OTL Extras logfile created on: 2012-02-22 09:33:02 - Run 1 OTL by OldTimer - Version 3.2.33.2 Folder = C:\Users\KSIĘGOWA\Desktop\VIRUS\KSIĘGOWA Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,07 Gb Available Physical Memory | 53,68% Memory free 4,23 Gb Paging File | 3,16 Gb Available in Paging File | 74,66% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 52,28 Gb Total Space | 14,94 Gb Free Space | 28,57% Space Free | Partition Type: NTFS Drive D: | 412,64 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: KSIĘGOWA | User Name: KSIĘGOWA | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 1 "InternetSettingsDisableNotify" = 1 "AutoUpdateDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{056D8522-9430-4B26-A84A-4C07AF2EE414}" = lport=5357 | protocol=6 | dir=in | app=system | "{05A14269-22DE-416D-81DF-77169B7A4613}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe | "{159B663E-AC56-4950-988B-F75B55F4F1C9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{1607B8A4-6AAF-447C-A329-A891A97EE66C}" = lport=rpc | protocol=6 | dir=in | svc=* | app=c:\windows\system32\svchost.exe | "{18330C14-39BB-48FF-AC29-1298E1726AD8}" = lport=5358 | protocol=6 | dir=in | app=system | "{18799D23-2109-4E1C-9E63-87B0D8273A49}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{2959FF81-BB7A-4E68-AD43-EDBCBAC62030}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe | "{2BAAFE16-A03F-490E-B803-06679FA1E5C1}" = lport=10243 | protocol=6 | dir=in | app=system | "{2D2FE35A-6405-40CB-9E15-3C40233C4F62}" = lport=445 | protocol=6 | dir=in | app=system | "{2EDF7323-8680-4EA1-B254-47E86D64EEF4}" = rport=5357 | protocol=6 | dir=out | app=system | "{370D18FA-874A-4663-A8CF-15E6A9DF731B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3C399C2C-7863-413F-A79A-DE7010AC3697}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3CE4E15B-A940-4706-A08C-AAF2B3DFB697}" = lport=139 | protocol=6 | dir=in | app=system | "{477BDA78-0182-4020-A991-4DC25379F020}" = rport=5358 | protocol=6 | dir=out | app=system | "{480DB3A1-47D3-4A17-8FD6-49A3BB73DE08}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{482FE84F-7C80-4D55-9C02-7776CD0CCE16}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{5BDB86BD-EF06-4BED-A886-BECB307386A2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6DA8C2AF-1E80-495A-B98C-8AE7DD48CD2D}" = lport=2869 | protocol=6 | dir=in | app=system | "{72719969-D2BF-429F-9094-35A451EE0AE5}" = rport=10243 | protocol=6 | dir=out | app=system | "{7949CF24-95C8-416C-A19A-D78E306C3DE3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{83EF4632-3DF4-4293-908E-89EE29A57D47}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8433D85F-1BDF-4C00-8B0F-9A7910EE4BD5}" = rport=137 | protocol=17 | dir=out | app=system | "{9941E8ED-47EB-46DA-8187-0B9296161AFD}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe | "{9DB67B6B-EF7F-48A9-B1C1-9A8F36758E38}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A726ADB7-37FA-4C29-8BC2-659F138681E9}" = rport=139 | protocol=6 | dir=out | app=system | "{AA4088D2-F4E7-41CC-B0B1-093809B09563}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\netproj.exe | "{B842C0C3-37AD-4A84-B95D-511E9E128D1E}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\netproj.exe | "{BE96B11D-89F3-4808-BDC4-88C3EFEF8710}" = rport=138 | protocol=17 | dir=out | app=system | "{BEA24AE6-B949-497E-A95A-32E8DC192B7E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CF07A79F-2095-4945-90F0-C7B47F6FC9BE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{CF90950D-1E6C-49A1-A467-97B56D770D2D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D7B4EA8F-BD65-4740-922B-53F1B3ADAA21}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E06A598C-B03E-4796-93E7-B6D0C0AB132F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{E1627BC5-4D88-4DDB-91B8-99E2FBEEEF01}" = lport=137 | protocol=17 | dir=in | app=system | "{E5A90269-5E3D-43C5-9B33-2222764F5A45}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{E783DFAF-D39E-43F2-99C1-91FE93311EF1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{EA2D9FC8-8EB0-47A2-889F-B666CB70F197}" = lport=2869 | protocol=6 | dir=in | app=system | "{EE92216E-10B2-4397-9FAF-CC88F8C468BD}" = lport=138 | protocol=17 | dir=in | app=system | "{EFBE0E2A-E72A-4962-A15D-7CA31B7DA9C9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{F2B09104-D3D2-4935-B42F-B79E07F27014}" = rport=445 | protocol=6 | dir=out | app=system | "{F779F251-9147-4ED5-B997-2D62CE23FE69}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{FAC7D276-487B-4CD4-B234-39FBD9FD1D51}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FCCA7B8A-31C8-4F2D-BBB2-A08F862D6E3D}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe | "{FE5FD60C-4105-4790-BE72-3FAB6C959037}" = lport=445 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0893DFFE-2D29-464B-B1C6-3E6ED17E8FBD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{11FED1C4-3CC0-4B84-94A5-63E9DAF75FBC}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe | "{15759C3A-B80C-4CE3-ADCD-CF9BFF89FDCD}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe | "{1CF72CF0-F044-4739-8AA1-DE7CE0E3115A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{1DB96577-98B8-4A64-BFD0-ADBA9B8321BF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2924B43A-144A-477E-BFDB-254D9B12D507}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{2A8B21A0-10BF-48CC-B1DE-8036483FBCBF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2EF0F839-8831-434D-A359-61FD7439D349}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{45810C9A-5C53-441F-A97A-D3B09D1307AB}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{4B9274CE-410D-4BC7-ABEF-1CA4AA396A55}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{4BCE7AEF-70A9-4140-9CCD-B3C08445AF81}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{4FAC527A-0A50-4B23-A10A-759E97923094}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{51CD37B0-D897-48F4-BF04-BC53779381C0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{5D5139EB-A0D0-4FEF-99A0-613F21FC8AB8}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{5FAE3E0B-53DC-41AC-AF79-60C5CF234CB0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{7395CFE7-570D-41BA-B7F1-82D802AA2D43}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{7B1A8923-0006-4304-A900-3EFE52D44B4F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7C27BE81-D7CB-4A0E-9891-8E8E0C7F1BE0}" = protocol=6 | dir=out | app=c:\windows\system32\netproj.exe | "{87B25725-689D-40EB-8D80-A81E0566B5E3}" = protocol=6 | dir=out | app=system | "{8B9DCFF4-C015-4452-A4A8-F1C402DAE6EA}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{9913B79E-7D1B-4548-A08A-C3867C7A6D87}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{ABBBD1FE-60EC-4D12-9876-F61E5B324794}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{AF8B1229-163D-4794-A75F-B00E416D3918}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{B22BAAFC-D27C-44D6-B9A3-9A2ACA510620}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BDB1FFAC-2ACF-40EA-8795-EBE71171FBF8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C57ADEE9-F975-43F9-B861-B275CD0015FE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{CD61A71A-FAA7-4F78-A3E2-BD98400A00B0}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe | "{D6ABB7CB-DF8F-49F8-A38B-08C5D185E37E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{E19176BB-0624-4CD3-BF98-BEE553CA5E8C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{E5A7ABAD-4A9E-41FD-8401-CC42AA9C7853}" = protocol=6 | dir=in | app=c:\windows\system32\netproj.exe | "{F55715AF-7953-45DC-800A-F510CC14876D}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe | "{F7F0FF06-4452-4C88-A047-416BB6AC4FE2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{0712D44E-1D8D-4056-A6EB-E339FE335F55}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | "TCP Query User{575A8CEC-7A56-4D96-84D2-2676B657839F}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe | "TCP Query User{5D61C5AB-FDD3-4953-9B03-66FE7B2C85F8}C:\program files\tlen.pl\tlen.exe" = protocol=6 | dir=in | app=c:\program files\tlen.pl\tlen.exe | "TCP Query User{7F478C2A-FCF5-4FBA-9FD0-CC93803376D0}C:\program files\tlen.pl\tlen.exe" = protocol=6 | dir=in | app=c:\program files\tlen.pl\tlen.exe | "TCP Query User{8840F048-C5ED-4401-ABAE-53F1927CA57D}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{975C584C-6A8B-40A4-8FF5-F09880C0929F}C:\program files\gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu\gg.exe | "TCP Query User{D5EADEF2-D040-4406-8891-BBA132500119}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{23244C8A-5FE3-4554-AB21-F82FE70935C5}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{3F27177E-F637-4F0D-87D1-13926414E612}C:\program files\tlen.pl\tlen.exe" = protocol=17 | dir=in | app=c:\program files\tlen.pl\tlen.exe | "UDP Query User{547E8140-E8E9-4B8B-BC84-BEA56C4C3BCB}C:\program files\tlen.pl\tlen.exe" = protocol=17 | dir=in | app=c:\program files\tlen.pl\tlen.exe | "UDP Query User{8460583E-59A6-4512-9668-7BFFF463BBC2}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{B8CE796F-7D22-412B-BB57-0AE9157EE495}C:\program files\gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu\gg.exe | "UDP Query User{C40A0989-94FC-4973-8E66-EB95914F032D}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe | "UDP Query User{D07B76E9-1F57-41D9-A6B9-BA30D89DF67C}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{10A44844-4465-456E-8C97-80BDD4F68845}" = Asystent rejestrowania za pomocą identyfikatora Windows Live "{173D51C6-869C-4C67-8694-11912F044570}" = Windows Live Writer "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 22 "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{6039C740-40B3-456C-8DDC-D63D29F634C8}" = Poczta systemu Windows Live "{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com "{847CAE64-4CD2-4B2D-AF00-978FF5431045}" = Nero 7 Essentials "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_HOMESTUDENTR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_HOMESTUDENTR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_HOMESTUDENTR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_HOMESTUDENTR_{E9EA2604-8AC9-47D2-8F4B-6BF60787A357}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_HOMESTUDENTR_{D45F91DE-F0FC-4D5F-9A0C-FDE5B251AAC6}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_HOMESTUDENTR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{91130415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003 "{9192066C-2E36-4A94-ABF3-463314819323}" = Windows Live Messenger "{975C8028-51D8-44A9-9585-82E9810FE96A}" = hp LaserJet 1000 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A6EC5250-2E27-1B1C-2283-BBD468EEB1B9}" = e-Deklaracje "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0 "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9 "{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4 "{B0BC0B99-C81A-4AAD-9713-14A82011364C}" = Windows Live Toolbar "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D659C084-24CE-477A-BC76-6BE150355C26}" = Windows Live installer "{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation) "{EDB2A321-4151-4624-AE7A-B0ADFEAA492E}" = Galeria fotografii usługi Windows Live "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "7-Zip" = 7-Zip 4.42 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "avast" = avast! Free Antivirus "Dr. Tax Polska" = Dr. Tax Polska "eMule" = eMule "Gadu-Gadu" = Gadu-Gadu 7.7 "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "ImgBurn" = ImgBurn "KalkulatorZaliczek_is1" = Kalkulator zaliczek podatki.pl "LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation) "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Mozilla Firefox (3.6.26)" = Mozilla Firefox (3.6.26) "NVIDIA Drivers" = NVIDIA Drivers "Polska klasyfikacja wyrobów i usług, wersja 1.0 (001)_is1" = Polska klasyfikacja wyrobów i usług, wersja 1.0 (001) "Program Pit 2009 - rozliczenie roczne podatku dochodowego_is1" = Program Pit 2009 - wersja 3.0.0.10 "Program Pit 2010 - rozliczenie roczne podatku dochodowego_is1" = Program Pit 2010 - wersja 4.0.0.15 "Program SAMOCHÓD" = Program SAMOCHÓD "RealPlayer 12.0" = RealPlayer "Roczne rozliczenie podatku dochodowego - PIT 2011_is1" = Program Pit 2011 - wersja 5.0.0.18 "SPRAWOZDANIE FINANSOWE 2008_is1" = SF v. 3.0.0.6 "SPRAWOZDANIE FINANSOWE 2009_is1" = SF v. 4.0.0.3 "SPRAWOZDANIE FINANSOWE 2010_is1" = SF v. 5.0.0.0 "SubEdit-Player_is1" = SubEdit-Player "Tlen.pl" = Tlen.pl "Totalcmd" = Total Commander (Remove or Repair) "uTorrent" = µTorrent "Windows Live Toolbar" = Windows Live Toolbar "Your Teacher" = Your Teacher 1.0 [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Antivirus Events ] Error - 2008-11-13 12:57:49 | Computer Name = KSIĘGOWA-PC | Source = avast! | ID = 33554522 Description = [ Application Events ] Error - 2011-12-19 02:30:13 | Computer Name = KSIĘGOWA | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\real\realplayer\plugins\rmxrend.dll". Nie można odnaleźć zestawu zależnego Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2011-12-20 07:02:00 | Computer Name = KSIĘGOWA | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd iexplore.exe, wersja 9.0.8112.16421, sygnatura czasowa 0x4d76255d, moduł powodujący błąd ntdll.dll, wersja 6.0.6002.18327, sygnatura czasowa 0x4cb73436, kod wyjątku 0xc0000005, przesunięcie błędu 0x000663d2, identyfikator procesu 0x15e8, godzina rozpoczęcia aplikacji 0x01ccbeedd4ace910. Error - 2011-12-22 03:39:47 | Computer Name = KSIĘGOWA | Source = System Restore | ID = 8193 Description = Error - 2011-12-27 02:28:05 | Computer Name = KSIĘGOWA | Source = System Restore | ID = 8193 Description = Error - 2011-12-28 05:43:52 | Computer Name = KSIĘGOWA | Source = System Restore | ID = 8193 Description = Error - 2011-12-30 02:32:02 | Computer Name = KSIĘGOWA | Source = System Restore | ID = 8193 Description = Error - 2011-12-30 05:23:32 | Computer Name = KSIĘGOWA | Source = System Restore | ID = 8193 Description = Error - 2012-01-03 02:13:29 | Computer Name = KSIĘGOWA | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\real\realplayer\plugins\rmxrend.dll". Nie można odnaleźć zestawu zależnego Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-01-03 02:13:40 | Computer Name = KSIĘGOWA | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\real\realplayer\plugins\rmxrend.dll". Nie można odnaleźć zestawu zależnego Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-01-03 02:32:56 | Computer Name = KSIĘGOWA | Source = System Restore | ID = 8193 Description = [ System Events ] Error - 2012-02-21 07:44:36 | Computer Name = KSIĘGOWA | Source = Service Control Manager | ID = 7026 Description = Error - 2012-02-21 08:05:23 | Computer Name = KSIĘGOWA | Source = Microsoft-Windows-TaskScheduler | ID = 412 Description = Error - 2012-02-21 08:06:02 | Computer Name = KSIĘGOWA | Source = Service Control Manager | ID = 7026 Description = Error - 2012-02-21 08:07:29 | Computer Name = KSIĘGOWA | Source = DCOM | ID = 10005 Description = Error - 2012-02-21 08:07:29 | Computer Name = KSIĘGOWA | Source = Service Control Manager | ID = 7009 Description = Error - 2012-02-21 08:07:29 | Computer Name = KSIĘGOWA | Source = Service Control Manager | ID = 7000 Description = Error - 2012-02-21 08:18:46 | Computer Name = KSIĘGOWA | Source = Microsoft-Windows-TaskScheduler | ID = 412 Description = Error - 2012-02-21 08:20:25 | Computer Name = KSIĘGOWA | Source = Service Control Manager | ID = 7026 Description = Error - 2012-02-22 02:07:57 | Computer Name = KSIĘGOWA | Source = Microsoft-Windows-TaskScheduler | ID = 412 Description = Error - 2012-02-22 02:09:34 | Computer Name = KSIĘGOWA | Source = Service Control Manager | ID = 7026 Description = < End of report >