OTL Extras logfile created on: 2014-03-02 01:20:33 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = F:\antiadware 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16798) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,87 Gb Total Physical Memory | 2,12 Gb Available Physical Memory | 54,85% Memory free 4,56 Gb Paging File | 3,03 Gb Available in Paging File | 66,51% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 208,88 Gb Total Space | 147,99 Gb Free Space | 70,85% Space Free | Partition Type: NTFS Drive D: | 25,00 Gb Total Space | 22,36 Gb Free Space | 89,43% Space Free | Partition Type: NTFS Drive F: | 683,59 Gb Total Space | 554,58 Gb Free Space | 81,13% Space Free | Partition Type: NTFS Computer Name: KOMPUTER | User Name: Malgorzata | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1493833752-2591686170-2324841812-1002\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- "C:\Users\Malgorzata\AppData\Roaming\File Scout\filescout.exe" /open "%1" Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- "C:\Users\Malgorzata\AppData\Roaming\File Scout\filescout.exe" /open "%1" Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07B2813C-61E6-480E-9BA7-76F20A0CA89E}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner | "{0E3AA156-812F-4247-90A9-C1F9E0FAD536}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1B3AC160-64FD-4AF8-8721-2DC8531B77D2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{1CF1784A-AAB1-4C8C-8B56-B22E787FAA71}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{1D92EA9D-E749-40E6-8935-6FED2C6843CA}" = rport=445 | protocol=6 | dir=out | app=system | "{20AB2290-94C5-4332-9C7A-24E6C9DDAD98}" = lport=2869 | protocol=6 | dir=in | app=system | "{279D67E6-268D-490B-8CBB-322D64A9BE28}" = lport=10243 | protocol=6 | dir=in | app=system | "{3AF1F206-CFF2-4D91-AE27-D40E9F310C43}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3FA94301-90C6-4BC0-AB3E-DD9D970B223E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{49A26406-CF7D-41D0-B6BB-2125028C4AD6}" = lport=139 | protocol=6 | dir=in | app=system | "{64BBE80F-4ACF-4C57-87F2-5E290CF18EAD}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6B685059-CD31-40FB-970B-C621BD7DDE7A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6C016D9D-E772-42FE-B4A3-79816E590EFD}" = rport=137 | protocol=17 | dir=out | app=system | "{A1899F67-FC73-4A59-97B4-CBF274E1189A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A9BD0672-D986-4A8F-A2D4-E1177F139209}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{B414F0E9-B2E5-44B7-A179-EDCAB88FFC59}" = lport=137 | protocol=17 | dir=in | app=system | "{B96509CF-1A4B-4059-8660-11DB8D6411FE}" = rport=10243 | protocol=6 | dir=out | app=system | "{C9D5D825-96DA-413E-94AD-DC2BBD89327E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D2BE5B6F-9A14-4943-88C1-214A8A99D7D7}" = rport=138 | protocol=17 | dir=out | app=system | "{D3867022-6926-4F6E-A04C-BC4BDDDD51A2}" = lport=445 | protocol=6 | dir=in | app=system | "{F5F35E93-D659-4B6F-BEDF-EF9D0DBD75F1}" = rport=139 | protocol=6 | dir=out | app=system | "{FF68F30F-F562-4339-B115-0365A5FCC2EF}" = lport=138 | protocol=17 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{029A3D6F-C1B4-4005-93A6-9299A7F0FDB5}" = dir=out | name=zinio | "{04317937-7DC3-48B6-97A5-5370F252CC6A}" = dir=out | name=@{microsoft.bingtravel_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{09D896CA-27DF-4EBE-983A-673810AB4497}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{0D6EB82D-EB61-4DBF-8DCC-B59B62A623E1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0FA97DA1-1F3E-41CF-853C-1BF34B41B622}" = protocol=17 | dir=in | app=f:\neverwinter nights 2\nwn2main_amdxp.exe | "{11B037C3-77A4-4351-91E4-6E81D04976AB}" = dir=out | name=@{microsoft.bingweather_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{1264D253-77F0-482B-BDC5-B51DC70B1036}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{16EC8EB2-DEA4-4617-9F0F-F81B3F831AA6}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{19C5EC9F-1D79-4055-B8A5-7F9B828E7F59}" = dir=in | name=evernote | "{1C89E212-B98B-485E-ADD7-0E8DCB3C51E3}" = dir=out | name=lenovo companion | "{1D6D8E67-3C39-4C96-B92C-82D277322B02}" = dir=out | name=@{microsoft.zunevideo_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{2019C0C0-CC9E-42AD-BC69-483325FDB76C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{21D05848-0B94-403C-B277-5912F5A321C0}" = protocol=6 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{29EA2CDC-212D-4D7E-A05B-CC3073452C28}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{2B1A1AF2-DACE-4923-AFCA-24DFF85843D1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{2BAFAE5A-89D2-499F-827A-B69C0C233720}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{30068603-99A7-4790-9C73-283672B2D263}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | "{30C0B0F1-123F-48F7-AEF9-5B0799E92C72}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{30D21239-D0D1-4058-9623-907907DC0E72}" = dir=out | name=@{microsoft.bingsports_1.8.0.51_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{31F5EB4F-851A-4C5A-8A57-FC3FE42CE489}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{340DB3A1-ECC4-440E-8BA3-31993B9B63F0}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{38831D85-860F-4C20-A705-442C260BE44A}" = protocol=6 | dir=in | app=f:\neverwinter nights 2\nwn2main_amdxp.exe | "{3AB6CE1C-4405-4F88-B02F-5ABD66ABCD8C}" = protocol=17 | dir=in | app=f:\starcraftii\starcraft ii\starcraft ii public test.exe | "{3B24B1CB-C687-4AC0-B9E2-F0800A88044E}" = dir=in | app=f:\the witcher enhanced edition\launcher.exe | "{3DEF2E7C-5BF1-4783-8220-A743579B92A7}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{3E309DAA-434A-4EB8-9D20-AE73251B181B}" = dir=in | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{46FE95D7-F0E2-4896-AFE5-8460E84DC91A}" = dir=in | name=@{microsoft.skypeapp_1.2.0.129_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{4A4485E8-CD21-4BA6-9E78-EF21AF4AE9CA}" = dir=out | name=@{microsoft.bingnews_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{4BA9FED4-8BDE-421B-9BD3-A6B4398D04BB}" = dir=out | name=lenovo cloud storage by sugarsync | "{55DDD541-E16A-4D58-B837-AC674F15AA2A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{58895F3A-555D-4FD0-991F-7B9588E3246F}" = dir=out | name=powerdvd for lenovo idea | "{59942AAA-1667-4FBF-A0BE-956E4D559A31}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5AA4BA5B-5E75-4ACD-AA04-35EEDF12C303}" = dir=out | name=windows_ie_ac_001 | "{5B761F25-4B8F-4F3F-B2BF-D3D1392E48B1}" = protocol=6 | dir=in | app=f:\neverwinter nights 2\nwn2server.exe | "{5B9A3D87-230A-4CEF-BAD3-585A8FBE1104}" = protocol=6 | dir=in | app=f:\starcraftii\starcraft ii\starcraft ii public test.exe | "{5C74CE04-977E-499E-926E-D6443CFEE335}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{5EB8FECB-AA31-4ADA-878E-903F00F3F349}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe | "{610B142E-815F-4FB9-B7F9-559770F2E9C5}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{617DA39A-3C0A-4857-8355-D2849E525857}" = protocol=6 | dir=in | app=f:\neverwinter nights 2\nwn2main.exe | "{676D2770-3B0D-446C-9E4B-D65C4B4E9C87}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | "{6A12EF96-18A3-411F-8150-04EF8C8BCCB6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{72750D28-E717-4D20-B909-ED8A95F02E41}" = dir=in | name=@{filmonlivetvfree.filmonlivetvfree_1.3.6.87_x64__zx03kxexxb716?ms-resource://filmonlivetvfree.filmonlivetvfree/resources/app-name} | "{7633EF58-FA6C-45B0-B8FF-4EAD76322461}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{7B8056CC-30C3-4EBF-AFDB-C3E7CDAC60A8}" = protocol=17 | dir=in | app=f:\neverwinter nights 2\nwn2server.exe | "{7D8843D2-0F47-45A7-B694-2DC01C0868E4}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd cinema\powerdvdcinema10.exe | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{811123BA-FFB9-4405-B1F1-766B1DD5A8B8}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{88B9DD95-76D1-45CD-B439-428F7F9B1A5D}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{8C570003-0388-40FD-A751-D830D4FE8D8D}" = dir=out | name=@{microsoft.skypeapp_1.2.0.129_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{92184876-8CFB-4553-90C3-29D5F581A0EC}" = dir=out | name=lenovo support | "{97E04E98-1B9C-4009-A411-2D1073D3C647}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{9827E04A-55E0-4021-B32F-0A076330F758}" = protocol=6 | dir=in | app=f:\neverwinter nights 2\nwupdate.exe | "{9E02E8AB-E021-4A3A-A13B-B3D233744EFE}" = dir=out | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{A1B64A74-4498-4BE6-9701-76EC63BD49B8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{A657F5F1-D3D7-4613-A8F7-1566B122B0AA}" = protocol=17 | dir=in | app=f:\neverwinter nights 2\nwn2main.exe | "{A70AB8D8-4AAD-45BF-AAAE-B3BBAA305369}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{A7E7138A-9B79-4EC3-9170-B8A735516DB1}" = dir=out | name=evernote | "{A8EF87B6-8FCB-4474-ADCE-4E30978C773F}" = protocol=6 | dir=in | app=f:\starcraftii\starcraft ii\starcraft ii.exe | "{AD9C8245-B15D-49F7-9576-D2AD60D7858E}" = protocol=17 | dir=in | app=f:\neverwinter nights 2\nwupdate.exe | "{AE560E35-767C-48BF-BEFA-C7DA7DAF48E0}" = dir=out | name=@{filmonlivetvfree.filmonlivetvfree_1.3.6.87_x64__zx03kxexxb716?ms-resource://filmonlivetvfree.filmonlivetvfree/resources/app-name} | "{B05BEE14-2AAE-44A7-A58D-39F52BD321F7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{B097992C-7A0A-4B34-AC2C-BEB8E016EDB3}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{B4576E95-AB13-45E1-97BF-B2AF197291EC}" = dir=in | app=f:\the witcher enhanced edition\system\witcher.exe | "{BA23585A-1CD8-4F07-A2BD-94C938BFF3EF}" = dir=out | name=mcafee security advisor for lenovo | "{BADFECDF-BDE4-412F-A65A-81AE001BD2A3}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{BF115037-9EF0-4048-B949-B24B3BFA8FFE}" = protocol=17 | dir=in | app=f:\starcraftii\starcraft ii\starcraft ii.exe | "{C27864FB-47F3-457B-91D0-E941BD2C005E}" = protocol=6 | dir=in | app=c:\programdata\esafe\egdpsvc.exe | "{C674D790-1774-486A-88F6-E8EFD54DE732}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{C95D4A2D-22DD-4ABD-BF44-559D6D385BD8}" = dir=out | name=@{microsoft.zunemusic_1.1.144.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{CE85742E-1596-45BD-AD69-0A25FAE09140}" = dir=out | name=@{microsoft.bingfinance_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{D575CBF3-EAA9-4C90-BF0E-E1DE9025399D}" = dir=in | name=accuweather for windows 8 | "{D57627AB-F30F-46AB-A559-B629C69CEFAA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe | "{DCDD00DF-7D11-4AE3-827B-22520BD331F8}" = protocol=17 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{E397E723-1D84-41AB-BD99-019224EA4FFB}" = dir=out | name=accuweather for windows 8 | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E9FECE73-0503-4F99-AE59-CFAA4F4D3158}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{ED5938BB-3C86-49CB-A80E-9E4E5BFD6D4C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{EF81EA95-C2B5-42F6-95C2-E146CC2B7B95}" = dir=in | app=c:\users\malgorzata\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{F48438D0-35D8-4F8C-8CE2-51A69CD79D4F}" = dir=out | name=@{microsoft.xboxlivegames_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{F64021E8-599B-4008-A5DE-9549FFE40C34}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F6B708CA-AA9D-4AA2-81E3-F8BF3E8D2AA2}" = protocol=6 | dir=out | app=system | "{F7E89EA1-69A2-4569-A218-A24BFDAF080A}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{FFF51E9E-46F5-4B8B-8CF7-22BADA9E5E56}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd10.exe | "TCP Query User{C0FB433E-99AB-4736-A1EC-A6B3CE77C29A}F:\starcraftii\starcraft ii\versions\base26490\sc2.exe" = protocol=6 | dir=in | app=f:\starcraftii\starcraft ii\versions\base26490\sc2.exe | "UDP Query User{DC41F5C0-A0B3-40F7-8174-2F862D58C14E}F:\starcraftii\starcraft ii\versions\base26490\sc2.exe" = protocol=17 | dir=in | app=f:\starcraftii\starcraft ii\versions\base26490\sc2.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1E939186-B443-4262-A278-3C82949EA7AC}" = Lenovo Solution Center "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{91CF16EE-876D-4409-9E3F-030BCDED616F}" = calibre 64bit "{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 307.45 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 307.45 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.12.0604 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B71CCF77-38A2-4805-9759-A6F7D2C52F3A}" = Adobe Photoshop Lightroom 4.2 64-bit "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64 "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "{f45b48a7-f616-4211-b927-17cab6a96613}" = Microsoft Visual C++ 2005 Redistributable (x64) "71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42" = Pakiet sterowników systemu Windows - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) "8A223E56FB1ED4F697B54E5BF96F1EB63B512684" = Pakiet sterowników systemu Windows - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) "CNXT_AUDIO_HDA" = Conexant HD Audio "FindRight" = FindRight "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable "{18192D3F-5537-4560-AD89-D695F72AF91D}" = OpenOffice.org 3.4.1 "{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 51 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program "{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support "{6015B0F7-DB20-4087-8673-A4662B0740E5}_is1" = Gothic Universe "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility "{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447 "{90150000-0138-0409-0000-0000000FF1CE}" = Microsoft Office "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A50DE037-B5C0-4C8A-8049-B0C576B313D1}" = Google+ Auto Backup "{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Polish "{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}" = Lenovo EasyCamera "{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2 "{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}" = Dolby Advanced Audio v2 "{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader "{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "{D1E7142C-6BC3-49EB-A71A-E5D7ADAC7599}" = Nikon File Uploader 2 "{DDD62492-32A7-412B-8AF1-2CF032AD42E3}" = ViewNX 2 "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = Lenovo PowerDVD10 "{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = Podręcznik użytkownika "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}_is1" = Wiedźmin Edycja Rozszerzona "{FB83EAC4-E3F6-4666-B45B-44522F2344B6}" = Brother MFL-Pro Suite DCP-J315W "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin "Atrise Lutcurve" = Atrise Lutcurve 1.8.0 "avast" = avast! Free Antivirus "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = Lenovo PowerDVD10 "InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide "Intel AppUp(SM) center 33057" = Intel AppUp(SM) center "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.75.0.1300 "Mozilla Firefox 27.0.1 (x86 pl)" = Mozilla Firefox 27.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NapiProjekt_is1" = NapiProjekt (2.2.0.2399) "Picasa 3" = Picasa 3 "RealPlayer 16.0" = RealPlayer "StarCraft II" = StarCraft II "SugarSync" = SugarSync Manager [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1493833752-2591686170-2324841812-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-02-14 14:33:20 | Computer Name = komputer | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe". Nie można odnaleźć zestawu zależnego rpshellextension.1.0,language="*",type="win32",version="1.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2014-02-14 14:36:50 | Computer Name = komputer | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe". Nie można odnaleźć zestawu zależnego rpshellextension.1.0,language="*",type="win32",version="1.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2014-02-15 05:42:42 | Computer Name = komputer | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2014-02-17 15:55:30 | Computer Name = komputer | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe". Nie można odnaleźć zestawu zależnego rpshellextension.1.0,language="*",type="win32",version="1.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2014-02-18 14:01:43 | Computer Name = komputer | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2014-02-19 09:33:11 | Computer Name = komputer | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2014-02-20 11:16:17 | Computer Name = komputer | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2014-02-20 14:07:08 | Computer Name = komputer | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe". Nie można odnaleźć zestawu zależnego rpshellextension.1.0,language="*",type="win32",version="1.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2014-02-20 14:11:41 | Computer Name = komputer | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe". Nie można odnaleźć zestawu zależnego rpshellextension.1.0,language="*",type="win32",version="1.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2014-02-23 08:43:15 | Computer Name = komputer | Source = Customer Experience Improvement Program | ID = 1008 Description = [ System Events ] Error - 2013-12-16 15:41:10 | Computer Name = komputer | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi BitGuard z powodu następującego błędu: %%3 Error - 2013-12-17 10:40:42 | Computer Name = komputer | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 2013-12-17 10:42:04 | Computer Name = komputer | Source = Service Control Manager | ID = 7022 Description = Usługa Wsys Service zawiesiła się podczas uruchamiania. Error - 2013-12-25 20:19:07 | Computer Name = komputer | Source = DCOM | ID = 10010 Description = Error - 2014-01-05 20:32:05 | Computer Name = komputer | Source = DCOM | ID = 10010 Description = Error - 2014-01-16 15:30:33 | Computer Name = komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 20:00:03 na ?2014-?01-?16 było nieoczekiwane. Error - 2014-01-16 15:30:05 | Computer Name = komputer | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 2014-01-16 15:32:31 | Computer Name = komputer | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 2014-02-12 19:11:34 | Computer Name = komputer | Source = DCOM | ID = 10010 Description = Error - 2014-02-14 11:19:13 | Computer Name = komputer | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = < End of report >