OTL Extras logfile created on: 2013-09-22 16:19:29 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Downloads 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16686) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,91 Gb Total Physical Memory | 2,54 Gb Available Physical Memory | 65,00% Memory free 7,83 Gb Paging File | 6,37 Gb Available in Paging File | 81,38% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 148,95 Gb Total Space | 6,82 Gb Free Space | 4,58% Space Free | Partition Type: NTFS Drive E: | 24,41 Gb Total Space | 20,72 Gb Free Space | 84,88% Space Free | Partition Type: NTFS Drive F: | 24,41 Gb Total Space | 1,23 Gb Free Space | 5,05% Space Free | Partition Type: NTFS Drive G: | 62,95 Gb Total Space | 32,94 Gb Free Space | 52,32% Space Free | Partition Type: NTFS Drive H: | 74,52 Gb Total Space | 6,25 Gb Free Space | 8,39% Space Free | Partition Type: NTFS Computer Name: TATA | User Name: admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software) [HKEY_USERS\S-1-5-21-4235837014-142630012-1256447241-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software) https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software) https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{130192E1-1155-4A4F-9397-4BEF19F10D83}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "{23B382CC-43F4-4D95-AA33-918BE80BA62F}" = rport=139 | protocol=6 | dir=out | app=system | "{37C20987-934F-41D2-AB9C-31D85CA293E6}" = rport=137 | protocol=17 | dir=out | app=system | "{5DB782ED-1A22-4D94-942B-BE80C2159EB8}" = lport=139 | protocol=6 | dir=in | app=system | "{71C8A608-B6F1-438A-823C-4144DB705E47}" = rport=138 | protocol=17 | dir=out | app=system | "{73F4F8EB-CFEE-4E03-B957-FAF7049251F9}" = lport=445 | protocol=6 | dir=in | app=system | "{7945920D-16C4-4655-9E99-75E8B3FC7AE0}" = lport=138 | protocol=17 | dir=in | app=system | "{BD0AAF68-3F94-49D6-BDFC-CA49D29EBE2D}" = lport=137 | protocol=17 | dir=in | app=system | "{CA3898D6-240C-4DCC-AE32-81BF0F50AABC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{CDD3EB0B-26A0-4F6C-8A47-FC9FE7C66312}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{EC124C2D-57E5-45CB-9170-3612B0AC347E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{FAA19E30-89F9-4E0F-B5D1-DB3DF4816978}" = rport=445 | protocol=6 | dir=out | app=system | "{FDAF4725-9913-46C3-80CE-E2E00D9A02F6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0EEF084E-9B19-4CDE-9CE2-78B102DFEEE2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{2A8CE4E7-295C-4B21-92F0-B498F5D33158}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{2C2B26D3-4CE7-475C-A9A5-EEABC0AEF896}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe | "{3C9DF611-562A-4103-BF37-C53E06908776}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{3DAFA327-9CA1-4C1B-8D87-711BFFAF9D26}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{4B8DED7F-2224-4AFE-8139-7DF708314045}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{4F09E455-46C6-401D-904E-1868BD216AC0}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{57D635E3-E58A-42A3-B6E8-9D343ABB35DF}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe | "{6174EB89-BE4D-44F5-B246-3B28B4408871}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{92BF3682-7966-46CA-AE1C-5488B2761669}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{97DF159F-4AB3-48D4-9EE1-436084D9E80C}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{B1C8D1D9-9597-452E-A7CB-D9766D0C3CD3}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe | "{B2743D96-C19A-4000-9ABA-2FE3A4D127B7}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe | "{B94E7E3B-1E1E-4383-8040-0C9488ABC03E}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{BEEC9550-63BC-4943-B5AF-9536A60FD3F9}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe | "{CA80EDBB-CF65-475E-B187-20CF59E7FBE0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{E2751329-A5A3-4A27-8F8F-BF3483CE738B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{F37A753A-2F20-40D0-8826-27C737943835}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe | "{F95CEA05-33A3-41C0-BB7B-7CD1118039C0}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | "TCP Query User{B79C26A2-D5FA-4AF6-8F55-0DF184DB0579}C:\users\admin\appdata\local\temp\7abb.tmp\kmservice.exe" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\temp\7abb.tmp\kmservice.exe | "UDP Query User{F2F0A28F-C8BD-4862-8B98-CE34D9CEC8BA}C:\users\admin\appdata\local\temp\7abb.tmp\kmservice.exe" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\temp\7abb.tmp\kmservice.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC3 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2010 "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "WinRAR archiver" = WinRAR 4.11 (64-bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = BitGuard "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver "{3C2379D2-337A-4FFA-9017-BDFB80EC0931}" = OSCAR Editor "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "{847CAE64-4CD2-4B2D-AF00-978FF5431045}" = Nero 7 Ultra Edition "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0015-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0016-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0018-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-0019-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001A-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001B-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-001F-0415-0000-0000000FF1CE}_Office14.PROPLUS_{1D751709-BA6C-49E2-844B-4F4F20F410C9}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0415-1000-0000000FF1CE}_Office14.PROPLUS_{0844B6E1-0A6F-4D81-8BCF-48F883F521FE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-002C-0415-0000-0000000FF1CE}_Office14.PROPLUS_{6606F321-8216-466E-981E-B75A14C46894}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-0044-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-006E-0415-0000-0000000FF1CE}_Office14.PROPLUS_{6AF8887A-72F7-4FA0-ABE4-396172B64550}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00A1-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{90140000-00BA-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "delta" = Delta toolbar "Delta Chrome Toolbar" = Delta Chrome Toolbar "DivX Setup" = DivX Setup "EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 9.1.1 Home Edition "Exact Audio Copy" = Exact Audio Copy 1.0beta3 "Foxit Reader_is1" = Foxit Reader "Google Chrome" = Google Chrome "HD Tach_is1" = HD Tach version 3 "InstallShield_{3C2379D2-337A-4FFA-9017-BDFB80EC0931}" = X7 Oscar Editor "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.2.0 "MediaCoder" = MediaCoder 0.6.1 "MKVToolNix" = MKVToolNix 5.7.0 "Mozilla Firefox 24.0 (x86 pl)" = Mozilla Firefox 24.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "OCCT" = OCCT 4.2.0 "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "Opera 16.0.1196.73" = Opera Stable 16.0.1196.73 "RegClean Pro_is1" = RegClean Pro "SoftwareUpdUtility" = Download Updater (AOL LLC) "Super Kulki_is1" = Super Kulki "The KMPlayer" = The KMPlayer (remove only) "UltraISO_is1" = UltraISO Premium V9.52 "uTorrent" = µTorrent "Winamp" = Winamp [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-4235837014-142630012-1256447241-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{79A765E1-C399-405B-85AF-466F52E918B0}" = Foxit PDF Creator Toolbar Updater "{C92C584E-C781-475E-A8E2-C67D993A6B95}" = WinFast PVR2 "GG" = GG "Mozilla Firefox Packages" = Mozilla Firefox Packages "Opera Packages" = Opera Packages [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-09-18 02:54:00 | Computer Name = tata | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: AudioDriver.exe, wersja: 3.3.8.1, sygnatura czasowa: 0x4f25baec Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18229, sygnatura czasowa: 0x51fb1072 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000528db Identyfikator procesu powodującego błąd: 0xab0 Godzina uruchomienia aplikacji powodującej błąd: 0x01ceb43bd93d084a Ścieżka aplikacji powodującej błąd: C:\Users\admin\AppData\Roaming\AudioDriver.exe Ścieżka modułu powodującego błąd: C:\Windows\SysWOW64\ntdll.dll Identyfikator raportu: 18321110-202f-11e3-84ee-5404a6a21426 Error - 2013-09-18 02:54:00 | Computer Name = tata | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: MSUpdate.exe, wersja: 3.3.8.1, sygnatura czasowa: 0x4f25baec Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18229, sygnatura czasowa: 0x51fb1072 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000528db Identyfikator procesu powodującego błąd: 0xaa0 Godzina uruchomienia aplikacji powodującej błąd: 0x01ceb43bd93382c9 Ścieżka aplikacji powodującej błąd: C:\Users\admin\AppData\Roaming\MSUpdate.exe Ścieżka modułu powodującego błąd: C:\Windows\SysWOW64\ntdll.dll Identyfikator raportu: 18323820-202f-11e3-84ee-5404a6a21426 Error - 2013-09-18 02:55:05 | Computer Name = tata | Source = WinMgmt | ID = 10 Description = Error - 2013-09-18 09:07:23 | Computer Name = tata | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: AudioDriver.exe, wersja: 3.3.8.1, sygnatura czasowa: 0x4f25baec Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18229, sygnatura czasowa: 0x51fb1072 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000528db Identyfikator procesu powodującego błąd: 0xa30 Godzina uruchomienia aplikacji powodującej błąd: 0x01ceb47002ea8923 Ścieżka aplikacji powodującej błąd: C:\Users\admin\AppData\Roaming\AudioDriver.exe Ścieżka modułu powodującego błąd: C:\Windows\SysWOW64\ntdll.dll Identyfikator raportu: 41b8c075-2063-11e3-b7d6-5404a6a21426 Error - 2013-09-18 09:07:23 | Computer Name = tata | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: MSUpdate.exe, wersja: 3.3.8.1, sygnatura czasowa: 0x4f25baec Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18229, sygnatura czasowa: 0x51fb1072 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000528db Identyfikator procesu powodującego błąd: 0xa24 Godzina uruchomienia aplikacji powodującej błąd: 0x01ceb47002e36502 Ścieżka aplikacji powodującej błąd: C:\Users\admin\AppData\Roaming\MSUpdate.exe Ścieżka modułu powodującego błąd: C:\Windows\SysWOW64\ntdll.dll Identyfikator raportu: 41bedaf5-2063-11e3-b7d6-5404a6a21426 Error - 2013-09-18 09:08:32 | Computer Name = tata | Source = WinMgmt | ID = 10 Description = Error - 2013-09-19 02:06:12 | Computer Name = tata | Source = WinMgmt | ID = 10 Description = Error - 2013-09-19 12:32:44 | Computer Name = tata | Source = WinMgmt | ID = 10 Description = Error - 2013-09-19 13:13:50 | Computer Name = tata | Source = WinMgmt | ID = 10 Description = Error - 2013-09-22 08:40:28 | Computer Name = tata | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2013-09-18 02:48:51 | Computer Name = tata | Source = DCOM | ID = 10005 Description = Error - 2013-09-18 02:48:51 | Computer Name = tata | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2013-09-18 02:48:51 | Computer Name = tata | Source = DCOM | ID = 10005 Description = Error - 2013-09-18 02:48:52 | Computer Name = tata | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2013-09-18 02:48:52 | Computer Name = tata | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2013-09-18 02:48:52 | Computer Name = tata | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2013-09-18 02:48:52 | Computer Name = tata | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2013-09-18 02:48:52 | Computer Name = tata | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2013-09-18 02:48:52 | Computer Name = tata | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2013-09-18 03:55:45 | Computer Name = tata | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. < End of report >