AF40-605567D90318}" = O2Micro Flash Memory Card Windows Driver "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{23EEC842-57ED-4055-A056-9D4185DFB1AA}" = Dell Mobile Broadband Manager "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 25 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6 "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "{574BF026-4487-4051-BCE5-83C4E40AAF6D}" = SlimComputer "{5A67D2EA-FB70-4033-A6F3-606AD85B2015}_is1" = Driver Sweeper wersja 3.2.0 "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{79361740-EAE3-11E2-9911-B8AC6F98CCE3}" = Google Earth Plug-in "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{87434D51-51DB-4109-B68F-A829ECDCF380}" = AccelerometerP11 "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90A4562F-D4A1-4B65-906D-41F236CF6902}" = Path of Exile "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9D583F01-A973-4B04-90BD-FB7886779090}" = Dell Wireless HSPA Mini-Card Drivers "{9E384B32-59C8-46EF-BEA6-4DC8F27CDB8E}" = InstallVC90Support "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-AA1000000001}" = Adobe Reader X (10.1.7) - Polish "{BF6379E6-9936-46B0-B6AC-C56EE3987D2E}" = inSSIDer "{C6A6036D-FBD0-4324-BEAA-C0845257160C}_is1" = BatteryCare 0.9.14.0 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS "{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}" = Wiedźmin 2 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F86B5FF0-E0C0-41AA-9FD3-5E9090FED323}" = Mumble 1.2.3 "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) OpenCL CPU Runtime "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AIMP2at" = AIMP2: Audio Tools "avast" = avast! Free Antivirus "Bandicam" = Bandicam "BandiMPEG1" = Bandisoft MPEG-1 Decoder "Battle.net" = Battle.net "bc8a6440-918f-11dd-ad8b-0800200c9a66_is1" = Dungeons & Dragons Online v01.21.01.8029 "BurnAware Free_is1" = BurnAware Free 4.8 "CrystalDiskInfo_is1" = CrystalDiskInfo 5.1.0 "Diablo III" = Diablo III "Duplicate Finder_is1" = Duplicate Finder "ENTERPRISE" = Microsoft Office Enterprise 2007 "HandBrake" = HandBrake 0.9.8 "HWiNFO32_is1" = HWiNFO32 Version 4.08 "InstallShield_{07A540AB-D785-11D5-8E89-0090275862A0}" = CorelDRAW Graphics Suite 11 "InstallShield_{0CB3B7EE-52C7-4136-AF40-605567D90318}" = O2Micro Flash Memory Card Windows Driver "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "Legend of Grimrock_is1" = Legend of Grimrock "MagicDisc 2.7.106" = MagicDisc 2.7.106 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Neverwinter" = Neverwinter "OpenAL" = OpenAL "OpenRA" = OpenRA "Origin" = Origin "RADVideo" = RAD Video Tools "rayatitray" = Ray Adams ATI Tray Tools "Redtube Video Downloader_is1" = Redtube Video Downloader 3.29 "ResourceHacker_is1" = Resource Hacker Version 3.6.0 "VLC media player" = VLC media player 2.0.0 "World of Warcraft" = World of Warcraft "XnView_is1" = XnView 1.98.6 "Xvid Video Codec 1.3.2" = Xvid Video Codec [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3195291957-1564524796-3624665937-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "101a9f93b8f0bb6f" = Curse Client - 1 "Counter-Strike 1.6: New Era" = Counter-Strike 1.6: New Era "Dropbox" = Dropbox "Mozilla Firefox 23.0.1 (x86 pl)" = Mozilla Firefox 23.0.1 (x86 pl) "Mozilla Thunderbird 17.0.8 (x86 pl)" = Mozilla Thunderbird 17.0.8 (x86 pl) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-03-04 11:55:04 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2013-03-04 11:55:04 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. Error - 2013-03-05 13:31:54 | Computer Name = T9K | Source = WinMgmt | ID = 10 Description = Error - 2013-03-05 13:35:35 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2013-03-05 13:35:35 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2013-03-05 13:35:35 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. Error - 2013-03-06 13:23:22 | Computer Name = T9K | Source = WinMgmt | ID = 10 Description = Error - 2013-03-06 13:29:32 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2013-03-06 13:29:32 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2013-03-06 13:29:32 | Computer Name = T9K | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. [ System Events ] Error - 2013-09-06 13:37:08 | Computer Name = T9K | Source = Ntfs | ID = 262199 Description = Struktura systemu plików na dysku jest uszkodzona i nie nadaje się do użytku. Uruchom narzędzie chkdsk na woluminie G:. Error - 2013-09-06 13:37:10 | Computer Name = T9K | Source = Ntfs | ID = 262199 Description = Struktura systemu plików na dysku jest uszkodzona i nie nadaje się do użytku. Uruchom narzędzie chkdsk na woluminie G:. Error - 2013-09-06 13:37:10 | Computer Name = T9K | Source = Ntfs | ID = 262199 Description = Struktura systemu plików na dysku jest uszkodzona i nie nadaje się do użytku. Uruchom narzędzie chkdsk na woluminie G:. Error - 2013-09-06 13:37:10 | Computer Name = T9K | Source = Ntfs | ID = 262199 Description = Struktura systemu plików na dysku jest uszkodzona i nie nadaje się do użytku. Uruchom narzędzie chkdsk na woluminie G:. Error - 2013-09-06 13:37:10 | Computer Name = T9K | Source = Ntfs | ID = 262199 Description = Struktura systemu plików na dysku jest uszkodzona i nie nadaje się do użytku. Uruchom narzędzie chkdsk na woluminie G:. Error - 2013-09-06 13:58:08 | Computer Name = T9K | Source = Ntfs | ID = 262199 Description = Struktura systemu plików na dysku jest uszkodzona i nie nadaje się do użytku. Uruchom narzędzie chkdsk na woluminie G:. Error - 2013-09-07 12:06:06 | Computer Name = T9K | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Hardlock z powodu następującego błędu: %%577 Error - 2013-09-07 12:07:58 | Computer Name = T9K | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Hardlock z powodu następującego błędu: %%577 Error - 2013-09-07 17:27:06 | Computer Name = T9K | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Hardlock z powodu następującego błędu: %%577 Error - 2013-09-08 13:39:42 | Computer Name = T9K | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Hardlock z powodu następującego błędu: %%577 < End of report >