OTL Extras logfile created on: 2014-12-25 16:33:45 - Run 1 OTL by OldTimer - Version Folder = C:\Users\x\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17501) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,49 Gb Total Physical Memory | 1,59 Gb Available Physical Memory | 45,51% Memory free 6,98 Gb Paging File | 4,65 Gb Available in Paging File | 66,64% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 244,04 Gb Total Space | 84,92 Gb Free Space | 34,80% Space Free | Partition Type: NTFS Drive D: | 221,62 Gb Total Space | 212,69 Gb Free Space | 95,97% Space Free | Partition Type: NTFS Computer Name: X-KOMPUTER | User Name: x | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 180 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html [@ = OperaStable] -- "C:\Program Files (x86)\Opera\Launcher.exe" -noautoupdate -- "%1" .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = OperaStable] -- "C:\Program Files (x86)\Opera\Launcher.exe" -noautoupdate -- "%1" [HKEY_USERS\S-1-5-21-1067321925-3578864132-775108078-1000\SOFTWARE\Classes\] .html [@ = OperaStable] -- "C:\Program Files (x86)\Opera\Launcher.exe" -noautoupdate -- "%1" [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate -- "%1" https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate -- "%1" https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07C263EE-520A-44B5-BED5-AA5AE111510E}" = lport=445 | protocol=6 | dir=in | app=system | "{0FEB8654-58F0-45F5-AC20-8CD79D396A7B}" = rport=137 | protocol=17 | dir=out | app=system | "{259AA121-5A88-466A-9E82-B915D9617D73}" = lport=137 | protocol=17 | dir=in | app=system | "{2AC092B1-E22A-44E6-8D8A-8104E2669F2F}" = rport=10243 | protocol=6 | dir=out | app=system | "{32C9F6D7-0E2D-49A5-B6E5-F6551CCA711B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{42E90BE3-457F-47A9-85D1-E2692D09853B}" = rport=445 | protocol=6 | dir=out | app=system | "{4436E5B2-EA82-41AB-8C0C-7E69583B1409}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{518899A6-ECFF-4576-BE6F-2FD2DFE1BB65}" = lport=10243 | protocol=6 | dir=in | app=system | "{769CA2C4-EF90-4046-AF75-63E2A303EF9A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7997C81C-C605-46BE-9CD5-B9BFF4A8F7D8}" = lport=139 | protocol=6 | dir=in | app=system | "{7CDFFE42-72BF-4CA5-93BF-1FF3B9F3F2A2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{87AC1A2B-914B-44F3-A54E-A856B13A59BF}" = lport=138 | protocol=17 | dir=in | app=system | "{8EF684C7-F4BD-45EE-A95F-4A7711DF0320}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{97D7D7F7-E4B5-40E8-9DFF-7EC8139D9E41}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BD30A3C2-3597-4000-BEBD-CF3D89403B45}" = lport=2869 | protocol=6 | dir=in | app=system | "{C3D6F11F-D7EA-4757-92AF-96AF8194C033}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CEDCD395-8B70-4347-B68D-5545CCF42EC0}" = rport=139 | protocol=6 | dir=out | app=system | "{D1F4882F-9313-44C3-B2EE-C9220ABB3A58}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{E008D04F-39F6-4318-B5D1-B68AA595B130}" = rport=138 | protocol=17 | dir=out | app=system | "{F0274AFC-66FC-44DE-B487-FF99DFA16973}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{F62D3DFF-0D49-4B6F-B218-45F8C5C6F1D4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F8BC6CA9-2F95-4ABA-A44A-DAFB4496B7E4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04B9CE70-9C62-4936-A639-A9057801208B}" = protocol=6 | dir=in | app=c:\programdata\turbine\the lord of the rings online\lotroclient.exe | "{0A54EA25-A50B-4300-BFBE-2D0A79D7C498}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{0DE2A8F9-145A-421E-848D-3D4E4A1AD253}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{151554D3-938E-450D-8E61-A6B30890BB37}" = protocol=17 | dir=in | app=c:\programdata\turbine\the lord of the rings online\turbinelauncher.exe | "{1530E2A3-12A1-4D2F-98B3-74B42B1D9355}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{16B29268-3BED-4311-9E66-4AEE1E4A2DA8}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{1EDB0E6F-5E85-48FE-AE81-5345EE145AC1}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{21334DD1-E236-4B3F-95D6-BE18F9416F9E}" = protocol=17 | dir=in | app=c:\program files\visicom media\manydownloader\manydownloader.exe | "{27579595-1162-4782-94B1-3CD2FDAFE7D7}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{32E98E1B-D0CF-4B94-B472-A12A73535419}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe | "{33A65D34-1F0E-493D-86D3-AC75DEB1803F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{367D0BB7-6529-4BCC-A608-5BABAB55009B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{3B409319-3A08-4BFE-9530-FFF9E962A6EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{3FE197CC-8EF4-482A-9F18-7C86B55FE60F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row 2\sr2_pc.exe | "{4004E2CB-F9DA-4917-BD0C-BAD99B82CF04}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{403C19CE-BB8F-4F9E-99EE-DA79AAED9AD1}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{41D1ADAD-1205-4311-82EA-CF2F49B8D8F7}" = protocol=17 | dir=in | app=c:\program files (x86)\mystarttb\toolbarcleaner.exe | "{4565A203-B612-43F6-985E-F93E7E492D3F}" = protocol=6 | dir=in | app=c:\program files (x86)\manycam\manycam.exe | "{47A1012B-524D-47EF-B339-4E4E505C01A2}" = protocol=6 | dir=out | app=system | "{4AFDA92B-A86F-4449-BF12-93C69820A6E3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{50D90740-8113-4C9E-8A79-370D904BC6F8}" = protocol=6 | dir=in | app=c:\users\x\appdata\roaming\utorrent\utorrent.exe | "{59A124A5-DB9D-4758-895B-DC2D3CB69E77}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{636A46A5-9C9A-4D20-A202-A8540799903C}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{649F3D5E-B02C-4424-A276-B4935CE188FA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{6D68C919-865C-4E5C-A188-AA182A6D719B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{724CC400-8E6E-43C1-8A35-EB1C0D1E537D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7B2BDBC0-5880-4F16-B544-F96F398736DA}" = protocol=6 | dir=in | app=c:\program files (x86)\mystarttb\dtuser.exe | "{85E0F63F-EC07-443E-95CA-8852F84D83CF}" = dir=in | app=c:\users\x\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{88331AF5-1D1F-4A58-A5E3-8A9F0708350C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{90D2DA66-7640-472B-8285-DF45A9150CC5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{9665A158-B35A-4F04-A8FD-944699630645}" = protocol=17 | dir=in | app=c:\programdata\emailnotifier\emailnotifier.exe | "{9F64B723-6B30-428B-9779-6133A4A76A00}" = dir=in | app=c:\users\x\appdata\local\microsoft\skydrive\skydrive.exe | "{9FD254B8-E1E9-4AAF-982F-66CAFA0212EF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{9FF247B8-F099-49B9-BF4F-57928B679426}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{A2FF3D98-F618-4321-AAFA-DF8805D8AA1F}" = protocol=17 | dir=in | app=c:\users\x\appdata\roaming\utorrent\utorrent.exe | "{A640CD28-E0DD-43B8-A284-2271CA2130A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{AD3414D9-DF14-4A05-8AD9-0AF1D43466D1}" = protocol=6 | dir=in | app=c:\programdata\emailnotifier\emailnotifier.exe | "{AD4D7D01-15A8-4C06-97DA-F31872F7CC9F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{BB2CE2FE-78FA-4CA2-8935-3D1C022114BB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{C9E466D4-73F1-43CC-B01B-2660E5E6453F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CD286432-7386-4C76-ABC4-0A67B7CF3153}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{CDD45106-F294-41B7-8E64-B1D49F026093}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row 2\sr2_pc.exe | "{D03C7659-9D97-4E98-8F6C-7B3476C6FAD3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe | "{DBFD0786-BB3B-4BF6-A14A-D8036C9D4546}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{DD01FAA3-4232-4368-8666-6D40B9FD85F1}" = protocol=17 | dir=in | app=c:\programdata\turbine\the lord of the rings online\lotroclient.exe | "{DE79C1D6-6DFC-4D46-831A-E0FFDCC3F4D7}" = protocol=6 | dir=in | app=c:\program files\visicom media\manydownloader\manydownloader.exe | "{E02A7D64-9259-4E43-8FAB-F04EA8C8B887}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{E3821556-847F-4258-BB8E-08ABA0130E09}" = protocol=6 | dir=in | app=c:\program files (x86)\mystarttb\toolbarcleaner.exe | "{E41093D0-30EB-489A-9926-877AD155E2B4}" = protocol=17 | dir=in | app=c:\program files (x86)\manycam\manycam.exe | "{EFB6E606-D895-4788-B3BC-BF0FF158730A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F47A5E83-8841-491E-9B36-71FE0AED3B85}" = protocol=17 | dir=in | app=c:\program files (x86)\mystarttb\dtuser.exe | "{F7020446-9ED4-42A8-9D41-81D0137E8B39}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{F889D9A8-6AEC-407D-B4C1-E4C5DDE927BA}" = protocol=6 | dir=in | app=c:\programdata\turbine\the lord of the rings online\turbinelauncher.exe | "TCP Query User{09E801D0-071A-429E-A1BA-388187085D66}C:\program files (x86)\chickeninvadersrotydemo\ci3demo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\chickeninvadersrotydemo\ci3demo.exe | "TCP Query User{0DB89311-EA19-4563-9D31-47B4F7435F0D}D:\program files (x86)\iq publishing\trapped dead\bin\trappeddead.exe" = protocol=6 | dir=in | app=d:\program files (x86)\iq publishing\trapped dead\bin\trappeddead.exe | "TCP Query User{17DCC4E7-6FD0-4B30-A9D5-DE0D830443CC}C:\program files (x86)\taxi madness london\london.exe" = protocol=6 | dir=in | app=c:\program files (x86)\taxi madness london\london.exe | "TCP Query User{4E774003-A6C0-47F6-ABDB-73A5CAD8EEAA}C:\windows\syswow64\dpnsvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dpnsvr.exe | "TCP Query User{5B05B3EB-A383-49EE-A8C8-98B33E983188}C:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe" = protocol=6 | dir=in | app=c:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe | "TCP Query User{79C9CA31-C558-4289-965B-E9E1DE377B0A}D:\gry\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=d:\gry\counter-strike 1.6\hl.exe | "TCP Query User{841D996B-448D-43BB-AFD5-CF7D093F0B7B}C:\program files (x86)\postal 2 stp\system\postal2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\postal 2 stp\system\postal2.exe | "TCP Query User{8AB2E36E-D857-46FD-818C-B5AFD6A21849}C:\program files (x86)\new star gp\new star gp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\new star gp\new star gp.exe | "TCP Query User{9C028EFC-B3BA-484B-A1DF-8995D8C83263}C:\program files (x86)\Postal 2 STP\System\Postal2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\postal 2 stp\system\postal2.exe | "TCP Query User{A4E712AE-B6F4-44F1-A277-E3B29F000447}C:\program files (x86)\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | "TCP Query User{E8D8BB26-3305-429D-A28A-35805D8D626F}C:\program files (x86)\secondlifeviewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\secondlifeviewer\slvoice.exe | "UDP Query User{233119E0-2CD7-4432-8E0D-5B24A01F1D94}D:\gry\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=d:\gry\counter-strike 1.6\hl.exe | "UDP Query User{2614EA5C-3633-4D77-9F0F-8EDCF4B2468E}C:\windows\syswow64\dpnsvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dpnsvr.exe | "UDP Query User{864B84F5-779D-4BA3-9211-5F906EB53C28}C:\program files (x86)\secondlifeviewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\secondlifeviewer\slvoice.exe | "UDP Query User{8B22F0FF-EDBB-4F59-AD8A-63CB661E173A}C:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe" = protocol=17 | dir=in | app=c:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe | "UDP Query User{8C5E927F-CCC4-4D17-9A2C-313A73BDC436}C:\program files (x86)\Postal 2 STP\System\Postal2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\postal 2 stp\system\postal2.exe | "UDP Query User{8E1FB286-7A6F-40B0-B7CA-C33FD2BA3EEF}C:\program files (x86)\new star gp\new star gp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\new star gp\new star gp.exe | "UDP Query User{9097E4DE-5452-4878-A54D-7C2DE5096EE9}C:\program files (x86)\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | "UDP Query User{91AB015A-4E67-408A-8926-FBEF04B34FF7}D:\program files (x86)\iq publishing\trapped dead\bin\trappeddead.exe" = protocol=17 | dir=in | app=d:\program files (x86)\iq publishing\trapped dead\bin\trappeddead.exe | "UDP Query User{B1AE2108-D86A-4345-B71E-CDF770E3504F}C:\program files (x86)\taxi madness london\london.exe" = protocol=17 | dir=in | app=c:\program files (x86)\taxi madness london\london.exe | "UDP Query User{DA713C42-801E-4DE9-9246-5E70E6CD71B0}C:\program files (x86)\chickeninvadersrotydemo\ci3demo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\chickeninvadersrotydemo\ci3demo.exe | "UDP Query User{F2E0188F-76E7-4225-9E5E-7418A774CDE3}C:\program files (x86)\postal 2 stp\system\postal2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\postal 2 stp\system\postal2.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{45F1F774-38B4-3CC3-BAAF-051E6D19E48E}" = Microsoft .NET Framework 4.5.1 (PLK) "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski) "{975290F7-01EE-6256-484A-EDD705037432}" = ccc-utility64 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DD562794-C098-A1E5-66ED-10E8BD1C84C5}" = AMD Catalyst Install Manager "{E94CF53A-B97F-DBCF-17F4-60AEECFC1A62}" = AMD Fuel "{F15287C6-10E3-1676-AF50-CB0355A302F1}" = AMD Accelerated Video Transcoding "AdvanceElite" = AdvanceElite [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{05D9CF80-826D-475D-8901-EAF211DF1075}_is1" = Moja Egzotyczna Farma "{0C7B34CC-3C7F-97F6-B989-1259B93E304F}" = CCC Help Turkish "{164AB611-16CC-4C5E-8A99-A759F93FD8F9}_is1" = FacebookMessenger version 2.0 "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{1D437FD2-BEBA-294A-14B0-73DF88537625}" = CCC Help Danish "{2091F234-EB58-4B80-8C96-8EB78C808CF7}" = Facebook Video Calling "{225E3607-953C-EFCF-84C5-727EBE431CAB}" = CCC Help Greek "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.20 "{27075564-0881-4B9B-AF9F-D7AB1230BBA6}" = Kurka w Ogniu - Polowanie na Kurczaki "{2AC22CBC-1E34-4942-BC27-890E5DD3F8BC}}_is1" = New Star GP 1.25 DEMO "{3567AA55-A730-4EFB-D419-C198EF9C3B51}" = CCC Help English "{37476589-E48E-439E-A706-56189E2ED4C4}_is1" = WildWestCoupon "{3A562A41-1EFD-4E53-9ABE-6B35B331F72A}_is1" = Racing Show wersja 1.5 "{3DE8A1D7-C77F-E02A-70DD-31D29EC5B988}" = QueenCoUipon "{3EA29604-AB1F-00F7-AD0C-11FC133CE7C0}" = CCC Help Thai "{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX "{40DC4B27-4588-C56F-7737-D03A0ACE4383}" = RoyalCoupon "{443F2BDB-67B3-E0BF-0A8D-D1FC7A83FB1C}" = CCC Help Japanese "{449DC4DE-157B-4CE5-685D-8A0ACCDAEE9F}" = CCC Help Chinese Standard "{4A85401C-71E6-5487-F1C0-598C10E22D3B}" = CCC Help Spanish "{501E43C9-C95D-8E8D-8D12-AA5FEFBA09EC}" = CCC Help Swedish "{5DE67937-45D5-45E4-923C-0B7F7EC929A7}" = League of Legends "{6395030F-815F-0948-F166-73ECC57097E3}" = CCC Help Norwegian "{69C610F3-4DEC-44C5-D142-E69217E88448}" = CCC Help Russian "{6A4945F7-5B9C-6DDA-A08A-048816260309}" = CCC Help German "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7204BDEE-1A48-4D95-A964-44A9250B439E}" = Facebook Messenger 2.1.4814.0 "{777D5DD4-8BBC-EADA-B300-815B68F33D5F}" = CCC Help Finnish "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = Rollercoaster Tycoon 3 ZE "{9243354A-3075-C91E-6E12-403D932B38E5}" = Catalyst Control Center InstallProxy "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9CC7011E-94E8-48BA-8610-90666BFEF8BA}_is1" = Skyscraper Simulator wersja "{9D2DD563-E1DD-920B-6E64-C057D4F080EB}" = CCC Help Hungarian "{9D6D7292-8EA9-B5DD-9C10-D5B2937CFD84}" = CCC Help Italian "{A5B4707E-CFD3-A08F-ED69-C500D541EAEF}" = CCC Help Korean "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-0804-1033-1959-001802114130}" = Adobe Refresh Manager "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Polish "{B6700BBF-1153-FA04-FD0A-ADEF36C564E3}" = CCC Help Dutch "{B8E7A402-AB25-F1EC-C21A-7E95F2BBDDB0}" = CCC Help Czech "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3 "{D6116D91-A114-671F-D075-73B4154F7390}" = AMD VISION Engine Control Center "{D87A50FE-11B3-3B70-77EB-E64570E82F9E}" = CCC Help French "{DA0106A3-216E-48DE-9CF6-655DA8FC1D22}" = OpenOffice 4.0.1 "{DF549E6D-193A-0EA3-7C90-F24B631CC2EB}" = CCC Help Portuguese "{DF7ADC65-EBCE-97DA-4C8A-4F0BCF7C0E73}" = CCC Help Polish "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{F0F34B75-C634-8714-D226-9259FC1A7E92}" = Catalyst Control Center Localization All "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FC53A2BD-6B34-C6FB-C3F4-9D8DC7ED5C92}" = CCC Help Chinese Traditional "{FE139F4C-CE5B-121A-8A2D-191FA2226094}" = topBuoyeR "Active WebCam" = Active WebCam "Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin "Avast" = avast! Free Antivirus "Battlefield 3 Repack" = Battlefield 3 Repack "Chicken Invaders: Revenge of the Yolk demo_is1" = Chicken Invaders: Revenge of the Yolk demo v3.79 "Chicken Invaders_is1" = Chicken Invaders v1.30 "Counter-Strike 1.6" = Counter-Strike 1.6 v48 "Counter-Strike Global Offensive_is1" = Counter-Strike Global Offensive [No-Steam] "Crossfire Europe" = Crossfire Europe "DAEMON Tools Lite" = DAEMON Tools Lite "DIVXCodec" = nAVI Vx3 MPEG-4 Codec "Gimnazjum część 1 – To jest fizyka" = Gimnazjum część 1 – To jest fizyka "Google Chrome" = Google Chrome "Icy Tower v1.3.1_is1" = Icy Tower v1.3.1 "Icy Tower v1.5_is1" = Icy Tower v1.5 "istartsurf uninstall" = istartsurf uninstall "iWebar" = iWebar "John Deere: Symulator Farmy_is1" = John Deere: Symulator Farmy "League of Legends 3.0.1" = League of Legends "ManyCam" = ManyCam 4.0.109 "ManyDownloader" = ManyDownloader "Megarace3" = Megarace3 "Mozilla Firefox 34.0.5 (x86 pl)" = Mozilla Firefox 34.0.5 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "New Super Mario Forever PC" = New Super Mario Forever PC "Object Browser" = Object Browser "Opera 25.0.1614.68" = Opera Stable 25.0.1614.68 "Origin" = Origin "Postal 2 - Share the Pain" = Postal 2 - Share the Pain "Razem w szkole klasa 3" = Razem w szkole klasa 3 "School Tycoon_is1" = School Tycoon "SearchProtect" = Search Protect "SecondLifeViewer" = SecondLifeViewer (remove only) "Sense" = Sense "setup" = setup (Remove only) "ShopperPro" = Shopper-Pro "Singles2" = Singles2 "SiteFinder" = SiteFinder "SocialSafe 6.6.8" = SocialSafe "SopCast" = SopCast 3.9.2 "Steam App 9480" = Saints Row 2 "sweet-page uninstall" = sweet-page uninstall "Szkoła podstawowa klasa 4 - Tajemnice przyrody" = Szkoła podstawowa klasa 4 - Tajemnice przyrody "TAXI MADNESS LONDON" = TAXI MADNESS LONDON "TeamViewer 9" = TeamViewer 9 "The Forest_is1" = The Forest "The KMPlayer" = The KMPlayer (remove only) "The Walking Dead Season 2 Episode 1_is1" = The Walking Dead Season 2 Episode 1 "Tibia Preview_is1" = Tibia Preview "Tibia Testserver_is1" = Tibia Testserver "Tibia_is1" = Tibia "Twoja Kamera" = Twoja Kamera "VOPackage" = Remote Desktop Access (VuuPC) "Winamp" = Winamp (remove only) "WindowsMangerProtect" = WindowsMangerProtect20.0.0.722 "WinRAR archiver" = Archiwizator WinRAR "WinZipper" = WinZipper "YTDownloader" = YTDownloader [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1067321925-3578864132-775108078-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Biegnąca Owca" = Biegnąca Owca "GG" = GG "HappyCloud" = Happy Cloud Client "Historia Mikrobów" = Historia Mikrobów "LOTROen" = The Lord of the Rings Online "OneDriveSetup.exe" = Microsoft OneDrive "OpenFM" = OpenFM "Świat Puzzli" = Świat Puzzli "UnityWebPlayer" = Unity Web Player "uTorrent" = µTorrent "WorldofTanks" = WorldofTanks [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-11-19 10:31:16 | Computer Name = x-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-19 11:46:31 | Computer Name = x-Komputer | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja:, sygnatura czasowa: 0x545c0a59 Nazwa modułu powodującego błąd: mozalloc.dll, wersja:, sygnatura czasowa: 0x545be5ee Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x00001425 Identyfikator procesu powodującego błąd: 0x558 Godzina uruchomienia aplikacji powodującej błąd: 0x01d0040ef22a074c Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll Identyfikator raportu: 3b3c6838-7003-11e4-8c3c-d43d7e352e65 Error - 2014-11-19 11:58:37 | Computer Name = x-Komputer | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja:, sygnatura czasowa: 0x545c0a59 Nazwa modułu powodującego błąd: mozalloc.dll, wersja:, sygnatura czasowa: 0x545be5ee Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x00001425 Identyfikator procesu powodującego błąd: 0x16b8 Godzina uruchomienia aplikacji powodującej błąd: 0x01d0041013ec80d2 Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll Identyfikator raportu: eb87c8a9-7004-11e4-8c3c-d43d7e352e65 Error - 2014-11-19 12:34:44 | Computer Name = x-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-19 12:47:20 | Computer Name = x-Komputer | Source = Application Hang | ID = 1002 Description = Program firefox.exe w wersji zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 16a8 Godzina rozpoczęcia: 01d00416c4010fbc Godzina zakończenia: 0 Ścieżka aplikacji: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Identyfikator raportu: Error - 2014-11-19 13:01:43 | Computer Name = x-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-19 14:00:52 | Computer Name = x-Komputer | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja:, sygnatura czasowa: 0x545c0a59 Nazwa modułu powodującego błąd: mozalloc.dll, wersja:, sygnatura czasowa: 0x545be5ee Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x00001425 Identyfikator procesu powodującego błąd: 0x1710 Godzina uruchomienia aplikacji powodującej błąd: 0x01d0041ae714edc1 Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll Identyfikator raportu: fff1a766-7015-11e4-ac33-d43d7e352e65 Error - 2014-11-19 14:07:15 | Computer Name = x-Komputer | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja:, sygnatura czasowa: 0x545c0a59 Nazwa modułu powodującego błąd: mozalloc.dll, wersja:, sygnatura czasowa: 0x545be5ee Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x00001425 Identyfikator procesu powodującego błąd: 0x14a4 Godzina uruchomienia aplikacji powodującej błąd: 0x01d00422d96ffb3c Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll Identyfikator raportu: e3e2dd4b-7016-11e4-ac33-d43d7e352e65 Error - 2014-11-19 14:33:30 | Computer Name = x-Komputer | Source = Application Hang | ID = 1002 Description = Program firefox.exe w wersji zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 1434 Godzina rozpoczęcia: 01d00423a76e76c3 Godzina zakończenia: 72 Ścieżka aplikacji: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Identyfikator raportu: 8d0ccdb8-701a-11e4-ac33-d43d7e352e65 Error - 2014-11-19 14:33:30 | Computer Name = x-Komputer | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: plugin-container.exe, wersja:, sygnatura czasowa: 0x545c0a59 Nazwa modułu powodującego błąd: mozalloc.dll, wersja:, sygnatura czasowa: 0x545be5ee Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x00001425 Identyfikator procesu powodującego błąd: 0x11cc Godzina uruchomienia aplikacji powodującej błąd: 0x01d00423b16232ca Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Ścieżka modułu powodującego błąd: C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll Identyfikator raportu: 8ecfba01-701a-11e4-ac33-d43d7e352e65 [ System Events ] Error - 2014-12-25 10:43:59 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = Error - 2014-12-25 10:51:18 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = Error - 2014-12-25 10:52:30 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = Error - 2014-12-25 11:01:34 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = Error - 2014-12-25 11:03:45 | Computer Name = x-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 16:02:36 na ?2014-?12-?25 było nieoczekiwane. Error - 2014-12-25 11:08:32 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = Error - 2014-12-25 11:08:39 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = Error - 2014-12-25 11:09:43 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = Error - 2014-12-25 11:11:31 | Computer Name = x-Komputer | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. Error - 2014-12-25 11:23:12 | Computer Name = x-Komputer | Source = DCOM | ID = 10016 Description = < End of report >