OTL Extras logfile created on: 2015-05-20 07:03:11 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Damian\Downloads 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17801) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,97 Gb Total Physical Memory | 2,17 Gb Available Physical Memory | 54,80% Memory free 11,90 Gb Paging File | 9,74 Gb Available in Paging File | 81,88% Paging File free Paging file location(s): c:\pagefile.sys 0 0d:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 43,94 Gb Total Space | 3,59 Gb Free Space | 8,17% Space Free | Partition Type: NTFS Drive D: | 421,82 Gb Total Space | 154,22 Gb Free Space | 36,56% Space Free | Partition Type: NTFS Drive G: | 7,50 Gb Total Space | 7,47 Gb Free Space | 99,61% Space Free | Partition Type: FAT32 Computer Name: DAMIAN-PC | User Name: Damian | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1461562640-103210102-4150413856-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- D:\PROGRA~3\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- D:\PROGRA~3\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00F9137E-EB23-4140-90D6-30A796C46E37}" = rport=137 | protocol=17 | dir=out | app=system | "{0310C306-98C6-4616-AC04-C78580682F2E}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | "{16B8B20C-D5CE-4856-A377-FE4DEFF7C90F}" = lport=2869 | protocol=6 | dir=in | app=system | "{1D9B1344-38D0-47C5-AA0D-1DE301F7875B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{228B72AD-999E-4E2C-80D1-F8D9402A4664}" = lport=138 | protocol=17 | dir=in | app=system | "{2A5487EC-6D78-4792-A794-6918E7AC2358}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{2C30CEF0-06F3-4E2B-AF67-A4C555F533AF}" = lport=137 | protocol=17 | dir=in | app=system | "{31C5092F-4BE2-4A9B-AA47-111D9C76ED53}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{475C9D79-01F8-4C3D-A7AB-90908AEB6EE3}" = lport=50248 | protocol=6 | dir=in | name=autodesk content service | "{482A1E21-F5C2-4343-BED4-FD9B3476BDC7}" = lport=445 | protocol=6 | dir=in | app=system | "{491D5433-1267-42D1-A433-0ECDB1895647}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{530CD64F-BE8A-431A-A499-2CC9DE33517D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5B008E6C-23C5-4D95-83C8-A9D043FB4F57}" = lport=6004 | protocol=17 | dir=in | app=d:\program files (x86)\microsoft office\office12\outlook.exe | "{6F81CB96-8F1C-4756-B6F5-21C72F7D7607}" = rport=445 | protocol=6 | dir=out | app=system | "{7CD80A22-4172-4079-B4DE-B50264A81623}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7D727F42-A38B-4B0B-BC7A-AC67C361824D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{84B84398-9D0E-4113-B0A0-13DD3EC4A232}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{870E1A9F-3253-4CB2-A4FF-1E4D11C35853}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{91B1FC83-44E9-4595-A0C3-8CAA649326F1}" = rport=138 | protocol=17 | dir=out | app=system | "{96507F3D-2BCC-4600-82FF-E452D2FC7B56}" = lport=139 | protocol=6 | dir=in | app=system | "{9BF5907A-FF43-484C-A277-73F8914FF997}" = lport=10243 | protocol=6 | dir=in | app=system | "{A104CD76-16E9-4845-B623-395C8FBCD4F5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B9FA11D0-DBCC-44A0-B191-84280D99FAB8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C2B51333-F216-4D81-B5B8-3E98B23BB4FF}" = rport=10243 | protocol=6 | dir=out | app=system | "{D390C112-A221-4F28-B229-7D4ABD12A9F7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D84FB849-BC6B-47C4-8C6E-2E862DE8AC25}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{F002400E-9C65-4D81-81C9-485C6F6AEBDD}" = rport=139 | protocol=6 | dir=out | app=system | "{F4284CE7-F039-4BA0-80A4-87FE670681FA}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{FB1CBFC3-349D-4470-A4E5-BB227BAE11D6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0015BE11-6E76-468C-9AB5-51D3FEC9450C}" = protocol=17 | dir=in | app=d:\program files (x86)\microsoft office\office12\onenote.exe | "{071FD18F-5DA0-4ACC-AD91-57698546F348}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "{0C98FF5C-3D87-4A8F-A799-05F026350D03}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{1376FA91-6B38-46B4-BA2F-3EE6B9AC4C7F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{1691DE97-DD92-41B3-B896-2062C19502AB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{16BBBB01-90C8-4160-BAF9-D9BD1EACA35C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{1E5EB688-1026-46F3-8B33-4C5147E1E28F}" = protocol=6 | dir=in | app=d:\program files (x86)\microsoft office\office12\onenote.exe | "{2AF5EAF3-1522-44A9-9064-E050575328DC}" = protocol=6 | dir=in | app=d:\program files\wolfram research\mathematica\9.0\math.exe | "{2FB2D45F-AB05-4C02-8213-31B70E1EC45E}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{33AE15B2-765C-49C5-8A40-ECAE996D5BF8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe | "{3D09FEB1-38BA-40D6-B409-3F8F8EFEAD5E}" = protocol=6 | dir=in | app=d:\program files (x86)\hearthstone\hearthstone.exe | "{498769EB-9F9A-404C-8372-E954216A2E1B}" = dir=in | app=d:\program files\itunes\itunes.exe | "{4CCB46C5-8287-4036-97EA-B611818CF73B}" = protocol=6 | dir=in | app=d:\program files (x86)\microsoft office\office12\groove.exe | "{4E8BC770-E17F-4075-806E-6A5B2AFDAEBB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{4E9559A4-97E3-47EE-9C63-C205B0EE7BFD}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe | "{53DD3039-7D8B-4248-A093-B7AA59D7DDFD}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3634\agent.exe | "{551647C7-9E6B-42D1-81DB-7E07D390B9CE}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{576F27BD-58BC-4C07-9E0C-301E3A95207D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{5B1B3AF8-F7EA-41C5-BF52-897602DF8689}" = protocol=6 | dir=in | app=d:\program files\wolfram research\mathematica\9.0\mathematica.exe | "{600B2B74-F557-4653-AB50-3D0DD3478CF3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{6EFDFC2D-DEAF-4FD1-8021-C5DE9D8385BD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{784967F9-0FD6-460B-B348-EA0EEED9C3DE}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{7E50CA92-778C-4D89-B507-226B11EF1CA0}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{83578341-D09D-4377-96A0-A951BC033206}" = protocol=6 | dir=in | app=d:\program files\battle.net\battle.net.exe | "{87BBEED0-E724-4504-B469-1C6CE350338D}" = protocol=17 | dir=in | app=d:\program files\wolfram research\mathematica\9.0\mathematica.exe | "{88E45D11-C011-455B-947C-7F62E43DCF9E}" = protocol=17 | dir=in | app=d:\program files\battle.net\battle.net.exe | "{939A1CF3-23AB-4685-9BE6-802059DC9A47}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{96266045-4AD0-4796-BD2C-ED1D73AD46CD}" = protocol=17 | dir=in | app=d:\program files\wolfram research\mathematica\9.0\math.exe | "{9B615B79-6EE5-4019-AB99-96C9F1A4853F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9E913661-C465-4BE5-8BFE-ED51E30C2712}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A99A3A93-C585-4486-BD4A-E18A2F415DE1}" = protocol=17 | dir=in | app=d:\program files (x86)\hearthstone\hearthstone.exe | "{AE7D65BF-F103-4F84-BF90-4A5FAF614ED5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B75B54C5-EDFE-4F55-8928-DEAC26E533A3}" = protocol=6 | dir=in | app=d:\program files\wolfram research\mathematica\9.0\mathkernel.exe | "{BB56F6E0-CFE1-4061-B2F3-464D6DA02D1D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BCC21FED-87E8-42A5-A0AB-36D8EABAC15C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe | "{C234A0F4-243C-44A8-BB17-288BFA046552}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CBDA2799-5326-4A1E-8D7E-BD8AB1B72ACE}" = protocol=6 | dir=out | app=system | "{CD0908D8-E1B5-43D1-9753-58B6B3D16942}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D18328CD-955E-4B39-9FA9-16B8FFAFE6D4}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "{D4FE83AE-EE43-4F2E-ABFD-515875CD2DA5}" = protocol=6 | dir=in | app=c:\users\damian\appdata\roaming\utorrent\utorrent.exe | "{D80515DB-7F82-4B2F-B12C-BC3A2530A89E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe | "{DA39103C-5E47-40F8-9CB3-6B34C3C485EB}" = protocol=17 | dir=in | app=c:\users\damian\appdata\roaming\utorrent\utorrent.exe | "{E005C265-595F-4096-B08D-403108E3DC8E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{E3D304C8-F5D8-4874-A38F-2D251E88C61A}" = dir=in | app=d:\program files (x86)\skype\phone\skype.exe | "{E6AE19F5-392B-4610-BC45-CD5780A774DB}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{EEB78FB7-D5EE-4B3A-A69B-80840491C55E}" = protocol=17 | dir=in | app=d:\program files\wolfram research\mathematica\9.0\mathkernel.exe | "{EEF0E262-58E1-44E1-90DB-DAE26AB7165D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3634\agent.exe | "{F1209490-D362-4972-A755-F490A8169289}" = protocol=17 | dir=in | app=d:\program files (x86)\microsoft office\office12\groove.exe | "{F57E4B29-5FB8-476C-BE88-1B44A10A2C06}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{F8C903E9-D085-41A6-853B-FC8B57B62930}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{1A07C51B-CC67-4728-9251-C9318B2F72DA}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "TCP Query User{262F77F1-17C6-4D62-86D1-20245C289D2E}D:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=d:\program files\gadu-gadu 10\gg.exe | "UDP Query User{5C78F188-CED4-417E-851B-9DD54D1F4482}D:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=d:\program files\gadu-gadu 10\gg.exe | "UDP Query User{8BB32790-DADB-40C7-A094-1C531AC4EE09}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = Lenovo Bluetooth with Enhanced Data Rate Software 6.1.0.5100 "{0DF7096B-715A-4233-8633-C7A16ED6D616}" = Obsługa programów Apple (64-bitowa) "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center "{45F1F774-38B4-3CC3-BAAF-051E6D19E48E}" = Microsoft .NET Framework 4.5.1 (PLK) "{49F3D04B-B849-4C89-AB31-2366A004EA28}" = Broadcom Gigabit Integrated Controller "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5783F2D7-D001-0000-0102-0060B0CE6BBA}" = AutoCAD 2014 — Polski (Polish) "{5783F2D7-D001-0415-1102-0060B0CE6BBA}" = AutoCAD 2014 Language Pack – Polski (Polish) "{5783F2D7-D001-0415-2102-0060B0CE6BBA}" = AutoCAD 2014 — Polski (Polish) "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A3BD9E70-84AD-4E93-A92F-E6A245CD786C}" = Autodesk Robot Structural Analysis Professional 2014 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 327.02 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 327.02 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 327.02 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.14.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Sterownik dźwięku HD 1.3.26.4 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{C4123106-B685-48E6-B9BD-E4F911841EB4}" = Apple Mobile Device Support "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant "{D227565A-0033-40AD-89BA-653A205CDC11}" = iTunes "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "{FEAB63F3-66AE-4D65-8354-A40F1586B124}" = Autodesk Robot Structural Analysis Professional 2014 - Polish regional settings "0A4175B489A1B4A6E07E11B063A6263480C51D71" = Windows Driver Package - Lenovo (ACPIVPC) System (10/19/2009 5.4.0.1) "AutoCAD 2014 — Polski (Polish)" = Autodesk AutoCAD 2014 — Polski (Polish) "AutoCAD 2014 — Polski (Polish) SP1" = Autodesk AutoCAD 2014 — Polski (Polish) SP1 "Autodesk Robot Structural Analysis Professional 2014" = Autodesk Robot Structural Analysis Professional 2014 "A-WIN-Extras 9.0.1 4055459_is1" = Mathematica Extras 9.0 (4055459) "CCleaner" = CCleaner "Lenovo EasyCamera" = Lenovo EasyCamera "M-WIN-L 9.0.1 4055652_is1" = Wolfram Mathematica 9 (M-WIN-L 9.0.1 4055652) "SMSERIAL" = Motorola SM56 Data Fax Modem "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{03D562B5-C4E2-4846-A920-33178788BE00}" = Windows Live Communications Platform "{0F929651-F516-4956-90F2-FFBD2CD5D30E}" = Photo Gallery "{0FF9CC94-EF23-401E-BDBD-37403D1A2B38}" = Windows Live SOXE Definitions "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{207DA277-6A6D-4863-B535-129931D2BB21}" = Galeria fotografii "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 7.4 "{26A24AE4-039D-4CA4-87B4-2F83218031F0}" = Java 8 Update 31 "{2F2363F9-102C-448B-8E3E-02FCFE78A28D}" = Movie Maker "{316EB047-4627-4B63-B0A6-8CD32D07D962}" = Avira "{447CDCE5-F555-429B-BFA6-642C3C6D684F}" = Obsługa programów Apple (32-bitowa) "{45898170-E68C-4F02-AA35-C2186BF347A3}" = Movie Maker "{46BC55A2-B4CE-46B5-8303-A2076B899505}" = Windows Live UX Platform Language Pack "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{51BF3210-B825-4092-8E0D-66D689916E02}" = Autodesk Material Library Base Resolution Image Library 2014 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5U8xx Media Driver ver.3.62.02 "{5A0EE0F0-E909-4F3B-B437-AAD9252427CB}" = Windows Live Installer "{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper "{62F029AB-85F2-0000-866A-9FC0DD99DDBC}" = Autodesk Content Service "{62F029AB-85F2-0001-866A-9FC0DD99DDBC}" = Autodesk Content Service Language Pack "{644E9589-F73A-49A4-AC61-A953B9DE5669}" = SketchUp Import for AutoCAD 2014 "{644F9B19-A462-499C-BF4D-300ABC2A28B1}" = Autodesk Material Library 2014 "{6B6923B9-8719-425B-916C-CD2908F31AAF}" = Windows Live SOXE "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime "{8A470330-70B2-49AD-86AF-79885EF9898A}" = FARO LS 1.1.501.0 (64bit) "{8B743AA0-53B2-11D2-808A-00600895FB43}" = Heroes of Might and Magic III - Złota Edycja "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{AC76BA86-0804-1033-1959-001802114130}" = Adobe Refresh Manager "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.11) - Polish "{b5675cc4-ab8b-4945-8c1d-4c5479556d6a}" = Avira "{C070121A-C8C5-4D52-9A7D-D240631BD433}" = Autodesk App Manager "{C268B5E1-A5DA-11DF-A289-005056C00008}" = Paragon Backup & Recovery™ 2013 Free "{C6B0EE9E-2128-4448-B7AE-5E2B46E0F0E7}" = Windows Live Photo Common "{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3445598-4424-4EE2-B71C-C23325F7FB71}" = Windows Live PIMT Platform "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E58739-2B4C-498F-9B0D-FF0F2FD52B61}" = Windows Live UX Platform "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F732FEDA-7713-4428-934B-EF83B8DD65D0}" = Autodesk Featured Apps "{FA12037C-B6FA-4825-86BC-D58AA6A9CC24}" = Podstawowe programy Windows Live "{FBA73805-0F67-428B-8E4F-FAE16A452685}" = Photo Common "Adobe Flash Player ActiveX" = Adobe Flash Player 17 ActiveX "Adobe Flash Player NPAPI" = Adobe Flash Player 17 NPAPI "APLUS_is1" = APLUS 14.032 "Autodesk Content Service" = Autodesk Content Service "Avira Antivirus" = Avira Antivirus "Battle.net" = Battle.net "Buderus C.O. 3.6_is1" = Buderus C.O. - Deinstalacja programu "Buderus OZC 6.1_is1" = Buderus OZC - Deinstalacja programu "DAEMON Tools Lite" = DAEMON Tools Lite "ENTERPRISE" = Microsoft Office Enterprise 2007 "EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 "Google Chrome" = Google Chrome "Hearthstone" = Hearthstone "InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "Max Payne 2" = Max Payne 2 "Mozilla Firefox 36.0.4 (x86 pl)" = Mozilla Firefox 36.0.4 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "VLC media player" = VLC media player "WinLiveSuite" = Podstawowe programy Windows Live [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1461562640-103210102-4150413856-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "OneDriveSetup.exe" = Microsoft OneDrive "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-08-18 09:31:51 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6895 Error - 2014-08-18 09:31:51 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6895 Error - 2014-08-18 09:31:52 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 2014-08-18 09:31:52 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 7893 Error - 2014-08-18 09:31:52 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 7893 Error - 2014-08-18 09:31:53 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 2014-08-18 09:31:53 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 8954 Error - 2014-08-18 09:31:53 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 8954 Error - 2014-08-18 09:31:54 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 2014-08-18 09:31:54 | Computer Name = Damian-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 9984 [ System Events ] Error - 2015-05-19 17:37:32 | Computer Name = Damian-PC | Source = Service Control Manager | ID = 7031 Description = Usługa Usługa udostępniania w sieci programu Windows Media Player niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error - 2015-05-19 17:37:32 | Computer Name = Damian-PC | Source = Service Control Manager | ID = 7031 Description = Usługa Instalator modułów systemu Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 120000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error - 2015-05-19 17:39:32 | Computer Name = Damian-PC | Source = Service Control Manager | ID = 7038 Description = Usługa TrustedInstaller nie może zalogować się jako NT AUTHORITY\SYSTEM za pomocą obecnie skonfigurowanego hasła z powodu następującego błędu: %%50 Aby upewnić się, że usługa jest skonfigurowana prawidłowo, użyj przystawki Usługi w programie Microsoft Management Console (MMC). Error - 2015-05-19 17:39:32 | Computer Name = Damian-PC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Instalator modułów systemu Windows z powodu następującego błędu: %%1069 Error - 2015-05-20 00:36:37 | Computer Name = Damian-PC | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Avira Service Host. Error - 2015-05-20 01:01:58 | Computer Name = Damian-PC | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\DR1. Error - 2015-05-20 01:01:59 | Computer Name = Damian-PC | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\DR1. Error - 2015-05-20 01:02:09 | Computer Name = Damian-PC | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\DR1. Error - 2015-05-20 01:02:09 | Computer Name = Damian-PC | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\DR1. Error - 2015-05-20 01:02:10 | Computer Name = Damian-PC | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\DR1. < End of report >