OTL Extras logfile created on: 2014-10-02 20:16:23 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\mrukk\Downloads 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.17088) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,89 Gb Total Physical Memory | 2,16 Gb Available Physical Memory | 55,41% Memory free 4,58 Gb Paging File | 2,72 Gb Available in Paging File | 59,38% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 449,75 Gb Total Space | 410,06 Gb Free Space | 91,18% Space Free | Partition Type: NTFS Computer Name: MRUKKK | User Name: mrukk | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2253055635-1566063098-3438977135-1001\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{09F60703-3507-4182-B609-37D8E4EBD105}" = lport=139 | protocol=6 | dir=in | app=system | "{0B0092C1-0663-402E-B7A2-575EEC33E92E}" = lport=137 | protocol=17 | dir=in | app=system | "{1BC7A631-A27F-4A76-A092-E7ACEBFAE2AC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{21343325-6A3D-4197-9C3D-EED2E713240B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{21888867-56F6-4B75-985F-7EBE515F2EFA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{22A1C7FE-A254-4100-9C97-60172B6FB82F}" = rport=445 | protocol=6 | dir=out | app=system | "{282654B0-D0BC-4C30-BE4B-8EDC987E9917}" = rport=138 | protocol=17 | dir=out | app=system | "{573DA205-9575-4C7F-B641-E200F398CAFB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5F6C4936-35E7-4EC9-80B3-03F6A888EE1C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{63225A66-765B-4CCB-925D-13DA148C1E35}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{78F9ACBE-B18B-41DA-B760-E2327D2209EF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7A41B56F-2323-4EA6-BA71-39C6637119E2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{826ECC2A-2192-4026-94AC-2CBDFB104144}" = lport=138 | protocol=17 | dir=in | app=system | "{989DCCC2-9DE0-456C-A0FD-D82BBE62A2EC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A0B931AB-D501-4FC7-B2D2-02E1ECCEF1CA}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{BAF1F5FF-A994-4BA6-9CF9-044C43B6DFD0}" = lport=2869 | protocol=6 | dir=in | app=system | "{C5DDA580-A4BB-4F63-A118-ADA72D75750D}" = lport=10243 | protocol=6 | dir=in | app=system | "{C6563118-7430-416D-9A47-7DCC9F2CC924}" = lport=445 | protocol=6 | dir=in | app=system | "{CB5A91B2-EA7D-4164-ABA3-718E7E13DBFB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F6CFD6D9-24C2-49A7-9569-6C2FF4A921DB}" = rport=137 | protocol=17 | dir=out | app=system | "{F6F73CE8-0FD9-44C1-988C-8A40916C669E}" = rport=10243 | protocol=6 | dir=out | app=system | "{FA87F521-90E4-4D4B-AE45-866BA4B27AE9}" = rport=139 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01D4C426-098F-472D-943A-24A08DA96C13}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{03B1CC8E-3E95-4BDB-99C2-2B8F529B6590}" = dir=out | name=@{microsoft.bingsports_2.0.0.273_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{0889EC48-6CC5-4EC2-9653-BDA9AFBFADDF}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{08BE1B98-554E-40BA-833E-D27F36C2C738}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{098732C7-4589-4E49-9A27-8BDF54D52067}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{0E214E40-BD7C-4156-9D8B-FEE79EBE8E77}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{0ED3A95B-C506-44A2-B11C-ECDAF6C13185}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{0F178FF8-857C-494D-893F-721F73A51FA3}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe | "{13A6226D-0E43-40D9-B4A6-CBA1E8057BFB}" = dir=out | name=@{microsoft.bingtravel_2.0.0.274_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{15B24A67-1AC6-45BB-A9A3-2473E3CF3E3A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{15BE254D-A58F-4C6A-9CF7-5CCEE466E642}" = protocol=17 | dir=in | app=c:\program files (x86)\nero\nero 12\nero backitup\backitup.exe | "{179371CD-879C-431B-9CC1-E84CA5A31849}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{18A0B747-6529-473F-8807-F87C1E79185F}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{1B446539-D7CD-4BF9-8AB7-05912CE06F40}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{1DCB3017-1C5F-4A77-9CCB-13D5ADD4B301}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{200C7182-0210-49B1-8D82-7806FCE81D7A}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{23ECA3E6-B3D6-4436-A331-0792AC1EEB93}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{24341C86-E6D7-4D29-B9B7-E59DC861FD07}" = dir=in | name=newsxpresso | "{2C525AB9-0DD1-47F5-9F8B-B7E991F9D99D}" = dir=in | name=acer explorer | "{2E880D53-D676-4EFA-A535-17DB5E48A149}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{3105EC4D-3AFC-4072-9F60-1819DD81E7FF}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\sdd.exe | "{33596A9F-598F-461E-B1D4-6F4119DA35D0}" = dir=in | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{341314DD-31CB-4A0E-8E21-6CFBE88B526A}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | "{3454E14A-2906-49BE-9D47-9DA0378AE18E}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\musicplayer.exe | "{363DD66A-7D3C-4EF4-A3FC-F9753DDD7C0E}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe | "{3D31A268-05C6-405E-9673-B2400618BEB8}" = dir=out | name=@{microsoft.bingnews_2.0.0.273_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{4B8209B7-41AE-46A7-B796-FF8D3CE46A5B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{4CE4D798-3AA0-4441-9B12-E0B4C0723AEC}" = dir=out | name=newsxpresso | "{5170C99E-BA09-46D5-AB7B-2981A475C6BE}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{519B4114-0B7E-4062-8623-BAC081200D05}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{51B84BA7-B875-42F9-96C8-D2A7A019BB3F}" = dir=out | name=weatherbug.a | "{56DDC128-C8AD-4909-8CB2-1EF1616AA044}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | "{59296332-1882-4666-AA99-D769613EF498}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | "{5D8AAACE-BDA0-457A-B638-61BE54DAEDF5}" = dir=out | name=skype | "{5E4D80A2-A372-4AB7-94B8-8A1749D8E984}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | "{5F0FCFBA-ED04-4A58-9594-5B5C160E17F7}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | "{5F7EE6DB-C9DB-4782-A9D5-CB145C4D8B30}" = dir=out | name=@{microsoft.zunemusic_1.4.18.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{60C6603F-C17F-4F6D-9316-9C1CBC2EB48D}" = dir=out | name=music maker jam | "{64524146-1065-4DC0-946F-11CF1FA0B4D8}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{6991A393-D9CB-467B-BAFA-7C2E728AB10B}" = dir=out | name=@{microsoft.bingweather_2.0.0.288_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{6C5F60D9-E45A-4423-A889-B0A82FD91CE2}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{6F1A54B1-D501-48C8-B3AE-C6FBFC1FC1F1}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{752D65A5-C6FB-469E-BE15-81EB18F64DA6}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{76541977-33BD-4AE4-830B-84573811A02D}" = dir=out | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{76AF9892-D99F-43F3-943B-C41BEC30EC40}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{7B574C87-B9E0-452D-8158-0505DC5A0CB8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{7E18503E-8119-47ED-A96A-A421E5DD8EE7}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\sdd.exe | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{84DC23FF-D863-4CA6-B271-138894FC9F65}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{8AA7BAC0-0C74-4DD8-8076-1451050E853E}" = protocol=6 | dir=out | app=system | "{8BF098F4-795E-46C2-977D-2B0C806ECF1F}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\virtualdrive.exe | "{8F196697-13A7-488D-8AF0-64A05856D275}" = dir=out | name=@{microsoft.zunevideo_1.4.19.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{8F660FF3-62EA-40BA-A589-A40F21431293}" = dir=out | name=zinio | "{91AAE7DE-8B2F-4A44-8AFC-2F9DC65D1559}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{91D8C7CC-EED4-450B-90D7-8613222252E1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{94FA4BD6-90CD-41BD-B0E0-08A2D7D34987}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{9B261764-BF23-4D6B-B205-8ACB64043BEC}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | "{9CE8E529-DE19-4744-80B3-7901BB68222A}" = dir=out | name=ebay | "{9DBC71AE-1CDE-4365-A746-21E5B3D50B12}" = dir=out | name=windows_ie_ac_001 | "{9FCA252C-3687-41EA-ACCF-4A0682927E0D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A172DEFD-5FEF-473A-8AFC-DE008CD71452}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A3A58309-063D-4CBA-85DB-CD257376C1D6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{A89B483D-3899-49D7-8461-EB8CC7AB9A90}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\videoplayer.exe | "{A8B98594-519A-4112-A279-E30B52271C95}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | "{AA12141B-4867-4D92-A90F-84DB7341C7ED}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{AEA759AD-FAFC-45AD-BF95-42AA7A36B351}" = protocol=6 | dir=in | app=c:\program files (x86)\nero\nero 12\nero backitup\backitup.exe | "{B1AF4E0D-36C2-4678-996C-BEE1B04F2FE0}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B5968567-2C63-4020-BD06-D6928B006407}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | "{B71C2386-C639-480A-9CB6-DA0585260BAB}" = dir=out | name=the treasures of montezuma 3 | "{BF407620-A475-4CB7-8E6C-44FE887041E5}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{C06257E9-EF4E-4148-8B63-10F9665C0558}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C06591E7-286D-4AE8-AFA4-F6DC7A72702F}" = dir=out | name=tunein radio | "{C45E2603-235F-4AC9-8F96-7B76F0403961}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{C5E91022-D3F8-45B3-A007-1F095BBF2BC6}" = dir=out | name=cut the rope | "{C886F5C6-5F3B-478A-A3C2-3709A30E8C41}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{C9DE6CE8-4C99-41E4-A6B1-5F0324F81C98}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\movie\playmovie.exe | "{CE393ECC-EA82-4105-98E7-F247366B96C4}" = dir=in | name=skype | "{D00EF8C0-8287-4D47-A8F3-E2C44223E5F0}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{D0E7AD84-28B0-4295-AB79-1B75265F2551}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | "{D19AFB39-2FAC-45BD-A8B5-8CB243470C21}" = dir=out | name=7digital music store | "{D4861BBE-E5EB-4BC5-9733-6D3BF93E43F2}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D565CF21-B4EA-4B0F-A281-4DC1CD31A385}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D7F1B627-A648-4CEA-B2FC-9BE7B2C443AE}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{DA90F5AB-8FC4-456D-99A6-03BB012F153E}" = dir=out | name=@{microsoft.bingfinance_2.0.0.300_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{DBA614B4-4405-44CA-89A4-196DC3FD0FFE}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{DBD78EEE-0F9F-43AB-819B-1BB77944A863}" = dir=out | name=kindle | "{E29DE1F4-1C5A-40BF-8D55-4F03ABDB839E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{E376A34B-9540-4BDC-9F84-F929120C0E03}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{E42CB49A-9DE3-41E3-8C51-E973F0731D18}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\virtualdrive.exe | "{E6647F73-37EE-46D7-8012-87D98364210D}" = dir=out | name=acer explorer | "{E6FB01D2-21FB-4BF3-806F-E42A7E279C04}" = dir=out | name=- games app - | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EB18765A-60FE-4ADD-AD07-E04355C037DA}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | "{EEA056AB-47B4-435F-AB9A-0825E4DD8701}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{EF82C375-09D0-4545-90AF-BEFB8BC44337}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | "{F2768E8C-78FD-4E5B-B760-22DA43F51886}" = dir=in | name=ebay | "{F2A6B9A8-EFB8-4AFC-B258-F4F8228463EE}" = dir=in | name=music maker jam | "{FFDA589D-FC19-4FBE-863E-96736EDCFB72}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FFFF5050-0BBC-465A-92C6-E933B7641903}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}" = Acer Recovery Management "{1415243E-E8F2-4260-8779-5B136C06BF8F}" = HP Deskjet Ink Advant K209a-z All-in-One Driver Software 14.0 Rel. 6 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}" = Acer Device Fast-lane "{67AA948F-8D83-4566-B84A-7CAABCF64E3F}" = Broadcom Card Reader Driver Installer "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{91F52DE4-B789-42B0-9311-A349F10E5479}" = Acer Power Management "{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64) "{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}" = Acer Launch Manager "{D1D7ED66-5C08-40A0-AEC0-B6DF977697BB}" = Broadcom NetLink Controller "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64 "{FA00A3CC-7440-4938-A271-F186F50DD40D}" = Intel® Trusted Connect Service Client "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "Elantech" = ETDWare PS/2-X64 11.6.23.203_WHQL "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "Shop for HP Supplies" = Shop for HP Supplies [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{0B311221-05A5-4766-8D03-7A6446794156}" = Nero RescueAgent Help (CHM) "{0E4630AF-0AB7-440E-A978-1A78FC4F43B9}" = Nero Launcher "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{16F96835-25C8-4C13-981D-55A966371619}" = DJ_AIO_06_K209a-z_SW_Min "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FCC073B-CC01-4443-AD20-E559F66E6E83}" = Office Addin 2003 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros WLAN and Bluetooth Client Installation Program "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}" = clear.fi SDK- Movie 2 "{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor "{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime "{3AAB08A3-F129-4BD5-B409-AE674F93759D}" = Prerequisite installer "{3CBE5580-B65E-48B0-B296-C0CB3A841351}" = K209a-z "{3D9CB654-99AD-4301-89C6-0D12A790767C}" = Identity Card "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{4CA8F973-6377-4ABF-9ED5-CC2323B3C000}" = Nero BackItUp 12 Essentials OEM.a01 "{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update "{6D2BBE1D-E600-4695-BA37-0B0E605542CC}" = Office Addin "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime "{90150000-0138-0409-0000-0000000FF1CE}" = Microsoft Office "{912D30CF-F39E-4B31-AD9A-123C6B794EE2}" = HP Update "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy "{A2D43081-CF7B-4637-A9F3-E2651AA5C4A8}" = Nero RescueAgent "{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}" = AcerCloud Portal "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{ABC88553-8770-4B97-B43E-5A90647A5B63}" = Nero ControlCenter "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{B5AD89F2-03D3-4206-8487-018298007DD0}" = clear.fi Photo "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components "{C994C746-C6D0-4EBA-B09E-DF7B18381B69}" = Nero ControlCenter Help (CHM) "{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}" = AcerCloud Docs "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch "{DA2D3078-A58C-45E8-8EE0-18B8BE6B34F7}" = Nero BackItUp "{E9AF1707-3F3A-49E2-8345-4F2D629D0876}" = clear.fi Media "{EBA33CAD-E071-48d5-A168-FBA4EEB42E93}" = clear.fi SDK - Video 2 "{EE26E302-876A-48D9-9058-3129E5B99999}" = Live Updater "{EF0D1292-8FC1-41BE-9740-DBC134F66415}" = Nero BackItUp Help (CHM) "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "Google Chrome" = Google Chrome "Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime "MSC" = McAfee Internet Security Suite "NARA" = Norton Online Backup ARA "Spotify" = Spotify "Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime "WildTangent wildgames Master Uninstall" = WildTangent Games "WinRAR archiver" = Archiwizator WinRAR "WTA-15d95f84-aabb-407d-b17d-fbd4d7fc1ea6" = John Deere Drive Green "WTA-304a6dae-267f-4d86-b955-5f0faf6b0677" = Bejeweled 3 "WTA-64bd2bfa-bcd4-4474-a781-d58b4fde50f0" = Jewel Match 3 "WTA-6814fcc2-1fee-4819-b28d-24a745fd31b2" = Tales of Lagoona "WTA-8adb6869-cea4-4244-9b65-6ed39a4121b3" = Delicious: Emily's Childhood Memories Premium Edition "WTA-9e41419b-9d26-4abb-9789-0fcbce4d606f" = Magic Academy "WTA-babb09a5-1623-432b-a14f-7fb2c0b00d31" = Plants vs. Zombies - Game of the Year "WTA-ceae7802-8d6e-4c8e-a921-9d6461316866" = Governor of Poker 2 Premium Edition [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2253055635-1566063098-3438977135-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Pokki" = Host App Service "Pokki_03d432a7e610c3e908213e7689d4342ce2111caf" = Acer Games "Pokki_Start_Menu" = Pokki Start Menu [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-10-01 13:20:45 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:20:45 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:20:45 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:20:50 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji Microsoft.SkypeApp_kzf8qxf38zg5c!App nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:29:16 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:35:45 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:35:45 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:35:45 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:35:45 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2014-10-01 13:35:51 | Computer Name = mrukkk | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji Microsoft.SkypeApp_kzf8qxf38zg5c!App nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. [ System Events ] Error - 2014-10-01 14:17:06 | Computer Name = mrukkk | Source = Service Control Manager | ID = 7034 Description = Usługa hpqcxs08 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-10-01 14:17:06 | Computer Name = mrukkk | Source = Service Control Manager | ID = 7034 Description = Usługa Usługa HP CUE DeviceDiscovery niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-10-01 14:33:23 | Computer Name = mrukkk | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 20:15:37 na ?2014-?10-?01 było nieoczekiwane. Error - 2014-10-01 14:34:21 | Computer Name = mrukkk | Source = Service Control Manager | ID = 7034 Description = Usługa hpqcxs08 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-10-01 14:34:21 | Computer Name = mrukkk | Source = Service Control Manager | ID = 7034 Description = Usługa Usługa HP CUE DeviceDiscovery niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-10-01 14:45:25 | Computer Name = mrukkk | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 20:33:23 na ?2014-?10-?01 było nieoczekiwane. Error - 2014-10-01 14:46:51 | Computer Name = mrukkk | Source = Service Control Manager | ID = 7034 Description = Usługa hpqcxs08 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-10-01 14:46:51 | Computer Name = mrukkk | Source = Service Control Manager | ID = 7034 Description = Usługa Usługa HP CUE DeviceDiscovery niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-10-01 15:05:26 | Computer Name = mrukkk | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 20:49:40 na ?2014-?10-?01 było nieoczekiwane. Error - 2014-10-01 15:07:49 | Computer Name = mrukkk | Source = Service Control Manager | ID = 7001 Description = Usługa Klient DHCP zależy od usługi Sterownik funkcji pomocniczej usługi Winsock, której nie można uruchomić z powodu następującego błędu: %%31 < End of report >