OTL Extras logfile created on: 2013-06-09 13:31:40 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Monika\Downloads 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16580) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,71 Gb Total Physical Memory | 2,17 Gb Available Physical Memory | 58,50% Memory free 8,21 Gb Paging File | 6,66 Gb Available in Paging File | 81,12% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 440,18 Gb Total Space | 335,34 Gb Free Space | 76,18% Space Free | Partition Type: NTFS Computer Name: MONICZKA | User Name: Monika | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03D247E0-43C3-41AC-81AF-2E394C691829}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{15536524-A04C-46F1-84A1-088876A2514C}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{1E2BF795-DFC9-4654-B65C-B0FABA419DD1}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1FBE6245-3DAD-4429-9D4A-C49F46EA3446}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2B9DE2A6-A7B2-4665-B0ED-60E5AF6F04B2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2BF86605-5C7E-4909-9CFC-2A2535BC5374}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\dashost.exe | "{3142335F-2AAF-4A48-B6D8-78022C40D6A6}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{342968C7-22BA-4F2D-8318-21B3C93B70B8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{44E4DEF4-BDBE-4336-8114-FF96368269E6}" = rport=10243 | protocol=6 | dir=out | app=system | "{5EB8283C-A369-419A-A2AE-61914D687D3A}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{5F87E89F-3305-4B02-9068-621F4A862B5D}" = lport=2869 | protocol=6 | dir=in | app=system | "{64E80B84-B0DE-45A0-8D62-E397D9368B3D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{65C8B6DA-E239-43CD-AD3B-59C1062F30FB}" = rport=139 | protocol=6 | dir=out | app=system | "{6F27EC3A-48A8-4C1E-86AB-5CDA7FD51B1F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{713BD7CB-F635-418D-9597-AD84777B5637}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{75CAAAE5-84B3-4CF0-9E2A-020672EF87FB}" = lport=10243 | protocol=6 | dir=in | app=system | "{7EB5EFD9-4C94-4020-A46E-E3BBEF710943}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8B5C1FEF-1714-484E-A00E-CB92F92E4EA9}" = rport=445 | protocol=6 | dir=out | app=system | "{8CED1456-9F34-4080-AF4F-C32680AEE7A3}" = lport=139 | protocol=6 | dir=in | app=system | "{98FB99DC-57C7-49AA-BA49-EC7109C652B8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{9A9E1133-4DEF-45E4-ACCD-AE1C245E1F91}" = rport=137 | protocol=17 | dir=out | app=system | "{9D0D9C68-8055-447A-9DFE-D4F53DCCD215}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{AF7D8123-D3A7-4AE4-BCB0-58F2AB36829E}" = rport=138 | protocol=17 | dir=out | app=system | "{B1EB57B6-CC3E-4368-BD47-CBAF5D2673C5}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{BCA9D888-4B7E-4BE8-BFB9-E541643B2E56}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C2AC14CD-513F-493B-96AB-CF382AC20A7F}" = lport=138 | protocol=17 | dir=in | app=system | "{CEE87C96-D0C0-4D9E-97E7-D88528DA6C4A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{DDD117BB-D8B8-4A49-B2BC-B9F958F6B283}" = lport=445 | protocol=6 | dir=in | app=system | "{DF481C8E-808F-4DB8-A687-63D9C196364F}" = rport=2869 | protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{E2182D8B-2707-4A1F-84AD-10B18F003581}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{EC65FA01-A054-4EE6-9CEA-BAA11555E396}" = lport=137 | protocol=17 | dir=in | app=system | "{F26BBD4A-E010-4B65-95B2-86E4B05143D1}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{FF4FA129-4E7B-4458-914D-44149AA53620}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0DE3285C-F05C-4C68-8CDD-ABE21DEBE68D}" = dir=out | name=evernote | "{121FBF99-86AF-457B-A193-643E1C5A8FAF}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{15646520-F785-47AC-9ED5-51A375AE217C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{1C742541-8C31-4DBC-8D66-F89364F109A9}" = dir=out | name=jamie's recipes | "{1DE87183-5F5C-477E-A25D-059AE1B084BB}" = dir=out | name=skype | "{1E2CA06F-6DF1-4A3C-BCBC-4B847208A1A7}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1E51D7F1-83C2-43C3-9B34-B1B831BB912D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1EDD2DF8-82FB-454E-BA5A-301F8EE584BC}" = dir=out | name=merriam-webster dictionary | "{23521C97-C749-4A81-BBE3-DE7A44799092}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{317989E7-8B2D-456F-8C81-18C9B69A0AB2}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{35452612-4F53-4D46-B83E-15AA3C6F3C3A}" = dir=out | name=kindle | "{39174352-7238-44E3-AFDE-6688F5489CEB}" = dir=out | name=adera | "{39B9BBA1-1A3E-408E-8521-55ABF22D2A9F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe | "{3F2E6FCA-AAAA-4E5C-BE85-A19B3C33A790}" = dir=out | name=windows_ie_ac_001 | "{419843B2-F62E-477B-B439-71716CD7C5FD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{43C2042C-3600-4AC4-8F53-BCCAC0733D17}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{4478DC59-D08F-4D29-8F8D-19A8F0BE4A6D}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{456566BA-D208-4701-B422-01DF0C5F15D4}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{47E53254-087D-4C4D-829E-0C8B966B6BA6}" = dir=in | name=tvn player | "{648B3F00-3E7F-4374-948A-6CE7C48500E3}" = dir=out | name=photoeditor | "{6547FCC4-C3F4-47C8-845D-4A3AAAAEB0B7}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{666D49CA-4403-481F-B8C6-3F3AE595AFCD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{691F94BA-625B-45D0-A8B0-D0334759716B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{69E447B9-A8B6-408F-AD4D-B5399A524614}" = protocol=6 | dir=out | app=system | "{6A60D766-E5EE-4303-B815-BDEBDEB9041E}" = dir=out | name=fresh paint | "{70B3275D-7A57-4B11-9210-ADBC3247CBD5}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{7690FFFB-2DB1-4ABA-BCFB-3C89EEF216A9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{7B87B13D-9C53-42B5-946D-4DF6551E8AEB}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{7D43EA8D-FFBA-439E-A53B-4D7C35850F48}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{7D5A5FA2-E069-4881-BA1B-C435CE3EE533}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7E312572-F83C-44F8-AFB8-325C0B03EBF4}" = dir=out | name=chaton | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{82E31EBC-DAA7-4582-91A5-18E84B6882DD}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{8392E43C-DAC1-4BF5-9402-EE80D606E198}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{9072FC2D-EBE1-4B03-A805-3E55B28194C4}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{933034BC-F6B0-4B4A-9BF2-675C2FF323F1}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{93AEC977-FDB3-479C-A6A6-165BBB6F0C9B}" = dir=in | name=evernote | "{98DA8D33-CE6D-40E2-BA02-60C18CE49EF1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{9CDCB9D0-E540-4FD0-B0D2-E4E05D02DB04}" = dir=out | name=s gallery | "{A1D081BC-946D-4163-9EF4-FE69292130E0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A20D2618-BE7C-403E-959F-3391B6B90120}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{A3CEC11E-4530-49E5-9E4C-3DE44CD92E57}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{A7A0A51C-ED3A-409A-ADC0-E74C01F02F37}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{A87974C6-858B-4984-A4E5-9C86E4D68EAA}" = dir=out | name=tvn player | "{AB4D1C98-9845-4F59-843A-E92EE8B1FDAF}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{AD812AA4-9CF3-4491-A013-B0A85ED2952E}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{B00F002F-055D-41DD-8662-B40CFDE08D45}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{B190999A-D0C3-453B-A607-538965D3C952}" = dir=out | name=onet news | "{B87C108A-5065-4841-8E52-BE13B9014F92}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{BF7B37B4-F0A3-462B-8688-8C3112290CF8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{C05FF8C9-EAFB-4539-9A52-61CB6A846292}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{CDE86CEB-2C5D-4678-9C8E-5243D6B59751}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{CF3C78A7-47F9-496D-9CB2-9F6B9A035E8C}" = dir=out | name=s camera | "{D47930DC-3442-49C4-8B86-8AC74B9085C7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{DD26B556-5552-4B3C-8039-0BCB969B29D8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{E21967C5-3557-49B6-BF0C-379E8BD8D3D8}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{E6344763-A434-4C32-BEDE-0E9055913BAB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E8F02728-B2DD-40C5-95C7-1ABC4BBDEA1A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe | "{E968E3B3-910E-4044-AF60-423577F732B4}" = dir=in | name=skype | "{EE5790F5-C7E3-46E5-9252-703F59D1682F}" = dir=in | name=kindle | "{F1920EEC-DD46-459E-946B-B0CD29F391AA}" = dir=out | name=match'a'shape | "{F3042ADA-1CB9-4E78-999A-40AE728B9359}" = dir=out | name=norton studio | "{F6B27730-8689-4DE0-BE1E-0C91ABF10900}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{F86272F5-6AE4-4E80-9D4E-DBD82B8AA175}" = dir=out | name=s player | "{FC54D535-556F-47FB-87A6-DC60D7738509}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{4085F9E6-0B9F-4709-BFAC-D5B1D12C1B7B}C:\totalcmd\totalcmd64.exe" = protocol=6 | dir=in | app=c:\totalcmd\totalcmd64.exe | "UDP Query User{CE6EC300-48F5-4E28-BB03-11C9F6C3D80B}C:\totalcmd\totalcmd64.exe" = protocol=17 | dir=in | app=c:\totalcmd\totalcmd64.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{332518C0-0D31-4FFA-9D15-24C9C3D70B08}" = Support Center "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{969B5BFB-094D-4D96-AC0C-C1A2675DB583}" = S Agent "{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0613 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{C85A891D-7AB4-46AE-84F0-B0C3FAC82280}" = Help Desk "{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}" = Quick Starter "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "{F842F8B0-6942-4930-821F-543E976B2C66}" = MSVCRT110_amd64 "9F04C462DAB591BDCCE784F77E4D4F1736010B92" = Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass (07/27/2012 20.57.1.735) "Elantech" = ETDWare PS/2-X64 11.7.2.1_WHQL "RawTherapee 3.0.1" = RawTherapee 3.0.1 "Totalcmd64" = Total Commander 64-bit (Remove or Repair) "WinRAR archiver" = WinRAR 4.20 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00AA59D7-B92D-4A06-8D06-0596081C0E68}" = Photo Gallery "{039EA659-E421-45C6-8913-BED5D69B5536}" = User Guide "{1057511B-F8FE-4230-9ED3-AB949A57EE4A}" = Windows Live PIMT Platform "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Recovery "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program "{29315CEC-E6CE-4394-84DC-6F862E8D9A52}" = Windows Live UX Platform "{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "{2AE414B5-7FE6-49A3-93C8-D864162CDEBC}" = Windows Live UX Platform Language Pack "{2D416A80-0BB1-4D8B-B770-7BE8F53D5937}" = Windows Live UX Platform Language Pack "{3B4E6027-AED5-4169-B030-B450E5A0F396}" = SW Update "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{40F55150-F43D-4C9F-9A00-1A0A6F1EB7F0}" = Movie Maker "{46316411-80D8-4F68-8118-696E05FCE199}" = Windows Live Essentials "{4689F012-C8E3-4F6E-BDEF-13671D53A6DC}" = Windows Live UX Platform Language Pack "{4F9A382F-4478-4036-905C-F77DF2EA0370}" = Windows Live SOXE "{4FA8F084-C42F-45E1-B7E5-E0C8A1083DC5}" = Windows Live SOXE Definitions "{52E5DE60-C96B-42CC-9A37-FE04725940AE}" = Settings "{5547725A-B333-475C-93C7-3B89267A72D4}" = Support Center FAQ "{5CC4C963-F772-4766-BFF2-DE551E205EE9}" = Photo Common "{60A1253C-2D51-4166-95C2-52E9CF4F8D64}" = Photo Gallery "{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX "{64DF7404-9D46-44AF-AFA1-A2F8D5648C2D}" = Windows Live Photo Common "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{698ED639-3A26-49EF-B1EF-CD89CB97C778}" = Windows Live Essentials "{76EE8FE7-1957-4C51-9074-4930A8CFB1AF}" = Windows Live Installer "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78F35489-621D-4FFD-BCE7-2C7C3897E47C}" = Windows Live "{7914488D-F56B-464F-B735-F8E972E5E208}" = Photo Common "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{8EEED220-D348-4F49-8C82-B11F6C5450C7}" = Movie Maker "{90B936B2-33E6-4FE8-9A64-08EEB42AF2B1}" = Podstawowe programy Windows Live "{91786428-D4AA-476D-8AF9-A63FFAC2901F}" = Allshare Play Link "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office "{96AA21F4-C8CE-4380-995A-992536463263}" = Galeria fotografii "{9846E46F-07E0-4BDF-985A-E3FBA8C15877}" = Movie Maker "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B2E55F8-5BA8-4A45-9682-ACB6F2CC0DA5}" = Photo Gallery "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent "{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}" = Easy File Share "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.7) MUI "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{BA73469B-D8C7-4FE3-B33C-1340D09F0709}" = Windows Live Communications Platform "{CCDB7ADB-1643-4C30-B39D-1562CFE51420}" = Movie Maker "{D48BCCD6-D2E2-42F4-B8E8-D7BC10C568EC}" = Windows Live UX Platform Language Pack "{D531FC91-6F4E-49A7-B912-15289D05B6F8}" = Photo Common "{D71BC54E-A4E6-4E06-866C-FD6EE16EA187}" = Movie Maker "{D77A6FED-256C-4E2F-9873-59C92C854A4E}" = Photo Common "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10 "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}" = E-POP "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Obsługa programów Apple "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "{FE8DFDD0-A543-4A83-B7A9-C411138194D5}" = Galerie de photos "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10 "Intel AppUp(SM) center 33070" = Intel AppUp(SM) center "KeePassPasswordSafe2_is1" = KeePass Password Safe 2.20 "Mozilla Firefox 20.0.1 (x86 pl)" = Mozilla Firefox 20.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NARA" = Norton Online Backup ARA "NIS" = Norton Internet Security "PhotoScape" = PhotoScape "Plants vs. Zombies" = Plants vs. Zombies "WinGimp-2.0_is1" = GIMP 2.6.11 "WinLiveSuite" = Windows Live [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-04-16 04:06:02 | Computer Name = Moniczka | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: GuaranaAgent.exe, wersja: 2.0.7.0, sygnatura czasowa: 0x503364b2 Nazwa modułu powodującego błąd: GuaranaAgent.exe, wersja: 2.0.7.0, sygnatura czasowa: 0x503364b2 Kod wyjątku: 0x40000015 Przesunięcie błędu: 0x000000000021dc91 Identyfikator procesu powodującego błąd: 0x84c Godzina uruchomienia aplikacji powodującej błąd: 0x01ce3a7939b77fda Ścieżka aplikacji powodującej błąd: C:\Program Files\Samsung\Support Center\GuaranaAgent.exe Ścieżka modułu powodującego błąd: C:\Program Files\Samsung\Support Center\GuaranaAgent.exe Identyfikator raportu: 7a3e5685-a66c-11e2-beb4-20689d6d18fe Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2013-04-16 13:32:19 | Computer Name = Moniczka | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: GuaranaAgent.exe, wersja: 2.0.7.0, sygnatura czasowa: 0x503364b2 Nazwa modułu powodującego błąd: GuaranaAgent.exe, wersja: 2.0.7.0, sygnatura czasowa: 0x503364b2 Kod wyjątku: 0x40000015 Przesunięcie błędu: 0x000000000021dc91 Identyfikator procesu powodującego błąd: 0x314 Godzina uruchomienia aplikacji powodującej błąd: 0x01ce3ac8541237e2 Ścieżka aplikacji powodującej błąd: C:\Program Files\Samsung\Support Center\GuaranaAgent.exe Ścieżka modułu powodującego błąd: C:\Program Files\Samsung\Support Center\GuaranaAgent.exe Identyfikator raportu: 96017607-a6bb-11e2-beb4-20689d6d18fe Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2013-04-19 10:00:27 | Computer Name = Moniczka | Source = Application Hang | ID = 1002 Description = Program gimp-2.6.exe w wersji 0.0.0.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 13bc Godzina rozpoczęcia: 01ce3d0627fe3839 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Program Files (x86)\GIMP-2.0\bin\gimp-2.6.exe Identyfikator raportu: 7a390e7b-a8f9-11e2-beb5-20689d6d18fe Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2013-04-22 02:18:24 | Computer Name = Moniczka | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2147467263. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2013-04-28 04:58:02 | Computer Name = Moniczka | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2147467263. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2013-04-28 04:58:02 | Computer Name = Moniczka | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2147467263. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2013-04-28 04:58:03 | Computer Name = Moniczka | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail nie powiodła się. Błąd: -2147467263. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2013-04-29 08:31:28 | Computer Name = Moniczka | Source = Application Hang | ID = 1002 Description = Program rawtherapee.exe w wersji 0.0.0.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: d3c Godzina rozpoczęcia: 01ce44a8d0e23ad8 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Program Files\RawTherapee3.0.1\rawtherapee.exe Identyfikator raportu: b59c8138-b0c8-11e2-beb9-20689d6d18fe Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2013-04-29 08:33:16 | Computer Name = Moniczka | Source = Application Hang | ID = 1002 Description = Program gimp-2.6.exe w wersji 0.0.0.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 5ec Godzina rozpoczęcia: 01ce44a39d483659 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Program Files (x86)\GIMP-2.0\bin\gimp-2.6.exe Identyfikator raportu: f4d7862d-b0c8-11e2-beb9-20689d6d18fe Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2013-05-03 10:21:48 | Computer Name = Moniczka | Source = Application Hang | ID = 1002 Description = Program gimp-2.6.exe w wersji 0.0.0.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 20c8 Godzina rozpoczęcia: 01ce480975130365 Godzina zakończenia: 0 Ścieżka aplikacji: C:\Program Files (x86)\GIMP-2.0\bin\gimp-2.6.exe Identyfikator raportu: c4bb8b84-b3fc-11e2-beba-20689d6d18fe Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: [ System Events ] Error - 2013-05-19 17:00:19 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-19 17:00:44 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-20 02:44:14 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-20 03:22:38 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-20 10:07:49 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-20 12:46:11 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-20 15:28:01 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-20 16:16:00 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-21 09:55:38 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 2013-05-21 09:55:55 | Computer Name = Moniczka | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = < End of report >