OTL Extras logfile created on: 2014-09-02 12:39:59 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Differ Shop\Downloads 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.17054) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,91 Gb Total Physical Memory | 0,96 Gb Available Physical Memory | 24,54% Memory free 7,91 Gb Paging File | 2,67 Gb Available in Paging File | 33,79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 891,90 Gb Total Space | 814,13 Gb Free Space | 91,28% Space Free | Partition Type: NTFS Drive D: | 25,00 Gb Total Space | 19,19 Gb Free Space | 76,75% Space Free | Partition Type: NTFS Drive F: | 596,17 Gb Total Space | 393,74 Gb Free Space | 66,05% Space Free | Partition Type: NTFS Computer Name: LENOVO-PC | User Name: Differ Shop | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-249513183-3251645164-300344122-1002\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0514E6B8-05A4-4056-B847-F0A685C97EA2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{074266F8-6042-4068-BD4E-EE4E778E4EB8}" = lport=2869 | protocol=6 | dir=in | name=upnp tcp 2869 | "{09A015BF-223E-4CB2-8037-EAD4D740D3FC}" = lport=10243 | protocol=6 | dir=in | app=system | "{10B3C1B6-06A3-4ADB-8D2C-111D4C543332}" = lport=137 | protocol=17 | dir=in | app=system | "{1542A48D-E04C-4552-9B90-4F665EEFB529}" = rport=137 | protocol=17 | dir=out | app=system | "{3133959B-7272-4EBD-A02E-D80911ED019E}" = lport=1900 | protocol=17 | dir=in | name=upnp udp 1900 | "{347CC049-FCD9-40D5-8017-DB0577D99AD7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{348E9523-6FA1-4EB3-9F22-4E170F003425}" = lport=139 | protocol=6 | dir=in | app=system | "{47C9447E-FF02-4B10-8234-B46983495134}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5056EAA2-7817-467C-A548-8676C66B0E9C}" = lport=138 | protocol=17 | dir=in | app=system | "{58D1A18E-25D8-4BE8-A971-AD449E37A7D0}" = rport=139 | protocol=6 | dir=out | app=system | "{6B3FC156-D32C-4C4C-B7BF-D28C02F01C05}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{6C02FDD8-69AB-4A5E-B4E5-D1D07E54544C}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{72F86636-B3E6-4964-A717-A2E28D0D3B15}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7D6178B1-DE1C-4489-A0FF-11D500E3E396}" = lport=2869 | protocol=6 | dir=in | app=system | "{9FF7C9C8-4E1D-4AD1-9F24-764F0D344CC0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A1455067-DB87-4845-BB60-7E750A677813}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A1DCE56A-3554-4A7B-B12B-E25179138783}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "{B5A88F1B-B99C-48E2-BFB2-42144CD00741}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BFB8B908-3FB1-45EE-9BB1-9F5A5026E583}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D98444E8-DAFA-4060-8A29-F5CBD6D4113B}" = lport=445 | protocol=6 | dir=in | app=system | "{E2A60157-5D21-4FC7-ACBB-85C091745B8C}" = rport=10243 | protocol=6 | dir=out | app=system | "{EBFDC229-0E51-49C8-BCC6-34644E7A225C}" = rport=138 | protocol=17 | dir=out | app=system | "{FA6866E9-0B2E-4FD9-8C07-F2E94AEE8509}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FDE800CB-8E29-4321-B84A-DDC4E853B33E}" = rport=445 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{014C585C-73E5-4783-8F54-1391AF46F575}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{01D681E0-4557-4521-94E1-4FD6B3C675A6}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | "{03825D61-696A-471D-B9EA-C120A906A850}" = dir=out | name=mcafee security advisor for lenovo | "{05DEB088-1CF8-4FA6-AB4D-B7D2F88186D6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{09E7B459-81DC-475F-96EE-7F4915E29EDD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{0CF051B9-674A-40DC-851E-05E9DAF9053A}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd cinema\powerdvdcinema10.exe | "{0D6A8741-EFF6-4CBE-9007-E68868F202C7}" = dir=in | app=c:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe | "{0DAB9468-4AB4-4380-8B25-F6532D2B3607}" = dir=out | name=@{microsoft.zunemusic_1.4.18.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{0E812879-CD66-4621-AB0A-0E58FC257C2B}" = dir=out | name=@{microsoft.bingweather_2.0.0.288_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{15654F5C-8FED-48F9-8A7D-7EBEA32BE1F7}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{15B8A9DC-DBA2-4674-AA84-BACE97D4BF56}" = protocol=6 | dir=in | app=c:\program files (x86)\airfun\directconnect.exe | "{1D8BDE2F-9EAE-4E3D-B977-B3082CEFAAEA}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd10.exe | "{1DEB0F24-502A-4B66-9148-A5EBB621A9E5}" = protocol=17 | dir=in | app=c:\users\differ shop\appdata\roaming\bittorrent\bittorrent.exe | "{20852A57-9C6D-4AF7-BBF5-1377EC1C6582}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{24714CE4-7CFE-4CB8-BDD9-A6D70DD2E910}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | "{2849F8BF-BB9C-4EE5-A51E-68DFA1F61D9E}" = dir=in | app=c:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicatorcom.exe | "{2C566780-6144-4295-B3F0-8A237F5457E8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{32B230F3-89B2-4D9A-B811-D38FEB1D0134}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{33C4AA15-A35A-464D-801B-FD6BAD8C1ABA}" = dir=in | name=@{filmonlivetvfree.filmonlivetvfree_1.3.6.87_x64__zx03kxexxb716?ms-resource://filmonlivetvfree.filmonlivetvfree/resources/app-name} | "{349929CA-62ED-46D6-B1D2-BF86723ED9F9}" = dir=out | name=@{microsoft.bingtravel_2.0.0.274_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{34C8138E-A844-453D-9133-FDBB62F6D552}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{3721E866-2FC5-444C-99C8-8E91971047C2}" = dir=out | name=lenovo support | "{38DE402A-AB22-45FA-8284-B1421CF312E1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3B4474E9-E316-410E-AB6A-9B21C4AE1B0D}" = protocol=6 | dir=in | app=c:\users\differ shop\appdata\roaming\bittorrent\bittorrent.exe | "{3B84FBA3-73CB-486D-9A79-6B6EFFCDC6D2}" = dir=out | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{3D15985D-8418-4D9A-BF4E-C791FB9EA86D}" = dir=out | name=accuweather for windows 8 | "{3D8AE7CB-73A0-4AC7-895F-FE5C14F2177C}" = protocol=6 | dir=out | app=system | "{43735DD2-BA60-47BA-B8CA-8CFECE6E1668}" = protocol=17 | dir=in | app=c:\program files (x86)\airfun\directconnect.exe | "{48881328-EA98-4C2F-ACF0-53A351F82CB3}" = dir=out | name=evernote | "{492E5FD9-3829-475A-8384-4E8391B9E2BF}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{4FE7662D-6FF8-422F-AE6E-02E01375515F}" = dir=in | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{52DB9AA7-8448-40D3-B553-306497685DB9}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{571A89D4-9F74-4E7D-82CC-2F91EABB654F}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{58ACAFA0-C78A-4161-B8C5-C47A756CD869}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{593A122C-974A-44E7-A0AB-93D57463E3A2}" = dir=out | name=@{microsoft.bingfinance_2.0.0.300_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{67666A2D-0F70-4784-8A63-80C0C05CBD62}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{703FA276-12F3-4148-A59C-996626168955}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{727963BD-B3E5-42AD-8921-53B108E58E8C}" = dir=in | name=accuweather for windows 8 | "{7E2EEA99-9520-427C-BECF-D05845CF7D2B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{855024C2-FB88-4F5F-BFBD-B67FB8F10F16}" = dir=out | name=@{microsoft.zunevideo_1.4.19.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{85ED83B7-5F4F-4B4E-9577-BF008DF7C6D7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{8BF40607-644A-48EA-80C2-2AF76274E7BF}" = dir=out | name=zinio | "{922C0C75-EEED-4087-8F6F-D202A9E67ACC}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{9692CA86-6588-4DBD-98DC-FEB67DD98BBF}" = dir=out | name=@{microsoft.bingsports_2.0.0.273_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{99B56300-1893-4ECA-B2C8-48F85170FF93}" = dir=in | name=mcafee security advisor for lenovo | "{9C43E576-B124-4E1A-A418-E5585F7BCF00}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{9F1FB451-4127-409B-B48F-DB25752B911F}" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "{A5365ADA-B4A9-4FEF-8E4D-B7D98DD93C4A}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{A5DEB323-768B-409A-B68D-171E907CADEE}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{A646213A-90B8-463D-B030-DE0245472AE4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A8DC1BCF-6849-44C0-884A-69EF231D309F}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{AC8A4C8F-0C87-48F9-B244-D4B11AB7666B}" = dir=out | name=lenovo companion | "{AE6E1815-4393-4A2F-9831-6934ACF32F6C}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{AFEAF19D-C7FC-49BD-A100-CFD51C01C325}" = dir=out | name=@{microsoft.bingnews_2.0.0.273_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{B0237641-FB09-447F-91CD-75A8C1F22743}" = dir=out | name=lenovo cloud storage by sugarsync | "{B6556A4E-91EC-43FA-9944-C2F91672C138}" = dir=out | name=windows_ie_ac_001 | "{B6C48637-D00C-48BF-95E3-CE13A59DDDDB}" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "{B7415D30-C825-430D-BEB7-2096AAC3927F}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{BEA31288-9C14-4583-B62C-57248D6306EE}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{BEDEFB64-1BE7-48CD-89BF-CBD823F5A9B3}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{C4972B99-B7E8-4EBA-AD63-D714C0CA54DA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{C6D7A7A3-42E5-422D-ADF9-6E051CE7F544}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{C7060F34-73C2-4D12-828D-DC622A239696}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CA71EA86-8788-40A7-9B50-1BB4B79751FF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CD6F0A46-1624-4782-887F-68DF8C304F5E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{CDF54450-50E7-43C1-A7A8-15120B93DD92}" = dir=out | name=@{filmonlivetvfree.filmonlivetvfree_1.3.6.87_x64__zx03kxexxb716?ms-resource://filmonlivetvfree.filmonlivetvfree/resources/app-name} | "{CFECE2C4-A3EE-4AF5-B2F9-8C440F14E73D}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{D2B013DD-2DB4-4B5C-87EC-661E03058BF2}" = dir=in | app=c:\program files\hp\hp deskjet 3520 series\bin\devicesetup.exe | "{D4EE6241-7F8B-4FF4-AB49-379171610F80}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{D8299300-B84E-4A9C-8C80-297C9E0216CD}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{DCBFF378-171B-4DE2-A32C-A54B48D5E4C1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{E18CB6C0-27C7-4A65-8A26-9C17F3ADCE72}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E40FE9A0-6E74-4FA3-989D-3FE9B9EE3F8E}" = dir=out | name=@{microsoft.skypeapp_1.2.0.129_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E7D095CA-559B-42E7-8E7E-3E13A2790777}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{E83D85DB-72CC-4239-8F08-DC3C3D9E58E7}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{EC4B665B-1211-431A-B172-ED2F29F59801}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{EFF8D25A-DF74-4336-9C0E-458CE5FEBF7E}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{F0A8818F-7CDD-4E91-87DA-EA9595748E97}" = dir=in | name=evernote | "{F22F4583-17EE-435B-B325-3D8E85E33486}" = dir=out | name=powerdvd for lenovo idea | "{F2D90CD6-9768-469A-B745-3D410AFA2820}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{F2F311FF-E29B-4184-B01A-6FF9C663D598}" = dir=in | name=@{microsoft.skypeapp_1.2.0.129_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{FC24691A-3868-4907-B28B-9042DE83576C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{6EFD4901-BB93-4991-AE75-72AECF5ACA5D}C:\program files (x86)\viewsonic\wpg-370\wpg-370.exe" = protocol=6 | dir=in | app=c:\program files (x86)\viewsonic\wpg-370\wpg-370.exe | "UDP Query User{3B96E0E4-EDFE-4A41-AB88-421189065813}C:\program files (x86)\viewsonic\wpg-370\wpg-370.exe" = protocol=17 | dir=in | app=c:\program files (x86)\viewsonic\wpg-370\wpg-370.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01078B88-2981-4F75-96B0-8B22E2D2DE03}" = Microsoft SQL Server 2008 R2 Setup (English) "{1334eac7-d6ef-4177-8780-05c963853cd3}" = Intel(R) PRO/Wireless Driver "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{234F6B0D-10AE-4BB7-B2F3-E48D4861952D}" = SQL Server 2008 R2 SP1 Common Files "{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}" = Microsoft SQL Server VSS Writer "{2AF6DE35-EF82-42D5-86CA-9DE53EA29318}" = HP Deskjet 3520 series — podstawowe oprogramowanie urządzenia "{302600C1-6BDF-4FD1-1306-148929CC1385}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{36F70DEE-1EBF-4707-AFA2-E035EEAEBAA1}" = SQL Server 2008 R2 SP1 Common Files "{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology "{44B72151-611E-429D-9765-9BA093D7E48A}" = Intel® Trusted Connect Service Client "{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{8909B8A7-CEAB-4772-BF29-1892C4E6603B}" = Microsoft SQL Server 2005 Backward compatibility "{8B11A672-F039-4B14-867C-3F0209ADC85A}" = Intel(R) Rapid Storage Technology "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver "{A2122A9C-A699-4365-ADF8-68FEAC125D61}" = SQL Server 2008 R2 SP1 Database Engine Shared "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 312.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 312.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.6.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 8.3.14 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.13.0725 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 8.3.14 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files "{C942A025-A840-4BF2-8987-849C0DD44574}" = SQL Server 2008 R2 SP1 Database Engine Shared "{D61F48DA-627B-404E-9315-32A651B18B64}" = Intel® PROSet/Wireless WiFi Software "{D8C23BDE-4748-44D9-A9DD-8AB64EB18BE3}" = Microsoft SQL Server 2008 R2 RsFx Driver "{E8F7904A-4780-4F3F-B153-21BE32857120}" = Microsoft SQL Server 2008 R2 Native Client "{EF04170D-0CE0-40E7-9F25-3A2BA2425C6E}" = HP Deskjet 3520 series — badanie mające na celu poprawę produktów "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64 "{F31183CF-E10F-4DE1-BB59-6C0FF38E481E}" = Sql Server Customer Experience Improvement Program "{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = SQL Server 2008 R2 SP1 Database Engine Services "{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = SQL Server 2008 R2 SP1 Database Engine Services "35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E" = Pakiet sterowników systemu Windows - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) "8A223E56FB1ED4F697B54E5BF96F1EB63B512684" = Pakiet sterowników systemu Windows - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) "Lenovo VeriFace" = Lenovo VeriFace "McAfee Security Scan" = McAfee Security Scan Plus "Microsoft SQL Server 10" = Microsoft SQL Server 2008 R2 (64-bit) "Microsoft SQL Server 2008 R2" = Microsoft SQL Server 2008 R2 (64-bit) "PDF-XChange 3_is1" = PDF-XChange 3 "WinRAR archiver" = WinRAR 5.10 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0ADC3B5A-E0EA-460A-ADEB-3EE2D27BE480}" = InsERT GT 1.34 SP3 "{133236FE-E2F7-4313-8BF8-A10ACAAA7CB9}" = Citrix online plug-in (USB) "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2EF2A21E-50C0-42F8-8029-66E2EF4DFCBA}" = Airfun "{2FC7287D-39DD-4A84-9806-D27D3CCDC51B}" = Citrix online plug-in (Web) "{3611CA6C-5FCA-4900-A329-6A118123CCFC}" = Bing Bar "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{4112625F-2D38-49EF-924F-48511BC5CD34}" = SQL Server 2008 R2 SP2 Database Engine Services "{4C9D82EB-9001-4E59-8F64-0BEEE5F4A30A}" = SQL Server 2008 R2 SP2 Database Engine Shared "{57287FDF-27E6-45BC-9DD2-A33545C46C1A}" = Citrix online plug-in (HDX) "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 "{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}" = HP Update "{6F2FDD50-E0F3-4117-B575-78E77F8D11EF}" = Citrix online plug-in (DV) "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6 "{77D28FF5-242F-488A-8215-937D6A4D69E0}" = Adobe AIR "{7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}" = NVIDIA PhysX "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010 "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{90150000-0138-0409-0000-0000000FF1CE}" = Microsoft Office "{913E2B02-1BA9-4B38-991B-31C717F9D00C}" = e-Deklaracje Desktop "{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}" = Onekey Theater "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{93998800-1608-403F-9A51-420A77D23C25}" = Sql Server Customer Experience Improvement Program "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent "{A79F748E-F89C-4E21-B767-F485D14373E0}" = Komponent Graficznej Wizualizacji 2014 "{A7DACFF9-9F24-4EFF-BE17-B0EC01B0D1C0}" = Microsoft SQL Server 2008 R2 RsFx Driver "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC768037-7079-4658-AC24-2897650E0ABE}" = Energy Manager "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.08) - Polish "{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}" = Lenovo EasyCamera "{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}" = HP Deskjet 3520 series Setup Guide "{B15746C1-344B-40F8-A54E-85AD2AD8E81E}" = HP Deskjet 3520 series Pomoc "{B26438B4-BF51-49C3-9567-7F14A5E40CB9}" = Dolby Home Theater v4 "{B8E9F8A1-9F4D-43D5-ABD6-1DF067FAA469}" = SQL Server 2008 R2 SP2 Database Engine Services "{BF9BF038-FE03-429D-9B26-2FA0FD756052}" = Microsoft SQL Server Browser "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6 "{c9967fbd-e3c3-4ed0-992a-5b33260f2944}" = Oprogramowanie Intel® PROSet/Wireless "{CACEA8C8-3D38-4F51-953D-1E6FC3346FEF}" = SQL Server 2008 R2 SP2 Common Files "{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files "{DAB2D121-A8A3-4E92-A7E5-4319F928735F}" = Microsoft SQL Server 2008 R2 Setup (English) "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = Lenovo PowerDVD10 "{E5CCEA56-DC84-440E-8785-D5A7A6B7FB39}" = Sterowniki firmy InsERT 5.12 "{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 "{F021CC0C-21C3-4038-AA4A-6E3CBC669CE8}" = SQL Server 2008 R2 SP2 Database Engine Shared "{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = Podręcznik użytkownika "{F0A8BF4A-972F-41E0-9800-1EFE3BF28266}" = Realtek Card Reader "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{FC47C7A5-BE63-11D5-B7C9-005004566E4D}" = ViewSonic Windows 8 64bit Signed Files "{FC835376-FF3B-4CAA-83E0-2148B3FB7C98}" = SQL Server 2008 R2 SP2 Common Files "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "1ClickDownload" = TornTV "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin "AnyProtect" = AnyProtect "Avast" = avast! Free Antivirus "CitrixOnlinePluginPackWeb" = Citrix online plug-in - web "e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1" = e-Deklaracje Desktop "Google Chrome" = Google Chrome "HP Photo Creations" = HP Photo Creations "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}" = Energy Manager "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = Lenovo PowerDVD10 "InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide "Intel AppUp(SM) center 33057" = Intel AppUp(SM) center "IrfanView" = IrfanView (remove only) "Microsoft SQL Server 10" = Microsoft SQL Server 2008 R2 "Microsoft SQL Server 2008 R2" = Microsoft SQL Server 2008 R2 "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "SugarSync" = SugarSync Manager "TeamViewer 9" = TeamViewer 9 "VOPackage" = Remote Desktop Access (VuuPC) "webssearches uninstall" = webssearches uninstall "Winamp" = Winamp "WindowsMangerProtect" = WindowsMangerProtect20.0.0.722 "WPG-370_is1" = WPG-370 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-249513183-3251645164-300344122-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "BitTorrent" = BitTorrent "Dropbox" = Dropbox [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-08-21 13:11:44 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error - 2014-08-22 05:07:39 | Computer Name = Lenovo-PC | Source = MsiInstaller | ID = 1024 Description = Error - 2014-08-22 05:08:47 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2014-08-22 05:08:47 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2014-08-22 05:08:47 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error - 2014-08-22 10:03:56 | Computer Name = Lenovo-PC | Source = Perflib | ID = 1023 Description = Error - 2014-08-22 10:03:56 | Computer Name = Lenovo-PC | Source = Perflib | ID = 1008 Description = Error - 2014-08-22 10:03:56 | Computer Name = Lenovo-PC | Source = Perflib | ID = 1023 Description = Error - 2014-08-22 10:03:56 | Computer Name = Lenovo-PC | Source = Perflib | ID = 1008 Description = Error - 2014-08-23 05:12:25 | Computer Name = Lenovo-PC | Source = MsiInstaller | ID = 1024 Description = [ System Events ] Error - 2014-07-29 06:24:45 | Computer Name = Lenovo-PC | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 12:20:34 na ?2014-?07-?29 było nieoczekiwane. Error - 2014-07-29 06:24:37 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 2014-07-30 04:40:07 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-Kernel-Boot | ID = 29 Description = Error - 2014-07-30 04:40:13 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 2014-07-30 04:40:25 | Computer Name = Lenovo-PC | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 18:24:45 na ?2014-?07-?29 było nieoczekiwane. Error - 2014-08-02 04:48:25 | Computer Name = Lenovo-PC | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 18:41:51 na ?2014-?08-?01 było nieoczekiwane. Error - 2014-08-02 04:48:16 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 2014-08-04 04:54:38 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-Kernel-Boot | ID = 29 Description = Error - 2014-08-04 04:54:46 | Computer Name = Lenovo-PC | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 2014-08-04 04:54:52 | Computer Name = Lenovo-PC | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 15:28:25 na ?2014-?08-?02 było nieoczekiwane. < End of report >