Extras.Txt

Toshiba Sattellite - zawirusowany laptop (wyskakujące reklamy) - logi.

Witam, serdecznie proszę o sprawdzenie logów - znowu jakiś męczący robak się przyczepił i reklamy nie dają mi spokoju. Pozdrawiam fly21


OTL Extras logfile created on: 2015-04-12 14:27:52 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Basia\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17690)
Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd

5,91 Gb Total Physical Memory | 3,02 Gb Available Physical Memory | 51,13% Memory free
6,85 Gb Paging File | 3,41 Gb Available in Paging File | 49,75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 687,93 Gb Total Space | 599,44 Gb Free Space | 87,14% Space Free | Partition Type: NTFS

Computer Name: BASIA | User Name: Basia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; extension & gt; ]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; extension & gt; ]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-188607031-2838451578-2325805074-1001\SOFTWARE\Classes\ & lt; extension & gt; ]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; key & gt; \shell\[command]\command]
batfile [open] -- " %1 " %*
cmdfile [open] -- " %1 " %*
comfile [open] -- " %1 " %*
exefile [open] -- " %1 " %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
htmlfile [opennew] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
htmlfile [print] -- " %systemroot%\system32\rundll32.exe " " %systemroot%\system32\mshtml.dll " ,PrintHTML " %1 "
http [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
https [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe " %1 " (Microsoft Corporation)
InternetShortcut [open] -- " C:\Windows\System32\rundll32.exe " " C:\Windows\System32\ieframe.dll " ,OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- " C:\Windows\System32\rundll32.exe " " C:\Windows\System32\mshtml.dll " ,PrintHTML " %1 " (Microsoft Corporation)
piffile [open] -- " %1 " %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- " %1 "
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- " %1 " /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe " %1 " (Microsoft Corporation)
Directory [ChomikBox.Upload] -- " C:\Program Files (x86)\ChomikBox\\ChomikBox.exe " -u " %1 " ( )
Directory [cmd] -- cmd.exe /s /k pushd " %V " (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- " C:\Program Files (x86)\Winamp\winamp.exe " /BOOKMARK " %1 " (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- " C:\Program Files (x86)\Winamp\winamp.exe " /ADD " %1 " (Nullsoft, Inc.)
Directory [Winamp.Play] -- " C:\Program Files (x86)\Winamp\winamp.exe " " %1 " (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- " C:\Program Files\Internet Explorer\iexplore.exe " (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; key & gt; \shell\[command]\command]
batfile [open] -- " %1 " %*
cmdfile [open] -- " %1 " %*
comfile [open] -- " %1 " %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe " %1 " ,%* (Microsoft Corporation)
exefile [open] -- " %1 " %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
htmlfile [opennew] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
htmlfile [print] -- " %systemroot%\system32\rundll32.exe " " %systemroot%\system32\mshtml.dll " ,PrintHTML " %1 "
http [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
https [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe " %1 " (Microsoft Corporation)
piffile [open] -- " %1 " %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- " %1 "
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- " %1 " /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe " %1 " (Microsoft Corporation)
Directory [ChomikBox.Upload] -- " C:\Program Files (x86)\ChomikBox\\ChomikBox.exe " -u " %1 " ( )
Directory [cmd] -- cmd.exe /s /k pushd " %V " (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- " C:\Program Files (x86)\Winamp\winamp.exe " /BOOKMARK " %1 " (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- " C:\Program Files (x86)\Winamp\winamp.exe " /ADD " %1 " (Nullsoft, Inc.)
Directory [Winamp.Play] -- " C:\Program Files (x86)\Winamp\winamp.exe " " %1 " (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- " C:\Program Files\Internet Explorer\iexplore.exe " %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
" cval " = 1

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
" VistaSp1 " = AC 1C AE C5 46 9F CE 01 [binary data]
" AntiVirusOverride " = 0
" AntiSpywareOverride " = 0
" FirewallOverride " = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
" UpgradeTime " = [binary data]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
" UpgradeTime " = Reg Error: Unknown registry data type -- File not found

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
" EnableFirewall " = 1
" DisableNotifications " = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
" EnableFirewall " = 1
" DisableNotifications " = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
" EnableFirewall " = 1
" DisableNotifications " = 0

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
" {0189F4CD-B1D2-43BD-B486-F862FB32D8F5} " = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
" {08AFA71B-1D15-4C02-A7E5-657101268803} " = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
" {1E4BA07B-82BD-484B-9EC6-562B962CEECF} " = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
" {1F914480-D73D-4C22-90DB-8DC6DC43BB2F} " = rport=10243 | protocol=6 | dir=out | app=system |
" {2B1FA86F-BAC6-4ED0-8F5E-574C26B28860} " = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
" {30FC678E-EAE9-49E9-B936-EB9D93E378FB} " = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
" {35403A1E-9497-45B1-A226-1176E299ECE3} " = lport=137 | protocol=17 | dir=in | app=system |
" {41DB966A-3A47-43F6-8FDD-68633091FAF4} " = lport=10243 | protocol=6 | dir=in | app=system |
" {4A1179C1-6951-46F4-840E-ECC6C344B27B} " = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
" {7207ADAA-4849-4698-852E-C3A66C0B6A34} " = lport=139 | protocol=6 | dir=in | app=system |
" {7DBA375B-CE94-4DDE-95F2-8A0B31F843BC} " = rport=138 | protocol=17 | dir=out | app=system |
" {83B6E752-33A2-40A9-9C3F-8C4D9322E173} " = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
" {8CD8B3ED-089E-4FED-BB07-A53ABB928C56} " = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
" {964F73E9-47D1-4EB0-A0AE-329F2CDFC587} " = lport=445 | protocol=6 | dir=in | app=system |
" {98233A88-119F-455C-BAC6-5F5239340288} " = rport=139 | protocol=6 | dir=out | app=system |
" {9A67945D-52C4-449A-B66A-12FE9D1FD78E} " = lport=138 | protocol=17 | dir=in | app=system |
" {B3FD0FFB-5D24-4D7A-93F6-00FA301936C7} " = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe |
" {DEB6E26D-A136-4B66-BC83-CC45FB47E22E} " = lport=2869 | protocol=6 | dir=in | app=system |
" {EB89DDB8-ACD2-4B1E-A731-89CA038D4191} " = rport=137 | protocol=17 | dir=out | app=system |
" {FAB0140A-27AB-4C66-9512-24BFBDCEA60E} " = rport=445 | protocol=6 | dir=out | app=system |
" {FB5EBAA3-DFAC-41C4-91D7-FA158E6514C8} " = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
" {FEF315A0-BFB4-461E-B220-0F62F39BB8CF} " = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
" {0109E97B-F9AF-4587-AFE5-0DC2722F031A} " = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
" {06965911-4747-4B81-B9E8-04A06FBADBD7} " = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
" {06E9777B-46E7-474C-86B9-AD37FF48F2A9} " = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
" {0A550D99-2112-443B-A1CC-E1B823095A82} " = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
" {11B6165B-F204-4310-9DDF-1CB75C864AFB} " = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
" {142D968E-3B23-4431-AA8B-9664ED089B6D} " = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
" {198F7B45-DA62-4FC0-ACE0-9320903E3020} " = dir=out | name=toshiba central |
" {216A0078-7465-44E9-B2A4-1100752C2F82} " = dir=in | name=onenote |
" {2183A8A8-12A3-4C09-8E9C-F0FFCAAF632C} " = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
" {25034311-5B49-49AC-9F55-F4B02D2392CB} " = dir=out | name=@{microsoft.bingweather_3.0.4.298_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
" {35F9A6ED-39A3-44C1-AB7D-65BC3444DB4B} " = dir=out | name=@{microsoft.zunevideo_2.6.434.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
" {361698A5-8CAC-4143-8659-17375EB3DC96} " = dir=in | name=toshiba media player by smedio truelink+ |
" {3E3B48E8-B259-43FB-93A9-88B592905D04} " = dir=out | name=- games app - |
" {4282FE99-8560-4BC7-9576-5F3ED84E263F} " = dir=in | name=checkpoint.vpn |
" {4734F931-163F-4BC9-860C-C26B2293D301} " = dir=out | name=netflix |
" {4DDDD4F2-4E6E-45D4-9072-999E2D368AD0} " = dir=out | name=@{microsoft.bingnews_3.0.4.268_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
" {5056FFA0-1711-4D46-99D4-18CA3DF0C2BC} " = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
" {523CEEE9-4DD8-4706-BA67-F14E988F9F3C} " = dir=in | name=hp all-in-one printer remote |
" {52E2AFC7-BCD3-44EC-A9CA-ECAB15813D25} " = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
" {533F148F-2EDC-4476-898C-933089C6A531} " = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
" {548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6} " = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
" {560448D6-095C-4907-B046-AC7F710701A7} " = dir=in | name=sonicwall.mobileconnect |
" {57AB5A13-7681-44CB-971B-CDB30F042E12} " = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
" {57DE2D1B-8828-443A-8005-D4F5C3CEDAC1} " = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
" {59D8AD60-D498-491D-A0BB-FAFECBC89B28} " = dir=in | name=evernote touch |
" {5E41FEAD-AC94-4108-94B6-D332B766A3D8} " = dir=out | name=zinio |
" {5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E} " = dir=out | name=sonicwall.mobileconnect |
" {62356618-69A1-436F-AF3C-397C93F13340} " = dir=in | app=c:\program files\hp\hp photosmart 7510 series\bin\devicesetup.exe |
" {6484CE7A-E921-4091-AFDB-4D442ECF0166} " = dir=out | name=windows_ie_ac_001 |
" {6581E297-2084-4D34-BEB4-9A9A92B2E5B6} " = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
" {6B8FAA62-BD92-4E61-B24B-491C259DB496} " = dir=out | name=hulu plus |
" {6C09E538-7DD8-4AA7-B40B-4F9F7450648F} " = dir=out | name=book place by toshiba |
" {6C3E3849-ACFF-496E-825B-6BC1293F95D5} " = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
" {6CC05CC2-30D6-419A-8344-18ABC58AC420} " = dir=out | name=evernote touch |
" {6F7A3DBB-7289-412A-BA0D-F4FBAA7A9021} " = dir=out | name=hp all-in-one printer remote |
" {70CE9DBE-90AA-4AD3-8D85-C7003F8B7F79} " = dir=out | name=next issue magazines |
" {71D74023-16A2-4C3D-9FAF-1B5263DC1E1C} " = dir=out | name=toshiba media player by smedio truelink+ |
" {7233919F-0F22-49B5-8441-D8276EBBF752} " = dir=out | name=kindle |
" {723496C8-19AC-4C3A-AC59-3F9281CAEAB8} " = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
" {72510256-B37C-4F61-8188-7855012CB5FB} " = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\movie\powerdvd cinema\powerdvdcinema12.exe |
" {73AE24F3-EBCB-49B5-B69F-C125EE2BF047} " = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
" {7488A93F-C25D-4A6F-A08D-29FB8200D799} " = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
" {77C58152-223F-4119-B202-DD8C4847BB6F} " = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
" {86536570-13C2-42B2-8EF9-0DCCD8C0B533} " = dir=out | name=skype |
" {88293712-617D-48F4-81F2-3CAA0A81DE4C} " = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
" {883D081B-4B16-4BFE-BBC7-FDEA7F1C112E} " = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
" {9026563A-4EC7-4E52-B6B5-12EF3FF38A82} " = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
" {92CB8506-9191-4973-933D-D348E331DE93} " = dir=out | name=@{microsoft.bingtravel_3.0.4.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
" {94FC94F9-1061-4BDA-8B3C-40EFDA7D5702} " = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
" {9E3D57FC-7C37-4424-9352-4831E97D029D} " = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
" {A139A2CC-556E-44FA-A345-0F3A43B6A776} " = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
" {A4BDBF2B-F2B2-4C40-AAB7-0DF3F0BB0508} " = dir=in | app=c:\program files\hp\hp photosmart 7510 series\bin\hpnetworkcommunicator.exe |
" {A652D3CC-49D6-44F7-BC34-B8BB4E330EEA} " = protocol=6 | dir=out | app=system |
" {A70F2E8E-BC61-4D54-8036-B225E69627BC} " = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
" {ABB526F3-1872-4A82-AEA5-5CA355B5E30A} " = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.313_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
" {AEFE7BCB-963F-4CFC-8147-1D67C8FAD561} " = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
" {B341C443-270B-46A1-878F-17753312503D} " = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
" {B648A855-6226-4B5C-AAE5-8AD2FC1E336C} " = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
" {B6AC638A-711F-4457-9805-CDB5317EE77A} " = dir=out | name=onenote |
" {B7A2DCB4-0F49-4131-B15B-CEF3DA191D61} " = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
" {B7F6E4E7-B414-4CD7-AAFB-323FCD53439C} " = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
" {BBB13777-ABB2-47C2-97F4-AB2A7389F9C0} " = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
" {BEA71885-997C-4A65-8EE9-BB19B0FA8F40} " = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
" {BF1B416B-27EB-4B84-9B21-86EBF6DF01A2} " = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
" {BFA781CC-C941-4414-B992-6814A41FE7E1} " = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
" {C054972E-856F-4EB8-9076-ED0F17887AD8} " = dir=out | name=@{microsoft.bingfinance_3.0.4.298_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
" {C549D7F2-C68F-463B-91BC-E7B48981126F} " = dir=out | name=ebay |
" {C8156503-A0A7-47D7-815E-E598AA89085C} " = dir=out | name=norton studio |
" {CBDED272-AA87-4CF2-9B4D-5B81C832971C} " = dir=out | name=deals & offers |
" {D10D9E67-14F5-4DF2-9859-CBE9BCD754A0} " = dir=out | name=amazon |
" {D6980480-941A-4DF6-AB81-3734ECD3D779} " = dir=out | name=junipernetworks.junospulsevpn |
" {DB59588E-ED90-4C47-A7B5-7929DD0C0BD2} " = dir=out | name=checkpoint.vpn |
" {E06315AD-71BB-45FE-A56C-ED57083F35DA} " = dir=in | app=c:\users\basia\appdata\local\microsoft\skydrive\skydrive.exe |
" {E6B74605-2865-4DB2-B76F-CD139210B4D5} " = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
" {EC799E33-72BA-42D7-9127-DEFE68F9799D} " = dir=in | name=junipernetworks.junospulsevpn |
" {F06C0171-8744-4C31-B54B-703F91ABBE61} " = dir=in | name=next issue magazines |
" {F186946F-A088-4295-A8A6-E207EE0F4512} " = dir=in | name=zinio |
" {F2333530-9084-46C1-8923-FCB2B3FDA6A4} " = dir=in | app=c:\program files\hp\hp photosmart 7510 series\bin\hpnetworkcommunicatorcom.exe |
" {F64300AD-D559-4000-BD45-0997BCC8E70A} " = dir=out | name=f5.vpn.client |
" {F77E5446-4378-4E99-8B7A-7061AAAEA193} " = dir=in | name=f5.vpn.client |
" {F81B9F51-8ADE-4D9D-BBEA-381D3180762B} " = dir=out | name=@{microsoft.bingsports_3.0.4.298_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
" {FE85B768-14B6-4D91-8641-90F36FF6770D} " = dir=out | name=iheartradio |
" {FE8BA429-9A5B-4DBB-8B2B-A4DB00E909AA} " = dir=out | name=@{microsoft.zunemusic_2.6.672.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
" {FEFF9904-0000-4BB2-BC83-2F43594B67DB} " = dir=in | name=skype |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
" {071c9b48-7c32-4621-a0ac-3f809523288f} " = Microsoft Visual C++ 2005 Redistributable (x64)
" {1515F5E3-29EA-4CD1-A981-032D88880F09} " = TOSHIBA Audio Enhancement
" {1844CFE2-EBA3-490A-8A5E-9BFC646342FD} " = TOSHIBA Function Key
" {1D8E6291-B0D5-35EC-8441-6616F567A0F7} " = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
" {21A63CA3-75C0-4E56-B602-B7CD2EF6B621} " = TOSHIBA Application Installer
" {24C7AD6B-F418-4D3B-B7F2-F3603FD720BF} " = HP Photosmart 7510 series Basic Device Software
" {27DEA29A-222C-45F8-B70D-0A7B303FC71B} " = Intel(R) Rapid Storage Technology
" {2ABBBD91-91E5-4AD7-929A-FE15D1DC0576} " = iTunes
" {37B8F9C7-03FB-3253-8781-2517C99D7C00} " = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
" {409CB30E-E457-4008-9B1A-ED1B9EA21140} " = Intel(R) Rapid Storage Technology
" {484A4296-6F3D-4182-8CFA-D664F7DA34AA} " = TOSHIBA Display Utility
" {566BB063-0E28-4273-A748-690BE86A7E26} " = HP Photosmart 7510 series Product Improvement Study
" {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4} " = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
" {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} " = Bonjour
" {8220EEFE-38CD-377E-8595-13398D740ACE} " = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
" {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} " = Microsoft Silverlight
" {90150000-008F-0000-1000-0000000FF1CE} " = Office 15 Click-to-Run Licensing Component
" {929FBD26-9020-399B-9A7A-751D61F0B942} " = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
" {9495AEB4-AB97-39DE-8C42-806EEF75ECA7} " = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
" {94D2A899-0C34-4420-880E-AE337E635AB0} " = TOSHIBA eco Utility
" {A749D8E6-B613-3BE3-8F5F-045C84EBA29B} " = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
" {ad8a2fa1-06e7-4b0d-927d-6e54b3d31028} " = Microsoft Visual C++ 2005 Redistributable (x64)
" {B00F3D06-90CA-4388-8622-FD018675C29A} " = ESET Smart Security
" {B5E06417-A4AC-4225-B36E-7E34C91616E7} " = Intel(R) Trusted Connect Service Client
" {BDD99690-3541-4619-9D2A-3CDDB3E15F9E} " = Apple Mobile Device Support
" {BFE4C813-4DD4-4B1C-97F4-76A459055C8D} " = TOSHIBA Service Station
" {CD95F661-A5C4-44F5-A6AA-ECDD91C240E3} " = WinZip 18.5
" {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97} " = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
" 0B624A43DD66DBF5CF3EDFA9741A364E688062A4 " = Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices (03/07/2012 )
" Microsoft Visual Studio 2010 Tools for Office Runtime (x64) " = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
" O365HomePremRetail - pl-pl " = Microsoft Office 365 - pl-pl
" SynTPDeinstKey " = Synaptics Pointing Device Driver
" WinRAR archiver " = WinRAR 5.10 (64-bitowy)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
" {12688FD7-CB92-4A5B-BEE4-5C8E0574434F} " = Utility Common Driver
" {12DA0E6F-5543-440C-BAA2-28BF01070AFA}{163ac2d4} " = LibraryProc
" {13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} " = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
" {1E6A96A1-2BAB-43EF-8087-30437593C66C} " = TOSHIBA System Driver
" {1F1C2DFC-2D24-3E06-BCB8-725134ADF989} " = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
" {2359C6E9-DE4F-4FDA-9C12-AE6EFC2EE330} " = Digital Pass Launcher
" {236BB7C4-4419-42FD-0409-1E257A25E34D} " = Adobe Photoshop CS2
" {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7} " = Skype(TM) 7.1
" {26A24AE4-039D-4CA4-87B4-2F83218031F0} " = Java 8 Update 31
" {2BFC7AA0-544C-4E3A-8796-67F3BE655BE9} " = Microsoft XNA Framework Redistributable 4.0
" {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App " = Update Installer for WildTangent Games App
" {3384E1D9-3F18-4A98-8655-180FEF0DFC02} " = TOSHIBA User's Guide
" {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} " = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
" {3611CA6C-5FCA-4900-A329-6A118123CCFC} " = Bing Bar
" {37476589-E48E-439E-A706-56189E2ED4C4} " = DiscountMan
" {37476589-E48E-439E-A706-56189E2ED4C4}_is1 " = Supreme AdBlocker
" {3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E} " = QuickTime 7
" {44157EB3-D8D0-4BB1-B0F5-AD2C38814ED1} " = HP Support Solutions Framework
" {4A03706F-666A-4037-7777-5F2748764D10} " = Java Auto Updater
" {4D57ED72-6B01-40BD-9CA9-012B8FC09CEB} " = TOSHIBA System Settings
" {4F0F44AF-90E9-4A6E-9E82-354A3AB79F22} " = TOSHIBA Start
" {59358FD4-252B-4B38-AB81-955C491A494F} " = TOSHIBA Password Utility
" {5AF550B4-BB67-4E7E-82F1-2C4300279050} " = TOSHIBARegistration
" {5BC2B5AB-80DE-4E83-B8CF-426902051D0A} " = Realtek Card Reader
" {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} " = Google Update Helper
" {620BBA5E-F848-4D56-8BDA-584E44584C5E} " = TOSHIBA Flash Cards Support Utility
" {6357D25F-A9C9-4CC7-A1FB-0DCF344E7C40} " = HP Photosmart 7510 series Help
" {65153EA5-8B6E-43B6-857B-C6E4FC25798A} " = Intel(R) Management Engine Components
" {6C36881B-0E51-4231-9D02-BF2149664D34} " = Google Drive
" {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba " = WildTangent Games App (Toshiba Games)
" {710f4c1c-cc18-4c49-8cbf-51240c89a1a2} " = Microsoft Visual C++ 2005 Redistributable
" {716C8275-A4A9-48CB-88C0-9829334CA3C5} " = Toshiba Quality Application
" {7299052b-02a4-4627-81f2-1818da5d550d} " = Microsoft Visual C++ 2005 Redistributable
" {77D28FF5-242F-488A-8215-937D6A4D69E0} " = Adobe AIR
" {786C5747-1033-0000-B58E-000000000001} " = Adobe Stock Photos 1.0
" {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} " = Apple Software Update
" {7f51bdb9-ee21-49ee-94d6-90afc321780e} " = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
" {83CAF0DE-8D3B-4C37-A631-2B8F16EC3031} " = Obsługa programów Apple
" {8833FFB6-5B0C-4764-81AA-06DFEED9A476} " = Realtek Ethernet Controller Driver
" {893CB813-4179-4BFE-8D33-ABCC38816B48} " = Amazon 1Button App
" {8EDBA74D-0686-4C99-BFDD-F894678E5B39} " = Adobe Common File Installer
" {90150000-008C-0000-0000-0000000FF1CE} " = Office 15 Click-to-Run Extensibility Component
" {90150000-008C-0415-0000-0000000FF1CE} " = Office 15 Click-to-Run Localization Component
" {912D30CF-F39E-4B31-AD9A-123C6B794EE2} " = HP Update
" {9A25302D-30C0-39D9-BD6F-21E6EC160475} " = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
" {9BE518E6-ECC6-35A9-88E4-87755C07200F} " = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
" {AC76BA86-7AD7-FFFF-7B44-AB0000000001} " = Adobe Reader XI (11.0.10) MUI
" {AD11DADE-C597-45D9-D8C5-1D2EB0B89613} " = Announcify
" {B175520C-86A2-35A7-8619-86DC379688B9} " = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
" {B46BEA36-0B71-4A4E-AE41-87241643FA0A} " = CyberLink PowerDVD 12
" {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF} " = TOSHIBA Recovery Media Creator
" {B74D4E10-1033-0000-0000-000000000001} " = Adobe Bridge 1.0
" {BD95A8CD-1D9F-35AD-981A-3E7925026EBB} " = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
" {C3A32068-8AB1-4327-BB16-BED9C6219DC7} " = Atheros Driver Installation Program
" {C7B52FAF-58D8-438C-B810-F78C3C927504} " = ChomikBox
" {ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} " = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
" {E9787678-1033-0000-8E67-000000000001} " = Adobe Help Center 1.0
" {E9AD2F38-EF9C-B9DA-048A-A92FBC17701E} " = NicieoOffeRS
" {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} " = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
" {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} " = Intel(R) Processor Graphics
" {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} " = Realtek High Definition Audio Driver
" {f65db027-aff3-4070-886a-0d87064aabb1} " = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
" {F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} " = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
" Adobe AIR " = Adobe AIR
" Adobe Flash Player NPAPI " = Adobe Flash Player 16 NPAPI
" Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D} " = Adobe Photoshop CS2
" GoPro Studio " = GoPro Studio 2.5.4
" HP Photo Creations " = HP Photo Creations
" InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F} " = Utility Common Driver
" InstallShield_{59358FD4-252B-4B38-AB81-955C491A494F} " = TOSHIBA Password Utility
" InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E} " = TOSHIBA Flash Cards Support Utility
" InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A} " = CyberLink PowerDVD 12
" Mozilla Firefox 37.0.1 (x86 en-US) " = Mozilla Firefox 37.0.1 (x86 en-US)
" MozillaMaintenanceService " = Mozilla Maintenance Service
" PhotoScape " = PhotoScape
" TOEFL Official Guide " = TOEFL Official Guide 4.0
" WildTangent wildgames Master Uninstall " = WildTangent Games
" Winamp " = Winamp
" WTA-0e1aac2b-cbd2-4ab5-b85b-bd19c0cb57fc " = Plants vs. Zombies - Game of the Year
" WTA-5661dc94-64c9-4666-b499-af46b93af82f " = Bejeweled 3
" WTA-727e6c6f-6a4f-4864-9619-70941e1bbb71 " = King Oddball
" WTA-a63a572c-5080-4a5c-96a7-89ffba188a5e " = Luxor Evolved
" WTA-ad5daadd-b9f0-49b7-b957-5c72307caf56 " = Cut the Rope

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-188607031-2838451578-2325805074-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
" OneDriveSetup.exe " = Microsoft OneDrive
" Pokki_893e2a8f4b240ed6d7def79e56791067c96f41be " = Groupon
" Pokki_Start_Menu " = Pokki Start Menu

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2015-03-26 01:23:25 | Computer Name = Basia | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2015-03-26 01:23:25 | Computer Name = Basia | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m- & gt; NextScheduledEvent 15234

Error - 2015-03-26 01:23:25 | Computer Name = Basia | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m- & gt; NextScheduledSPRetry 15234

Error - 2015-03-27 18:36:02 | Computer Name = Basia | Source = Office 2013 Licensing Service | ID = 0
Description =

Error - 2015-03-27 18:41:52 | Computer Name = Basia | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 2015-03-28 00:34:39 | Computer Name = Basia | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2015-03-28 00:34:39 | Computer Name = Basia | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m- & gt; NextScheduledEvent 20490719

Error - 2015-03-28 00:34:39 | Computer Name = Basia | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m- & gt; NextScheduledSPRetry 20490719

Error - 2015-03-28 13:38:25 | Computer Name = Basia | Source = Office 2013 Licensing Service | ID = 0
Description =

Error - 2015-03-29 22:36:50 | Computer Name = Basia | Source = Office 2013 Licensing Service | ID = 0
Description =

[ System Events ]
Error - 2015-03-13 01:40:55 | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3022796).

Error - 2015-03-13 01:40:55 | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3012235).

Error - 2015-03-13 01:40:55 | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3012702).

Error - 2015-03-13 01:40:55 | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3036562).

Error - 2015-03-13 01:40:55 | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3025417).

Error - 2015-03-13 01:40:55 | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3024755).

Error - 2015-03-14 12:29:00 | Computer Name = Basia | Source = Schannel | ID = 36888
Description = A fatal alert was generated and sent to the remote endpoint. This
may result in termination of the connection. The TLS protocol defined fatal error
code is 70. The Windows SChannel error state is 105.

Error - 2015-03-17 01:36:31 | Computer Name = Basia | Source = DCOM | ID = 10010
Description =

Error - 2015-03-17 07:36:39 | Computer Name = Basia | Source = Schannel | ID = 36888
Description = A fatal alert was generated and sent to the remote endpoint. This
may result in termination of the connection. The TLS protocol defined fatal error
code is 70. The Windows SChannel error state is 105.

Error - 2015-03-17 11:35:08 | Computer Name = Basia | Source = EventLog | ID = 6008
Description = The previous system shutdown at 01:31:08 on ?2015-?03-?17 was unexpected.


& lt; End of report & gt;


Download file - link to post