OTL Extras logfile created on: 2014-02-27 11:00:20 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Raven\Desktop\Download 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16518) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 7,19 Gb Total Physical Memory | 5,04 Gb Available Physical Memory | 70,05% Memory free 8,32 Gb Paging File | 5,77 Gb Available in Paging File | 69,41% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 209,46 Gb Total Space | 113,56 Gb Free Space | 54,21% Space Free | Partition Type: NTFS Drive D: | 22,70 Gb Total Space | 2,25 Gb Free Space | 9,91% Space Free | Partition Type: NTFS Drive F: | 488,28 Gb Total Space | 258,00 Gb Free Space | 52,84% Space Free | Partition Type: NTFS Drive G: | 209,96 Gb Total Space | 134,38 Gb Free Space | 64,00% Space Free | Partition Type: NTFS Drive H: | 7,80 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: KALIVA | User Name: Raven | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1456361715-324973510-1321076691-1002\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [ACDSee 10.0.Browse] -- "C:\Program Files (x86)\ACD Systems\ACDSee\10.0\ACDSeeQV10.exe" "%1" (ACD Systems) Directory [ChomikBox.Upload] -- "C:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( ) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [ACDSee 10.0.Browse] -- "C:\Program Files (x86)\ACD Systems\ACDSee\10.0\ACDSeeQV10.exe" "%1" (ACD Systems) Directory [ChomikBox.Upload] -- "C:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( ) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1A597C5C-5A88-4D8A-A8E3-2C94A6C58A6F}" = rport=138 | protocol=17 | dir=out | app=system | "{1C5DE382-16E3-4050-B0A0-8C1725B48A05}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{47AE96EA-6C51-48C2-8075-DF094FF3862C}" = lport=137 | protocol=17 | dir=in | app=system | "{584AC14A-51CB-4B41-8705-F4B200A148DF}" = lport=445 | protocol=6 | dir=in | app=system | "{703642C7-81D7-4F03-A70C-946DD27F29E8}" = rport=137 | protocol=17 | dir=out | app=system | "{7DCCCF0B-B77E-45AB-9958-9DE8AFEB59E5}" = rport=139 | protocol=6 | dir=out | app=system | "{9BD610AC-EE8A-4613-BC82-4981E77CDBE3}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{AC7F85CB-2312-40E2-AE38-05C59B59FBF8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{C08FA71E-9D54-43C7-91D6-9D1BBE4BA3C6}" = lport=138 | protocol=17 | dir=in | app=system | "{CE610FAF-22DB-4DC3-85C7-45E3EE178BA0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{CE61251A-5168-467C-8A9A-61844A47F511}" = lport=139 | protocol=6 | dir=in | app=system | "{E65B1982-D1E4-43E0-9BBD-48D81C49EA81}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F6914EF1-B51C-4F5A-B6C9-51DFA1ABC90F}" = rport=445 | protocol=6 | dir=out | app=system | "{FEB9FE5E-265F-46BE-A4C5-D9A38D89465F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{097FDB96-9A4B-4D6D-969F-0C8320E11029}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{0B5CE4A7-D334-4729-8566-7A789C7385D4}" = dir=in | app=c:\program files (x86)\hpconnectedmusic\hpconnectedmusic.exe | "{0C9D5868-980C-4471-8C08-DC8F0EA30F36}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{0DBE4778-E46D-42AC-B623-044682097A5D}" = protocol=17 | dir=in | app=c:\users\raven\appdata\roaming\utorrent\utorrent.exe | "{10415C69-BCD5-403A-A85F-834098C180C4}" = dir=out | name=@{microsoft.bingmaps_2.0.2009.2356_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{1416D46E-E628-4EEF-AA65-4B60783E87E5}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{168E70AB-3055-4849-8A4B-F6028902293B}" = dir=out | name=@{microsoft.zunevideo_2.2.41.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{191487FE-D290-4C6D-BE29-896BB8402A76}" = dir=out | name=windows_ie_ac_001 | "{1C3D5C13-8BA2-4FB0-8174-9FAD240E2E04}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{1C773CCD-645B-4E2D-AFC7-F906C64F5AE1}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{2409BF86-04BA-4EEA-AA71-9B5EFE1A3BE5}" = protocol=17 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{24DE9B09-061E-4201-9FAE-54F92C96240C}" = dir=out | app=%localappdata%\hpconnectedmusic\application\hpconnectedmusic.exe | "{36E924B5-E97D-40FC-B77B-2DC2583CE651}" = dir=in | name=sonicwall mobile connect | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{5009B839-09FF-4B91-9472-330072F24A5A}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{52F85852-7B48-4E7B-8EC5-1FF288C12D81}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{53A366B1-1784-4DD5-8DE1-C55497B48354}" = dir=out | name=check point vpn | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{58C0FFBC-55A0-4C9C-882D-1A6B94EF1070}" = dir=out | name=windows_ie_ac_001 | "{591FFE66-E0F8-4AE1-AE53-8776136E21ED}" = dir=in | app=%localappdata%\hpconnectedmusic\application\hpconnectedmusic.exe | "{5D6B6203-70B4-4FFE-8B24-45C362E6BB74}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{6088CB84-A59F-4792-A4AC-2691F2F5FD15}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{6192226E-31A5-4C7D-8522-FBC6901F2474}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\powerdvd12ml.exe | "{61EFC615-C86D-42FE-92E7-A044E9EE950A}" = protocol=6 | dir=in | app=c:\users\raven\appdata\roaming\utorrent\utorrent.exe | "{63ACD3B5-4D25-4A49-8479-E7716472A31D}" = dir=in | name=f5 vpn | "{6A4E1D0E-8A22-4E9C-9773-A0476F2D851F}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{6E7FC6C3-4D8D-4877-85EC-6BE3BDCEBEC3}" = dir=in | name=check point vpn | "{734F56A3-8E6D-49FA-98C4-967071DE84F6}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe | "{75AC0212-ECB2-412C-BC67-9B1191DFD920}" = dir=out | name=@{microsoft.skypeapp_1.3.0.112_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{78938A80-3146-41A4-BDFC-C97BC04B8AAD}" = protocol=6 | dir=in | app=c:\users\raven\appdata\roaming\dropbox\bin\dropbox.exe | "{7A8F3F38-7438-4AC4-A370-A954C2DCDA53}" = dir=in | app=%localappdata%\hpconnectedmusic\application\spotify_helper.exe | "{7D0FA5B8-07F1-4476-A03C-442AA43A7639}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe | "{7F6BB9FB-7F2D-4B5D-8355-972E0EFDB2DB}" = dir=in | app=c:\users\administrator\appdata\local\microsoft\skydrive\skydrive.exe | "{7FE730F2-7C60-4054-83E3-001F0E475084}" = dir=out | name=@{microsoft.xboxlivegames_2.0.20.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{8277DAAC-751D-479C-830B-4481E2702931}" = dir=in | name=@{microsoft.skypeapp_1.3.0.112_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{82FACDD7-299E-4F49-99AB-F657C6D2B728}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{89217C53-B102-4CFC-9098-260B3DED51A3}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{99C48050-F2A4-4422-8E8F-1B6931F7B206}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\kernel\dmr\powerdvd12dmrengine.exe | "{9AA4D78A-9A52-4CF7-A365-4A3882A6EE83}" = dir=out | name=youcam for hp | "{9BC58834-A3A6-4C58-B5C5-E2D5D6137CBF}" = dir=in | name=juniper networks junos pulse | "{9CB691E3-4555-4DFA-8E57-79F3A207224D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{9FDD0B8B-6653-4B03-B0A3-5B8C60ED964E}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\movie\powerdvd.exe | "{A4EAAC25-49C2-43FB-BDED-B1D398ED0F13}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{AA4DB2DF-E1BB-444D-B58E-D1120DE68416}" = dir=out | name=hp registration | "{BA174892-015B-493B-80BA-8DEE2173D42B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{BEA1B4AC-841D-411D-8A8E-D9A7088EC455}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe | "{BF1A831D-FBD5-4898-BCDF-D8576667AAFC}" = dir=out | app=%localappdata%\hpconnectedmusic\application\spotify_helper.exe | "{C109DE9E-3CC7-436F-A3F3-6195F943AA0B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector10\pdr10.exe | "{C7A6B856-236A-4CAE-AC58-7E5351EF8061}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{CCEB5CB2-15FF-4837-84DE-F76ED7341363}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{CEC9DE56-8601-4E81-B61A-6214D1FC5123}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\powerdvd12agent.exe | "{D0611D3B-9227-4D75-9ABD-B45922F81F6B}" = dir=out | app=c:\program files (x86)\hpconnectedmusic\hpconnectedmusic.exe | "{D4F25BE3-CBD1-4600-B8EA-E29B95957DD8}" = dir=out | name=windows_ie_ac_001 | "{D58437F2-D2A6-4FBD-B4E0-59AA9837938B}" = dir=out | name=norton studio | "{D61B6622-7C26-49AB-A861-BEEF0B755CAD}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\powerdvd12.exe | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{D9BD439D-18E4-4C9E-AD86-DF8320266DE6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{E164117D-2690-4A32-BFE7-680211B9325A}" = dir=out | name=juniper networks junos pulse | "{E1C0A1C1-0132-4309-9577-4987D74909E1}" = dir=out | name=sonicwall mobile connect | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{F0F3DE4D-B713-4AA9-B2DD-ECADEEFDC453}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{F0FB2D95-4FB7-4B38-8E8B-B299E22115A7}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{F262E858-EC58-4483-BF3B-B6C05FEC8368}" = dir=out | name=f5 vpn | "{F495A2EF-6AD0-4020-B1A6-D43974D5B7FD}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.4.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F5E65BCA-C832-4D87-84A8-2B686F54332F}" = protocol=17 | dir=in | app=c:\users\raven\appdata\roaming\dropbox\bin\dropbox.exe | "{F61B5663-FDA6-4ACA-9C3D-FAC1193B1A4F}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.4.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{FCFFBC18-5579-4A05-B6B7-A7AD8EE53D03}" = dir=out | name=@{microsoft.zunemusic_2.2.41.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{FD19C390-28BB-49FD-B364-38E512134C39}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{FD9D396F-4006-47DD-8621-3D55B74D37DC}" = protocol=6 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{FE3A6ABA-293D-4CEB-BB5D-631EC5A70DF0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\kernel\dms\clmsserverpdvd12.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{451F582F-6396-BBE3-59A3-CA059F82C905}" = ccc-utility64 "{4AA3584E-0EF3-C288-F7BB-1C3E560D1035}" = AMD Accelerated Video Transcoding "{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}" = DisableMSDefender "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{98BB5224-BC5D-4028-9D20-536C1C263AA9}" = Classic Shell "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{A48BD764-CFDF-40A5-A07A-710908044F5D}" = HP Utility Center "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{D1E8F2D7-7794-4245-B286-87ED86C1893C}" = HP Registration Service "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DEC772E6-D0C7-9964-5D30-DEC57EF1B26F}" = AMD Catalyst Install Manager "{DEDBBB0B-5D54-FB6C-E492-CDFC5059DAEB}" = AMD Fuel "{E3047FA0-2D6B-4BD6-8CD4-599955F1CE9D}" = Microsoft Mouse and Keyboard Center "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform "{07F6DC37-0857-4B68-A675-4E35989E85E3}" = HP 3D DriveGuard "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{0C8460B7-2353-8A38-0EBA-9CEEF5E330ED}" = CCC Help Polish "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19CEFEDF-B7E1-5456-0B04-09A3EBF1902A}" = CCC Help Hungarian "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10 "{205EEB6D-4F17-9D9F-7824-335B7842BA90}" = CCC Help Dutch "{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = MPC-HC 1.7.1 "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13 "{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "{2FD3D244-27D1-3ED2-EE97-CE99B61172BB}" = CCC Help Chinese Standard "{30B2D1D8-0A07-4B71-9553-0710C5D31E35}" = HP Wireless Button Driver "{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery "{31FA2F81-E064-F51F-962A-B4B2556E7328}" = CCC Help Italian "{3217E6F2-0936-29B1-4ABB-E22EE065E3FD}" = CCC Help Thai "{35117303-ABE1-7A51-8376-EE6F20A4B508}" = CCC Help Spanish "{39337565-330E-4ab6-A9AE-AC81E0720B10}" = Cyberlink PhotoDirector "{394B14EA-B072-4440-9510-87797CB12371}" = HP CoolSense "{39AF20F1-AAAF-4188-E044-D21F18CA8AA0}" = CCC Help Danish "{3C40E146-C825-9608-8B0C-D596E66D5901}" = CCC Help Portuguese "{3CED9B67-F62D-A4DC-D41C-14BA08E8E25B}" = CCC Help Czech "{3DEC528E-1701-B8E6-1A32-72B2FBDB12EA}" = Catalyst Control Center InstallProxy "{3E106AEA-3238-F3CD-513F-83833C633488}" = CCC Help Korean "{49110532-D289-4BFF-807C-45B782E66A7C}" = Photo Common "{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform "{4EEB5E30-34C5-4322-B6BC-8A039C25D3B0}" = Catalyst Control Center Graphics Previews Common "{50544133-820C-0D4F-1E03-5B133835DC6D}" = CCC Help Norwegian "{548083DD-D99B-2CE1-8D2B-D78BEB834F7A}" = OEM Application Profile "{574F0207-8E98-46CD-8F79-318348C98C46}" = HP Quick Start "{5AF7F374-E84D-C576-7FE4-E574197C192D}" = Catalyst Control Center Localization All "{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}" = Realtek Card Reader "{61245005-66F1-4001-AEE8-2E2D36F65C28}" = HP Documentation "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{63824BC0-B747-43F3-9863-1066D64AD919}" = Photo Gallery "{65A9C91A-FD05-D9A0-E1F8-779E3A2166E4}" = CCC Help Greek "{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform "{6CEA775F-E70A-4D72-A3B4-1EB3A5AD4B5C}" = Windows Live Essentials "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{82251DD6-6C81-8475-2152-663354B1D5C1}" = CCC Help Turkish "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions "{8D54C4CE-734B-39BB-2C6A-E4DB5F70865E}" = AMD VISION Engine Control Center "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{8E6E8CBB-8E58-493C-943F-4664F5F2FEDB}" = Movie Maker "{92323FF7-7417-4C28-9683-2FEA6F654735}" = Catalyst Control Center - Branding "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9D7628BE-6E32-42B9-A188-2917E1EB24FB}" = ChomikBox "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC2C8AF6-11A8-D181-F86E-E4C561C9B238}" = CCC Help Swedish "{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10 "{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" = CyberLink PowerDVD 12 "{B7CD8ECF-42D2-D8FD-83E8-D4BD3CCF00DF}" = CCC Help Finnish "{BBEFCF92-EFFE-62CA-0864-98F77EBFE97E}" = CCC Help Japanese "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Qualcomm Atheros Driver Installation Program "{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer "{C438C1D0-A46C-4BFA-AF02-11261DE9CCE0}" = Dragon Notes en-GB "{C78E8F51-3EAD-4F0C-83F0-EF371075E0B4}" = HP System Event Utility "{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common "{D182780A-D847-B859-31CD-9C5C74313665}" = CCC Help German "{D2D3D146-67BC-43D0-9015-2E7BAC2E032B}" = OpenOffice.org 3.1 "{D80DFEF9-7E50-CF19-AD3D-AD61F4209B1C}" = CCC Help French "{DA99D27A-8942-0D97-5CFB-3C231536D8A9}" = CCC Help Russian "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E236C764-7D92-36AE-ABF8-0938E055B809}" = CCC Help Chinese Traditional "{E849965E-4771-440C-936F-AF5BFD144416}" = HP Recovery Manager "{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F21F0424-B2FF-40BF-A984-9E0D7FB4C97E}" = Windows Live UX Platform Language Pack "{F264279A-4A82-181D-FC35-0F4B1DFAB05D}" = CCC Help English "{F8B98EB6-FC06-45BF-87D4-9784E0408611}" = ACDSee 10 Photo Manager "{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}" = Energy Star "{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE "Adobe Shockwave Player" = Adobe Shockwave Player 12.0 "foobar2000" = foobar2000 v1.3 "Foxit Reader" = Foxit Reader "Google Chrome" = Google Chrome "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10 "InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}" = Cyberlink PhotoDirector "InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10 "InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" = CyberLink PowerDVD 12 "NapiProjekt_is1" = NapiProjekt (2.2.0.2399) "NIS" = Norton Internet Security "phgram_60_is1" = Profesor Henry 6.0 Gramatyka "SoulseekQt" = SoulseekQt "StartHPConnectedMusic" = HP Connected Music (Meridian - installer) "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver "World of Warcraft" = World of Warcraft [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1456361715-324973510-1321076691-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "Spiral Knights" = Spiral Knights "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-01-18 19:19:23 | Computer Name = Kaliva | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 14891 Error - 2014-01-18 19:19:23 | Computer Name = Kaliva | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 14891 Error - 2014-01-24 15:37:57 | Computer Name = Kaliva | Source = Microsoft-Windows-RestartManager | ID = 10007 Description = Application or service 'HPWMISVC' could not be restarted. Error - 2014-01-24 21:43:13 | Computer Name = Kaliva | Source = .NET Runtime | ID = 1026 Description = Error - 2014-01-24 21:43:14 | Computer Name = Kaliva | Source = Application Error | ID = 1000 Description = Faulting application name: CCC.exe, version: 3.5.0.0, time stamp: 0x4f8350e0 Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp: 0x523d557d Exception code: 0xe0434352 Fault offset: 0x000000000000ab78 Faulting process ID: 0xa28 Faulting application start time: 0x01cf196e4eca6e01 Faulting application path: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe Faulting module path: C:\WINDOWS\system32\KERNELBASE.dll Report ID: 0d85e2d1-8562-11e3-be7d-a0481c1bc3e1 Faulting package full name: Faulting package-relative application ID: Error - 2014-01-26 17:45:38 | Computer Name = Kaliva | Source = .NET Runtime | ID = 1026 Description = Error - 2014-01-26 17:45:40 | Computer Name = Kaliva | Source = Application Error | ID = 1000 Description = Faulting application name: CCC.exe, version: 3.5.0.0, time stamp: 0x4f8350e0 Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp: 0x523d557d Exception code: 0xe0434352 Fault offset: 0x000000000000ab78 Faulting process ID: 0xd7c Faulting application start time: 0x01cf1adfe1d58242 Faulting application path: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe Faulting module path: C:\WINDOWS\system32\KERNELBASE.dll Report ID: 3264ebfa-86d3-11e3-be7e-a0481c1bc3e1 Faulting package full name: Faulting package-relative application ID: Error - 2014-02-01 15:18:40 | Computer Name = Kaliva | Source = Application Hang | ID = 1002 Description = The program uTorrent.exe version 3.3.2.30303 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 16fc Start Time: 01cf1f826347778c Termination Time: 12 Application Path: C:\Users\Raven\AppData\Roaming\uTorrent\uTorrent.exe Report Id: a667521b-8b75-11e3-be7f-a0481c1bc3e1 Faulting package full name: Faulting package-relative application ID: Error - 2014-02-03 19:35:11 | Computer Name = Kaliva | Source = .NET Runtime | ID = 1026 Description = Error - 2014-02-03 19:35:12 | Computer Name = Kaliva | Source = Application Error | ID = 1000 Description = Faulting application name: CCC.exe, version: 3.5.0.0, time stamp: 0x4f8350e0 Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp: 0x523d557d Exception code: 0xe0434352 Fault offset: 0x000000000000ab78 Faulting process ID: 0xb04 Faulting application start time: 0x01cf213885c3434c Faulting application path: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe Faulting module path: C:\WINDOWS\system32\KERNELBASE.dll Report ID: d2cb46e6-8d2b-11e3-be80-a0481c1bc3e1 Faulting package full name: Faulting package-relative application ID: [ Hewlett-Packard Events ] Error - 2014-01-26 19:13:50 | Computer Name = Kaliva | Source = HPSF.exe | ID = 2000 Description = [ System Events ] Error - 2014-02-12 22:18:38 | Computer Name = Kaliva | Source = Service Control Manager | ID = 7034 Description = The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 13 time(s). Error - 2014-02-13 06:54:04 | Computer Name = Kaliva | Source = DCOM | ID = 10016 Description = Error - 2014-02-13 09:07:40 | Computer Name = Kaliva | Source = Service Control Manager | ID = 7034 Description = The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 14 time(s). Error - 2014-02-13 19:06:18 | Computer Name = Kaliva | Source = DCOM | ID = 10016 Description = Error - 2014-02-13 19:49:38 | Computer Name = Kaliva | Source = Ntfs | ID = 55 Description = A corruption was discovered in the file system structure on volume Windows. The Master File Table (MFT) contains a corrupted file record. The file reference number is 0x2000000031a26. The name of the file is "". Error - 2014-02-13 19:49:38 | Computer Name = Kaliva | Source = Ntfs | ID = 55 Description = A corruption was discovered in the file system structure on volume Windows. A corruption was found in a file system index structure. The file reference number is 0x20000000319fe. The name of the file is "\Windows\System32\config". The corrupted index attribute is ":$I30:$INDEX_ALLOCATION". Error - 2014-02-13 20:24:49 | Computer Name = Kaliva | Source = DCOM | ID = 10010 Description = Error - 2014-02-13 20:24:51 | Computer Name = Kaliva | Source = Service Control Manager | ID = 7034 Description = The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s). Error - 2014-02-14 09:02:52 | Computer Name = Kaliva | Source = Service Control Manager | ID = 7034 Description = The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 2 time(s). Error - 2014-02-15 06:00:07 | Computer Name = Kaliva | Source = DCOM | ID = 10016 Description = < End of report >