OTL Extras logfile created on: 2014-01-04 18:53:07 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\padi1_000\Downloads 64bit- Enterprise Edition (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16750) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,87 Gb Total Physical Memory | 1,39 Gb Available Physical Memory | 48,61% Memory free 3,49 Gb Paging File | 1,39 Gb Available in Paging File | 39,95% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 48,83 Gb Total Space | 18,20 Gb Free Space | 37,28% Space Free | Partition Type: NTFS Drive D: | 346,93 Gb Total Space | 339,47 Gb Free Space | 97,85% Space Free | Partition Type: NTFS Drive G: | 20,00 Gb Total Space | 17,04 Gb Free Space | 85,21% Space Free | Partition Type: NTFS Drive H: | 654,81 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive S: | 50,00 Gb Total Space | 37,24 Gb Free Space | 74,49% Space Free | Partition Type: NTFS Computer Name: MATEUSZ | User Name: padi1_000 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 1 Day [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "G:\Program Files\Microsoft Office\Office15\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "G:\Program Files\Microsoft Office\Office15\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "G:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "G:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "G:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "G:\Program Files\Microsoft Office\Office15\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "G:\Program Files\Microsoft Office\Office15\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "G:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "G:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "G:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01E9B697-F3EF-4181-B7DD-D7D9AA17D6BA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{096F4825-5336-4EF7-B854-A353B2181C66}" = lport=6004 | protocol=17 | dir=in | app=g:\program files\microsoft office\office15\outlook.exe | "{0E95375F-4E48-4F7C-88CD-32DB225B8CD0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{18387239-5E32-4265-83F7-7B72E06C8EE0}" = lport=445 | protocol=6 | dir=in | app=system | "{249573CC-CDBD-4935-93FB-EF06C3FD3605}" = lport=10243 | protocol=6 | dir=in | app=system | "{3A32271C-7ECF-4EBE-89D4-00690B113C32}" = rport=445 | protocol=6 | dir=out | app=system | "{4ACB6F38-27C9-44D2-8355-357F0C4C93D5}" = rport=139 | protocol=6 | dir=out | app=system | "{516584E7-FACD-4E57-81A0-1E2E16F740E3}" = rport=137 | protocol=17 | dir=out | app=system | "{5344D6E7-C09B-445C-818C-E9FD99AEDED8}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5DACA473-9752-4E85-8EAA-53A628894882}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7B080604-7E94-4B1B-8FCF-20299CC8D88C}" = lport=2869 | protocol=6 | dir=in | app=system | "{87E79CED-5287-4FE3-AD22-EECDCF66A108}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{8F99580A-D4DB-4ABB-96FA-45627BD93D12}" = lport=139 | protocol=6 | dir=in | app=system | "{9A585822-015A-41C3-A971-E77F382185EF}" = rport=138 | protocol=17 | dir=out | app=system | "{9A66C500-A588-4A5D-B8E6-C4772B46B1A3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C3470D26-954A-420E-BE11-24F416499395}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DCB7ADF1-F404-4974-84C3-F8F7F59A5143}" = rport=10243 | protocol=6 | dir=out | app=system | "{DE796A0A-FA70-45E7-ABD9-167C503AF6C5}" = lport=138 | protocol=17 | dir=in | app=system | "{EE83D5DE-2241-491E-BD2B-21A41C81C950}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{F3263874-19EE-4BD1-B099-73B7D1CBB1ED}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FC9D11D8-EEB1-4153-8B86-CCD0A3A31EAC}" = lport=137 | protocol=17 | dir=in | app=system | "{FFC1D923-EBB8-4BB4-A3D1-148818B4D23B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00696085-D2F9-42C3-97D9-267DA13AC824}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{011095D7-B61C-45DF-960A-0A9F51997EB9}" = protocol=17 | dir=in | app=g:\program files (x86)\avg\avg2014\avgnsa.exe | "{01CC269D-F3A2-48D5-A7D4-0FF9E09BDFB3}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{0785A564-83B5-46F8-9AC0-22AC821C30B8}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{0E3D61A2-A57C-454E-9C80-362A0BF07297}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{110479FB-BB0F-4AE3-B784-7EF1D7381BB0}" = protocol=17 | dir=in | app=g:\program files\microsoft office\office15\lync.exe | "{16D73485-BF75-43D1-BF28-86A3320773CF}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{170C6431-5531-47CE-8069-3F3700D1E2FD}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{1FC49F59-5BAA-4032-91B3-D18E49A4CC0C}" = protocol=17 | dir=in | app=g:\program files (x86)\avg\avg2014\avgdiagex.exe | "{240F5C7A-2714-49D3-AFBB-96D045DA836E}" = protocol=17 | dir=in | app=g:\program files\microsoft office\office15\ucmapi.exe | "{242D7DF1-6B6D-4CA1-BF1A-D8F17587C166}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{24A259C4-C430-4C97-9678-BA35AD4188E8}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{24D2A96C-9D16-4FB3-9862-E00EC31D3F10}" = protocol=17 | dir=in | app=g:\program files (x86)\winamp\winamp.exe | "{340FF541-A238-4FE3-86EA-EBFC0C01042A}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{387A5571-C625-4EE2-AF16-FE766E947BB1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3979FA8E-771E-41E2-A51E-AB191F332E6B}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{4001E305-0A68-44A3-B2FF-8B356DFE064F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{43C158ED-FC20-48B0-BAFD-90430AC298E3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{4815BC86-EDF7-46B3-8F51-209B35C11002}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{4C2C54D4-3B87-4145-8CAF-2574894084A3}" = protocol=17 | dir=in | app=g:\program files (x86)\steam\steam.exe | "{4D0D52BE-B35B-4E05-B339-CBC0F1FDC25C}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{57E03108-B3B4-48D0-92F2-C974C66BA32A}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{58F1B26B-ACC0-4BE1-9103-507B1A650D50}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{5E608351-9EEE-4CF7-B16C-3FF542F13A02}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{61D8AA90-F63B-438E-8130-6675FD26E52F}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{63683247-F4A8-48F2-AD2F-3B7F955A33C1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{64D623DC-14FC-4953-BF32-0E40F500FDBF}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe | "{6940E44B-F9B0-4323-AB79-43AD0E36F1B0}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{70B49DA2-1B04-45F1-B8B1-CCF1F8B2EDEF}" = protocol=17 | dir=in | app=c:\users\padi1_000\appdata\roaming\bittorrent\bittorrent.exe | "{7203D790-A1C3-4AE9-9F49-9470BCF12362}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{74AADF5D-B637-4260-9D83-67F26C6827DE}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{75B5FCFE-CA2D-4DB4-AD02-9EBC09E9F766}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{75D356DC-2CDD-4CA3-801D-6E2BFB89D80E}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{77726E4B-42BD-46FC-8CBA-297FA1CB614C}" = protocol=6 | dir=in | app=g:\program files (x86)\avg\avg2014\avgemca.exe | "{780E3E8F-F7E4-46A3-8751-8C8B5BFB6E21}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{7B5DDC30-D1F1-4E92-9DE3-C4A3C1C27E3C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{7C2D12D4-61D3-486C-801E-C15779A2E82A}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{8950C098-27A6-43A8-9246-FF1E185585AF}" = protocol=6 | dir=in | app=g:\program files (x86)\avg\avg2014\avgmfapx.exe | "{8D464B02-7A22-49F1-98D8-EE353CC439A0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{8E3FFEB0-BE43-485F-A055-2A642E07B067}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9911AC8E-E455-4768-A3C9-21482A3D885B}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{9FFF5F1F-C42A-4074-BB82-41A7745A7929}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{A3C405D5-20C7-4636-9D51-EF4B5FF00A77}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A4A1B6F9-1D92-4A60-8D1A-AB5729A5B761}" = protocol=6 | dir=in | app=g:\program files (x86)\steam\steam.exe | "{A8CB7E8A-1B6E-48FC-8DDE-291DDB695BA5}" = protocol=6 | dir=in | app=g:\program files\microsoft office\office15\ucmapi.exe | "{A9B2D5EA-7B4A-41C7-BC02-6ECBD3BCD0FD}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{B07E5809-EBC1-455B-B6EA-7D0C295BA1C5}" = protocol=6 | dir=in | app=g:\program files (x86)\avg\avg2014\avgdiagex.exe | "{B0EE69BC-BE2B-407A-81BB-6B7074D0C3DE}" = protocol=17 | dir=in | app=g:\program files (x86)\avg\avg2014\avgemca.exe | "{BA588883-6BAA-4FCA-9A61-64E597132934}" = protocol=6 | dir=out | app=system | "{C0633137-8A2A-4EAC-AC04-C57B5937A8AF}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe | "{C3E149A2-57B8-4529-AB7D-507D9811BFD1}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{C5F61BAB-95C7-4018-9A1C-5856BEE38AFE}" = protocol=6 | dir=in | app=g:\program files\microsoft office\office15\lync.exe | "{CF744DB1-3A77-462A-8844-DACF4F2FA591}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{D2044643-47C6-441C-AE33-56E4D4E72DD4}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D2F22583-E5BB-4D7D-A0C8-4F96FF28A9A1}" = protocol=6 | dir=in | app=c:\users\padi1_000\appdata\roaming\bittorrent\bittorrent.exe | "{D6E35F39-B443-4FC4-BAC5-28948446C0D0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{E1D5619E-28CB-46B4-B744-338ED0F347C1}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{E7414A55-AB5C-4FE2-8C28-035FBC7E11E2}" = protocol=17 | dir=in | app=g:\program files (x86)\avg\avg2014\avgmfapx.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EE4315E6-4DA1-43B8-B764-EB1BE708A0A8}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{F02BF4C4-8837-4250-93DE-F720C095DB7A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{F1D51710-7D86-4A92-B17E-0BB611C39162}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{F40DF8F8-8711-4630-9E7B-F90FDE493DF2}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe | "{F5A3E2FD-7D88-4FE9-A56F-A7B735C79232}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe | "{F6E56C6B-50FC-4B0E-B39D-E65A1335A874}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F9BC573A-B116-48E6-B4E1-7565C05FEE93}" = protocol=6 | dir=in | app=g:\program files (x86)\winamp\winamp.exe | "{FEB47DC4-1F6F-4469-A15E-6A3B41466D23}" = protocol=6 | dir=in | app=g:\program files (x86)\avg\avg2014\avgnsa.exe | "TCP Query User{15969B7C-9FCE-44BB-85F0-67EE65B33B2B}G:\program files (x86)\sopcast\sopcast.exe" = protocol=6 | dir=in | app=g:\program files (x86)\sopcast\sopcast.exe | "TCP Query User{454B4C75-725B-49E7-8EFD-8E3CDF3A29E1}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | "UDP Query User{1E389059-5591-4F91-BD54-42F2276CB161}G:\program files (x86)\sopcast\sopcast.exe" = protocol=17 | dir=in | app=g:\program files (x86)\sopcast\sopcast.exe | "UDP Query User{E95CAD6B-5701-4D0B-A179-AF689E4CA6B8}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{34883B9C-CDFE-46F0-9C5B-935484C218C3}" = AVG 2014 "{7F624BD1-4FE0-432F-B928-68302E156D04}" = AVG 2014 "{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables "{90150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013 "{90150000-0015-0415-1000-0000000FF1CE}" = Microsoft Access MUI (Polish) 2013 "{90150000-0016-0415-1000-0000000FF1CE}" = Microsoft Excel MUI (Polish) 2013 "{90150000-0018-0415-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (Polish) 2013 "{90150000-0019-0415-1000-0000000FF1CE}" = Microsoft Publisher MUI (Polish) 2013 "{90150000-001A-0415-1000-0000000FF1CE}" = Microsoft Outlook MUI (Polish) 2013 "{90150000-001B-0415-1000-0000000FF1CE}" = Microsoft Word MUI (Polish) 2013 "{90150000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch "{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English "{90150000-001F-0415-1000-0000000FF1CE}" = Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski "{90150000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2013 "{90150000-0044-0415-1000-0000000FF1CE}" = Microsoft InfoPath MUI (Polish) 2013 "{90150000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2013 "{90150000-0090-0415-1000-0000000FF1CE}" = Microsoft DCF MUI (Polish) 2013 "{90150000-00A1-0415-1000-0000000FF1CE}" = Microsoft OneNote MUI (Polish) 2013 "{90150000-00BA-0415-1000-0000000FF1CE}" = Microsoft Groove MUI (Polish) 2013 "{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013 "{90150000-00C1-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2013 "{90150000-00E1-0415-1000-0000000FF1CE}" = Microsoft Office OSM MUI (Polish) 2013 "{90150000-00E2-0415-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (Polish) 2013 "{90150000-012B-0415-1000-0000000FF1CE}" = Microsoft Lync MUI (Polish) 2013 "{C23EE7CE-C1A3-4F94-A8F0-9E0AC9C6DE6E}" = Adblock Plus for IE (32-bit and 64-bit) "AVG" = AVG 2014 "Office15.PROPLUS" = Microsoft Office Professional Plus 2013 "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 5.00 (64-bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1035B082-201E-466E-9084-D096589C05CD}" = Wielki słownik angielsko-polski i polsko-angielski PWN-OXFORD "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.11 "{52E225FC-FCB4-41F7-837B-6E37FB05BD7B}" = Adobe AIR "{56D4499E-AC3E-4B8D-91C9-C700C148C44B}" = Google Drive "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.05) "{fd97d1e2-368a-4cd9-af63-8eeff938044a}" = Adblock Plus for IE "Adobe AIR" = Adobe AIR "AVG SafeGuard toolbar" = AVG SafeGuard toolbar "DAEMON Tools Lite" = DAEMON Tools Lite "Google Chrome" = Google Chrome "Odkurzacz 13.4_is1" = Odkurzacz "SopCast" = SopCast 3.8.3 "TeamViewer 9" = TeamViewer 9 "Winamp" = Winamp [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "BitTorrent" = BitTorrent "GG" = GG [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-01-03 15:32:48 | Computer Name = Mateusz | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=458e1bec-837a-45f6-b9d5-925ed5d299de;NotificationInterval=1440;Trigger=NetworkAvailable Error - 2014-01-03 17:06:43 | Computer Name = Mateusz | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=458e1bec-837a-45f6-b9d5-925ed5d299de;NotificationInterval=1440;Trigger=NetworkAvailable Error - 2014-01-03 17:39:34 | Computer Name = Mateusz | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: TeamViewer.exe, wersja: 9.0.24951.0, sygnatura czasowa: 0x52b02898 Nazwa modułu powodującego błąd: TeamViewer.exe, wersja: 9.0.24951.0, sygnatura czasowa: 0x52b02898 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00083f0f Identyfikator procesu powodującego błąd: 0x39c Godzina uruchomienia aplikacji powodującej błąd: 0x01cf08ba7a7c0b21 Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe Identyfikator raportu: 88930cfc-74bf-11e3-be77-00266c6e3753 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2014-01-03 17:39:36 | Computer Name = Mateusz | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: TeamViewer.exe, wersja: 9.0.24951.0, sygnatura czasowa: 0x52b02898 Nazwa modułu powodującego błąd: TeamViewer.exe, wersja: 9.0.24951.0, sygnatura czasowa: 0x52b02898 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00083f0f Identyfikator procesu powodującego błąd: 0x39c Godzina uruchomienia aplikacji powodującej błąd: 0x01cf08ba7a7c0b21 Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe Identyfikator raportu: 8a519e70-74bf-11e3-be77-00266c6e3753 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2014-01-04 12:08:49 | Computer Name = Mateusz | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=458e1bec-837a-45f6-b9d5-925ed5d299de;NotificationInterval=1440;Trigger=NetworkAvailable Error - 2014-01-04 12:09:05 | Computer Name = Mateusz | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=458e1bec-837a-45f6-b9d5-925ed5d299de;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error - 2014-01-04 12:17:06 | Computer Name = Mateusz | Source = Customer Experience Improvement Program | ID = 1008 Description = Error - 2014-01-04 12:19:06 | Computer Name = Mateusz | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=458e1bec-837a-45f6-b9d5-925ed5d299de;NotificationInterval=1440;Trigger=NetworkAvailable Error - 2014-01-04 12:49:33 | Computer Name = Mateusz | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=458e1bec-837a-45f6-b9d5-925ed5d299de;NotificationInterval=1440;Trigger=NetworkAvailable Error - 2014-01-04 12:49:35 | Computer Name = Mateusz | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004F074 Argumenty wiersza polecenia: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=458e1bec-837a-45f6-b9d5-925ed5d299de;NotificationInterval=1440;Trigger=UserLogon;SessionId=2 [ System Events ] Error - 2013-12-14 19:12:03 | Computer Name = Mateusz | Source = DCOM | ID = 10010 Description = Error - 2013-12-16 06:55:55 | Computer Name = Mateusz | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Ochrona oprogramowania. Error - 2013-12-16 06:55:55 | Computer Name = Mateusz | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Ochrona oprogramowania z powodu następującego błędu: %%1053 Error - 2013-12-18 18:15:46 | Computer Name = Mateusz | Source = DCOM | ID = 10010 Description = Error - 2013-12-25 09:42:42 | Computer Name = Mateusz | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070002: Synaptics - Other hardware - Synaptics PS/2 Port Compatible TouchPad. Error - 2013-12-26 08:01:23 | Computer Name = Mateusz | Source = Microsoft-Windows-Kernel-General | ID = 5 Description = Error - 2013-12-26 08:04:38 | Computer Name = Mateusz | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070002: Synaptics - Other hardware - Synaptics PS/2 Port Compatible TouchPad. Error - 2013-12-28 08:44:19 | Computer Name = Mateusz | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070002: Synaptics - Other hardware - Synaptics PS/2 Port Compatible TouchPad. Error - 2014-01-02 14:53:59 | Computer Name = Mateusz | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070002: Synaptics - Other hardware - Synaptics PS/2 Port Compatible TouchPad. Error - 2014-01-03 15:30:26 | Computer Name = Mateusz | Source = DCOM | ID = 10010 Description = < End of report >