OTL Extras logfile created on: 2012-09-10 21:45:17 - Run 1 OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\xxx\Desktop\Pulpit Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16982) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,87 Gb Total Physical Memory | 0,97 Gb Available Physical Memory | 51,88% Memory free 3,96 Gb Paging File | 2,69 Gb Available in Paging File | 67,91% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 68,36 Gb Total Space | 16,30 Gb Free Space | 23,84% Space Free | Partition Type: NTFS Drive D: | 200,39 Gb Total Space | 200,03 Gb Free Space | 99,82% Space Free | Partition Type: NTFS Drive E: | 29,33 Gb Total Space | 28,66 Gb Free Space | 97,72% Space Free | Partition Type: NTFS Drive F: | 177,82 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: XXX-PC | User Name: xxx | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\S-1-5-21-4069265516-2848520116-2794156362-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-4069265516-2848520116-2794156362-1000] "EnableNotifications" = 0 "EnableNotificationsRef" = 1 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02F0750C-87C6-4A74-96CE-D4C71F23AC21}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{03228102-0891-41AD-B53C-DCD2B83458D9}" = lport=80 | protocol=6 | dir=in | app=system | "{0395302A-3FEB-404C-816C-2FCE5E043789}" = lport=rpc | protocol=6 | dir=in | svc=eventlog | app=c:\windows\system32\svchost.exe | "{0460A099-6E5B-4E9A-835B-D98792F1C445}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{05F293F4-083C-448E-B225-1DDC28928EB4}" = lport=445 | protocol=6 | dir=in | app=system | "{06343726-DED9-4E00-B28A-FD56085A8362}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{0EAE27F2-1F1A-488D-94E6-B648A036C7E3}" = rport=445 | protocol=6 | dir=out | app=system | "{12E3AF89-8841-44CE-96C3-CBD09E6CD3C5}" = lport=138 | protocol=17 | dir=in | app=system | "{14421394-64CD-49EB-A037-C955277823D7}" = lport=445 | protocol=6 | dir=in | app=system | "{146FC9BD-9179-4AA6-B2A6-68290B0A1C09}" = rport=138 | protocol=17 | dir=out | app=system | "{1835281F-9862-43D8-B24A-7ED4230E3995}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe | "{1C935526-1C34-4905-B8C4-6FA6ECE9F53B}" = lport=rpc | protocol=6 | dir=in | svc=ktmrm | app=c:\windows\system32\svchost.exe | "{1CC95765-CD63-43A0-AB93-AA565B22CD95}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{2787A6A4-0758-4C5A-9A7E-30F50FFE7ECF}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe | "{2A470B75-BF6A-4C63-BCF3-7F81EF08D3DA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{2E48F75D-160F-4AE7-B3A7-6D32143FF057}" = lport=162 | protocol=17 | dir=in | svc=snmptrap | app=c:\windows\system32\snmptrap.exe | "{362BF2D8-7F59-4D8A-AE89-873F49AF6683}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe | "{37B1FB2E-F653-403C-9F1D-CBAB69DCA995}" = rport=137 | protocol=17 | dir=out | app=system | "{392ECB45-9097-4160-B0F2-0C7F32CDAE80}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=udostępnianie plików i drukarek (usługa buforu — rpc-epmap) | "{3F508349-7D11-44C0-8978-F8E914587585}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\vdsldr.exe | "{4413A0E5-2699-44FE-B620-B5062F4D3F6C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{4573A6AE-2914-40AE-AACD-2A53DFE6EC17}" = lport=1701 | protocol=17 | dir=in | app=system | "{47CA5283-B38C-4AC6-990B-65A7E4B432B5}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe | "{47DF2F68-9078-4065-90B5-E9BEBEC5E7D5}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{48C1C3D9-D52D-4246-8673-1BEF3DC25607}" = rport=10244 | protocol=6 | dir=out | app=system | "{4C3C0CB5-7DCB-4D54-A750-93C6AA2CB0B7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{52E65B5B-B019-4298-A0A8-790ABF5F4697}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=c:\windows\system32\dfsr.exe | "{53ACE017-120E-4E4E-ACCD-FF34F62BAA24}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{55631434-F1EA-499F-A196-086A8452E12F}" = lport=5357 | protocol=6 | dir=in | app=system | "{55CB70D1-BB77-419A-873D-889695C2D2A9}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe | "{59770D6A-D04B-4397-9787-4D6AF0017E28}" = lport=2178 | protocol=6 | dir=in | app=system | "{5AB8A8BD-6F58-48B4-8E56-D0A121D7BC50}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{5F2A25DE-21B4-4227-A74D-81CBED7BA1E2}" = lport=3702 | protocol=17 | dir=in | svc=bits | app=c:\windows\system32\svchost.exe | "{600F61A0-203E-4490-92DE-E9F9AC924E20}" = lport=10243 | protocol=6 | dir=in | app=system | "{6241362A-0051-4245-82AF-2753796B21F0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{65079EC2-D8A8-4A1D-B74D-8D9F91F3EA1C}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{6A5A5359-AB53-4EB4-8E81-B536AC46CDF8}" = rport=5358 | protocol=6 | dir=out | app=system | "{6CBD044B-986E-43E2-A1DC-E8FD17203F8F}" = rport=2178 | protocol=6 | dir=out | app=system | "{6F0CCEFB-BCE4-4D6B-85DF-18378A76B582}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{6F601661-D08B-4AE3-987A-36866829A4AC}" = lport=445 | protocol=6 | dir=in | app=system | "{73735706-36A1-431D-8CD7-5061D159AD2C}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe | "{79C83DA0-74F7-4D01-9AA0-38A6506C4A64}" = rport=10243 | protocol=6 | dir=out | app=system | "{7D4925C1-C364-439B-8548-B38EE38330E4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{7ED2C24E-A543-408D-A266-76EF772F3FE0}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe | "{8923D738-4BCA-4D8F-BDE7-30DDCCB8AFC7}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\netproj.exe | "{8DCF3C01-BF2C-4660-A1B6-014D17ED4933}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe | "{90470157-4F6D-4EAB-A1A2-AB25BB0ED1DC}" = lport=2869 | protocol=6 | dir=in | app=system | "{9091FEB6-16CA-4359-BDAC-D73D5A7CF541}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{91655E77-0223-4604-9929-50549F3C1237}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{934B80BF-E9B5-4D15-BABD-9ACD301B3E70}" = lport=2869 | protocol=6 | dir=in | app=system | "{98E5BBC8-CDE6-46A0-AA35-9D1BC403BE71}" = lport=rpc | protocol=6 | dir=in | svc=bits | app=c:\windows\system32\svchost.exe | "{A112EEA8-5DF6-49EE-8771-25AB4CDF0AA2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{A4E9EBE8-423D-4C5A-85CC-50CEC29E4C47}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{AC1668D4-78F4-46E5-BF5B-C606A9CF66EE}" = lport=445 | protocol=6 | dir=in | app=system | "{B030914B-11B4-40C8-AD75-FC40F5345AC8}" = lport=137 | protocol=17 | dir=in | app=system | "{B0C3C49A-43B6-4DD2-A852-5C2490E85966}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{B198AEB6-40BD-4BF0-9BD3-C323C383F6C4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{B2F665D2-36AF-4685-8FF4-4A2B19AA8433}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=c:\windows\system32\svchost.exe | "{BD6EF79D-CE8A-467D-B939-ECC5D7B12734}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{BECBF8DF-E7F4-4B51-B290-A27070509D79}" = lport=rpc | protocol=6 | dir=in | svc=* | app=c:\windows\system32\svchost.exe | "{C06D1DE5-F4CF-45B3-84CB-3392172D8696}" = lport=3390 | protocol=6 | dir=in | app=system | "{C4944557-EA37-4B3E-87F8-4CB4B3C91F3A}" = lport=10244 | protocol=6 | dir=in | app=system | "{C4DF31B8-39F3-4152-BD39-C9EDCF82C9B1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{C585CC7A-1B9E-417E-85DC-703906BE191E}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\netproj.exe | "{C731B19F-A8C7-4EED-BB3D-EB57E73E4E1A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{C7802431-D384-4A08-8C49-0209B926FD8A}" = lport=139 | protocol=6 | dir=in | app=system | "{CAA47C5E-B9A1-4074-866E-CB239F5F55FE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{CD7F8891-75BE-4B67-BEC5-A3C83082FBEE}" = rport=5357 | protocol=6 | dir=out | app=system | "{CE05DCD8-50CA-46AA-AB19-CDE70B100DF1}" = lport=rpc | protocol=6 | dir=in | svc=vds | app=c:\windows\system32\vds.exe | "{D1E37596-57AF-4137-AB3C-2789DF3D7FE1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{D203F8E1-5563-43C0-B227-D525D04D7129}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{D51F358C-36A2-42EB-BAC3-11A2E2F83523}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{D7F9C237-1467-4E45-B6E9-96A13A4D9E5A}" = rport=139 | protocol=6 | dir=out | app=system | "{DCCE38BD-FE9F-4A39-BA3B-1B0634DC7A86}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=c:\windows\system32\svchost.exe | "{DFE67335-303D-44CA-ACBA-6984216A6C02}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe | "{E42C0785-DA2B-49CC-ABD8-18CC2BEE7965}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\services.exe | "{EC5BBFAF-BD5F-4DD3-AD5F-08AE26D13D2B}" = lport=rpc | protocol=6 | dir=in | svc=schedule | app=c:\windows\system32\svchost.exe | "{EE2D5093-583D-443D-9047-139BBADCC38D}" = lport=5358 | protocol=6 | dir=in | app=system | "{EE32DA2D-2428-45AC-BE41-73A2F6AEBEAE}" = lport=1723 | protocol=6 | dir=in | app=system | "{EF99B091-7282-45B3-9592-A8FC6EA76154}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe | "{F06B7B53-E9BE-4851-B2B3-EF2739354F53}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=c:\windows\system32\dfsr.exe | "{F274C83F-F469-48C0-A85B-D13FCB585041}" = rport=3702 | protocol=17 | dir=out | svc=bits | app=c:\windows\system32\svchost.exe | "{F7EE3FA1-CB9E-47AE-B153-5A49DEA549B0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{F981DD5B-2F27-47E8-9F78-1B4EEF084DC6}" = rport=1701 | protocol=17 | dir=out | app=system | "{FE705354-DDB4-4098-AE8A-622A9A48DBC9}" = rport=1723 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{003BAB5E-19A4-4BAA-90D9-6150FACC63D5}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | "{0DAB53DB-D83E-4C84-A951-B2FBA72E0463}" = protocol=6 | dir=in | app=c:\windows\system32\plasrv.exe | "{16F0AC9B-8A8B-4214-BD5E-65176C2ED7A8}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe | "{1F8A5793-AE29-4A88-9510-AC0C27F69E31}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe | "{33CB4D5C-F585-4A5C-8D2E-6A8F51384576}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | "{37C4A1D2-508E-47C7-B0DC-3194FF069E62}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{3831F8E2-FE5D-402E-95D3-33DD95B31E37}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | "{46D1A7FD-9226-477F-91C0-4811630CBA36}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{4732E752-BE65-41D0-A1BA-32FE68179458}" = dir=in | app=c:\program files\htc\htc sync manager\htc sync\htcsyncloader.exe | "{4CC22B57-84D6-4AE9-8036-158226DC861A}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe | "{5A4B3080-FFEC-45E6-88E9-86438CFD287C}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{5D31BE3E-EE51-4275-805A-9AB95695AEF5}" = protocol=6 | dir=in | app=c:\program files\windows collaboration\wincollab.exe | "{5D430C05-C254-4B6D-A7D3-F6529437F762}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe | "{5D7CE47A-53F0-4DEA-90FA-68B7B3A1E74C}" = protocol=1 | dir=out | name=udostępnianie plików i drukarek (żądanie echa — ruch wychodzący icmpv4) | "{5E1D9189-A06D-4DA3-A759-3DA623950F43}" = protocol=58 | dir=in | name=udostępnianie plików i drukarek (żądanie echa — ruch przychodzący icmpv6) | "{6577FF71-726C-4D67-B83F-DD5EF9E8838D}" = protocol=58 | dir=out | name=udostępnianie plików i drukarek (żądanie echa — ruch wychodzący icmpv6) | "{659D2E82-6839-4A25-82FA-693DDA1FB628}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{666CC0B8-A8CF-42A3-822A-006799A910D9}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe | "{75ED43E1-74A6-40C2-9CF0-0307F6666B38}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{7817E079-5FC0-47C9-9AF6-CAFC17C92C36}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | "{7B7CDDF4-CA2A-4C7A-B232-DD6F942EFB26}" = protocol=6 | dir=out | app=system | "{80914923-C928-4FE9-B400-A24DAB1CE6AF}" = protocol=6 | dir=out | app=c:\windows\system32\msdtc.exe | "{861D4F49-6F70-4D27-8DE4-2376E800152A}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe | "{8CC71CB1-F6B9-4CCB-AD29-94607B442F07}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{8D7730B3-9A1B-44E2-B086-305A54E453F1}" = protocol=17 | dir=in | app=c:\program files\windows collaboration\wincollab.exe | "{8E23F93E-3E2D-4507-9ED6-D07A8B1F09A0}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe | "{92E2313B-2AA1-4884-9214-6C2BFF2ADE31}" = protocol=6 | dir=out | app=system | "{977F72CB-3839-4429-892C-ADC57A70BB1F}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe | "{9830DB1E-2391-40AF-B40A-72CB722B8748}" = protocol=6 | dir=out | app=c:\windows\system32\netproj.exe | "{B196689D-57F0-4059-A06B-23F20BAE4D3A}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe | "{B8815D88-75F4-48D3-84B8-359744E525A1}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{BCE1A6BA-E718-4E2A-9DAC-95332FEC1423}" = protocol=1 | dir=in | name=udostępnianie plików i drukarek (żądanie echa — ruch przychodzący icmpv4) | "{C2A27B75-1635-43B4-ACA4-E06ABE08F219}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{C34B9BB6-4C99-451B-BFD2-4CF9D3D610AC}" = protocol=17 | dir=out | app=c:\program files\windows collaboration\wincollab.exe | "{CB79742C-1B2E-47BC-8D76-E7E4CA31D918}" = protocol=6 | dir=out | svc=msiscsi | app=c:\windows\system32\svchost.exe | "{D45C9BF4-9B03-4A3C-A541-F3EAE0C23813}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{D88B5F25-DFE1-403C-A291-E65FD6754B63}" = protocol=6 | dir=in | app=c:\windows\system32\msdtc.exe | "{DB01E9D5-09AF-4261-9228-2F999DFAD2E1}" = protocol=6 | dir=out | app=c:\program files\windows collaboration\wincollab.exe | "{DCD38698-AEA5-4553-B85E-4A0EE2D223C9}" = protocol=6 | dir=in | svc=msiscsi | app=c:\windows\system32\svchost.exe | "{E60398F5-944B-4284-BFFE-5DAC775376A9}" = protocol=6 | dir=in | app=c:\windows\system32\netproj.exe | "{E769F82F-162A-48A8-8D60-86B4898779B7}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{EF4C7710-BCA8-4744-BC0E-FFBA98C957E6}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07FD2F53-6822-7CE3-6811-3AD8E697A5AB}" = ccc-utility "{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.8 "{0C38A07F-1DDF-E2B2-3A74-9F8D08D2A4B3}" = CCC Help Dutch "{0C4B62E3-BEEB-A320-1ECC-C8EA53F9739C}" = CCC Help Thai "{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox "{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update "{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBB0249-BCFE-5D05-0E0D-B57AF25F9557}" = Catalyst Control Center Localization All "{1FD53608-9508-1679-48D2-717A2AFB3B0B}" = Skins "{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5 "{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE "{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant "{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba "{37E8B4FD-785B-8EBC-7A32-6B5E703F5838}" = CCC Help English "{3840944B-55B4-C8F6-451D-35F2E77F2649}" = Catalyst Control Center Graphics Full Existing "{3AEFE39F-E123-0C17-DE54-0EC559FEA1AA}" = CCC Help Czech "{3C7A7831-FE65-1026-F9EA-BF39F7BC3375}" = CCC Help Korean "{40AF6D9C-557C-22E0-FDDF-F4D2D5D9B896}" = CCC Help Finnish "{41CE67B3-7766-4CC0-9E5A-D28DF12072E7}" = HTC Sync Manager "{47C67E25-8475-115C-2231-C56E927E6B45}" = CCC Help Swedish "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B6D5F50-47FE-2FE3-661F-33756CCB0D48}" = CCC Help Polish "{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC "{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery "{58AD6029-C294-08CF-85EC-7F4D26420917}" = CCC Help Spanish "{5A4E0548-F962-292C-5C46-9EF3CC1C380C}" = Catalyst Control Center InstallProxy "{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm "{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{77C3933F-A477-081C-FB44-6EF9792434DD}" = Catalyst Control Center Graphics Light "{7988ba74-4a27-4685-991a-53f072f22808}" = F2200_Help "{8000251D-3F26-B842-14F2-CD28B1094E99}" = Catalyst Control Center Graphics Full New "{812F9789-A7FA-604D-FCC8-DA7D92EE1032}" = CCC Help German "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{85304D84-FC34-7A24-5B6A-D216B77F6225}" = CCC Help Greek "{89B552EA-1C1E-6C04-1CCF-2CC8E9FB1C05}" = CCC Help Turkish "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport "{8BE463F5-310B-C042-F56C-3C98690B9844}" = ATI Catalyst Install Manager "{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status "{A11409F1-CD33-4076-85CB-4EE4A8439BFE}" = Scan "{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter "{A6CBFF09-BFBF-7243-EABF-596088645914}" = CCC Help Portuguese "{A847F5DA-9B94-0EEA-D554-6A1A1570C5D3}" = CCC Help Danish "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{ABB5261D-9039-4211-8410-9DE4A215B186}" = O2Micro Flash Memory Card Reader Driver (x86) "{AC0081B6-1624-1B4F-7D51-4DAE59FA8D03}" = CCC Help Chinese Traditional "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4) "{AD04BDEA-DCCD-15AA-F70C-44F23D0020D4}" = CCC Help Italian "{AF0068AB-786D-FB3D-4055-FAD4DBAACA8C}" = CCC Help Japanese "{B4D81323-E455-1933-6401-299B7E13E5CD}" = CCC Help Norwegian "{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply "{B9C66B24-1FA8-EFF5-EBE2-701B1F0441B4}" = ccc-core-static "{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5 "{C0544715-692E-02F6-C8E3-5C15CC06C110}" = Catalyst Control Center Core Implementation "{c6922d7f-c698-4d9e-9671-8b3de04d1511}" = DJ_AIO_03_F2200_Software_Min "{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver "{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D1CF9BAD-2DA6-A309-DA60-5864E92DC9E3}" = CCC Help Hungarian "{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch "{D3BBF36F-E1E5-A34A-D9AA-2677D4C124DD}" = Catalyst Control Center Graphics Previews Vista "{D77D43B5-ED55-426b-B67B-E21F804F6102}" = HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3 "{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component "{db18dc72-cd20-4801-be82-f5d2caeec4d7}" = DJ_AIO_03_F2200_Software "{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01 "{E3D63B95-4B21-414A-A2C7-D6D6A6AC6D79}" = Catalyst Control Center - Branding "{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}" = F2200 "{eca3039b-e429-420f-bd5e-7dec0683fc32}" = DJ_AIO_03_F2200_ProductContext "{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS "{F0DF8FE9-6BF0-2E76-697F-0D6CEDF0E58D}" = CCC Help French "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F2BA788A-D028-36D8-116B-FAB835CD2E56}" = CCC Help Chinese Standard "{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy "{FA79A820-F535-D2E8-EF2E-8CB3F2361D41}" = CCC Help Russian "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "avast" = avast! Free Antivirus "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5051&SUBSYS_1179" = HDAUDIO Soft Data Fax Modem with SmartCP "HP Imaging Device Functions" = HP Imaging Device Functions 10.0 "HP Photosmart Essential" = HP Photosmart Essential 2.5 "HP Smart Web Printing" = HP Smart Web Printing "HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0 "HPExtendedCapabilities" = HP Customer Participation Program 10.0 "KLiteCodecPack_is1" = K-Lite Codec Pack 9.0.2 (Full) "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.62.0.1300 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox 15.0 (x86 pl)" = Mozilla Firefox 15.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Notepad++" = Notepad++ "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver "uTorrent" = µTorrent "Winamp" = Winamp "WinRAR archiver" = WinRAR 4.20 (32-bitowy) [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-4069265516-2848520116-2794156362-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Mozilla Firefox 15.0.1 (x86 pl)" = Mozilla Firefox 15.0.1 (x86 pl) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-08-24 03:05:03 | Computer Name = xxx-PC | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Program Files\AVAST Software\Avast\AvastUI.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-08-24 03:05:03 | Computer Name = xxx-PC | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Program Files\AVAST Software\Avast\AvastUI.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-08-24 03:12:26 | Computer Name = xxx-PC | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Program Files\AVAST Software\Avast\AvastUI.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-08-24 03:12:26 | Computer Name = xxx-PC | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Program Files\AVAST Software\Avast\AvastUI.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-08-24 06:14:23 | Computer Name = xxx-PC | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "C:\Program Files\AVAST Software\Avast\AvastUI.exe". Nie można odnaleźć zestawu zależnego Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-08-28 13:36:36 | Computer Name = xxx-PC | Source = System Restore | ID = 8193 Description = Error - 2012-09-04 10:07:42 | Computer Name = xxx-PC | Source = VSS | ID = 8194 Description = Error - 2012-09-07 14:47:38 | Computer Name = xxx-PC | Source = VSS | ID = 8194 Description = Error - 2012-09-07 14:54:37 | Computer Name = xxx-PC | Source = MsiInstaller | ID = 11904 Description = Error - 2012-09-08 03:10:59 | Computer Name = xxx-PC | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd HpqSRmon.exe, wersja 10.0.0.202, sygnatura czasowa 0x46c64b4e, moduł powodujący błąd HpqSRmon.exe, wersja 10.0.0.202, sygnatura czasowa 0x46c64b4e, kod wyjątku 0xc0000005, przesunięcie błędu 0x000032db, identyfikator procesu 0x47c, godzina rozpoczęcia aplikacji 0x01cd8d91028e762d. [ System Events ] Error - 2012-08-25 04:05:36 | Computer Name = xxx-PC | Source = DCOM | ID = 10010 Description = Error - 2012-08-25 04:08:08 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 6, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. Error - 2012-08-25 04:08:09 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 4, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. Error - 2012-08-25 04:08:09 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 5, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. Error - 2012-08-25 04:08:09 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 7, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. Error - 2012-08-25 04:08:29 | Computer Name = xxx-PC | Source = Microsoft-Windows-Kernel-WHEA | ID = 10 Description = Error - 2012-08-25 11:31:09 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 6, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. Error - 2012-08-25 11:31:10 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 4, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. Error - 2012-08-25 11:31:10 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 5, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. Error - 2012-08-25 11:31:10 | Computer Name = xxx-PC | Source = ACPI | ID = 327686 Description = IRQARB: System ACPI BIOS nie zawiera przerwania dla urządzenia w gnieździe PCI 7, funkcja 0. Skontaktuj się z dostawcą systemu w celu uzyskania pomocy technicznej. < End of report >