OTL Extras logfile created on: 2012-07-24 16:20:27 - Run 5 OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\Joanna\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,56 Gb Available Physical Memory | 52,12% Memory free 6,22 Gb Paging File | 4,87 Gb Available in Paging File | 78,29% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 172,69 Gb Total Space | 71,76 Gb Free Space | 41,56% Space Free | Partition Type: NTFS Drive D: | 100,00 Mb Total Space | 58,41 Mb Free Space | 58,42% Space Free | Partition Type: NTFS Drive E: | 195,31 Gb Total Space | 16,92 Gb Free Space | 8,66% Space Free | Partition Type: NTFS Drive F: | 95,41 Gb Total Space | 52,81 Gb Free Space | 55,36% Space Free | Partition Type: NTFS Computer Name: KAMIL-PC | User Name: Joanna | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\S-1-5-21-2620197854-1719786493-1418023469-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AntiSpywareOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{372D9978-BC39-4EA1-A923-BB0717A5DB83}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0AED0D96-2498-4E47-86C3-C6A2469B0C13}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zs8d82.tmp\symnrt.exe | "{0D6FDC66-E6FF-40E1-BD40-CAD3C8FB7D00}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{0F11E840-F1E5-4564-B84E-20A2C1EE806C}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsbf4.tmp\symnrt.exe | "{132A2873-E27D-4143-AED8-3E255AE6CB0D}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe | "{1D197D28-CFEA-4F0E-B971-8ED36EB40BB4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{1F357655-975D-4FE7-AC05-1B00456F21E9}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe | "{25070B81-75C8-43FB-88B6-D4A652A4752F}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxwbgw.exe | "{255F9F77-0B74-4129-B942-03F7BA5BF157}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{33DB1BBC-0E38-4451-AC32-77E724C4369C}" = protocol=6 | dir=in | app=c:\windows\system32\lxdxcoms.exe | "{3A53AF54-FF38-4193-9492-FBD288D708D1}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zse977.tmp\symnrt.exe | "{3DD15A8A-01CD-4BFA-8F46-1A0600E2AD22}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zs8d82.tmp\symnrt.exe | "{3FD3EA3C-6317-425A-981B-FD8CBCFE79F2}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe | "{42E37B49-66BD-4CA1-A051-D2366EA30AD3}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe | "{465C8DA2-B64C-445D-A9CF-F450B84907B5}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxjswx.exe | "{47C28BAC-3DAC-4393-9B7F-9EF5132A31D2}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsf681.tmp\symnrt.exe | "{484EE9DE-AFC7-4102-99D3-CCAAE53F926F}" = protocol=6 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe | "{5174D031-7833-4B4D-814B-2C673C955F40}" = protocol=6 | dir=in | app=c:\program files\proxy switcher standard\proxyswitcher.exe | "{5B12D523-FB4E-42F1-A7CC-A6625A33439D}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | "{5E4E86B5-1DC3-4D23-B59D-5409A216F45E}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxtime.exe | "{60B9460C-2C8D-4B8C-B66B-6C2541BDC9DE}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zs35ee.tmp\symnrt.exe | "{666A34C7-06C5-41B5-9A18-728773037B69}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxtime.exe | "{68DDE076-3F32-496D-ABFE-5EBC66E30D23}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsb05e.tmp\symnrt.exe | "{6E5F7A2A-C874-4A82-B1FA-FE60FF02DD39}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zse977.tmp\symnrt.exe | "{7069E067-56F0-4682-ACFA-5B7291355B36}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsbf4.tmp\symnrt.exe | "{73660268-9F98-4F46-96E9-D8FD89AB0A7C}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsb05e.tmp\symnrt.exe | "{7697A994-0807-4493-B469-300E5A6716B1}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxwbgw.exe | "{7E53D085-1357-44E4-93E6-35F4399D5E01}" = protocol=6 | dir=in | app=c:\windows\system32\lxdxcoms.exe | "{7E670373-89E7-46EE-A55C-14F2EF689B1D}" = protocol=17 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe | "{80CF9392-B43F-4897-A2BE-D65CE52991DB}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsd0aa.tmp\symnrt.exe | "{80E72B4D-55AA-4F25-BD59-C5871507701F}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zs4f99.tmp\symnrt.exe | "{92CBEA6E-0AB4-4AA7-8A37-B4C9CEAAE561}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe | "{97A2707E-A642-41BC-AB32-595EB7395271}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsc351.tmp\symnrt.exe | "{99F1A69A-271E-4104-B34B-C38E1224818E}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxjswx.exe | "{9DD0EBDB-BB3A-4ECC-94C5-DFD8C9C570DB}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsd0aa.tmp\symnrt.exe | "{9DDC65B2-63DE-4DA2-AB7C-7116E1D6B95B}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zs4f99.tmp\symnrt.exe | "{A2FA4FC6-018C-4B65-8C6D-8C38CF1D855A}" = protocol=17 | dir=in | app=c:\windows\system32\lxdxcoms.exe | "{BAA27C54-8BEB-4BBC-92E8-5B68405AC4E4}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe | "{BF23818D-CB10-41DF-A2F1-248E5723E3C6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{D0829A48-E14C-4247-869A-19B2C8B9C4B1}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe | "{D5924B85-6910-4AAD-8E15-A7B70862D2FC}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxlscn.exe | "{D6836273-C5B9-4D39-96D8-760246E45747}" = protocol=17 | dir=in | app=c:\program files\proxy switcher standard\proxyswitcher.exe | "{E99D276D-0BEC-419C-A54E-880B58CF6EFC}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxlscn.exe | "{EB87490B-E1FD-4E44-B0BB-F6E31A9D1F82}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxtime.exe | "{EECCB1C2-D293-466A-930A-0DAA02AAF698}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | "{EFF68419-9B86-4F3A-8F3F-5C4F236484B5}" = protocol=17 | dir=in | app=c:\windows\system32\lxdxcoms.exe | "{F0663E49-B58F-4A04-AADA-F5E74BF2FE73}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsc351.tmp\symnrt.exe | "{F29DC40C-C0EB-45CA-AA7F-C96214C62ECC}" = protocol=6 | dir=in | app=c:\users\joanna\appdata\local\temp\7zsf681.tmp\symnrt.exe | "{F41A826D-5791-441A-BF6F-5A013AAB9DDE}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe | "{F5AE3942-5487-4ABA-8082-2EA6149F9D6A}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe | "{F868708B-F27A-49CB-AD53-5129841FE5AA}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxtime.exe | "{FB79E448-0952-4B0A-B399-E399CFF11BA8}" = protocol=17 | dir=in | app=c:\users\joanna\appdata\local\temp\7zs35ee.tmp\symnrt.exe | "{FBD32EBD-E0F2-4A02-9E33-55CD3687C3F0}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe | "TCP Query User{019548EC-0CA0-4564-B4B7-BFDC534E4696}C:\valve\hl.exe" = protocol=6 | dir=in | app=c:\valve\hl.exe | "TCP Query User{09F06A36-FDA4-4791-A32B-C5C59A38F530}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{483FCFB1-780B-4459-8394-D02AD2ED11E5}C:\program files\lexmark 3600-4600 series\lxdxmon.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe | "TCP Query User{50EBD574-C5F9-44C7-AB82-43946D7ED2D7}C:\program files\common files\pplivenetwork\ppap.exe" = protocol=6 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | "TCP Query User{5AB77EA2-33A0-4057-B203-024B18E34881}C:\users\joanna\downloads\utorrent.exe" = protocol=6 | dir=in | app=c:\users\joanna\downloads\utorrent.exe | "TCP Query User{5D437837-3A8E-465B-8E8F-3F1CE24AE7D2}C:\valve\hl.exe" = protocol=6 | dir=in | app=c:\valve\hl.exe | "TCP Query User{63F2DE54-8424-4641-91E9-9481EC3719BF}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{6B005D7D-5838-4CFF-ADAC-170DE93F2F59}C:\users\joanna\desktop\programy\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe" = protocol=6 | dir=in | app=c:\users\joanna\desktop\programy\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe | "TCP Query User{77DF793E-FF48-47D7-B6E3-4A994E47CBEC}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | "TCP Query User{795AAC7F-5557-490A-ABE1-FC32054F4007}C:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe | "TCP Query User{7D80C322-AB10-4ABB-A57B-D5318F0AF0A5}C:\program files\lexmark 3600-4600 series\lxdxlscn.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxlscn.exe | "TCP Query User{99093DF5-6379-41D1-87EA-CA6023A0D2F4}C:\users\joanna\desktop\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe" = protocol=6 | dir=in | app=c:\users\joanna\desktop\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe | "TCP Query User{AE4509D6-4EA7-4FB4-B864-215289FCCF72}C:\program files\flashget\flashget.exe" = protocol=6 | dir=in | app=c:\program files\flashget\flashget.exe | "TCP Query User{B94F83A1-6A41-4C7C-A931-CA5761DAE2AB}C:\program files\microsoft office\office12\groove.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "TCP Query User{C33F0264-DE84-4FD5-99CE-C1F5CC9F0406}C:\program files\winpcap\rpcapd.exe" = protocol=6 | dir=in | app=c:\program files\winpcap\rpcapd.exe | "TCP Query User{C87987F0-565A-470D-B624-14CCED8A4B17}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | "TCP Query User{F6DBF32A-CFD7-4508-AE51-AA210CDA87F9}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{FDF7B474-FA22-4883-824A-2713C5614D67}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{08A7A300-80C4-470B-AF24-AE2EBF42CE17}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | "UDP Query User{14D5E25B-A139-4B25-A7F6-F988A9DFD3E7}C:\program files\common files\pplivenetwork\ppap.exe" = protocol=17 | dir=in | app=c:\program files\common files\pplivenetwork\ppap.exe | "UDP Query User{2F02EA46-FAC1-49E7-A718-CE827D389749}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{33BDCC6E-2F96-4B16-BFCC-D62CCED9A332}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{37D55EEF-6EA3-4406-BD5C-2B9E135A1F2D}C:\program files\winpcap\rpcapd.exe" = protocol=17 | dir=in | app=c:\program files\winpcap\rpcapd.exe | "UDP Query User{3BDF1D2D-9049-469A-9557-E5965A7405AF}C:\users\joanna\desktop\programy\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe" = protocol=17 | dir=in | app=c:\users\joanna\desktop\programy\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe | "UDP Query User{3DEB9499-C74A-40B0-A8F8-1006B99123AA}C:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe | "UDP Query User{3DF74023-8BF5-47A0-A58A-454603977859}C:\program files\flashget\flashget.exe" = protocol=17 | dir=in | app=c:\program files\flashget\flashget.exe | "UDP Query User{4EAB54C7-F864-45B0-92E2-ED03C023464E}C:\users\joanna\desktop\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe" = protocol=17 | dir=in | app=c:\users\joanna\desktop\ubisoft\heroes of might and magic v - dzikie hordy\bin\h5_game.exe | "UDP Query User{5063976C-8617-4412-8443-3AC0765F87BD}C:\program files\lexmark 3600-4600 series\lxdxlscn.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxlscn.exe | "UDP Query User{50D18CAD-465A-471C-B101-4282ABFBED9A}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{7555B8A5-EAF5-45A3-B15A-CC003ACF48F6}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | "UDP Query User{7ABE8764-6813-450F-8AA9-D89FA7C34003}C:\valve\hl.exe" = protocol=17 | dir=in | app=c:\valve\hl.exe | "UDP Query User{89378BE2-930D-454B-A856-51A6438ACBDD}C:\program files\lexmark 3600-4600 series\lxdxmon.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe | "UDP Query User{965D516F-C395-42EE-80F6-219ACF129CF0}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{A7ECED80-30B9-43B7-85A2-43F194F1481B}C:\program files\microsoft office\office12\groove.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "UDP Query User{B598489F-9A58-4B82-882F-4D4D5C5489E5}C:\users\joanna\downloads\utorrent.exe" = protocol=17 | dir=in | app=c:\users\joanna\downloads\utorrent.exe | "UDP Query User{DCAD08DC-5BD7-450F-81F1-BC93EA898BE7}C:\valve\hl.exe" = protocol=17 | dir=in | app=c:\valve\hl.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B8.1224.1 "{09F55516-AC75-43EA-8127-292E5A28B7DF}" = Monster Trux Extreme - Offroad Edition "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Pasek narzêdzi "{10812DE7-2E57-4740-B226-6B3BE34AF9D7}" = Lexmark Tools for Office "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F295D95-3E65-4A53-902F-615F4B1EC627}" = ESET NOD32 Antivirus "{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 26 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4C0A8D65-4286-4B58-87FE-18AD24289285}" = NVIDIA Performance Drivers "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7AC15160-A49B-4A89-B181-D4619C025FFF}" = Samsung Samples Installer "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{E9EA2604-8AC9-47D2-8F4B-6BF60787A357}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{D45F91DE-F0FC-4D5F-9A0C-FDE5B251AAC6}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1" = ALLConverter PRO 1.1 "{94B4E2D8-A184-415C-BF9E-F699D76466BD}" = Heroes of Might and Magic IV - Z³ota Edycja "{9FB9BA8A-E711-40E6-BBF0-77ED60A2940F}" = Facebook Messenger 2.1.4587.0 "{ABC87B55-2B02-40E7-B5F2-70555F7B1BF5}" = Internet w Cyfrowym Polsacie "{AC76BA86-7AD7-1045-7B44-A95000000001}" = Adobe Reader 9.5.1 - Polish "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint "{BD49141C-188C-4B75-9F46-C2C42F2D1033}" = Nero 7 Essentials "{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas "{DD401D5B-35E2-4EA4-8585-4A44CB2DCC78}" = Jade Empire "{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer "{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0 "{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "AC3Filter_is1" = AC3Filter 1.63b "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "ALLPlayer_is1" = ALLPlayer V4.X "Anti-phishing Domain Advisor" = Anti-phishing Domain Advisor "AviSynth" = AviSynth 2.5 "blueconnect" = blueconnect "CCleaner" = CCleaner (remove only) "CoreAAC Audio Decoder" = CoreAAC Audio Decoder (remove only) "Digital Editions" = Adobe Digital Editions "ENTERPRISE" = Microsoft Office Enterprise 2007 "EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 "ffdshow_is1" = ffdshow [rev 3299] [2010-03-03] "FlashGet" = FlashGet 1.9.6.1073 "Gadu-Gadu 10" = Gadu-Gadu 10 "HaaliMkx" = Haali Media Splitter "Hard Disk Low Level Format Tool_is1" = Hard Disk Low Level Format Tool 4.12 "Inkscape" = Inkscape 0.48.2 "KLiteCodecPack_is1" = K-Lite Codec Pack 8.3.2 (Full) "Lexmark 3600-4600 Series" = Lexmark 3600-4600 Series "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.61.0.1400 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "MKV Player_is1" = MKV Player 2.0 "Mozilla Firefox 13.0.1 (x86 pl)" = Mozilla Firefox 13.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Mp3 Knife_is1" = Mp3 Knife 3.0 "Multi-Devices Production Tool_is1" = MFPT 1.65.14.0 "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "Opera 11.50.1074" = Opera 11.50 "Picasa 3" = Picasa 3 "Rapid Express_is1" = Rapid Express "RealPlayer 12.0" = RealPlayer "Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "SpeedFan" = SpeedFan (remove only) "TNod" = TNod User & Password Finder "TomTom HOME" = TomTom HOME 2.7.6.2056 "Winamp" = Winamp "WinPcapInst" = WinPcap 4.1 beta2 "WinRAR archiver" = WinRAR archiver "Xvid_is1" = Xvid 1.2.2 final uninstall [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2620197854-1719786493-1418023469-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "PhotoFiltre Studio X" = PhotoFiltre Studio X "Winamp Detect" = Detektor Winampa [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-17 12:47:32 | Computer Name = Kamil-PC | Source = RasClient | ID = 20227 Description = Error - 2012-07-18 07:14:07 | Computer Name = Kamil-PC | Source = Application Error | ID = 1000 Description = Faulting application gg.exe, version 8.0.0.10102, time stamp 0x4ae83b16, faulting module gg.exe, version 8.0.0.10102, time stamp 0x4ae83b16, exception code 0xc0000005, fault offset 0x00208afa, process id 0xf90, application start time 0x01cd64d635d30dc2. Error - 2012-07-20 16:10:54 | Computer Name = Kamil-PC | Source = RasClient | ID = 20227 Description = Error - 2012-07-21 03:07:42 | Computer Name = Kamil-PC | Source = RasClient | ID = 20227 Description = Error - 2012-07-21 03:08:40 | Computer Name = Kamil-PC | Source = RasClient | ID = 20227 Description = Error - 2012-07-21 03:08:43 | Computer Name = Kamil-PC | Source = RasClient | ID = 20227 Description = Error - 2012-07-21 03:11:15 | Computer Name = Kamil-PC | Source = RasClient | ID = 20227 Description = Error - 2012-07-22 06:09:15 | Computer Name = Kamil-PC | Source = Application Error | ID = 1000 Description = Faulting application sidebar.exe, version 6.0.6001.18000, time stamp 0x4791952a, faulting module kernel32.dll, version 6.0.6001.18631, time stamp 0x4da467f0, exception code 0xc0000002, fault offset 0x00044503, process id 0xe40, application start time 0x01cd67d9853d72e6. Error - 2012-07-24 03:01:10 | Computer Name = Kamil-PC | Source = Application Error | ID = 1000 Description = Faulting application TNODUP.exe, version 1.4.1.0, time stamp 0x4e763684, faulting module ntdll.dll, version 6.0.6001.18538, time stamp 0x4cb733dc, exception code 0xc0000005, fault offset 0x0004308e, process id 0xd18, application start time 0x01cd6969934b383f. Error - 2012-07-24 05:51:46 | Computer Name = Kamil-PC | Source = Google Update | ID = 20 Description = [ Media Center Events ] Error - 2011-04-07 15:04:05 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 2011-06-03 00:16:37 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 2012-05-22 15:53:30 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 2012-05-23 08:35:53 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 2012-05-24 00:08:16 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 2012-05-24 11:01:47 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 2012-05-25 07:07:40 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 2012-06-18 10:15:24 | Computer Name = Kamil-PC | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. [ System Events ] Error - 2012-07-24 04:18:24 | Computer Name = Kamil-PC | Source = disk | ID = 262151 Description = The device, \Device\Harddisk0\DR0, has a bad block. Error - 2012-07-24 04:18:26 | Computer Name = Kamil-PC | Source = disk | ID = 262151 Description = The device, \Device\Harddisk0\DR0, has a bad block. Error - 2012-07-24 04:18:29 | Computer Name = Kamil-PC | Source = disk | ID = 262151 Description = The device, \Device\Harddisk0\DR0, has a bad block. Error - 2012-07-24 04:43:28 | Computer Name = Kamil-PC | Source = disk | ID = 262151 Description = The device, \Device\Harddisk0\DR0, has a bad block. Error - 2012-07-24 04:43:30 | Computer Name = Kamil-PC | Source = disk | ID = 262151 Description = The device, \Device\Harddisk0\DR0, has a bad block. Error - 2012-07-24 05:50:04 | Computer Name = Kamil-PC | Source = Dhcp | ID = 1002 Description = The IP address lease 93.154.135.98 for the Network Card with network address 0026FAEF349C has been denied by the DHCP server 93.154.159.173 (The DHCP Server sent a DHCPNACK message). Error - 2012-07-24 07:18:55 | Computer Name = Kamil-PC | Source = HTTP | ID = 15016 Description = Error - 2012-07-24 07:19:31 | Computer Name = Kamil-PC | Source = Dhcp | ID = 1002 Description = The IP address lease 93.154.206.17 for the Network Card with network address 0026FAEF349C has been denied by the DHCP server 93.154.184.79 (The DHCP Server sent a DHCPNACK message). Error - 2012-07-24 07:20:40 | Computer Name = Kamil-PC | Source = Service Control Manager | ID = 7009 Description = Error - 2012-07-24 07:20:40 | Computer Name = Kamil-PC | Source = Service Control Manager | ID = 7000 Description = < End of report >