OTL Extras logfile created on: 10/12/2014 5:32:16 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kami\Desktop\New folder 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17278) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.45 Gb Total Physical Memory | 1.77 Gb Available Physical Memory | 51.16% Memory free 4.08 Gb Paging File | 1.86 Gb Available in Paging File | 45.62% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 456.46 Gb Total Space | 336.20 Gb Free Space | 73.66% Space Free | Partition Type: NTFS Computer Name: KAMIL | User Name: Kami | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3496297941-2762090934-1988784446-1001\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{039B6A24-D36C-45B9-A749-4FB3042B5C3C}" = lport=10243 | protocol=6 | dir=in | app=system | "{053A0C4A-3B2A-4E2D-AFC7-916F2207E776}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{0CC3EF53-E410-44DD-ADED-6DEAB84C86C1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2024E02D-3DE7-4810-BBB9-05450F13CD8C}" = lport=139 | protocol=6 | dir=in | app=system | "{227EBBED-0799-4B4D-B992-02D578FD0DE6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4421A1E1-53CE-4433-9A44-5A18F8A0B592}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{470187C6-9E16-48D2-9123-356CFBBAF41C}" = rport=137 | protocol=17 | dir=out | app=system | "{4B823B90-00A8-483D-9710-7838BA2FD4D5}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{51453F5E-7F1B-4C26-957C-18100916D212}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{59652BCA-AB92-4C2A-9B9D-1D588D25EDA2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{6377EC94-3A0F-4700-B548-46D5633E9FA0}" = lport=137 | protocol=17 | dir=in | app=system | "{679BD350-E136-4FEA-A025-EF47823F9488}" = rport=139 | protocol=6 | dir=out | app=system | "{6E622063-3419-44D8-8EBD-CE9F3B806B0A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{7030D662-F426-4781-9F70-7606F723ED11}" = lport=2869 | protocol=6 | dir=in | app=system | "{77E8329D-B491-4695-87DA-F8CBB2AF9ECF}" = rport=445 | protocol=6 | dir=out | app=system | "{A07A5D91-F8FD-497F-9350-5D081BE47E9A}" = lport=445 | protocol=6 | dir=in | app=system | "{AA004067-CEFA-4315-9948-D47A5B0BDDDC}" = rport=138 | protocol=17 | dir=out | app=system | "{AA56D48E-4416-4FA5-8E48-5FCFD708DF0A}" = lport=138 | protocol=17 | dir=in | app=system | "{BB204F30-AF51-45E8-BE49-C6C3FCE9BD80}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C1A24B72-E96E-49CA-A256-7A8E72E3CCF6}" = rport=10243 | protocol=6 | dir=out | app=system | "{C94CE64C-850B-4A9A-89D4-0B4C6B07CC84}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F37FB99E-CB73-4355-BB35-0C5084BF28EF}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{033DBA71-0374-452B-97B7-A5404A7B7794}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{04CC2FB9-E3C2-447A-846D-87F981C6348C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{0669CE96-8C75-4E38-B212-ACF92B1A6932}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{0ABEF910-EB7C-4539-A8DA-32F583BC566D}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{0BDAD45B-CB46-4774-BF93-4359D1688315}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{0C31963F-D37D-4934-8DAB-995BA3447EC0}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{0EB2F1C7-7CA9-431F-BD43-1BDE99FD0C68}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{1876AA0B-FD41-415D-8F1C-B7CCB67D7D6E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{1BA9FA0A-89BB-4812-8952-3D97A31D86A8}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{1BBF7DCE-872C-4F3E-8099-5D97773D1A2A}" = dir=out | name=@{microsoft.bingweather_3.0.4.214_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | "{2A6E9F70-266E-4F7D-A52D-75144271BCD1}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{2CF0D8AA-4664-437F-AF10-A36362D378C8}" = dir=out | name=evernote touch | "{2D3D39B4-B74E-403A-845A-90EDF5728AE2}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{30B922A4-9D11-44B5-BFE3-CD2B94F06ED0}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{325A2248-142B-4974-878B-A8BE7745D2B5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{3E8FF115-B2CC-4AE4-A057-46B01F460874}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{41CFDCF1-22C0-4EB8-832F-24561B8D3E46}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{4824EF8E-3454-471E-8FE0-D469734AA7C3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{48B2DC71-E852-4CB3-A08D-0B599A646893}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{4A0B8BBA-5042-4067-8585-93CE5C1500D2}" = dir=out | name=norton studio | "{5440EC5B-8AC3-4274-8942-FFA0CF08544E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{5790712A-DFDC-4113-B634-3B8840A7F54F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5B6CA139-FE3E-4AD4-B8E4-B9324EC3E3E8}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{5C6CB251-AD92-4156-BBBB-42F680EE9F99}" = dir=out | name=@{microsoft.zunemusic_2.6.320.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{6291326D-E29B-4311-A680-6DA6192ECC6C}" = dir=out | name=@{microsoft.bingsports_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{6AD173E5-1D0C-45AC-A627-FD310EE57167}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{776B725D-C9EE-418A-BC85-7D87423E9834}" = dir=out | name=toshiba central | "{79BB9627-D179-46AF-8A1B-8B58B1945F35}" = dir=out | name=deals & offers | "{7B017AFA-1006-4D6B-A231-90EC3BA4EFB9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{7F9240DD-CF59-4333-968D-523367EFDA94}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{86506176-5E73-4310-ACF7-1D9266C89426}" = dir=in | name=@{microsoft.xboxcompanion_1.4.2.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxcompanion/resources/33279} | "{87C0D545-0F20-4544-8BAA-7F360EE10B88}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{88B7E7D7-A488-4054-92B8-F0F4C15DBD2D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{9327EE4A-7AC1-4D2C-B37C-681BA28BD10B}" = dir=in | name=zinio | "{93806193-3DA3-4D2A-8844-BA6E8A3430BB}" = dir=out | name=- games app - | "{987AAD15-9105-4303-B12F-6991323B17BD}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{9AB10B47-70D0-4F42-AE3E-BF235988FC10}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{9F805023-59B0-45EF-BA19-2C56321DD137}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{A31C7C3B-2F6B-4358-B154-8F532171D50E}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{AD3F8C81-837A-464E-8A6A-C54D6B5AE566}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{B1419F99-5E9D-482F-B67F-52C28DD5A5FF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B2020EA4-A9FA-4392-A61B-893575F9DC22}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{B31E9015-530C-4ACC-AF00-121531E93967}" = dir=out | name=iheartradio | "{B6258528-2279-43AB-B4C9-1DA8962C5E1E}" = dir=out | name=hulu plus | "{BB891EF9-60E9-4947-9FB4-9D76C080986D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{BD2C8011-3F3A-4720-A998-28941B502230}" = dir=in | name=evernote touch | "{C05133AE-C126-44F3-9D48-62266443E4C3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{C2B3F71B-E169-45CD-A43C-2C6ED41C944F}" = dir=out | name=skype | "{C5311711-8C42-4F54-B588-EC112A14A6F6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{CAD09936-AD00-431A-B79B-49957C5DFA11}" = dir=out | name=toshiba media player by smedio truelink+ | "{D04885DE-DE6A-4115-B1B4-F72278C10D27}" = dir=out | name=@{microsoft.zunevideo_2.6.283.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{D1FE4441-9855-4372-9842-7BB638935301}" = dir=out | name=windows_ie_ac_001 | "{D2798B57-1CD8-4CC1-A626-E908D4F2C045}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{DB2C305D-9A09-4B05-9B47-F033F2365572}" = dir=out | name=zinio | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{DC9BD30F-5088-496D-BDD1-44F411A451AC}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{DD2EE509-30B8-47CD-86A4-35C9D1912FD6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DFEFE843-AE25-41E4-99C4-092A62FB305D}" = dir=in | name=toshiba media player by smedio truelink+ | "{E1754F4B-4860-4615-AF2E-E430549F8471}" = dir=in | name=skype | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{ED3BF3BE-401A-4FA3-B099-1253B05E69D0}" = dir=out | name=@{microsoft.xboxcompanion_1.4.2.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxcompanion/resources/33279} | "{F14035A4-2108-49BD-A339-3745C182F3C0}" = dir=out | name=book place | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{F8996760-74F3-4689-B0DC-F39127B537D0}" = protocol=6 | dir=out | app=system | "{F909B29B-DDF0-4B72-9D3F-2CE9B0A91BED}" = dir=out | name=netflix | "{FB23AE08-6C17-4053-A60F-F6506029A5F6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{FCAAC211-6405-45D0-AEDD-AF77804F0AB5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FF59061A-9FE5-40B5-8DE6-A15B57862360}" = dir=out | name=ebay | "TCP Query User{79FB545E-E368-4FAC-A59E-F4FD0252113A}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "UDP Query User{34FAB89A-BC30-48E4-8D2D-6E1037CCB062}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1515F5E3-29EA-4CD1-A981-032D88880F09}" = TOSHIBA Audio Enhancement "{16562A90-71BC-41A0-B890-D91B0C267120}" = TOSHIBA Function Key "{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}" = TOSHIBA Application Installer "{509E2F77-9E85-EDA9-1EBA-B79B080A3394}" = AMD Accelerated Video Transcoding "{5944B9D4-3C2A-48DE-931E-26B31714A2F7}" = TOSHIBA eco Utility "{5A68A656-979F-4168-8795-E2E368AA4DC2}" = iTunes "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{787136D2-F0F8-4625-AA3F-72D7795AC842}" = Apple Mobile Device Support "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0415-1000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0016-0415-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0018-0415-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0019-0415-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-001A-0415-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001B-0415-1000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0415-1000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2010 "{90140000-0044-0415-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00BA-0415-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{AF08DEBD-05F7-F9D5-5A9E-DC52C9292C1D}" = AMD Start Now "{B280788C-B671-E08D-4219-CE907B7BFF75}" = AMD Catalyst Install Manager "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{E163A1D2-BAEA-6786-8E73-0ABD5A2D4C5B}" = ccc-utility64 "{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream "{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}" = TOSHIBA Service Station "{FF07604E-C860-40E9-A230-E37FA41F103A}" = TOSHIBA VIDEO PLAYER "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{05A55927-DB9B-4E26-BA44-828EBFF829F0}" = TOSHIBA System Settings "{05A58326-ED31-10B1-44CD-224C8FD2E3CE}" = CCC Help Spanish "{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}" = Cisco PEAP Module "{10AB7F4D-ECCD-AC5D-D777-7EDEF7988375}" = CCC Help Dutch "{11244D6B-9842-440F-8579-6A4D771A0D9B}" = Toshiba Book Place "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{15AAD730-E115-1050-A894-987BF5CE3B2A}" = CCC Help Russian "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{1E6A96A1-2BAB-43EF-8087-30437593C66C}" = TOSHIBA System Driver "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.20 "{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0 "{2D152AF7-856E-13AE-B6EF-15598C4AC7F8}" = CCC Help French "{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}" = DTS Sound "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{3384E1D9-3F18-4A98-8655-180FEF0DFC02}" = TOSHIBA User's Guide "{33A68EF9-2654-9930-EDB5-9DC714F05D5A}" = CCC Help Finnish "{33E76701-B59A-169A-2278-9CEFFEBAA25C}" = Catalyst Control Center Localization All "{431DD095-10B2-1390-AF45-22EBADE16D25}" = Catalyst Control Center Graphics Previews Common "{43914AB6-FA86-2D31-2FCA-6AB76626DB63}" = CCC Help Thai "{497D7F1F-22D7-3BBF-5DA1-A2E01B3FA99F}" = CCC Help Chinese Standard "{49CC9650-573C-775B-34D0-C716DEB5FA15}" = CCC Help Italian "{4DA0141D-9081-1CAC-2C38-E32BD7E69BFA}" = CCC Help Hungarian "{509A86C9-FA75-52C2-22D7-AE695C197475}" = CCC Help Turkish "{520F5284-9F72-D43D-0871-46377E624781}" = CCC Help Portuguese "{5A7A707B-BC18-253F-A347-5B5C67D3504E}" = CCC Help Greek "{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = TOSHIBARegistration "{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}" = Realtek Card Reader "{643677D1-3E33-0C9B-FA97-4226E512B7B3}" = CCC Help Danish "{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module "{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call "{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}" = OEM Application Profile "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79A407A1-F121-5A5F-6825-B55363A38A62}" = CCC Help English "{79BC8CD7-9CF2-0217-E14C-6F2EF0DA52EA}" = CCC Help Korean "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8A77B756-325B-F675-6DFD-BF7B67010175}" = CCC Help Swedish "{90150000-0138-0409-0000-0000000FF1CE}" = Microsoft Office "{95F38874-065A-40AB-AFC1-B764B192FFE7}" = REALTEK Wireless LAN Driver "{9C50EB8A-2DF1-8752-60EC-AAFA3F47A2CE}" = AMD Catalyst Control Center "{A74C9CC1-2211-4A75-A688-6F7CFE2C2B12}" = TOSHIBA Start "{A9CD695B-B730-CC02-067B-0C5737F5F4CC}" = CCC Help German "{AC76BA86-7AD7-FFFF-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) MUI "{AD29E049-CAA6-4EC0-9553-19B375DB8658}" = Catalyst Control Center - Branding "{AF312B06-5C5C-468E-89B3-BE6DE2645722}" = Cisco LEAP Module "{B1786E63-2127-42C9-95A3-146E5F727BF1}" = TOSHIBA Password Utility "{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator "{BBD6219B-C455-1291-B399-52BC69AD4F44}" = CCC Help Japanese "{C5B5791A-17BD-0136-8A38-0405FE65C680}" = CCC Help Polish "{C5E77038-9644-580F-13E6-4F3C4FCA08E9}" = CCC Help Norwegian "{D5C8E580-C2D5-F457-CB3F-A05195FA556F}" = CCC Help Chinese Traditional "{D9DAD0FF-495A-472B-9F10-BAE430A26682}" = Apple Application Support "{E69992ED-A7F6-406C-9280-1C156417BC49}" = TOSHIBA Quality Application "{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}" = Toshiba App Place "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FA954F79-9F5F-C062-D60B-F3AB99CBDAF6}" = CCC Help Czech "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin "CinemaP-1.4" = CinemaP-1.4 "CleanGP_is1" = CleanGP 4.4 Build 4005 "InstallShield_{95F38874-065A-40AB-AFC1-B764B192FFE7}" = REALTEK Wireless LAN Driver "Mozilla Firefox 32.0.3 (x86 pl)" = Mozilla Firefox 32.0.3 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "WinRAR archiver" = WinRAR 5.01 (32-bit) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 9/14/2014 11:16:48 PM | Computer Name = kamil | Source = Application Error | ID = 1000 Description = Faulting application name: firefox.exe, version: 31.0.0.5310, time stamp: 0x53c75e72 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc00001a5 Fault offset: 0x0ac1a336 Faulting process id: 0x20e0 Faulting application start time: 0x01cfd0934ce70d70 Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Faulting module path: unknown Report Id: ba4d45d4-3c86-11e4-82ad-008cfaa38768 Faulting package full name: Faulting package-relative application ID: Error - 9/14/2014 11:16:59 PM | Computer Name = kamil | Source = Application Error | ID = 1000 Description = Faulting application name: firefox.exe, version: 31.0.0.5310, time stamp: 0x53c75e72 Faulting module name: ntdll.dll, version: 6.3.9600.17114, time stamp: 0x53648f36 Exception code: 0xc0000005 Fault offset: 0x00040ab4 Faulting process id: 0x20e0 Faulting application start time: 0x01cfd0934ce70d70 Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: c0cc36b8-3c86-11e4-82ad-008cfaa38768 Faulting package full name: Faulting package-relative application ID: Error - 9/16/2014 1:34:45 PM | Computer Name = kamil | Source = Toshiba App Place | ID = 0 Description = Error - 9/16/2014 1:40:11 PM | Computer Name = kamil | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17239, time stamp: 0x53d22946 Faulting module name: jscript9.dll, version: 11.0.9600.17239, time stamp: 0x53d2481e Exception code: 0xc0000005 Fault offset: 0x00008dd6 Faulting process id: 0x1654 Faulting application start time: 0x01cfd1d534414a16 Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\Windows\SYSTEM32\jscript9.dll Report Id: 81ccf14b-3dc8-11e4-82ad-008cfaa38768 Faulting package full name: Faulting package-relative application ID: Error - 9/16/2014 1:41:16 PM | Computer Name = kamil | Source = Perflib | ID = 1023 Description = Error - 9/16/2014 1:42:46 PM | Computer Name = kamil | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17239, time stamp: 0x53d22946 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc00000fd Fault offset: 0x77118a5d Faulting process id: 0x29e0 Faulting application start time: 0x01cfd1d565e1f0c9 Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: unknown Report Id: ddff810e-3dc8-11e4-82ad-008cfaa38768 Faulting package full name: Faulting package-relative application ID: Error - 9/16/2014 1:46:22 PM | Computer Name = kamil | Source = Application Error | ID = 1000 Description = Faulting application name: plugin-container.exe, version: 31.0.0.5310, time stamp: 0x53c75e91 Faulting module name: mozalloc.dll, version: 31.0.0.5310, time stamp: 0x53c72e91 Exception code: 0x80000003 Fault offset: 0x0000141b Faulting process id: 0x2c4c Faulting application start time: 0x01cfd1d5c3576c44 Faulting application path: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Faulting module path: C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll Report Id: 5e860596-3dc9-11e4-82ad-008cfaa38768 Faulting package full name: Faulting package-relative application ID: Error - 9/19/2014 2:23:51 PM | Computer Name = kamil | Source = Toshiba App Place | ID = 0 Description = Error - 9/19/2014 2:42:36 PM | Computer Name = kamil | Source = Toshiba App Place | ID = 0 Description = Error - 9/19/2014 3:16:48 PM | Computer Name = kamil | Source = Toshiba App Place | ID = 0 Description = [ System Events ] Error - 9/1/2014 12:39:23 PM | Computer Name = kamil | Source = Service Control Manager | ID = 7000 Description = The Util ClearThink service failed to start due to the following error: %%1053 Error - 9/14/2014 1:40:38 AM | Computer Name = kamil | Source = Microsoft-Windows-Kernel-General | ID = 5 Description = Error - 9/14/2014 11:20:41 PM | Computer Name = kamil | Source = DCOM | ID = 10010 Description = Error - 9/14/2014 11:20:41 PM | Computer Name = kamil | Source = DCOM | ID = 10010 Description = Error - 9/19/2014 2:41:10 PM | Computer Name = kamil | Source = EventLog | ID = 6008 Description = The previous system shutdown at 10:58:44 AM on ?9/?16/?2014 was unexpected. Error - 9/19/2014 3:00:09 PM | Computer Name = kamil | Source = DCOM | ID = 10010 Description = Error - 9/19/2014 3:00:39 PM | Computer Name = kamil | Source = DCOM | ID = 10010 Description = Error - 9/19/2014 3:15:21 PM | Computer Name = kamil | Source = EventLog | ID = 6008 Description = The previous system shutdown at 11:41:10 AM on ?9/?19/?2014 was unexpected. Error - 9/19/2014 3:58:21 PM | Computer Name = kamil | Source = EventLog | ID = 6008 Description = The previous system shutdown at 12:15:21 PM on ?9/?19/?2014 was unexpected. Error - 9/19/2014 4:32:31 PM | Computer Name = kamil | Source = EventLog | ID = 6008 Description = The previous system shutdown at 12:58:21 PM on ?9/?19/?2014 was unexpected. < End of report >