OTL Extras logfile created on: 2013-03-21 11:59:12 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = H:\otl 64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,75 Gb Available Physical Memory | 58,53% Memory free 5,99 Gb Paging File | 4,63 Gb Available in Paging File | 77,25% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 150,69 Gb Total Space | 15,68 Gb Free Space | 10,41% Space Free | Partition Type: NTFS Drive D: | 139,26 Gb Total Space | 51,13 Gb Free Space | 36,71% Space Free | Partition Type: NTFS Drive E: | 8,13 Gb Total Space | 1,56 Gb Free Space | 19,24% Space Free | Partition Type: NTFS Drive H: | 14,53 Gb Total Space | 13,18 Gb Free Space | 90,73% Space Free | Partition Type: FAT32 Computer Name: DOGI0-PC | User Name: dogi0 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) .scr [@ = AutoCADScriptFile] -- C:\Windows\SysWow64\notepad.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [TC PowerPack 2] -- "C:\Program Files (x86)\TC PowerPack 2\TCPowerPack.exe" /O /T "%1" (BuKoX) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [TC PowerPack 2] -- "C:\Program Files (x86)\TC PowerPack 2\TCPowerPack.exe" /O /T "%1" (BuKoX) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{06580D4C-B3F0-43A0-A193-34926C6D1954}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{0833B8A3-C2A4-49B6-8749-C84C99DA45B7}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{09432BC1-33DD-4D5B-8446-712450ADE3CD}" = lport=139 | protocol=6 | dir=in | app=system | "{0F84BD46-96C3-4F06-9A7D-F458D825DA2C}" = lport=80 | protocol=6 | dir=in | name=porty80_443 | "{13ECF413-9BA3-4F19-A1D0-C67B35FEC0CC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{1A0C3516-91E4-4C46-A65A-FCEFCB67428C}" = rport=139 | protocol=6 | dir=out | app=system | "{1D3510F0-CCEB-4928-87F7-C0489C25BA03}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{1FBA3250-002F-4ECC-9F39-4D61600D65D9}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{219734C2-D485-477B-BC75-9F147BE24190}" = lport=475 | protocol=17 | dir=in | name=hasp port | "{23F37800-7F7D-4450-8709-46DBE84F3185}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{281449A6-E0BF-49A9-BB5C-032910245A5A}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{2E8B81EA-F05B-4680-9454-BD207058A38F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3F037CCE-3EA7-4FEF-8CB6-74954C304F3F}" = lport=445 | protocol=6 | dir=in | app=system | "{3F0941EC-94F8-4CDD-A85E-23A9C48CBDEA}" = rport=445 | protocol=6 | dir=out | app=system | "{41B09CD5-89F4-483C-99EA-3016DBD467BC}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 | "{4285A1C6-673B-4F20-AB93-69286BB75FB3}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{442EC318-5C43-418E-831B-FD3FB0CCA2A3}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{4720392D-9F78-4B0D-8B7E-E07516C346CC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4D86D29B-FC77-4BD5-92F1-705A5F6AE74C}" = lport=2869 | protocol=6 | dir=in | app=system | "{67E9D180-52F5-4CD4-B13C-9F78920CCD41}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6A8D134B-BB6E-4D1E-836A-98A000DBBB4E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6C9BEA8D-F793-4D98-9B4D-9C697DD597CB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{71E93EE9-F557-4814-9126-B1FBAFFE34CA}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{7E310C90-12A3-4461-B8B1-1B2063F7F55B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{80B9A27B-BD82-4E3A-AA70-100437C27017}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{888E0E2F-F8F9-499A-96A8-47C45D64FF2C}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{90582F7C-583C-45F1-97B6-FCD1E022C9B5}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{9755DC31-FD9D-4B70-9AC8-ABDC8E02163D}" = rport=138 | protocol=17 | dir=out | app=system | "{99A8CE99-0446-4A8D-8279-1B8C1AC3D200}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{A0D49218-52BA-455E-BF7B-D83BEFD80474}" = lport=2869 | protocol=6 | dir=in | app=system | "{A50B1EEF-A663-4C46-ADF1-6D2B052DC7A6}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A59B0DCC-2D7B-4DF3-A787-454C2D166EC4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{A9FCDF9B-9B9C-433C-910C-C32E0C2ECDC7}" = rport=2869 | protocol=6 | dir=out | app=system | "{AE1E27A7-5F16-46EC-9A0D-E2663EDF3DF1}" = rport=10243 | protocol=6 | dir=out | app=system | "{B33069AC-E4BA-4F07-B75A-36CF71F639D6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BD99135D-AF72-4140-8A6B-7732106B3818}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | "{BEED538F-C286-4049-A417-65DDE5C7BE0A}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe | "{C291ECB0-BEAF-40DC-92E8-1DE3AA474E19}" = rport=80 | protocol=6 | dir=out | name=porty80_443wy | "{C684E91D-1D7E-4447-B0AB-14BC7744F8CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CDFCED96-62D1-473A-926F-8BE33526C160}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{D07C90C7-A5F4-4426-BAAB-11E9B0EFA378}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{D38E8D2E-7D02-45AF-A67E-7309B0C1D934}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D493E53F-DFF6-421F-A00C-7EF65007CE47}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{D8810949-B9C9-4E7E-B90E-B8628E05BE56}" = lport=138 | protocol=17 | dir=in | app=system | "{DCFC1229-D7FC-469E-93EC-6CC8DF251A87}" = lport=137 | protocol=17 | dir=in | app=system | "{E93AB39E-FB82-43EB-BAC5-7E61C7DADD67}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{EF679845-A36E-461E-85A3-9CA2F2A07829}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F7CE2937-2D90-4A9A-A942-6305D369A669}" = lport=10243 | protocol=6 | dir=in | app=system | "{F9269042-F0AD-4462-A713-8C22F7E6D175}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FF719029-D1E5-406C-9520-BE13B301D9CA}" = rport=137 | protocol=17 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01725EDF-0345-468A-AC5B-4B984B359AF2}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{02C0EF03-9896-4313-8EE4-2846B6CFFA30}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{04CBCB15-E006-42BE-BEE4-CA3492FEFFE0}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{07F60CE0-D827-40A7-84F1-4FFC9C04481E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{0882E4AD-C6A2-40DA-A651-6B9F6C591E98}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{08CA1018-139F-4EE1-9273-94F985A04588}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{0A34D7B8-CE2F-4FF2-898F-FA5E7E0E815C}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{0A6AABC9-B9F2-4BD2-9545-E548C2C956B9}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsasvr.exe | "{0C4BB22D-2588-4C8C-B3D0-FB06700A3F69}" = protocol=17 | dir=in | app=c:\users\dogi0\appdata\local\temp\cprogram files (x86)opera\opera.exe | "{0C783BBF-EF10-47D1-917E-E325FD8F9337}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{0E36B885-DE0A-4956-8C0F-2B51282985A0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{0F405800-6593-451F-BD27-BF6824C8B58B}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{106B45AA-4EBC-4100-B495-B450D61BF92B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{14FDDAAF-85F5-4D4E-B2B2-D3502204225F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1702D7CD-ADF3-466E-BFB1-0B7F4BEEB326}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1BE8D493-B6C1-437E-AF93-4312D7EE78F1}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe | "{1E5B9BE5-E369-4B6C-A456-1D49CC8EB894}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{1EFEC5E0-62E2-4C36-B385-B7FB2AA9C6E7}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{229313BC-403A-489C-BD8F-D68116127AFA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{24735B24-8686-4DED-963B-54CE3AA00A89}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe | "{2547CAE6-FDFE-4F27-8B09-FFB8CD545BFA}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{2A70BEC3-7E29-4F1F-A484-17EF98DDC643}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe | "{2C67AB3B-5FAD-4A13-89B2-A83887D144C7}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{3206B761-88CD-4881-BCA9-7FD17C28B6F5}" = dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe | "{328CFFE2-83C3-4C73-98E2-D80BD56B9491}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{33C030A2-A088-4584-852C-1FD584529D82}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsvsvr.exe | "{376E0F85-9A85-4A2F-B298-53681F5E2392}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsvsvr.exe | "{3BA723AC-DDFF-423A-B2B5-E0638AF36F85}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd8\powerdvd8.exe | "{41938B5A-6C50-4B9D-BF12-A36C1B5AEED3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{42B55EEB-A2DE-4D5F-AF8B-980B3DB331A6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{463434D7-C553-44C1-9C8E-D5E9F3D3D783}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{4A68EADB-4054-4A86-B424-EACDDD57C519}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{4A73883B-0ECE-42B3-AF74-3DF19BFC5472}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{4B62A3DB-6122-475E-98EC-10448BA7C71C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{502A71B7-5366-4BEE-8615-9200BEC85E8A}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{529D6887-6FEA-45ED-AC59-FE60ADE96036}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{53372A2E-6F5F-43D5-A277-4EB148C12DC1}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{55386ABB-CB56-47D6-943D-4D2F177B435E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{61DB71CD-CDB9-4D02-933D-10D0C36D7C29}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{6303F2F3-E638-4065-BCD1-CD07630BD93E}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsasvr.exe | "{642DB203-9BE1-4883-967F-9144C36E7794}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{64F6D923-B383-4EEE-AA8C-B03682941DF8}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{69C8E2D5-01DF-4DE1-915C-D32B0A71769B}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe | "{6D31687F-75EA-412C-88B9-35B150B0406A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{6E3E89A7-CBE8-4BB5-8076-E1D904363576}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{70A76453-1EA6-4D91-9D29-45D918661B76}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{71B96548-69B6-4313-9EE0-648E2FA24DDE}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{74CDE1DC-B6C3-4B52-A274-D4CB2047D90F}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{761F53CC-12F0-4BBE-894F-E84464926ECB}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{77D8BC9B-3DD5-4617-8851-B41946319D38}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe | "{7A38E9F7-3007-4331-B73E-19F4C4DEBB15}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{7F2D0776-D19B-4536-937A-77C8029B749F}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{819A0A73-DF6D-47BC-B1DD-DEF83B188C5B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{84B94B90-BCA6-4269-8609-6FA667788F51}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{84DCA4E1-5D28-4E95-B1BE-F625508FF88D}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe | "{86E6136D-32B2-4DD4-98D2-B36F7557CD6E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{901AE348-2159-4333-88D7-8FC5082A9ED5}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{921F9C07-3169-4CC9-9954-BEDB1F3B4323}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe | "{92474C51-2CDE-417F-81AF-156A3F523D0B}" = protocol=6 | dir=in | app=c:\users\dogi0\appdata\local\temp\cprogram files (x86)opera\opera.exe | "{99AE4366-2D32-4139-9133-38AE4358AA57}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{9AEEEAEE-080D-4F00-A997-4340352B6A29}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{9E7024F9-3A61-42C1-B3AC-2283D3DB393B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{A1005B52-8391-4C68-945C-EC7E1039C53A}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "{A31CC6CF-19D8-4BC7-835D-ADB26ABCF25D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{A455EA34-5C43-4FEC-A623-26E818069A05}" = dir=in | app=c:\windows\system32\hasplms.exe | "{AC6D6559-27A6-490A-BF51-78195516DACE}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{AD6374D8-FFDD-4EE3-9651-DC4FD683474A}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{B25C6940-8120-4883-A4EF-2910B171992F}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{B48FE042-F9C9-4667-AD6C-4E44A10B9194}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{B4E230FB-B4E6-40C6-BA75-20AC92FF8FBB}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe | "{B9406954-7441-41BE-9F80-CA2532F00588}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe | "{BD8336F1-B4A4-4878-8685-97B07F52B981}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{C03BB60E-2EE7-4A27-8E02-9A4ADCF12AEF}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{C12CDA79-ADA4-47A5-AF31-48CC90851265}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{C1340A3C-6A3B-4EB5-AA15-081447BC1067}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{C2DE20C8-977E-4333-BB60-C0E9C9B0F702}" = protocol=6 | dir=in | app=c:\users\dogi0\appdata\local\akamai\netsession_win.exe | "{C67ECDFF-DACB-4DA5-B72F-633D7BF2CFB4}" = protocol=6 | dir=out | app=system | "{C73E71F1-B29D-4E91-8B31-8FC894E3E56A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{D2BD0780-D8FB-457A-A079-622C85B02330}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{D3CC5C9C-3FF1-49B8-BDC8-664D80630D53}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{DEB7A8DB-C5D1-4962-A458-FFAB336E90DA}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe | "{E1D4BE7D-88E0-4732-92D0-D66DF6343253}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe | "{E1EC5D15-C8A2-4012-ACBB-65868B41EF39}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{E23AAE3C-BFAF-4347-B380-815A1ABA1EB5}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{E776D443-0EE1-45B6-8C3E-F5E7819E0D04}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{EA9180C1-989E-4D08-B761-28003B6F2094}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{EAB3970F-3144-4570-B1F6-63E263914DA9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{EB99F35A-6CBB-4F44-978D-F3964EC0B886}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{F03D7B2B-1FBD-4EF1-980C-D1BE6CDFF6E5}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "{F0DC0BE4-AAE9-4899-8E59-38446C111CF2}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{F2FB0C79-8DE2-49BE-8722-BBA596506F1F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe | "{F3836A2C-3C53-45F2-802E-2094E3551625}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{F47304AE-7061-4C9D-A47C-9253923B9CAD}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{F534825F-F351-482E-B5AA-61D6033A3B72}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{F88CC5A0-797B-4FEA-B682-8589B61742E1}" = protocol=17 | dir=in | app=c:\users\dogi0\appdata\local\akamai\netsession_win.exe | "{F9098766-36B8-4411-839E-C4A013215ED7}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{FACE8CA9-96A3-4C9B-871C-05D97C9B94F4}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FD48F9C2-B1AE-4C07-8941-59E5DFFCADC4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "TCP Query User{307C1328-8D01-49E6-9CAA-AE9EFA33E0E8}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "TCP Query User{3A077BF7-A7B2-48CA-9B2D-8E83BC05899C}C:\program files (x86)\soti\pocket controller-pro\pocketcontroller.exe" = protocol=6 | dir=in | app=c:\program files (x86)\soti\pocket controller-pro\pocketcontroller.exe | "TCP Query User{5494D917-CEC0-4989-847C-29189256470A}C:\program files (x86)\altium designer summer 09\dxp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\altium designer summer 09\dxp.exe | "TCP Query User{6F9E0C7A-010A-4A2E-BB1A-422B716A78F0}C:\program files (x86)\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "TCP Query User{931726BA-3D24-4DAB-9467-FA9DCD3E295E}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "TCP Query User{C2084885-F40E-407A-93FA-14280CF3E83A}C:\users\dogi0\appdata\local\temp\b624.tmp\kmservice.exe" = protocol=6 | dir=in | app=c:\users\dogi0\appdata\local\temp\b624.tmp\kmservice.exe | "TCP Query User{D99F99FE-1211-4412-8F9A-B22F3081FAB9}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "TCP Query User{E49B56C3-75B1-4498-8A3A-F41F1B09F75B}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "TCP Query User{EF74672C-1A74-4C83-B69A-4A3AD1E694C1}C:\users\dogi0\desktop\jdownloader_portable\commonfiles\java\bin\javaw.exe" = protocol=6 | dir=in | app=c:\users\dogi0\desktop\jdownloader_portable\commonfiles\java\bin\javaw.exe | "TCP Query User{F0DA94FC-EC31-4D83-B41C-842E1D4A6393}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "UDP Query User{0E1E4B1B-1D84-4DD6-B6D1-64D686250547}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "UDP Query User{2CCFBE6A-A0E6-45A8-9462-0FE0329B6723}C:\users\dogi0\appdata\local\temp\b624.tmp\kmservice.exe" = protocol=17 | dir=in | app=c:\users\dogi0\appdata\local\temp\b624.tmp\kmservice.exe | "UDP Query User{5F85134A-69D0-41E1-9BFD-9EBA388FC41E}C:\users\dogi0\desktop\jdownloader_portable\commonfiles\java\bin\javaw.exe" = protocol=17 | dir=in | app=c:\users\dogi0\desktop\jdownloader_portable\commonfiles\java\bin\javaw.exe | "UDP Query User{963FBB5C-9653-4495-BE9F-6AFE606437DD}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "UDP Query User{C5FE5226-C1E1-440D-994A-1E1C74DCF9C6}C:\program files (x86)\soti\pocket controller-pro\pocketcontroller.exe" = protocol=17 | dir=in | app=c:\program files (x86)\soti\pocket controller-pro\pocketcontroller.exe | "UDP Query User{CC107D72-D1CF-4477-A87F-E1245530F793}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "UDP Query User{D4E53504-4208-4E55-A62D-4AE8C8420257}C:\program files (x86)\altium designer summer 09\dxp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\altium designer summer 09\dxp.exe | "UDP Query User{E2C32F85-B434-4EFC-B751-63BFE71E2D76}C:\program files (x86)\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files (x86)\bearshare applications\bearshare\bearshare.exe | "UDP Query User{E7A89975-848B-4E8F-92BD-7E32DA360EA6}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "UDP Query User{FCB53D00-8629-4D47-8F60-5908FBB9F095}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer "{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64 "{266597A9-1664-0000-0100-DCBF2B69166B}" = Autodesk Vault 2012 (Client) English Language Pack "{30296AB9-984A-415B-8909-1FE367438B47}" = DigitalPersona Personal 4.01 "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2 "{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer "{5783F2D6-7028-0409-0100-0060B0CE6BBA}" = DWG TrueView 2009 "{5783F2D7-9028-0409-0100-0060B0CE6BBA}" = DWG TrueView 2011 "{5783F2D7-A028-0409-0100-0060B0CE6BBA}" = DWG TrueView 2012 "{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Centrum obsługi urządzeń z systemem Windows Mobile "{6D80AAE7-FF65-4950-B1CA-3A7EA4995574}_is1" = Adobe Reader 64-bit fixes "{71E42D57-36CD-4992-B162-F58439CEB9EF}" = HP Deskjet F735 All-in-one Driver Software 13.0 Rel. 4 "{7244B345-B413-408B-9D04-F55BE1CC93FA}" = Autodesk Inventor Content Center Libraries 2011 (Desktop Content) "{76D6189D-1664-0400-0000-DFC2EE337EAC}" = Autodesk Inventor View 2012 "{76D6189D-1664-0400-0001-DFC2EE337EAC}" = Autodesk Inventor View 2012 English Language Pack "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{7F4DD591-1564-0409-0000-7107D70F3DB4}" = Autodesk Inventor Professional 2011 "{7F4DD591-1564-0409-0001-7107D70F3DB4}" = Autodesk Inventor Professional 2011 Polski pakiet językowy "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64 "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0415-1000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0016-0415-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0018-0415-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0019-0415-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-001A-0415-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001B-0415-1000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0415-1000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2010 "{90140000-0044-0415-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-0054-0415-1000-0000000FF1CE}" = Microsoft Office Visio MUI (Polish) 2010 "{90140000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00BA-0415-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{91140000-0057-0000-1000-0000000FF1CE}" = Microsoft Office Visio 2010 "{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64 "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64 "{92DBCA36-9B41-4DD1-941A-AED149DD37F0}" = Centrum obsługi urządzeń z systemem Windows Mobile — aktualizacja sterowników "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64 "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64 "{CF526A26-1664-0000-0000-02E95019B628}" = Autodesk Vault 2012 (Client) "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{F65B8208-5221-43D9-AA12-DDEA64EC4AF6}" = Validity Sensors software "07B260955637F1FF7587ED2AA87459040DD09BF7" = Pakiet sterowników systemu Windows - ENE (enecir) HIDClass (09/04/2008 2.6.0.0) "Autodesk Inventor Professional 2011" = Autodesk Inventor Professional 2011 Polski "Autodesk Inventor View 2012" = Autodesk Inventor View 2012 English "DWG TrueView 2011" = DWG TrueView 2011 "DWG TrueView 2012" = DWG TrueView 2012 "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Photosmart Essential" = HP Photosmart Essential 3.5 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "LegrandPDFWriter" = LegrandPDFWriter "MatlabR2009b" = MATLAB R2009b "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "NVIDIA Drivers" = NVIDIA Drivers "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "Office14.VISIOR" = Microsoft Visio Professional 2010 "Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software "Shop for HP Supplies" = Shop for HP Supplies "WinRAR archiver" = Archiwizator WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0100BD88-3990-431F-9175-AB60E31AFFDE}" = EPLAN License Client "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{086F9A69-CD39-4893-A9FB-D3A0634CE3F7}" = Autodesk Content Service "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help "{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86 "{12EB3782-71A4-4828-B54C-891D2F5D6B0E}" = Farm Frenzy - Viking Heroes "{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F3A9498-0F8F-43B1-97A9-5B809A99AA0A}" = ArcSoft Panorama Maker 4 "{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java(TM) 6 Update 25 "{27307A16-0624-4AB8-A9EB-76FE8199F92A}" = Open Design Alliance DWGdirectX V2 "{2A414CBE-CDF3-48C6-A91B-D3D4522F8EB5}" = Sentinel Runtime "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "{2E4EA28A-7F64-44E4-81C5-7BDF656E3B1D}" = Samsung PC Studio 3 "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons "{359FCAA7-B544-4147-AE3B-8C8A526E2427}" = Sony Image Data Suite "{363BF927-C2EE-43CF-B765-2025BCED5089}" = F735 "{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{44194879-DEA3-4B4D-B05F-2B61A9C1D52A}" = XLPro3 v3.1.06 -b4 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport "{53E1C4C4-808C-4408-98A8-C9480E706107}" = PSIM 9.0.1 "{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01) "{5E152D08-572A-3375-8FDE-DAD1EFB379BA}" = Microsoft Report Viewer Redistributable 2008 "{611A0E8E-94EF-4836-BD14-2E55AEEE6C95}" = Composants Communs Legrand "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{65420DC9-306E-4371-905F-F4DC3B418E52}" = Autodesk Material Library Base Resolution Image Library 2012 "{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1 "{69C65CD8-E97F-4647-BB42-99693BC5A505}" = DJ_AIO_04_F735_Software_Min "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{85E0DA75-0795-4377-B079-CFB9F7C5691F}" = Phone Software Update - Windows Mobile "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B5D3F44-8150-4471-B093-28BA8A7D67C8}" = Phone Software Update - Windows Mobile "{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}" = Autodesk Material Library 2012 "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58 "{975951E7-14D0-49AF-A630-89680D12D7F6}" = Autodesk Material Library 2011 Medium Image library "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BF3C220-0401-4945-A46F-63AFE6F4C114}" = Altium Designer Summer 09 "{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011 "{A0466DD7-F335-427E-BDE1-3CA371477E1F}" = Mod_RSsim "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A49BDCBE-590E-43A6-AB77-7C40E499B7C1}" = Autodesk Design Review 2012 "{AC76BA86-1048-8780-7760-000000000005}" = Adobe Acrobat X Pro - English, Russian "{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2 "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9 "{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9 "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C2A63701-7959-4897-A437-6A99DF78BBC1}" = DWGdirectX 2.5 "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3 "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility "{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player "{E10A62BA-FDE9-409A-8CB4-3FFA0951228F}" = EPLAN Electric P8 1.9.5 "{E31DED25-539A-4865-B19E-B644695922A5}" = EPLAN Education 2.2 "{E330CE0C-386C-452C-BAE7-5C2F2439CB08}" = EPLAN Trial Education Data 2.2 "{E37DA179-60DA-4044-8FAE-504831332AD3}" = EPLAN Platform 2.2 "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer "{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.136 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL "{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint "{F4CFD2EA-F432-4EC0-9538-661CD1C173D2}" = Lokalizator zasobów Autodesk "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "Akamai" = Akamai NetSession Interface Service "Autodesk Design Review 2012" = Autodesk Design Review 2012 "Autodesk Vault 2012 (Client)" = Autodesk Vault 2012 (Client) "AVG Secure Search" = AVG Security Toolbar "Avira AntiVir Desktop" = Avira Free Antivirus "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2) "DWGdirectX 2.5" = DWGdirectX 2.5 "EAGLE 6.1.0" = EAGLE 6.1.0 "Eaton Software" = Eaton Software "ElektroSym" = ElektroSym 2.0 "EPLAN Education 2.2" = EPLAN Education 2.2 "Gadu-Gadu 10" = Gadu-Gadu 10 "Hardlock Device Drivers" = Hardlock Device Drivers "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "IrfanView" = IrfanView (remove only) "JDownloader" = JDownloader "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.60 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft Report Viewer Redistributable 2008" = Microsoft Report Viewer Redistributable 2005 "Mozilla ActiveX Control v1.7.1" = Mozilla ActiveX Control v1.7.1 "Mozilla Firefox (3.6.28)" = Mozilla Firefox (3.6.28) "Odlotowa farma" = Odlotowa farma "Odlotowa Farma 2" = Odlotowa Farma 2 "Odlotowa Farma 3: American Pie" = Odlotowa Farma 3: American Pie "Odlotowa farma 3: Epoka lodowcowa" = Odlotowa farma 3: Epoka lodowcowa "Odlotowa farma 3: Madagaskar" = Odlotowa farma 3: Madagaskar "Odlotowa farma 3: Rosyjska ruletka" = Odlotowa farma 3: Rosyjska ruletka "Odlotowa Farma: Na Ryby" = Odlotowa Farma: Na Ryby "Odlotowa farma: Starożytny Rzym" = Odlotowa farma: Starożytny Rzym "Open Design Alliance DWGdirectX V2" = Open Design Alliance DWGdirectX V2 "OpenVPN" = OpenVPN 2.1.1 "Opera 11.61.1250" = Opera 11.61 "Opera 12.14.1738" = Opera 12.14 "PAJĄK_is1" = PAJĄK 2.10.1-PL/PL "PCSCHEMATIC Automation" = PC|SCHEMATIC Automation 40 "PCschematic Elautomation 40" = PCschematic® ELautomation 40 10.0 "PIT Format 2011_is1" = PIT Format 2011 "PrimoPDF" = PrimoPDF -- brought to you by Nitro PDF Software "Program Cennikowy Eaton" = Program Cennikowy Eaton "PSIM" = PSIM 7.0 "ST6UNST #1" = SuperMon Serial V5.5 "TC PowerPack 2" = Total Commander PowerPack 2.0 beta "Winamp" = Winamp "XnView_is1" = XnView 1.97.8 "Yenka" = Yenka [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-02-28 07:37:50 | Computer Name = dogi0-PC | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Setup.exe_Setup, wersja: 1.0.0.0, sygnatura czasowa: 0x5001325d Nazwa modułu powodującego błąd: PresentationFramework.ni.dll, wersja: 4.0.30319.298, sygnatura czasowa: 0x504dc7da Kod wyjątku: 0x80131623 Przesunięcie błędu: 0x0000000000e04933 Identyfikator procesu powodującego błąd: 0x1910 Godzina uruchomienia aplikacji powodującej błąd: 0x01ce15a7f6f0ddcf Ścieżka aplikacji powodującej błąd: C:\Users\dogi0\Downloads\EPLAN_Education_2.2.5.6338\Setup\Setup.exe Ścieżka modułu powodującego błąd: C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\9acf78eb30602fa08d0888be7335ec95\PresentationFramework.ni.dll Identyfikator raportu: 4776e678-819b-11e2-b188-b3921f01a68a Error - 2013-03-07 00:31:09 | Computer Name = dogi0-PC | Source = MsiInstaller | ID = 11609 Description = Error - 2013-03-18 05:03:49 | Computer Name = dogi0-PC | Source = MsiInstaller | ID = 11609 Description = Error - 2013-03-19 06:12:36 | Computer Name = dogi0-PC | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.1.7600.16768, sygnatura czasowa: 0x4d688122 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7600.16915, sygnatura czasowa: 0x4ec4b137 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000002eab Identyfikator procesu powodującego błąd: 0x530 Godzina uruchomienia aplikacji powodującej błąd: 0x01ce248a3a56fc93 Ścieżka aplikacji powodującej błąd: C:\Windows\Explorer.EXE Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: 8583d581-907d-11e2-8650-9b578130aeb6 Error - 2013-03-19 07:24:01 | Computer Name = dogi0-PC | Source = WinMgmt | ID = 29 Description = Error - 2013-03-21 09:26:22 | Computer Name = dogi0-PC | Source = Application Hang | ID = 1002 Description = Program svchost.exe w wersji 6.1.7600.16385 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 7e4 Godzina rozpoczęcia: 01ce26372a0f3b2b Godzina zakończenia: 234 Ścieżka aplikacji: C:\Windows\syswow64\svchost.exe Identyfikator raportu: ea17fd1f-922a-11e2-86b1-cdcab78b7d8f Error - 2013-03-21 09:51:22 | Computer Name = dogi0-PC | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.1.7600.16768, sygnatura czasowa: 0x4d688122 Nazwa modułu powodującego błąd: msvcrt.dll, wersja: 7.0.7600.16930, sygnatura czasowa: 0x4eeb01e3 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000000000000104d Identyfikator procesu powodującego błąd: 0x5f4 Godzina uruchomienia aplikacji powodującej błąd: 0x01ce263b1f72e5e5 Ścieżka aplikacji powodującej błąd: C:\Windows\Explorer.EXE Ścieżka modułu powodującego błąd: C:\Windows\system32\msvcrt.dll Identyfikator raportu: 69ac9eb2-922e-11e2-8a3c-a55e1ac85899 Error - 2013-03-21 10:00:16 | Computer Name = dogi0-PC | Source = EventSystem | ID = 4622 Description = Error - 2013-03-21 10:01:56 | Computer Name = dogi0-PC | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.1.7600.16768, sygnatura czasowa: 0x4d688122 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7600.16915, sygnatura czasowa: 0x4ec4b137 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000000319b0 Identyfikator procesu powodującego błąd: 0x7f0 Godzina uruchomienia aplikacji powodującej błąd: 0x01ce263c98aefbd3 Ścieżka aplikacji powodującej błąd: C:\Windows\Explorer.EXE Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: e3c649d7-922f-11e2-851e-ae9c096a7d97 Error - 2013-03-21 10:08:15 | Computer Name = dogi0-PC | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.1.7600.16768, sygnatura czasowa: 0x4d688122 Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 6.1.7600.17206, sygnatura czasowa: 0x50e669a2 Kod wyjątku: 0xc000041d Przesunięcie błędu: 0x000000000000a993 Identyfikator procesu powodującego błąd: 0x5fc Godzina uruchomienia aplikacji powodującej błąd: 0x01ce263d7d98ea74 Ścieżka aplikacji powodującej błąd: C:\Windows\Explorer.EXE Ścieżka modułu powodującego błąd: C:\Windows\system32\KERNELBASE.dll Identyfikator raportu: c591b1e8-9230-11e2-b19f-ced32906f994 Error - 2013-03-21 10:11:44 | Computer Name = dogi0-PC | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Explorer.EXE, wersja: 6.1.7600.16768, sygnatura czasowa: 0x4d688122 Nazwa modułu powodującego błąd: KERNELBASE.dll, wersja: 6.1.7600.17206, sygnatura czasowa: 0x50e669a2 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000000000001470b Identyfikator procesu powodującego błąd: 0x850 Godzina uruchomienia aplikacji powodującej błąd: 0x01ce263df6acd285 Ścieżka aplikacji powodującej błąd: C:\Windows\Explorer.EXE Ścieżka modułu powodującego błąd: C:\Windows\system32\KERNELBASE.dll Identyfikator raportu: 41fe0d9e-9231-11e2-8537-dad399f27a99 Error - 2013-03-21 10:17:09 | Computer Name = dogi0-PC | Source = Application Hang | ID = 1002 Description = Program svchost.exe w wersji 6.1.7600.16385 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: c94 Godzina rozpoczęcia: 01ce263ebc5e0ab0 Godzina zakończenia: 50 Ścieżka aplikacji: C:\Windows\syswow64\svchost.exe Identyfikator raportu: 02ace766-9232-11e2-b195-fe428f0b0f96 [ System Events ] Error - 2013-03-21 06:55:08 | Computer Name = dogi0-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012 Description = Wystąpił błąd podczas próby odczytu lokalnego pliku hosts. Error - 2013-03-21 06:55:14 | Computer Name = dogi0-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012 Description = Wystąpił błąd podczas próby odczytu lokalnego pliku hosts. Error - 2013-03-21 06:55:21 | Computer Name = dogi0-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012 Description = Wystąpił błąd podczas próby odczytu lokalnego pliku hosts. Error - 2013-03-21 06:56:51 | Computer Name = dogi0-PC | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: StarOpen Error - 2013-03-21 06:57:46 | Computer Name = dogi0-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012 Description = Wystąpił błąd podczas próby odczytu lokalnego pliku hosts. Error - 2013-03-21 06:58:02 | Computer Name = dogi0-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012 Description = Wystąpił błąd podczas próby odczytu lokalnego pliku hosts. Error - 2013-03-21 06:58:05 | Computer Name = dogi0-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012 Description = Wystąpił błąd podczas próby odczytu lokalnego pliku hosts. Error - 2013-03-21 06:58:09 | Computer Name = dogi0-PC | Source = ipnathlp | ID = 34001 Description = Error - 2013-03-21 06:58:09 | Computer Name = dogi0-PC | Source = ipnathlp | ID = 30013 Description = Error - 2013-03-21 06:58:22 | Computer Name = dogi0-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012 Description = Wystąpił błąd podczas próby odczytu lokalnego pliku hosts. < End of report >