OTL Extras logfile created on: 2013-01-18 00:40:42 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\kamilox09\Downloads 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16453) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,45 Gb Total Physical Memory | 1,98 Gb Available Physical Memory | 57,40% Memory free 6,95 Gb Paging File | 5,23 Gb Available in Paging File | 75,21% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 186,30 Gb Total Space | 126,30 Gb Free Space | 67,79% Space Free | Partition Type: NTFS Drive D: | 258,44 Gb Total Space | 224,89 Gb Free Space | 87,02% Space Free | Partition Type: NTFS Drive E: | 9,99 Gb Total Space | 9,99 Gb Free Space | 100,00% Space Free | Partition Type: FAT32 Drive F: | 100,00 Gb Total Space | 64,42 Gb Free Space | 64,42% Space Free | Partition Type: NTFS Drive G: | 177,88 Gb Total Space | 141,41 Gb Free Space | 79,50% Space Free | Partition Type: NTFS Computer Name: KAMIL | User Name: kamilox09 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1705020764-1417337395-498579948-1001\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{09CE66F3-3114-4CAF-AD5C-950EB4218B15}" = lport=10243 | protocol=6 | dir=in | app=system | "{11472CA1-7421-444C-8CF8-C5EFE8DC93F6}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{1FDA833A-01ED-49D5-87C7-770E0EE220EF}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{22AB7501-CDC9-4523-8355-C11DE3C3F08C}" = rport=10243 | protocol=6 | dir=out | app=system | "{32036149-77D1-4A6A-AD95-CB7B762A424D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3311B728-3EDF-463E-B68E-F3A99F4A5507}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{42771BE7-A4A0-4039-94B1-5B877860FAE0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{480B5456-39C0-413D-9E68-87CBC13E80FB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4BACD258-7E90-4E45-86C4-A356251E2DCE}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{8A8DB07A-210A-440F-BCC6-2632E408CFC8}" = lport=2869 | protocol=6 | dir=in | app=system | "{9C4D8A13-46CE-4394-9807-BF901584EF2A}" = rport=2869 | protocol=6 | dir=out | app=system | "{AF0CB796-E594-419A-9FAC-8B0CFCF0FCFB}" = lport=2869 | protocol=6 | dir=in | app=system | "{B2CD25BB-8C7A-4134-96DF-7D97F3311568}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BE2B4A7D-7D41-4A62-AD81-E72DC43DB34F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CAEFBF8D-F613-4E8B-81D4-AABF389C0104}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{DB31D4E7-2FAF-4273-9E5A-0FA97F7650F8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E132D506-59F7-47DE-B1D1-5A2FC6E586D3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F64FE254-6B56-4CB9-A8CE-F4C4DBB5DE2B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F8208BC8-EF92-4085-9487-FEBB60AB0FC2}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0468657F-A1DE-4F2C-9B1A-9DFBB4C9CBB3}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{04AC3678-5890-4D66-80EE-A95C565B4F2F}" = dir=in | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{0728F54F-7714-4CD0-801B-91F57566C0B6}" = protocol=17 | dir=in | app=d:\games\fifa 13\game\fifa13.exe | "{072B247A-FA3F-4233-977C-A8D80A682B3C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{07987CBE-B202-4EB9-8AA0-E6185B96D8A1}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{08C9B392-9F3B-4F3B-8B6F-92E74A18E7CC}" = protocol=17 | dir=in | app=c:\users\kamilox09\appdata\roaming\dropbox\bin\dropbox.exe | "{0B6EB989-A5D5-41F1-A48E-A08F56CBBD04}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{0F662501-853E-4047-A025-0F3E9F7AA238}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{1151500A-B3F1-408D-9B27-663DB100032C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{185F3153-6A26-4C74-B1D8-130D82B40B3D}" = protocol=17 | dir=in | app=c:\users\kamilox09\appdata\roaming\dropbox\bin\dropbox.exe | "{190991C3-9E9D-46BC-AD6E-4934DD19B977}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{1D0E3940-BC4D-4865-A134-C0760D942C0C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{1F06C72D-EA37-4339-8AD7-B00A2248E284}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | "{275292C0-51F8-4680-AE76-964D855406B5}" = dir=out | name=ipla | "{2BB53741-3E5F-496D-9952-FF498717AC95}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{2C89F3E9-1D37-4856-B31B-6A00E1FA0C03}" = dir=in | name=@{microsoft.skypeapp_1.3.0.112_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{337287D9-B1A8-4D3E-9B7C-34361F3C1EE2}" = dir=out | name=krzyżówki | "{33AF82E7-0907-42D7-B65D-F7D4EE222C01}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{35B6045B-F026-494F-83EA-9402D8CF237B}" = protocol=6 | dir=out | app=system | "{38E8D644-66CD-40CA-8AF4-99AA6112F937}" = dir=out | name=fresh paint | "{400DFF32-B6B6-461D-917F-0081BA621350}" = dir=out | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{439C771A-60CE-4288-B800-2F2D70568970}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{43FA3090-414D-4E2D-B217-40BCFA3DF7D5}" = dir=out | name=@{microsoft.xboxlivegames_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{457C7863-9000-4731-83BC-F1EAB7272004}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{489426D6-A3FD-45AF-9728-E71C1F38D346}" = dir=out | name=@{microsoft.bingnews_1.7.0.31_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{48D9B919-FA71-4C87-87D7-ED65AABE1775}" = dir=out | name=taptiles | "{49078641-01B6-4842-98EE-EB1401A4A44C}" = dir=out | name=@{microsoft.zunemusic_1.1.144.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{4FACC8DA-3DA4-4359-B50F-483F17A43D33}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{57DC58A6-4E8A-41CE-BB1A-86892EBCCB83}" = dir=out | name=ling.pl | "{5BC60829-1ADE-4172-9784-08D3DD22D0BA}" = protocol=6 | dir=in | app=c:\users\kamilox09\appdata\roaming\dropbox\bin\dropbox.exe | "{60077DFD-C73E-4C91-81AE-C20015C08217}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{62CA6593-905C-4F80-A3E9-F3BD6419C2B9}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{6936ABBA-B9E9-4B99-8D84-1C36DE79EB06}" = dir=out | name=wirtualny alkomat | "{6A5B58A9-DBF1-4BD9-B5CF-83E09F636813}" = dir=out | name=@{microsoft.bingtravel_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{6EC412F9-7F7D-43F4-AE20-8D8811A92BDB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7022B81E-4A00-47E4-9DF8-B6C9BF3B9437}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | "{740FFF2F-4CA0-4C42-B2A5-DE7B16C4003E}" = protocol=6 | dir=in | app=d:\games\fifa 13\game\fifa13.exe | "{74B1077D-A8BD-4977-B6C3-677CFB2CC5E9}" = dir=out | name=@{microsoft.bingfinance_1.7.0.29_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{7B77B7DC-7270-4CD1-A06E-BF55B4A6BBE3}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{7DAA21AB-817C-4108-A6C1-FB7E286E990E}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{85175A50-0A5F-42CF-9705-E0A7D189CE8B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{8B9FD43F-0E5B-4E1F-9DBF-C803FD86A3BF}" = dir=out | name=wordament | "{8E504A65-095F-477D-86D5-9A360AC95453}" = dir=out | name=translatica – translator pwn.pl | "{8FDDDD20-2756-46A7-8051-C4DF8249063E}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{9578D8C6-29FD-4B7B-8D73-BFA3D30436A2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{9DFD505E-B3A7-4F78-9920-725650CF4806}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{A0BEB4B6-6138-4E07-BE57-BFE0E95B8169}" = dir=out | name=windows_ie_ac_001 | "{A1463DFF-5A9C-49CA-8486-63348DA9911B}" = dir=out | name=@{microsoft.bingweather_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{A47D96CD-719C-4939-97B1-AA687D8770A6}" = dir=out | name=@{microsoft.bingsports_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{A876D5E1-B152-416E-BAD5-D6AC25AE24D0}" = dir=out | name=@{microsoft.skypeapp_1.3.0.112_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{B3994C94-FE6B-4546-A570-E22D07014358}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{BC350505-DB7F-4EA0-8FB1-3C81FC99D828}" = dir=out | name=adera | "{C5050CE3-3FB4-40CA-B571-B495372BDC12}" = dir=out | name=accuweather for windows 8 | "{C82F941C-C189-418A-ADAD-0392C3B574BD}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{C9397686-9FAF-4569-8C33-667F4E9EBABE}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CADFA79D-C356-4982-B9B5-ABF3B73BCD82}" = dir=out | name=microsoft solitaire collection | "{CB9038E5-5DCC-49D4-BE22-2B0E58C0552A}" = protocol=6 | dir=in | app=c:\users\kamilox09\appdata\roaming\dropbox\bin\dropbox.exe | "{CDCDB8F8-BB6C-4056-BEC5-ED352591A2BC}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{D116C014-675A-4F70-9EC4-EA63D6FD8AC3}" = dir=out | name=microsoft minesweeper | "{D1CD8369-E646-48F2-890A-873C5DC5E8C4}" = dir=out | name=google search | "{DBA41DCA-E6A3-412B-99A1-954621D5E17D}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{E61F8003-78BF-487F-8F92-CFBA103027CB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EB6F781A-3F0F-4D28-8B97-8B30609E9D15}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FC1CE861-E647-470D-BE62-CD003A3800C5}" = dir=out | name=@{microsoft.zunevideo_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "TCP Query User{CD4DAB44-4E05-4E96-B215-19693D788C69}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "UDP Query User{3DC6985E-C5B4-4575-867E-B1C825B4FDE1}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0015-0415-1000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0015-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0415-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0016-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0415-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0018-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0415-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-0019-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0415-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001A-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0415-1000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001B-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUS_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0415-1000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-001F-0415-1000-0000000FF1CE}_Office14.PROPLUS_{329A3D98-9583-4B84-B18B-498E7AB65C43}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-002C-0415-1000-0000000FF1CE}_Office14.PROPLUS_{BFEB53FA-3044-47FD-BB50-9DCBBEED79EF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0043-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2010 "{90140000-0043-0415-1000-0000000FF1CE}_Office14.PROPLUS_{FF5F6090-64DF-4BF6-BADD-71A64FDA70D2}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0415-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-0044-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-006E-0415-1000-0000000FF1CE}_Office14.PROPLUS_{3A96ABFF-5202-47B1-B5A2-DDE76563AF61}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0415-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00A1-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0415-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{90140000-00BA-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1) "{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64) "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64 "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "5AB9160B769DD2E134ADCB8010377DECA2479378" = Pakiet sterowników systemu Windows - ASUS (ATP) Mouse (11/09/2012 1.0.0.153) "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "WinRAR archiver" = WinRAR 4.20 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3 "{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 11 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D3286A6-F6AB-498A-82A4-E4F040529F3D}" = ASUS Smart Gesture "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1 "{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries "{58172D66-2F69-4215-9AEC-ED8196023736}" = ASUS Tutor "{63B7AC7E-0178-4F4F-A79B-08D97ADD02D7}" = System Requirements Lab for Intel "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{749F674B-2674-47E8-879C-5626A06B2A91}" = ASUS InstantOn "{7A21C722-F259-4976-B7AA-6658E5FDEDAF}" = Google Drive "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}" = ASUS Instant Connect "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}" = FIFA 13 "{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.5) MUI "{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Battle for Wesnoth 1.11.1" = Battle for Wesnoth 1.11.1 "Combined Community Codec Pack_is1" = Combined Community Codec Pack 2012-12-30 "IrfanView" = IrfanView (remove only) "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.70.0.1100 "Mozilla Firefox 18.0 (x86 pl)" = Mozilla Firefox 18.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "SpeedFan" = SpeedFan (remove only) "Winamp" = Winamp [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1705020764-1417337395-498579948-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "Winamp Detect" = Detektor Winampa [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-01-03 12:56:17 | Computer Name = Kamil | Source = McLogEvent | ID = 5022 Description = Error - 2013-01-03 14:53:07 | Computer Name = Kamil | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: mpc-hc.exe, wersja: 1.6.6.6419, sygnatura czasowa: 0x50df9a44 Nazwa modułu powodującego błąd: splitter.ax, wersja: 1.11.288.0, sygnatura czasowa: 0x4e68caa4 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000080d1 Identyfikator procesu powodującego błąd: 0x19d4 Godzina uruchomienia aplikacji powodującej błąd: 0x01cde9e0dcbfe511 Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Combined Community Codec Pack\MPC\mpc-hc.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\Combined Community Codec Pack\Filters\Haali\splitter.ax Identyfikator raportu: cf34f568-55d6-11e2-be7c-50465d9b03ee Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2013-01-03 17:19:16 | Computer Name = Kamil | Source = Microsoft-Windows-Immersive-Shell | ID = 2486 Description = Aplikacja 95AD97AE.Translaticatranslatorpwn.pl_6dfnepbt1ht20!App nie została uruchomiona w wyznaczonym czasie. Error - 2013-01-03 17:20:21 | Computer Name = Kamil | Source = ESENT | ID = 454 Description = wwahost (5992) ModernDatalayerESE: Odzyskiwanie/przywracanie bazy danych nie powiodło się z powodu nieoczekiwanego błędu: -545. Error - 2013-01-07 14:58:24 | Computer Name = Kamil | Source = Microsoft-Windows-Immersive-Shell | ID = 2486 Description = Aplikacja 44328PrzemoApps.WirtualnyAlkomat_pzgy41vsed258!App nie została uruchomiona w wyznaczonym czasie. Error - 2013-01-07 14:58:54 | Computer Name = Kamil | Source = Application Hang | ID = 1002 Description = Program Breathalyzer.exe w wersji 1.0.0.0 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 324 Godzina rozpoczęcia: 01cded08eea83c97 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Program Files\WindowsApps\44328PrzemoApps.WirtualnyAlkomat_1.0.0.10_neutral__pzgy41vsed258\Breathalyzer.exe Identyfikator raportu: 3e0495a1-58fc-11e2-be85-5e85de6a9d0b Pełna nazwa pakietu powodującego błąd: 44328PrzemoApps.WirtualnyAlkomat_1.0.0.10_neutral__pzgy41vsed258 Identyfikator aplikacji względem pakietu powodującego błąd: App Error - 2013-01-07 14:59:00 | Computer Name = Kamil | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Aktywacja aplikacji 44328PrzemoApps.WirtualnyAlkomat_pzgy41vsed258!App nie powiodła się. Błąd: -2144927142. Więcej informacji można znaleźć w dzienniku Microsoft-Windows-TWinUI/Działa. Error - 2013-01-07 15:02:00 | Computer Name = Kamil | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: svchost.exe, wersja: 6.2.9200.16420, sygnatura czasowa: 0x505a9a4e Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.2.9200.16420, sygnatura czasowa: 0x505ab405 Kod wyjątku: 0xc000000d Przesunięcie błędu: 0x00000000000f49e8 Identyfikator procesu powodującego błąd: 0xab0 Godzina uruchomienia aplikacji powodującej błąd: 0x01cded08fca0b338 Ścieżka aplikacji powodującej błąd: C:\Windows\System32\svchost.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: b6d930fd-58fc-11e2-be85-5e85de6a9d0b Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2013-01-09 13:10:51 | Computer Name = Kamil | Source = Microsoft-Windows-Immersive-Shell | ID = 2484 Description = Działanie pakietu Microsoft.BingSports_1.7.0.26_x64__8wekyb3d8bbwe zostało zakończone, ponieważ operacja wstrzymywania pakietu trwała zbyt długo. Error - 2013-01-09 13:13:01 | Computer Name = Kamil | Source = Application Hang | ID = 1002 Description = Program wwahost.exe w wersji 6.2.9200.16420 przestał współpracować z systemem Windows i został zamknięty. Aby sprawdzić, czy jest dostępnych więcej informacji na temat tego problemu, sprawdź historię problemu w aplecie Centrum akcji w Panelu sterowania. Identyfikator procesu: 9c4 Godzina rozpoczęcia: 01cdee8c232d4799 Godzina zakończenia: 4294967295 Ścieżka aplikacji: C:\Windows\system32\wwahost.exe Identyfikator raportu: 84e1ea44-5a7f-11e2-be86-50465d9b03ee Pełna nazwa pakietu powodującego błąd: Microsoft.BingSports_1.7.0.26_x64__8wekyb3d8bbwe Identyfikator aplikacji względem pakietu powodującego błąd: AppexSports [ System Events ] Error - 2013-01-10 18:39:43 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 18:41:58 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 18:48:13 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 18:50:28 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 18:56:42 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 18:58:57 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 19:05:12 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 19:06:53 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 19:06:53 | Computer Name = Kamil | Source = ipnathlp | ID = 34001 Description = Error - 2013-01-10 19:06:54 | Computer Name = Kamil | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = < End of report >