OTL Extras logfile created on: 2012-08-27 10:49:57 - Run 1 OTL by OldTimer - Version 3.2.59.1 Folder = C:\Users\user\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 2,86 Gb Available Physical Memory | 71,48% Memory free 7,99 Gb Paging File | 6,81 Gb Available in Paging File | 85,21% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 97,56 Gb Total Space | 39,74 Gb Free Space | 40,74% Space Free | Partition Type: NTFS Drive D: | 195,31 Gb Total Space | 92,73 Gb Free Space | 47,48% Space Free | Partition Type: NTFS Drive E: | 172,79 Gb Total Space | 169,55 Gb Free Space | 98,13% Space Free | Partition Type: NTFS Computer Name: USER-KOMPUTER | User Name: user | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software) [HKEY_USERS\S-1-5-21-1836913075-3883909762-3358614920-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. https [open] -- "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04C408C1-27DB-4F2C-AD07-1D9FF8F4CD7E}" = rport=138 | protocol=17 | dir=out | app=system | "{0894CDD7-2394-43BB-B6A7-81932E3EF342}" = rport=139 | protocol=6 | dir=out | app=system | "{0F8353DD-7C45-4DBF-9011-76C6C4896E18}" = lport=137 | protocol=17 | dir=in | app=system | "{12859A19-7CFA-4004-B0E1-8F99D5387A3E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{1D0669E3-7013-41DC-B97A-621271D91799}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{228ED7B1-CC35-476C-9A5B-B83763A1BB82}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{228F68CA-7797-4727-A1A2-B386950ED796}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2350214B-51C2-4303-BBF5-6E365F5F3E23}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{2D4A9915-A05D-4525-8B61-A138D380AEF5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{55FCE3D4-C3F2-45D2-9909-769710BBFD90}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{67340AD7-3B5E-4012-9D88-9F366D40359B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6DE10FA1-8603-4450-ABBD-08323ACB6FB0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{7071D99C-8941-4A7C-ADC5-C0D48A641C6F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{762394A6-DFA4-43FB-A9A6-85259CE1B76C}" = rport=445 | protocol=6 | dir=out | app=system | "{8169E3F9-3C4C-4FE9-B4CA-A94AB9F1DB1A}" = lport=138 | protocol=17 | dir=in | app=system | "{984CD7C1-1A5C-479A-820D-C8E9557DA319}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{A96656F4-2D01-45C8-985E-565A00209703}" = lport=139 | protocol=6 | dir=in | app=system | "{AB759DE5-030C-4B9E-8DC0-5BCE46A63FA7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{BFDFEAB5-2CAE-4FA3-B3AF-D0FE22F65447}" = lport=445 | protocol=6 | dir=in | app=system | "{DAEF2E3C-1669-4296-80BC-E3999A28CBA0}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{DCEB49E5-FD63-4513-AD3A-E8E0DF266B6A}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{DD8D4305-6504-43BB-89FC-CB10D14813BD}" = rport=137 | protocol=17 | dir=out | app=system | "{EFC9DAFA-D8D4-4488-96C9-9F3CFAFB79F0}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05AE9082-2C27-46B9-97E8-883A1AF658B7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{153286BD-D46B-4131-AF5D-97607EDB2530}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe | "{19C8AF0E-0FDF-4D09-9726-628F89403640}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1BDDF307-DF6C-48E0-9677-76A5EB20F52A}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{1C86E9AF-0A51-47D8-8570-58B0EA5106C8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{21B3EB89-9A67-4A8C-B136-19C1B8AD2CC4}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{2BE9A0EA-6658-4102-AC02-04DD17E8E7D3}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{32F31642-7D8A-4E92-81C2-2997D1FEAA4A}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe | "{351C5E47-F96C-473F-AEA9-991ACDFF3673}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{36911C5C-D824-489F-B65A-F12040AA192E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{4E3C9EE0-A12F-47F8-AD58-DFED23F44DF1}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "{5023164B-CF4B-4C7B-B92B-0E949D180BA4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{50630B16-25A1-48F2-8B84-3239E6683E75}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{520C8D0D-D036-4D2E-948D-427280068EA7}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{7FB60886-02CF-4B8B-893E-7C9CB22A72EE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{8A42C7DC-9F3C-4DB1-8A7A-5215B4B85577}" = protocol=17 | dir=in | app=d:\avg\avgmfapx.exe | "{91AF53FD-EA69-42E9-8626-2BC804328C3A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{91FD1301-9456-4DA7-8F5B-F34301F9D584}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{9B7CDC4E-EA74-4B3C-B816-3CC320628719}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{9B7D8E00-1DB8-4242-97E9-17F0402BCE1E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{A025B242-0F68-43C2-BE2D-FAD0D9FF6CC0}" = protocol=6 | dir=in | app=d:\avg\avgmfapx.exe | "{A732FA41-9AD8-4A87-BD12-8A2A2096C5C6}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{AB4CEFD0-FFA8-48DC-9C6B-F92075F1A4F8}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{B3E0BEF8-9A67-46B4-9C06-A91C7632A057}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{B93766C8-4E28-4D7E-AB37-08B115673E34}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "{BCAB09A8-EF9E-434A-9272-55CD2ABCFD43}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{BF6C7CD9-CB78-4701-AC8D-6E29D83A6B32}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe | "{C77A45C0-3D50-4E0C-B548-F042BA969D37}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D501CA5F-E351-4164-84DF-B731B7B60127}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe | "{DCF3833F-AB2A-4202-A8C3-A7B4F306A2E9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{E50BCC5F-DF8E-4749-A30E-FC283804B325}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{E76E6DCE-AEB0-4B16-8171-66BE11A4F344}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{F0E3C709-FAC0-44D7-8F63-5D2F1D0479A6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{F2CCF11B-1B75-4E00-95B6-2D17FB428B86}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{F38BE643-042E-47D0-8CBC-FCBFB7AAD856}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe | "{F9871D76-F25E-49FF-B7B7-6AB0D24145AA}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1050 j410 series\bin\usbsetup.exe | "TCP Query User{13792A23-3EA6-4ADE-851F-EFF96E374BF6}G:\gv\lol.launcher.exe" = protocol=6 | dir=in | app=g:\gv\lol.launcher.exe | "TCP Query User{21D92844-A2AD-474D-A52C-D114449C480D}E:\bartek\gry\lol\lol.launcher.exe" = protocol=6 | dir=in | app=e:\bartek\gry\lol\lol.launcher.exe | "TCP Query User{403007CC-59FF-452B-B54D-A64D039EE9A1}D:\gg\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=d:\gg\gadu-gadu 10\gg.exe | "TCP Query User{94E3FA5E-3B87-43EB-89B6-0496B90AE974}C:\users\user\desktop\wingate_6.6.4_1338.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\wingate_6.6.4_1338.exe | "TCP Query User{A8F95CE7-D618-4D77-8309-C3720C377F2F}D:\dc++\dcplusplus.exe" = protocol=6 | dir=in | app=d:\dc++\dcplusplus.exe | "TCP Query User{B49A8073-7E59-4165-BB1B-2AE08878B0B9}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "TCP Query User{D2CA5862-FF52-4BD5-AF35-B82E8F929D41}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "TCP Query User{DD4F8702-88BD-4919-A6DC-0F7D7D7DF1CD}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "TCP Query User{E9AAB08D-2A3C-44F5-829F-CE8C74C7BDAC}D:\gg\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=d:\gg\gadu-gadu 10\gg.exe | "TCP Query User{F412E1C6-6761-49C8-9F3F-3B8B3BE535A9}C:\program files (x86)\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nowe gadu-gadu\gg.exe | "UDP Query User{275F3E12-852C-4D6B-A9B5-46739B2DDF63}E:\bartek\gry\lol\lol.launcher.exe" = protocol=17 | dir=in | app=e:\bartek\gry\lol\lol.launcher.exe | "UDP Query User{34BC3CA6-CEC8-46E9-AD1A-A22C3BA954BE}C:\users\user\desktop\wingate_6.6.4_1338.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\wingate_6.6.4_1338.exe | "UDP Query User{3CA96CE0-2CDD-4027-81D6-9A10C145C374}D:\dc++\dcplusplus.exe" = protocol=17 | dir=in | app=d:\dc++\dcplusplus.exe | "UDP Query User{4B4B1A57-7F44-4A80-927E-826FB05FE612}G:\gv\lol.launcher.exe" = protocol=17 | dir=in | app=g:\gv\lol.launcher.exe | "UDP Query User{4D962A61-CD34-4B46-8F18-AAF1864FF553}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "UDP Query User{56C90054-5A10-4042-BFC0-CF2787E94265}C:\program files (x86)\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nowe gadu-gadu\gg.exe | "UDP Query User{62EA5FD7-1AD9-4C15-9138-A4A7A79CFE5C}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "UDP Query User{7BE4488A-9A0D-499B-A205-D07FF9F0DC35}D:\gg\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=d:\gg\gadu-gadu 10\gg.exe | "UDP Query User{7BF3562E-7D89-4F33-8325-2EE31E63E838}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "UDP Query User{8601A2FC-5E64-4CE7-90BA-32FF0067E99B}D:\gg\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=d:\gg\gadu-gadu 10\gg.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP495_series" = Canon MP495 series MP Drivers "{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode "{481A433E-2DB0-4650-9CEC-BE02413DF815}" = AVG 2011 "{61A3F855-4587-4187-9D77-2EF8CD825A47}" = AVG 2011 "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2BF224C-9818-4942-BF11-8929859E53AE}" = HP Deskjet 1050 J410 series Podstawowe oprogramowanie urządzenia "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit "AVG" = AVG 2011 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2B29EAF9-352F-4A0D-8CB1-D34113993DB7}" = OpenOffice.org 2.0.2 "{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}" = HP Deskjet 1050 J410 series Pomoc "{6C8FE025-F3BD-4F5E-A79C-57932DAEB3CF}" = ADONIS Community Edition 2.0 (English) "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1" = ALLConverter PRO 1.2 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A1DD0268-4069-4D39-B6D2-E00DB50CA9C4}" = League of Legends "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-A95000000001}" = Adobe Reader 9.5.0 - Polish "{ACEB2BAF-96DF-48FD-ADD5-43842D4C443D}" = Adobe AIR "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3 "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8 "{F1000000-0001-0000-0000-074957833700}" = ABBYY FineReader 10 Professional Edition "{F61DD673-0030-4BB2-A382-7E57E97F1045}" = Nero 7 Essentials "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "ALLPlayer_is1" = ALLPlayer V5.X "Android SDK Tools" = Android SDK Tools "BabylonToolbar" = Babylon toolbar on IE "Burger Island" = Burger Island (remove only) "Butterfly Escape_is1" = Butterfly Escape 1.0 "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "ENTERPRISE" = Microsoft Office Enterprise 2007 "funmoods" = Funmoods on IE and Chrome "Google Chrome" = Google Chrome "ipla" = ipla 2.3.5 "KLiteCodecPack_is1" = K-Lite Codec Pack 6.2.0 (Basic) "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151) "Opera 12.01.1532" = Opera 12.01 "Picasa 3" = Picasa 3 "RealPlayer 12.0" = RealPlayer "Rzeźnik MPEGów 1.1.991_is1" = Rzeźnik MPEGów 1.1.991 "SoftwareUpdUtility" = Download Updater (AOL LLC) "uTorrent" = µTorrent "Winamp" = Winamp "WinGimp-2.0_is1" = GIMP 2.6.10 "WinRAR archiver" = Archiwizator WinRAR [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1836913075-3883909762-3358614920-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Winamp Detect" = Detektor Winampa [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-01-01 08:31:21 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-02 04:28:05 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-02 11:00:16 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-03 04:54:56 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-03 12:50:11 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-04 04:16:07 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-04 17:18:27 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-05 16:32:16 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-06 06:24:17 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. Error - 2012-01-07 13:58:06 | Computer Name = user-Komputer | Source = MSSQLServer | ID = 19011 Description = SuperSocket info: FillAddress(MSAFD TCP/IP [TCP/IPv6]) : Error 0. [ OSession Events ] Error - 2010-11-01 16:07:40 | Computer Name = user-Komputer | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash. Error - 2012-01-13 07:48:15 | Computer Name = user-Komputer | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6654.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 8735 seconds with 1860 seconds of active time. This session ended with a crash. [ System Events ] Error - 2012-08-26 17:13:39 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-26 17:13:52 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7030 Description = Usługa PEVSystemStart jest oznaczona jako usługa interakcyjna. System jest jednak skonfigurowany tak, aby nie zezwalać na usługi interakcyjne, dlatego ta usługa może nie działać właściwie. Error - 2012-08-26 17:14:35 | Computer Name = user-Komputer | Source = atikmdag | ID = 52236 Description = CPLIB :: General - Invalid Parameter Error - 2012-08-26 17:14:35 | Computer Name = user-Komputer | Source = atikmdag | ID = 43029 Description = Display is not active Error - 2012-08-26 17:14:46 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7023 Description = Usługa Windows Defender zakończyła działanie; wystąpił następujący błąd: %%126 Error - 2012-08-26 17:16:16 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Usługa raportowania błędów systemu Windows. Error - 2012-08-26 18:00:22 | Computer Name = user-Komputer | Source = atikmdag | ID = 52236 Description = CPLIB :: General - Invalid Parameter Error - 2012-08-26 18:00:22 | Computer Name = user-Komputer | Source = atikmdag | ID = 43029 Description = Display is not active Error - 2012-08-27 04:44:42 | Computer Name = user-Komputer | Source = atikmdag | ID = 52236 Description = CPLIB :: General - Invalid Parameter Error - 2012-08-27 04:44:42 | Computer Name = user-Komputer | Source = atikmdag | ID = 43029 Description = Display is not active < End of report >