OTL Extras logfile created on: 1/18/2014 11:03:25 AM - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\basiak xd\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16750) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2.00 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 45.88% Memory free 4.00 Gb Paging File | 2.43 Gb Available in Paging File | 60.82% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 116.45 Gb Total Space | 27.86 Gb Free Space | 23.93% Space Free | Partition Type: NTFS Drive D: | 101.79 Gb Total Space | 27.70 Gb Free Space | 27.21% Space Free | Partition Type: NTFS Computer Name: BASIA | User Name: basiak xd | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htafile [open] -- "%1" %* htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- Reg Error: Key error. Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htafile [open] -- "%1" %* htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- Reg Error: Key error. Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AutoUpdateDisableNotify" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0402361B-1ED1-4445-8E4C-017790B5AD1C}" = lport=10243 | protocol=6 | dir=in | app=system | "{04CEE6A1-234E-421E-8453-5639BB9C5E23}" = rport=139 | protocol=6 | dir=out | app=system | "{0E2B0B3A-C26B-4047-B3EA-0183429FC9DF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{11EAF5B3-7CAB-435F-974D-27EB5474F7E9}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{19E1208F-6DB0-4655-8A4C-F7FC0418EE7B}" = lport=137 | protocol=17 | dir=in | app=system | "{205744DD-CE32-454F-9BBC-34D16E4BB44A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{38FE5E09-0376-480E-85CD-FA1A696D2627}" = lport=445 | protocol=6 | dir=in | app=system | "{40976DE7-7BAE-4EF9-A535-B243F2CF122A}" = rport=138 | protocol=17 | dir=out | app=system | "{441AB10F-8D63-4B31-820B-5D4DC4EFA630}" = rport=10243 | protocol=6 | dir=out | app=system | "{486050FB-9768-4229-A3DD-A60BFBF2FC9D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4884340A-9974-4E19-8326-301D38A333A3}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{59ECA49F-496F-408E-8152-5C1C777C3B63}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5B7EA648-7216-4EBB-AB6B-C69758694F8A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{60AFA537-FD5F-480D-9689-E590BEAF668E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{67935803-9A6D-4FB7-9165-9141C1434FE9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{7651D86F-24AE-47A1-8B15-43ACAE965A7F}" = lport=19312 | protocol=6 | dir=in | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe | "{89254919-0742-4745-B0CE-8C53BB91BF18}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8A608E50-5A7B-411B-A189-D739EB473D8A}" = lport=19312 | protocol=17 | dir=in | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe | "{8EFDC82D-4231-4943-A318-4521F98DB180}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{948721D7-9EA6-4BE9-BA9E-E11B0F938733}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{9810A192-1D71-4B5B-9553-736F87668F0C}" = rport=445 | protocol=6 | dir=out | app=system | "{984FD25B-31E2-44A0-A531-6A804C9FEBE7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{9C1E7132-6BE1-4EC6-B30B-B9009ACA60E2}" = lport=139 | protocol=6 | dir=in | app=system | "{A3D455EC-E81C-4765-B0D3-ACC199538F0F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A773A97D-B870-44C8-B788-34DEC6786515}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{A8E03EB9-8EEF-421C-B679-C848A5D21343}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{AFCBF347-4585-4F3E-AC0E-622067D021A2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B9862AF8-5A04-4CC3-855C-4E8629F0A30B}" = rport=137 | protocol=17 | dir=out | app=system | "{C4983BC9-240E-43E1-BEB2-6A4CDBC70E41}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{C7CEE552-5437-4890-A19A-DC0BEAE28D88}" = lport=2869 | protocol=6 | dir=in | app=system | "{D7DD0DA0-4439-42E7-A5BC-BA1D6F927CA6}" = lport=2869 | protocol=6 | dir=in | app=system | "{E4D02F9A-579F-49DB-A456-82196BBC2FB5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EA40698C-118F-40A7-BCF0-4697AE91F642}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F1A80EE3-E0B8-4683-88AC-C7D02873B666}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F27793A8-A3DA-4070-BAE3-393A74C34B4C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FB513E68-7FDD-4D98-90FA-D7B2772AADDA}" = lport=138 | protocol=17 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01332FD7-5836-4682-8E24-34C156978973}" = protocol=17 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{043A0755-DCFB-4FBF-BCB5-B8B5DC67B1EC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{132155E2-9700-41DA-9C5A-E83953B6A81F}" = protocol=6 | dir=in | app=c:\programdata\esafe\egdpsvc.exe | "{16F26C8E-2FB9-428A-B9DE-1F03F4C2B96D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{25AF4063-DA1D-4182-94BC-F43BACDA9C8B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{2B07443D-2C68-42B2-878C-FAB5BBC57F94}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{2E37F463-9B4B-473D-94C0-BFA3D968DBA5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3EC222E1-0534-48AC-B108-231AAFF94850}" = protocol=17 | dir=in | app=c:\program files (x86)\bitspirit\bitspirit.exe | "{40E0B7E2-9057-4690-967C-B28BC9DE2FDF}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{42C92409-EBE5-45B8-B16B-0E8BB0421C9A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{4C454E15-B0AC-4351-AA31-DE8E166D1977}" = dir=in | app=c:\windows\syswow64\dfrg\btc-miner.exe | "{598A2351-6F5B-4328-A332-FC0D605CF014}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{60396FCD-2C45-4B5F-81C7-4E6AE42E2A0D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{6DD0C2F4-FCF9-4AA1-A812-20B2C6CF09AE}" = protocol=6 | dir=in | app=c:\users\basiak xd\downloads\sweetimsetup.exe | "{6E50C011-1001-4088-8774-D986C5CCBF02}" = dir=out | app=c:\windows\syswow64\config\systemprofile\appdata\local\windows internet name service\wins.exe | "{7501294A-6FE4-4BC1-8613-A35416333786}" = protocol=6 | dir=in | app=c:\program files (x86)\bitspirit\bitspirit.exe | "{772C1E1A-7746-41A1-BD47-B3E92B0B958B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7AC1A5D2-1FEC-48D1-8AAF-DD5999306EB3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{7AF480FB-1226-4F3E-8A09-006B9B5C9C78}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8456330F-2835-4958-A939-6C4AFA03BC24}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{891161E9-64FF-4BD6-A2B2-525A20364607}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{89D2E9F1-AD75-42BE-92CF-6011E1AC5D0A}" = dir=out | app=c:\users\basiak xd\desktop\codecperformersetup.exe | "{8BC7F14B-D7EC-45DD-9A79-BE1617C8645C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{94A46CA0-95F2-4723-902F-6F1B0A491940}" = protocol=58 | dir=in | app=system | "{95ABAF5F-2F1C-440D-8C33-3E5AF9AD1CDF}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{A5285B6E-6AA9-484D-B30A-15822072F17A}" = protocol=17 | dir=in | app=c:\users\basiak xd\downloads\sweetimsetup.exe | "{AF3640DF-6042-4F70-9E5F-9E23F1194154}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B3465995-4DE3-4070-BC4A-77969FDF13AD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{B5BE8506-C7D4-47C4-A1AD-3AD3B668353B}" = protocol=6 | dir=out | app=system | "{B65385B3-A11C-4DD8-95E6-96F7C18E6528}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{BB2FBCAF-AF61-4FFA-81DD-2979E3724370}" = dir=in | app=c:\users\basiak xd\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{BE7D9D16-8312-4B16-BBCC-1A4B9C199099}" = protocol=6 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{C1C5CFE3-4847-45D0-B141-91F747A8781F}" = dir=in | app=c:\users\basiak xd\desktop\codecperformersetup.exe | "{CC761544-F5A2-4354-BB70-08DD08190FEA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{CD198150-DFDD-4387-B34C-B429841116EB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D570BC52-729B-4A7E-802F-3B05D8DED4D4}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{E47EB3B6-C45E-4A1D-B536-44AD0F792C73}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{F1A993E7-0538-4220-B5F9-54107628AE1A}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{F7DCE90A-995A-4A89-B781-55681D5F379D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{FD397169-9030-4965-A2AC-F9ED06B02A0B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FE112F86-8E7B-4AEE-9144-5BFEB14D3899}" = dir=out | app=c:\windows\syswow64\dfrg\btc-miner.exe | "TCP Query User{08034D91-5049-463E-B90D-BE7EFBAA7161}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe | "TCP Query User{2C3F6CC9-E9DE-4A92-B01C-B51EB5046B45}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "TCP Query User{5E2ED70D-564D-49DE-AFDF-D6911EAE7C4D}C:\program files (x86)\gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu\gg.exe | "TCP Query User{63E29E41-8A5F-4348-99D7-88EDE8A6E662}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe | "TCP Query User{7A68B107-A4C0-4590-9059-666413FAC4F7}C:\program files (x86)\gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu\gg.exe | "TCP Query User{8B9E3215-5FFA-4690-9C82-F1EA9CEE2CC9}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "TCP Query User{95587A5B-431E-4CDC-92ED-BA1D2A12F5AB}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "TCP Query User{B6C3D7F3-7B05-4B9D-B420-2D332910DE26}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "TCP Query User{BAD16645-FB59-4D20-A780-19A5FF5E3EBA}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "UDP Query User{30531477-E104-4A5F-9E53-AAB69ACCC708}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "UDP Query User{3065E676-6EBF-4B1C-8E2F-8BE833CB78B0}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe | "UDP Query User{31EEDABB-A9C4-455A-B9EC-5F18191DCD89}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "UDP Query User{321636ED-2F91-4E9A-A31B-7091D9641DE3}C:\program files (x86)\gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu\gg.exe | "UDP Query User{7B885720-CEFF-4D31-A98E-1125D61A9290}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "UDP Query User{A9E5AC33-EEE5-48EA-AFED-AD9AFF0923E5}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe | "UDP Query User{C167C2DA-6FAE-4A0D-A2EC-8E07F771A0B2}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "UDP Query User{FE85400F-06DE-4752-A11C-47182EA7BCBC}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "UDP Query User{FE9D3361-D499-4EC0-AD25-E5211478B9AB}C:\program files (x86)\gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu\gg.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot "{1DF5019A-68B5-4ba1-8E59-E185C7B7FF11}" = Komunikator WTW 0.9.14.3742 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{95F7B3C3-3D4C-471B-982A-76DB26E0EA2B}" = Bezpieczeństwo rodzinne usługi Windows Live "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{A7500970-FE98-11E1-B560-F04DA23A5C58}" = Vegas Pro 12.0 (64-bit) "{AB085680-FE98-11E1-A232-F04DA23A5C58}" = MSVCRT Redists "{E102B843-786A-4F58-AF75-6504570E207B}" = Microsoft Security Client "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft Security Client" = Microsoft Security Essentials "NVIDIA Drivers" = NVIDIA Drivers "ZTE USB Driver" = ZTE USB Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0B63BF75-9F0A-4E93-A69D-BDCC6A26C4B1}" = Podstawowe programy Windows Live "{117B6BF6-82C3-420C-B284-9247C8568E53}" = The Sims™ 3 Impreza w plenerze Akcesoria "{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Narzędzie do przekazywania usługi Windows Live "{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3 "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 45 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program "{2A5FBE73-76DA-4A31-BD86-1B0E01DC33F8}" = Windows Live Messenger "{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2 "{40CC0CC6-C1BA-476D-98CF-5430DA439B4F}" = Galeria fotografii usługi Windows Live "{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = The Sims™ 3 Po zmroku "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6 "{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 Nowoczesny apartament Akcesoria "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B11296A-F894-449C-8DF6-6AAAA7D4D118}" = The Sims™ 3 Miejskie Życie Akcesoria "{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447 "{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0415-1000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Kariera "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{9D6D7811-43B3-463C-BC79-5D1755269989}" = Net4Switch "{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI "{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6 "{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 Wymarzone Podróże "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3 "{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media "{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service "{DB4690C5-9015-401D-A96C-A49909B7C372}" = Poczta usługi Windows Live "{DD49053A-0140-44EF-AE75-C4BC1FDB8286}" = Windows Live Writer "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}" = The Sims™ 3 Pokolenia "{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}" = The Sims™ 3 Szybka jazda Akcesoria "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}" = ASUS FancyStart "{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27) "{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Anki" = Anki "Audacity_is1" = Audacity 1.2.6 "BitSpirit_is1" = BitSpirit v3.6.0.550 Stable "DC-Bass Source" = DC-Bass Source 1.3.0 "DivX Setup" = DivX Setup "Dzielenie i łączenie plików_is1" = Dzielenie i łączenie plików v1.2.2 "ENTERPRISE" = Microsoft Office Enterprise 2007 "Heroes of Might and Magic III - Złota Edycja_is1" = Heroes of Might and Magic III - Złota Edycja "LAME_is1" = LAME v3.99.3 (for Windows) "Odkurzacz 13.3_is1" = Odkurzacz "OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter 1.0.0.5 "Overlord_is1" = Overlord "PhotoScape" = PhotoScape "Picasa 3" = Picasa 3 "PowerISO" = PowerISO "SecureW2 EAP Suite" = SecureW2 EAP Suite 1.1.3 for Windows "The Sims 2 MegaPack_is1" = The Sims 2 MegaPack "vsfilter_is1" = DirectVobSub 2.40.4209 "WinLiveSuite_Wave3" = Podstawowe programy Windows Live "WinRAR archiver" = Archiwizator WinRAR "Xvid Video Codec 1.3.2" = Xvid Video Codec [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "Video Converter Packages" = Video Converter Packages [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 1/17/2014 8:58:19 PM | Computer Name = Basia | Source = Google Update | ID = 20 Description = Error - 1/17/2014 11:35:31 PM | Computer Name = Basia | Source = Google Update | ID = 20 Description = Error - 1/17/2014 11:58:19 PM | Computer Name = Basia | Source = Google Update | ID = 20 Description = Error - 1/18/2014 2:35:32 AM | Computer Name = Basia | Source = Google Update | ID = 20 Description = Error - 1/18/2014 2:58:18 AM | Computer Name = Basia | Source = Google Update | ID = 20 Description = Error - 1/18/2014 5:32:02 AM | Computer Name = Basia | Source = MsiInstaller | ID = 10005 Description = Error - 1/18/2014 5:32:03 AM | Computer Name = Basia | Source = MsiInstaller | ID = 10005 Description = Error - 1/18/2014 5:32:09 AM | Computer Name = Basia | Source = MsiInstaller | ID = 10005 Description = Error - 1/18/2014 5:32:10 AM | Computer Name = Basia | Source = MsiInstaller | ID = 10005 Description = Error - 1/18/2014 5:53:29 AM | Computer Name = Basia | Source = Microsoft-Windows-CAPI2 | ID = 513 Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się. Details: AddWin32ServiceFiles: Unable to back up image of service ADSM Service since QueryServiceConfig API failed System Error: Nie można odnaleźć określonego pliku. . [ Media Center Events ] Error - 4/22/2012 5:15:43 AM | Computer Name = basiakxd | Source = MCUpdate | ID = 0 Description = 11:15:43 - Nie można pobrać pakietu Directory (Błąd: Nie można połączyć się z serwerem zdalnym) Error - 4/24/2012 8:52:59 AM | Computer Name = basiakxd | Source = MCUpdate | ID = 0 Description = 14:52:59 - Błąd podczas nawiązywania połączenia z Internetem. 14:52:59 - Nie można skontaktować się z serwerem.. Error - 4/24/2012 8:53:09 AM | Computer Name = basiakxd | Source = MCUpdate | ID = 0 Description = 14:53:04 - Błąd podczas nawiązywania połączenia z Internetem. 14:53:04 - Nie można skontaktować się z serwerem.. Error - 6/20/2012 7:22:01 AM | Computer Name = basiakxd | Source = MCUpdate | ID = 0 Description = 13:21:54 - Błąd podczas nawiązywania połączenia z Internetem. 13:21:54 - Nie można skontaktować się z serwerem.. [ OSession Events ] Error - 12/30/2009 4:45:53 PM | Computer Name = basiakxd | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 68 seconds with 0 seconds of active time. This session ended with a crash. Error - 2/10/2013 5:55:38 AM | Computer Name = basiakxd | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3787 seconds with 900 seconds of active time. This session ended with a crash. [ System Events ] Error - 1/15/2014 1:13:47 PM | Computer Name = Basia | Source = NetBT | ID = 4321 Description = Nie można zarejestrować nazwy „BASIA :20” w interfejsie o adresie IP 158.75.90.107. Komputer o adresie IP 158.75.88.206 nie zezwolił na przejęcie tej nazwy przez ten komputer. Error - 1/15/2014 1:13:47 PM | Computer Name = Basia | Source = NetBT | ID = 4321 Description = Nie można zarejestrować nazwy „BASIA :0” w interfejsie o adresie IP 158.75.90.107. Komputer o adresie IP 158.75.88.206 nie zezwolił na przejęcie tej nazwy przez ten komputer. Error - 1/16/2014 8:38:12 PM | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Internet Explorer 11 dla systemu Windows 7 - wersja dla systemów opartych na procesorach x64. Error - 1/16/2014 9:16:41 PM | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Internet Explorer 11 dla systemu Windows 7 - wersja dla systemów opartych na procesorach x64. Error - 1/17/2014 6:02:16 AM | Computer Name = Basia | Source = Microsoft-Windows-LanguagePackSetup | ID = 1000 Description = Inicjacja klienta CBS nie powiodła się. Ostatni błąd: 0x8007045b Error - 1/17/2014 6:02:18 AM | Computer Name = Basia | Source = Service Control Manager | ID = 7023 Description = Usługa Wstępne ładowanie do pamięci zakończyła działanie; wystąpił następujący błąd: %%13 Error - 1/17/2014 6:15:55 PM | Computer Name = Basia | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 23:13:48 na ?2014-?01-?17 było nieoczekiwane. Error - 1/17/2014 6:15:56 PM | Computer Name = BASIA | Source = BugCheck | ID = 1001 Description = Error - 1/17/2014 8:17:59 PM | Computer Name = Basia | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Internet Explorer 11 dla systemu Windows 7 - wersja dla systemów opartych na procesorach x64. Error - 1/17/2014 8:29:47 PM | Computer Name = Basia | Source = BugCheck | ID = 1001 Description = < End of report >