OTL Extras logfile created on: 2013-10-19 15:13:12 - Run 2 OTL by OldTimer - Version Folder = C:\Users\tds\Desktop 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16721) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 6,00 Gb Total Physical Memory | 4,11 Gb Available Physical Memory | 68,46% Memory free 8,00 Gb Paging File | 5,81 Gb Available in Paging File | 72,66% Paging File free Paging file location(s): c:\pagefile.sys 2048 2048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 111,79 Gb Total Space | 30,61 Gb Free Space | 27,38% Space Free | Partition Type: NTFS Drive D: | 811,32 Gb Total Space | 347,04 Gb Free Space | 42,77% Space Free | Partition Type: NTFS Drive E: | 232,88 Gb Total Space | 37,63 Gb Free Space | 16,16% Space Free | Partition Type: NTFS Drive F: | 585,94 Gb Total Space | 219,96 Gb Free Space | 37,54% Space Free | Partition Type: NTFS Drive X: | 76,69 Gb Total Space | 34,93 Gb Free Space | 45,55% Space Free | Partition Type: NTFS Computer Name: TDSXXX | User Name: tds | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .hlp [@ = WinHelpCustomView.Scenario] -- C:\Windows\SysWow64\winhlp32.exe %1 .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .hlp [@ = WinHelpCustomView.Scenario] -- C:\Windows\SysWow64\winhlp32.exe %1 .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2337871059-3691734657-1116950341-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [runas] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [takeownership] -- cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 1 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07F2060D-9DFC-491F-B8B9-C05D31F69062}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3E6E6EF9-FFF1-49B2-995E-C0F80A19660E}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | "{458D8C9A-EBB4-489F-B00B-B9ED3EC022BD}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{5E7D3D9C-7E1C-420C-BD5E-28DD250CE840}" = lport=7878 | protocol=6 | dir=in | name=allshare tcp port | "{6ED2E627-53F5-4548-8219-FAB72ABB2446}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{719EFA1E-A9F7-4436-815B-1E1F527F3B7D}" = rport=10243 | protocol=6 | dir=out | app=system | "{8B53D8F8-83B8-4B5E-8BEC-231940BB8F04}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9FEB2327-7AD3-4989-9692-44AF5DF7DBD7}" = lport=20102 | protocol=6 | dir=in | name=allshare udp port | "{ACABE655-039B-4391-A066-3CB3E827258D}" = lport=10243 | protocol=6 | dir=in | app=system | "{DB2DC3EF-6EC7-4939-BD9E-2B0C17EC9937}" = lport=2869 | protocol=6 | dir=in | app=system | "{DDC13359-810D-4CD8-B4B0-399B75321A1B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{DF6070A5-5434-4708-B7E8-4A8C7E182EC1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{EC48E5CD-4FE8-4254-B9E8-1045C29E4F54}" = lport=1900 | protocol=6 | dir=in | name=allshare multicast port | "{F6B6BEB9-8F29-4F91-8330-6114AF23A1C9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0923D6FA-B8D3-4F31-B3FF-7638EF4DF77A}" = protocol=6 | dir=in | app=e:\program files (x86)\rayman origins\gu.exe | "{09DDF7BC-AA4D-4815-AA9F-DF59786214DD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{0B200968-4D9D-4806-8EF7-DE3BF05F0188}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{0D89C4D5-63A5-47C0-82FD-960B7E2BF079}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{143ACAA7-4955-4D47-9BDE-E9BBF327F37F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{18D478EA-09F8-41B3-BB20-4A56C88759B5}" = dir=in | app=%programfiles% (x86)\rockstar games\max payne 3\maxpayne3.exe | "{1ED594AD-5F35-4CA7-BADD-E96BF568670B}" = protocol=6 | dir=in | app=e:\program files (x86)\rayman origins\rayman origins.exe | "{22C4194C-7EC8-4B56-A948-502A332DBB30}" = dir=in | app=%programfiles% (x86)\rockstar games\max payne 3\playmaxpayne3.exe | "{23EDF64D-A569-458F-8A5E-F90C73AB2F91}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\allshare control\allshare control pc.exe | "{28ADD72A-3E70-4AED-A757-0FFD73B4E749}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{2CECAC0D-5EF2-4567-9FB3-B59166AB9F78}" = dir=out | app=%programfiles% (x86)\rockstar games\max payne 3\playmaxpayne3.exe | "{2E3AFD7C-FA6D-4DA9-9D63-FB1C7F8645C2}" = protocol=6 | dir=out | app=system | "{2EFFF912-6186-45AB-B698-CE17D8EFA39B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{3349B562-18FA-4E04-88C1-5AEDCDC4C040}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{33D41D04-593D-4119-A7B4-020F1E9A0510}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{379711BE-ACD9-48D7-8862-86C9F399CFBD}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{37FC6F83-7A16-4D59-B3DA-DA914CCB9C4E}" = protocol=6 | dir=in | app=e:\program files (x86)\przygody tintina - tajemnica jednorozca\tintin.exe | "{3B241A1D-E7BD-4A7F-9198-3927475751E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{421D4029-3D08-42CA-83FE-73ECC53D5144}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | "{437818DA-ACF7-4B23-B300-918B3B604C64}" = protocol=6 | dir=in | app=e:\program files (x86)\assassin's creed iii\assassinscreed3.exe | "{494360E6-3DAF-42EA-81FF-C82717F033A0}" = protocol=17 | dir=in | app=e:\program files (x86)\assassin's creed iii\ac3mp.exe | "{512CCFEA-A87C-4891-B320-A808271D07C6}" = protocol=17 | dir=in | app=e:\program files (x86)\rayman origins\gu.exe | "{5A93D59A-A944-45CD-908B-C00A5DADAB09}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{5E7C9DF6-14D0-4A8D-93BF-E3E02896FAE9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{5F8C1E2D-4715-4641-839E-2BB6D082DEE7}" = protocol=6 | dir=in | app=c:\program files (x86)\maxthon3\bin\mxup.exe | "{64FC1325-1DB1-4F38-8134-DF1850648706}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{654F86F2-4602-4C90-BDA5-1AACBB05EA03}" = protocol=17 | dir=in | app=e:\program files (x86)\przygody tintina - tajemnica jednorozca\tintin.exe | "{696AC9B0-B8D0-4803-9807-DD13C2DF9397}" = protocol=17 | dir=in | app=c:\program files (x86)\maxthon3\bin\maxthon.exe | "{69DDE15F-58A8-41A2-BA62-F0F7D6767D7D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{6BA1644C-EEF6-4630-A488-C1B3DD3E1921}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{6C345397-78E6-4B68-BF5B-DB7890B61734}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{7705C534-8390-4E37-8C88-AC1000A33551}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{782CD5EB-40B2-424B-BBA7-AADE4D9ED520}" = protocol=6 | dir=in | app=e:\program files (x86)\dead space 3\deadspace3.exe | "{7962AB10-8B4D-490F-93CC-DF327F100CF5}" = protocol=6 | dir=in | app=e:\program files (x86)\assassin's creed iii\ac3mp.exe | "{7F0E37F3-2248-41A1-ABBD-FB78FD408E97}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{89D2A2E1-4B6A-4759-84ED-BE06473347C4}" = protocol=17 | dir=in | app=c:\program files (x86)\adfender\adfender.exe | "{910CECFD-CCF9-423C-A586-E001DE33EACD}" = protocol=17 | dir=in | app=e:\program files (x86)\dead space 3\deadspace3.exe | "{91B96A65-80A7-45B2-87E7-3DC823FB50CB}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{9897A0F5-19D4-44C7-B46D-05F5E9D4FC91}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{9A89B33A-9640-4C8F-8E69-3CACDA4F45BA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{9C078F4B-099E-49B6-BB02-8E51CA0C06BE}" = protocol=17 | dir=in | app=c:\users\tds\appdata\roaming\dropbox\bin\dropbox.exe | "{9DCFB107-7DC4-4B0C-8346-34BCB7DCF255}" = protocol=6 | dir=in | app=e:\program files (x86)\assassin's creed iii\ac3sp.exe | "{ABD76148-F52D-4794-83A6-5FF6F3084451}" = protocol=6 | dir=in | app=c:\program files (x86)\adfender\adfender.exe | "{B61F6904-D298-4084-8ABC-B0D57185CEC3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{B7A0A7A7-5CFC-44B3-9834-16ECA83AB92E}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | "{BA543AE3-AE3F-475E-ACC6-FBD5370FCB83}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{BD6987AF-CAFA-46AE-B1E2-A712764383E1}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{BDA777F8-D55C-42CC-9FDC-0457B709860C}" = protocol=17 | dir=in | app=e:\program files (x86)\assassin's creed iii\ac3sp.exe | "{BEE9E83F-846D-4B8E-BE82-02280FFE1DDA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{BF377EFB-BF14-425A-A39B-F8959CA3D394}" = protocol=6 | dir=in | app=c:\program files (x86)\maxthon3\bin\maxthon.exe | "{C054FBCC-33F6-4E2B-B3EF-A82FEB4C3BF7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C96E0084-578C-47B4-91D4-C31F85A188B0}" = protocol=17 | dir=in | app=c:\program files (x86)\maxthon3\bin\mxup.exe | "{CD0799CA-78B0-4C7E-B03C-DE9A9F158D02}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | "{CEBD17E9-A35D-4F20-9127-42901FCB10DC}" = protocol=6 | dir=in | app=c:\users\tds\appdata\roaming\dropbox\bin\dropbox.exe | "{D2A3B17D-F7F7-46D8-8B4C-2839CE582C7C}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\allshare control\allshare control pc.exe | "{E09B4AD6-552A-4F43-B35D-C081FE3BB9F9}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{E2EF0BBB-41D1-4753-930B-7C158E3C2E79}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{E4D336DD-9C69-4E98-9810-D751497BC2E1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E605D6CC-23B7-49FD-A2DA-69F5551F7085}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{EF1A342D-5956-4030-AA6E-A144E6E68786}" = dir=out | app=%programfiles% (x86)\rockstar games\max payne 3\maxpayne3.exe | "{EFAC659F-4456-4F78-BF8B-F8B15F9A0268}" = protocol=17 | dir=in | app=e:\program files (x86)\rayman origins\rayman origins.exe | "{F1D580C5-DB9A-45CC-A3D2-DAA3F5E7F197}" = protocol=17 | dir=in | app=e:\program files (x86)\assassin's creed iii\assassinscreed3.exe | "{F5123501-4286-4CFB-A6E6-9F47A574FFBB}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{FAA76702-A96A-4551-BFE9-0734A348898B}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | "TCP Query User{0694E739-5E1C-4726-B66B-47ED3B371BD5}C:\program files (x86)\adfender\adfender.exe" = protocol=6 | dir=in | app=c:\program files (x86)\adfender\adfender.exe | "TCP Query User{3FF8B761-331F-4A25-9CC4-D4758672BC3D}F:\prog-instalki\----microsoft.windows.7.professional.edition.with.sp1.x64-zwtiso\zwin7p1x\crack\keygen.exe" = protocol=6 | dir=in | app=f:\prog-instalki\----microsoft.windows.7.professional.edition.with.sp1.x64-zwtiso\zwin7p1x\crack\keygen.exe | "TCP Query User{42F53169-2962-4AE5-8663-A573D65F75AF}C:\program files (x86)\aqq\aqq.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aqq\aqq.exe | "TCP Query User{487CA8BE-C0DB-482B-8254-F780D78EAF04}X:\temp\temp\9cf0.tmp\kmservice.exe" = protocol=6 | dir=in | app=x:\temp\temp\9cf0.tmp\kmservice.exe | "TCP Query User{7323581F-7778-4D4D-9775-0D7743F7D007}C:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core" = protocol=6 | dir=in | app=c:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core | "TCP Query User{8409675F-5A59-4444-832A-01233F850449}X:\iphone4\iphone\isutal_v271009\isutal\fscommand\iphone_tunnel-v1.01\iphone_tunnel.exe" = protocol=6 | dir=in | app=x:\iphone4\iphone\isutal_v271009\isutal\fscommand\iphone_tunnel-v1.01\iphone_tunnel.exe | "TCP Query User{9D8CD1CB-28BD-4E27-8DE7-281D9A3DB36B}E:\program files (x86)\prototype 2\prototype2.exe" = protocol=6 | dir=in | app=e:\program files (x86)\prototype 2\prototype2.exe | "TCP Query User{B06182E5-41E5-4A60-9160-95DC12136AF8}C:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core" = protocol=6 | dir=in | app=c:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core | "TCP Query User{B9ABFF0C-B2D3-448B-B82C-27472DD3D492}C:\program files (x86)\aqq\aqq.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aqq\aqq.exe | "UDP Query User{0E2F02CD-16E5-4249-BA38-DB1571A29516}C:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core" = protocol=17 | dir=in | app=c:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core | "UDP Query User{2E3F336C-A383-49B1-AF68-E3CACDD4AE6E}X:\iphone4\iphone\isutal_v271009\isutal\fscommand\iphone_tunnel-v1.01\iphone_tunnel.exe" = protocol=17 | dir=in | app=x:\iphone4\iphone\isutal_v271009\isutal\fscommand\iphone_tunnel-v1.01\iphone_tunnel.exe | "UDP Query User{5ECFD37E-836F-4AE5-B0D3-AFB7C251274D}C:\program files (x86)\aqq\aqq.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aqq\aqq.exe | "UDP Query User{73E0BD75-26F4-4CBF-9155-AFE5B0F5BF2E}C:\program files (x86)\adfender\adfender.exe" = protocol=17 | dir=in | app=c:\program files (x86)\adfender\adfender.exe | "UDP Query User{7D564B62-FD92-465A-8321-4CD1C39E5B8E}X:\temp\temp\9cf0.tmp\kmservice.exe" = protocol=17 | dir=in | app=x:\temp\temp\9cf0.tmp\kmservice.exe | "UDP Query User{88622083-F185-4DBB-8C7B-4B3956F3BA6C}C:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core" = protocol=17 | dir=in | app=c:\users\tds\wapster\aqq folder\profiles\tds\plugins\skypecore\skype.core | "UDP Query User{8B6B1E4F-B91D-4041-84C0-26F634C7112B}C:\program files (x86)\aqq\aqq.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aqq\aqq.exe | "UDP Query User{E7CDB55A-78B7-4B6B-B127-FEFCD12CBA78}E:\program files (x86)\prototype 2\prototype2.exe" = protocol=17 | dir=in | app=e:\program files (x86)\prototype 2\prototype2.exe | "UDP Query User{F61870B9-F5AF-4DE1-9DE7-FF66CE1AE20C}F:\prog-instalki\----microsoft.windows.7.professional.edition.with.sp1.x64-zwtiso\zwin7p1x\crack\keygen.exe" = protocol=17 | dir=in | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{DDD2D4A5-F79E-4605-8CBD-E9FE9B13903F}" = ESET Smart Security

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 "{90140000-001F-0415-1000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2010 "{90140000-0044-0415-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00BA-0415-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{AB98EBC0-1F36-4525-8CBE-E1C63700C7AD}" = Smart Technology Programming Software "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 327.23 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 327.23 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 327.23 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Sterownik kontrolera 3D Vision 314.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.13.0604 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.14.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.1 "{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{DDD2D4A5-F79E-4605-8CBD-E9FE9B13903F}" = ESET Smart Security "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "EZ CD Audio Converter (64-bit)" = EZ CD Audio Converter (64-bit) "HashCheck Shell Extension" = HashCheck Shell Extension (x86-64) "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "OptimizerPro" = OptimizerPro "Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software "sp6" = Logitech SetPoint 6.32 "WhoCrashed_is1" = WhoCrashed 4.02 "WinRAR archiver" = WinRAR 4.01 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01db25f3-1b76-4d97-88c8-1c90634d88fb}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{085DB58C-42DC-4E37-8CF7-B1048257EBBF}" = Scooby-Doo! [Example entries from uninstall list showing variety of installed software]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.9
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.05) (RePack) "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable "{F9C62746-BB57-48B2-853D-38DE983A703C}" = IncrediMail "abgx360" = abgx360 v1.0.6 "Ad Muncher" = Ad Muncher v4.93.33707 "AdFender" = AdFender "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 12.0 "AIMP3" = AIMP3 "Ant Movie Catalog_is1" = Ant Movie Catalog "AQQ" = WapSter AQQ "Ashampoo Burning Studio Elements_is1" = Ashampoo Burning Studio Elements 10.0.9 "Audacity_is1" = Audacity 2.0.3 "AudioCS" = Creative Audio Console "Burger Bustle Ellies Organics 1.00" = Burger Bustle Ellies Organics 1.00 "com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Console Launcher" = Creative Console Launcher "DAEMON Tools Lite" = DAEMON Tools Lite "Deluge" = Deluge 1.3.6 "DiskAid_is1" = DiskAid 5.14 "EasyBCD" = EasyBCD 2.2 "Ekipa ratunkowa" = Ekipa ratunkowa "F1 Race Stars_is1" = F1 Race Stars "foobar2000" = foobar2000 v1.0.1 "Foxit Reader_is1" = Foxit Reader "Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version "G-Force_R.G. Mechanics_is1" = G-Force "Hitman Absolution_is1" = Hitman Absolution "ImgBurn" = ImgBurn "IncrediMail" = IncrediMail 2.0 "InstallShield_{11192AA7-FBE3-4150-9667-EE7279CCC769}" = LEGO® Indiana Jones™ 2: The Adventure Continues "InstallShield_{2FB04107-7BC2-449C-915A-530B29B5E0FE}" = UE3Redist "InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}" = Samsung Story Album Viewer "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "InstallShield_{990166FA-1ACB-4AA7-B592-4D370C7CDD1A}" = Spider-Man 3 (TM) "InstallShield_{E6607F5B-50E7-4B54-81B7-F0600E3C8CF4}" = Belkin F5D8053 N Wireless USB Adapter "KeyScrambler" = KeyScrambler "Maxthon3" = Maxthon 3 "Minecraft1.6.2" = Minecraft1.6.2 "Mozilla Firefox 22.0 (x86 pl)" = Mozilla Firefox 22.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NapiProjekt_is1" = NapiProjekt ( "NirSoft BlueScreenView" = NirSoft BlueScreenView "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "OpenAL" = OpenAL "Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator "PrecisionX" = EVGA Precision X 4.2.1 "Q2FsbG9mSnVhcmV6R3Vuc2xpbmdlcg==_is1" = Call of Juarez Gunslinger (c) Ubisoft version 1 "Q2FzdGxlb2ZJbGx1c2lvbg==_is1" = Castle of Illusion "QuickStores-Toolbar_is1" = QuickStores-Toolbar 1.1.0 "R1JJRDI=_is1" = GRID 2 (c) Codemasters version 1 "RealAlt_is1" = Real Alternative 2.0.2 "RHVja1RhbGVzUmVtYXN0ZXJlZA==_is1" = DuckTales Remastered "RocketDock_is1" = RocketDock 1.3.5 "Rockstar Games Social Club" = Rockstar Games Social Club "Royal Envoy 3 Campaign for the Crown Collectors Updated 1.0.1" = Royal Envoy 3 Campaign for the Crown Collectors Updated 1.0.1 "RTSS" = RivaTuner Statistics Server 5.2.0 "Scribblenauts Unmasked A DC Comics Adventure_is1" = Scribblenauts Unmasked A DC Comics Adventure "Setup - Deadpool ..." = Setup - Deadpool ... "Spider-Man - Shattered Dimensions_R.G. Mechanics_is1" = Spider-Man - Shattered Dimensions "Splinter Cell - Blacklist_R.G. [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-2337871059-3691734657-1116950341-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"MyFreeCodec" = MyFreeCodec

[color=#E56717]========== Last 20 Event Log Errors ==========[/color] Błąd w pliku manifestu lub w pliku zasad "c:\program files (x86)\AQQ\System\DelZip179.dll" w wierszu 8. Wartość "*" atrybutu "language" elementu "assemblyIdentity" jest nieprawidłowa. Error - 2013-09-14 04:27:42 | Computer Name = tdsxxx | Source = NvStreamSvc | ID = 131073 Description = Error - 2013-09-14 04:28:02 | Computer Name = tdsxxx | Source = NvStreamSvc | ID = 131073 Description = Error - 2013-09-14 04:28:02 | Computer Name = tdsxxx | Source = NvStreamSvc | ID = 131073 Description = Error - 2013-09-14 04:28:02 | Computer Name = tdsxxx | Source = NvStreamSvc | ID = 131073 Description = Error - 2013-09-14 04:29:28 | Computer Name = tdsxxx | Source = WinMgmt | ID = 10 Description = Error - 2013-09-14 19:51:41 | Computer Name = tdsxxx | Source = SideBySide | ID = 16842815 Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files (x86)\AQQ\System\DelZip179.dll". Błąd w pliku manifestu lub w pliku zasad "c:\program files (x86)\AQQ\System\DelZip179.dll" w wierszu 8. Wartość "*" atrybutu "language" elementu "assemblyIdentity" jest nieprawidłowa. Error - 2013-09-14 20:18:08 | Computer Name = tdsxxx | Source = SideBySide | ID = 16842815 Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files (x86)\AQQ\System\DelZip179.dll". Błąd w pliku manifestu lub w pliku zasad "c:\program files (x86)\AQQ\System\DelZip179.dll" w wierszu 8. Wartość "*" atrybutu "language" elementu "assemblyIdentity" jest nieprawidłowa. [ System Events ] Error - 2013-10-19 09:39:30 | Computer Name = tdsxxx | Source = Application Popup | ID = 1060 Description = Ładowanie sterownika \SystemRoot\SysWow64\Drivers\StarOpen.SYS zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Error - 2013-10-19 09:39:42 | Computer Name = tdsxxx | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: StarOpen Error - 2013-10-19 09:39:50 | Computer Name = tdsxxx | Source = Service Control Manager | ID = 7024 Description = Usługa Usługa nasłuchująca grup domowych zakończyła działanie; wystąpił specyficzny dla niej błąd %%-2147023143. Error - 2013-10-19 09:45:19 | Computer Name = tdsxxx | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk8\DR8. Error - 2013-10-19 09:56:44 | Computer Name = tdsxxx | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk5\DR5. Error - 2013-10-19 10:01:20 | Computer Name = tdsxxx | Source = Application Popup | ID = 1060 Description = Ładowanie sterownika \SystemRoot\SysWow64\Drivers\StarOpen.SYS zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Error - 2013-10-19 10:01:32 | Computer Name = tdsxxx | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: StarOpen Error - 2013-10-19 10:01:37 | Computer Name = tdsxxx | Source = Service Control Manager | ID = 7024 Description = Usługa Usługa nasłuchująca grup domowych zakończyła działanie; wystąpił specyficzny dla niej błąd %%-2147023143. Error - 2013-10-19 10:05:39 | Computer Name = tdsxxx | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk7\DR7. Error - 2013-10-19 10:15:05 | Computer Name = tdsxxx | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk5\DR5. < End of report >