OTL Extras logfile created on: 2013-06-02 16:43:58 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = I:\ 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16576) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,97 Gb Total Physical Memory | 2,69 Gb Available Physical Memory | 67,73% Memory free 7,93 Gb Paging File | 6,62 Gb Available in Paging File | 83,44% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 232,88 Gb Total Space | 62,11 Gb Free Space | 26,67% Space Free | Partition Type: NTFS Drive D: | 221,16 Gb Total Space | 130,16 Gb Free Space | 58,85% Space Free | Partition Type: NTFS Drive I: | 490,38 Mb Total Space | 488,63 Mb Free Space | 99,64% Space Free | Partition Type: FAT Computer Name: BARTŁOMIEJ-NB | User Name: Bartłomiej | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3482223651-1940617740-2938588835-1001\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- D:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07955452-BD60-4AC9-8A75-51E75B2A3008}" = lport=138 | protocol=17 | dir=in | app=system | "{16C7E1D7-57AB-41D4-92E8-6B8B280A3FED}" = rport=139 | protocol=6 | dir=out | app=system | "{1E959AA8-528A-4DB4-BFC3-DEF86380DCDD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{316B8B3B-B54D-499A-9416-9F696910FB7E}" = rport=137 | protocol=17 | dir=out | app=system | "{3BB23269-CDD1-4CF3-8BDF-BE0B4606C000}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{4C09208B-2556-454A-9CAC-1CA2351F1EF7}" = lport=445 | protocol=6 | dir=in | app=system | "{6D0F84BB-C05E-478F-A4B9-A253911A4B71}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7172EB33-F0ED-4DBF-A94E-8314CC0C91A8}" = lport=139 | protocol=6 | dir=in | app=system | "{7748326C-A68E-4832-B5A8-DEEBB8D0A27E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{82D52720-A3D5-44DA-B55F-EFC24BBC26AB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{9E5A7A49-6311-4C6D-841A-831EE4FC31B3}" = rport=138 | protocol=17 | dir=out | app=system | "{A2F02E30-A697-43AF-969B-924691E96A79}" = lport=137 | protocol=17 | dir=in | app=system | "{F2843D3B-1AED-4BCA-8AA0-031556719CF1}" = rport=445 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1E55ABC8-2FE8-4282-B589-AA2E413502FA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{2133F5E2-117D-46EE-8805-6659BA05C569}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2F50F099-01F1-4CEC-A0D7-8CE9FEFACA26}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{3013F3DA-0D75-4614-B023-05BC85D3BBC1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{35119AC8-DCCB-4B9A-9466-3DC5FCBEA88B}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{3768CCBC-8932-41D8-8E57-781FFB511B3A}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{470AFD5F-6B82-4A2D-8854-7065666A16AD}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{4EFD7960-1B16-4236-A1DB-04FC3CEACFA1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{62FCA069-0A01-4415-8A12-12EDEF25D613}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{65171D52-1B52-4828-A00D-D37CDFB9024F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{6FEB4342-C2C6-41BD-B79C-491F281E4380}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{775FF73E-6DAD-4954-9358-6E2ECB66C78C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{81A3FBF1-DB7B-47FD-8E54-68A453DC3180}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{858CB972-8263-48B3-9967-D24F8D46E2FC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{9063C17F-9F92-4885-844B-77D645127F7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9BFF7792-DEFF-40EE-9839-F6BE3B45E96A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{A397BA41-0E8E-4862-94EF-C5C16D9D3BAE}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{AF157C49-D2BC-4296-B5FA-2FC6B5986700}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{B9293D48-8C6C-4854-8B5B-DA2DD4C06EC3}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{C0996C59-1A35-45DC-AFB6-FED078492B5E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C2279453-69BA-4236-AF06-D157D494CBDE}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{C338BD4B-DEE6-4A2B-BC49-A6A2A7EEB614}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{D10F505C-F761-4441-A2E8-067AD40BDFCB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{D18B0EBD-D0BB-48D5-A994-D65E969475F2}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{D201CF66-3F7A-438A-B4C8-B411CF83931A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{D782FE3C-3BC1-474B-9D37-26A499640E21}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{E96396DB-E896-4DD2-81E2-60AB97D7F8F3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{EB55DA94-98E3-4A3F-8FB8-85686115B6C6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{FBC930D9-59EA-4287-901F-64EBE9003013}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "TCP Query User{0E124336-FA0F-4682-8510-6067F2A31E7F}D:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe" = protocol=6 | dir=in | app=d:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe | "TCP Query User{1D476C7A-29D5-462C-A262-12AD2AC01066}D:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\games\world_of_tanks\wotlauncher.exe | "TCP Query User{26A49DF3-801F-485F-A5D0-9298EAD47BE4}D:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe" = protocol=6 | dir=in | app=d:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe | "TCP Query User{35086C2D-5D0A-4C09-B346-FE0FA9BD49C2}D:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=d:\games\world_of_tanks\worldoftanks.exe | "TCP Query User{5E0D9A89-D1F0-4CE0-9101-3FEEB279FD3C}C:\program files (x86)\hp\common\hpdevicedetection3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hp\common\hpdevicedetection3.exe | "TCP Query User{7358A612-BCDA-457A-84B6-7CFD1E4C6771}D:\program files (x86)\metin2\metin2client.bin" = protocol=6 | dir=in | app=d:\program files (x86)\metin2\metin2client.bin | "UDP Query User{7A3FDF3D-2693-456F-B903-3EF9EF1D36FC}D:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe" = protocol=17 | dir=in | app=d:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe | "UDP Query User{87B56F6C-2073-408E-8945-8B11EA23B753}D:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe" = protocol=17 | dir=in | app=d:\users\bartłomiej\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe | "UDP Query User{C155D350-715B-4707-8FE4-F77A9EBA29E5}C:\program files (x86)\hp\common\hpdevicedetection3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hp\common\hpdevicedetection3.exe | "UDP Query User{C36E7229-A535-4B3B-8C4A-2AE441D9424F}D:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=d:\games\world_of_tanks\worldoftanks.exe | "UDP Query User{F544B81C-17B0-40EC-95EC-41EE529613A7}D:\program files (x86)\metin2\metin2client.bin" = protocol=17 | dir=in | app=d:\program files (x86)\metin2\metin2client.bin | "UDP Query User{FCD73BA3-5EB0-4AA9-A3B4-9EEC6751ABC0}D:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\games\world_of_tanks\wotlauncher.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5783F2D7-8001-0415-0102-0060B0CE6BBA}" = AutoCAD 2010 - Polski "{5783F2D7-8001-0415-1102-0060B0CE6BBA}" = Pakiet językowy programu AutoCAD 2010 - polski "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6051912A-F7B8-445C-A99D-81AA4C118836}" = HP Deskjet Ink Advant K209a-z All-in-One Driver Software 14.0 Rel. 6 "{81D2827C-FA6D-40E7-BBAD-3F72E67D6223}" = Autodesk Robot Structural Analysis Professional 2013 - Polish regional settings "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0015-0415-1000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0015-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0415-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0016-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0415-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0018-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0415-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-0019-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0415-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001A-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0415-1000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001B-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUS_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0415-1000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-001F-0415-1000-0000000FF1CE}_Office14.PROPLUS_{329A3D98-9583-4B84-B18B-498E7AB65C43}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-002C-0415-1000-0000000FF1CE}_Office14.PROPLUS_{BFEB53FA-3044-47FD-BB50-9DCBBEED79EF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2010 "{90140000-0043-0415-1000-0000000FF1CE}_Office14.PROPLUS_{FF5F6090-64DF-4BF6-BADD-71A64FDA70D2}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0415-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-0044-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-006E-0415-1000-0000000FF1CE}_Office14.PROPLUS_{3A96ABFF-5202-47B1-B5A2-DDE76563AF61}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0415-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00A1-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0415-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{90140000-00BA-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{AEA27EB6-3B7A-4BDB-9639-A1E1B3C6D3A8}" = Autodesk Robot Structural Analysis Professional 2013 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "AutoCAD 2010 - Polski" = AutoCAD 2010 - Polski "Autodesk Robot Structural Analysis Professional 2013" = Autodesk Robot Structural Analysis Professional 2013 "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "scilab-5.4.1 (64-bit)_is1" = scilab-5.4.1 (64-bit) "Shop for HP Supplies" = Shop for HP Supplies [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{0A50CB27-D2D5-4B7D-A001-30B1782A450B}" = DJ_AIO_06_K209a-z_SW_Min "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = BrowserProtect "{18192D3F-5537-4560-AD89-D695F72AF91D}" = OpenOffice.org 3.4.1 "{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1" = World of Tanks "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{2E295B5B-1AD4-4d36-97C2-A316084722CF}" = Python 2.7.2 "{2F48C80C-3A76-495A-A4B5-C0CC946FEEBD}" = Autodesk Download Manager "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status "{5A3ECDDA-562C-4281-BFE5-A4C8F32EACA3}" = K209a-z "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter "{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{80A07844-CA64-4DE4-AB61-D37DDBE8074F}" = PDF Architect "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{8B743AA0-53B2-11D2-808A-00600895FB43}" = Heroes of Might and Magic III - Złota Edycja "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A2F166A0-F031-4E27-A057-C69733219436}_is1" = RaiderZ "{A34CC51D-C2FF-4E0E-9F27-28B0249A15DD}" = HP Product Detection "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Obsługa programów Apple "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "avast" = avast! Free Antivirus "Bandicam" = Bandicam "BandiMPEG1" = Bandisoft MPEG-1 Decoder "bi_uninstaller" = Bundled software uninstaller "DAEMON Tools Lite" = DAEMON Tools Lite "delta" = Delta toolbar "Delta Chrome Toolbar" = Delta Chrome Toolbar "Mozilla Firefox 19.0.2 (x86 pl)" = Mozilla Firefox 19.0.2 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Odinstaluj Soldis PROJEKTANT_is1" = Soldis PROJEKTANT "WinRAR archiver" = WinRAR 4.20 (32-bitowy) "wxPython2.8-unicode-py27_is1" = wxPython 2.8.12.1 (unicode) for Python 2.7 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3482223651-1940617740-2938588835-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "GG" = GG "Mozilla Firefox 20.0.1 (x86 pl)" = Mozilla Firefox 20.0.1 (x86 pl) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-05-25 08:25:49 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-05-25 15:25:30 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-05-26 10:07:58 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-05-26 11:23:06 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-05-27 06:47:01 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-05-28 12:07:21 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-05-28 19:51:30 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-05-28 20:12:57 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-06-01 19:20:35 | Computer Name = Bartłomiej-Nb | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2013-06-02 07:49:26 | Computer Name = Bartłomiej-Nb | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: heroes3.exe, wersja: 3.2.0.0, sygnatura czasowa: 0x40e04aad Nazwa modułu powodującego błąd: MP3DEC.ASI, wersja: 3.0.0.0, sygnatura czasowa: 0x36910efa Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000076f1 Identyfikator procesu powodującego błąd: 0x1a70 Godzina uruchomienia aplikacji powodującej błąd: 0x01ce5f7875f41500 Ścieżka aplikacji powodującej błąd: D:\Program Files (x86)\Ubisoft\Heroes of Might and Magic III - Zlota Edycja\heroes3.exe Ścieżka modułu powodującego błąd: D:\Program Files (x86)\Ubisoft\Heroes of Might and Magic III - Zlota Edycja\MP3DEC.ASI Identyfikator raportu: 7920eefb-cb7a-11e2-b15b-00261872ee2e [ System Events ] Error - 2013-05-29 05:50:37 | Computer Name = Bartłomiej-Nb | Source = Microsoft-Windows-Bits-Client | ID = 16392 Description = Uruchomienie usługi BITS nie powiodło się. Błąd 2147943515. Error - 2013-05-29 05:50:37 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7024 Description = Usługa Usługa inteligentnego transferu w tle zakończyła działanie; wystąpił specyficzny dla niej błąd %%-2147023781. Error - 2013-05-29 05:50:37 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7023 Description = Usługa Serwer zakończyła działanie; wystąpił następujący błąd: %%13 Error - 2013-06-02 09:36:39 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7031 Description = Usługa BrowserProtect niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error - 2013-06-02 09:36:39 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7034 Description = Usługa hpqcxs08 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2013-06-02 09:36:39 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7034 Description = Usługa Usługa HP CUE DeviceDiscovery niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2013-06-02 09:37:14 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7032 Description = Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Uruchom usługę ponownie) po nieoczekiwanym zakończeniu usługi BrowserProtect, ale ta akcja nie powiodła się przy następującym błędzie: %%1056. Error - 2013-06-02 09:48:42 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7030 Description = Usługa PEVSystemStart jest oznaczona jako usługa interakcyjna. System jest jednak skonfigurowany tak, aby nie zezwalać na usługi interakcyjne, dlatego ta usługa może nie działać właściwie. Error - 2013-06-02 09:52:36 | Computer Name = Bartłomiej-Nb | Source = Application Popup | ID = 1060 Description = Ładowanie sterownika \??\C:\ComboFix\catchme.sys zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Error - 2013-06-02 09:53:44 | Computer Name = Bartłomiej-Nb | Source = Service Control Manager | ID = 7030 Description = Usługa PEVSystemStart jest oznaczona jako usługa interakcyjna. System jest jednak skonfigurowany tak, aby nie zezwalać na usługi interakcyjne, dlatego ta usługa może nie działać właściwie. < End of report >