OTL Extras logfile created on: 12/4/2012 11:47:20 PM - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Michał\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2.93 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 47.07% Memory free 5.86 Gb Paging File | 3.92 Gb Available in Paging File | 66.98% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 284.99 Gb Total Space | 236.30 Gb Free Space | 82.92% Space Free | Partition Type: NTFS Computer Name: LUDWIK | User Name: Michał | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_USERS\S-1-5-21-3542797096-4280232732-1929941010-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with FastStone] -- "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with FastStone] -- "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03538A09-5077-414E-9BA3-DF0404CE2514}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{0F48C12F-CCF8-4E52-9516-AFF7902775D3}" = lport=2869 | protocol=6 | dir=in | app=system | "{11991927-3110-413B-B43E-287231287E21}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{156D0122-2A65-49E6-8676-2B8F9170C779}" = rport=2869 | protocol=6 | dir=out | app=system | "{222AA0D0-F4D3-4234-BC2B-7F9C5252B357}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{22D78FDA-E0DA-476C-8976-FEDF279B8FE4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{22E94743-2557-4F0E-9790-3DB6D665F8EE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{233B7F88-4C45-4FF3-BF41-D429231097F4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{27F1CC34-657F-4BEF-B9DE-52E1A48CD4F1}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{2AD05227-62C4-4050-96DD-EC9789D7A9D6}" = lport=10243 | protocol=6 | dir=in | app=system | "{304222E0-0532-4DC6-8960-CDC596C55218}" = rport=137 | protocol=17 | dir=out | app=system | "{39E30805-9EC1-4E08-9AE4-AEF65BD0B2E4}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{3DF9774B-BE68-40DD-B1E9-D31071FE321B}" = lport=138 | protocol=17 | dir=in | app=system | "{419383F4-7D34-4C94-B633-3FC428177D0A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{457349A1-4A25-414B-A64A-107627FC3EA6}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{497DC692-BEBF-4405-A45B-3D09C9F64F6D}" = rport=139 | protocol=6 | dir=out | app=system | "{4FEFCAE5-8C8D-4706-9CC1-6B0D19E11B98}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{511AE810-AD2D-433D-AEF8-AA15BAF9C5C2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{5370F2A1-D0DE-4520-86F7-350FE53577D9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5A362718-A72C-405A-ACD0-B06C93345B60}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5B25EE6C-ACDC-460B-BB56-5BF39FE05B15}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{60A313F6-56D3-4435-BB90-5251E17B52B3}" = lport=137 | protocol=17 | dir=in | app=system | "{61247E20-CCCD-48FC-972F-514C9752360A}" = lport=445 | protocol=6 | dir=in | app=system | "{62FD40E1-40B1-4754-ADBA-01ABDDD43AF5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{67733B4B-9EA7-42AC-B6A1-CF6E27135FFE}" = rport=445 | protocol=6 | dir=out | app=system | "{74EF07D6-2098-4754-A8BA-7965B3709EDD}" = lport=2869 | protocol=6 | dir=in | app=system | "{77CA083E-CF1E-4F8D-AEF8-03DA31226676}" = rport=10243 | protocol=6 | dir=out | app=system | "{79F86DED-D46D-45C6-BBA9-2F55C351F793}" = lport=139 | protocol=6 | dir=in | app=system | "{7A19FBB7-5A97-491B-8C35-D0DD0C578D85}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{874F69EB-C1D7-445B-AD18-E38E4E5FC803}" = rport=137 | protocol=17 | dir=out | app=system | "{8FDC32A5-4590-4846-9866-D590265AEADC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{93E8B7D3-2F58-4351-9953-29F5B6FFCF40}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{9440FCEA-D7BD-425A-B5B8-5DA6FD947F85}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{957CC6B2-7827-4427-BEA6-A01C8F479751}" = lport=2869 | protocol=6 | dir=in | app=system | "{97981B5D-8638-4202-AE78-233B578D62C8}" = lport=139 | protocol=6 | dir=in | app=system | "{9C4721AD-B942-4816-AB48-C53BFBE1B7FD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{AF352D15-B2A5-4355-81E5-D4983ED77415}" = lport=445 | protocol=6 | dir=in | app=system | "{B3E32B55-E021-4BAB-9DBB-A0030359DA1C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{B5B49E52-3DE3-4A85-BC4F-CD41D7687006}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B5C59631-2DA5-45B1-98C1-0E3471A83A48}" = rport=138 | protocol=17 | dir=out | app=system | "{BD87C513-7F73-4169-AC56-04C1D72981E0}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{BEBC3048-5021-4FC0-BF87-9EABF2CB889D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BFBAC62D-C6BA-45F6-8FD0-710911A36B6E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C2167DBE-E56E-4222-B958-656CAFC6E3F8}" = lport=138 | protocol=17 | dir=in | app=system | "{CA3C69E6-DD0E-41D1-ABE1-ED028107DE03}" = lport=137 | protocol=17 | dir=in | app=system | "{D97DE1CB-7FFD-473E-A04E-E8153ADE4AAA}" = rport=138 | protocol=17 | dir=out | app=system | "{DA353409-2D2D-4F9A-B5B4-8A0A46FF18AF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DD8E7075-17D0-40DD-A343-9E75F58BC718}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{DED5591D-C34E-4747-B14E-10E46A8BC7E4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{DF7D0CD7-8EF3-4D1E-9854-4DE9E544E238}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E7792FC6-E6E0-41F5-8278-C81C00A3ECBB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E9FA8412-F766-472F-AE91-5B419AEB02BD}" = rport=445 | protocol=6 | dir=out | app=system | "{FEE2AEA3-CE89-4E31-878E-B9C60F52D505}" = rport=139 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0003E70A-8621-4E12-B24E-1ABDB717BA26}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{072381FD-5E0C-4E0A-B88F-C42E054155B3}" = protocol=17 | dir=in | app=c:\program files (x86)\atube\dtuser.exe | "{080FA823-9324-4DF7-8F57-C56CC51DD894}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{0AF1061D-0188-4BB6-B2D8-61DE0F5CC237}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{10157823-8E5B-4980-8EA9-4411E8781719}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{10DA4819-3F29-42A5-AC7A-2AB21668EA46}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{1916258E-5905-467E-8E60-3A1EC9C3671E}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe | "{1CB3AE9B-ADD9-4AAA-9EB8-90EECFA58159}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{233CF88A-0AE2-42D8-9524-91913D8DAF71}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{25802478-05CF-47E8-91C4-6CC85474BDB6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{2885FF54-CC11-45A8-A59B-0962A0058B85}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{2E3671E5-926D-49DC-8B11-FC5D222A6D38}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{322BCF10-D70F-472A-8E55-9B90F78F749F}" = protocol=6 | dir=out | app=system | "{3DA4A09A-41E9-4D42-AE2F-9B1A291F5127}" = protocol=17 | dir=in | app=c:\program files (x86)\bitcomet\bitcomet.exe | "{41E26358-25D0-4008-BF77-3AB65978D4D8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{5040259A-A5ED-4A59-8892-D9A5944FA28E}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{506E6F76-F2AA-4A19-AE0A-37ADE9B10898}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "{5E89F59F-10B7-4858-BFC9-47C10447C645}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{5F24EEF5-ACFA-4B26-AC2C-D7CB0EB5F00C}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{6191F7F7-D4B4-42B7-AAC5-3C7F299DF37F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{77083804-8F25-41EB-A9EC-F752EF1CC7A0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{7D3845A3-8F4B-4115-8F31-CFD59A3F615B}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\pluginwrapper\opera_plugin_wrapper.exe | "{803C5812-4245-44C2-91AF-11AFDC2792F1}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{87263215-984A-4422-AF4B-1D9E927D86B1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{8DBBB837-6957-4340-9257-2F3B17FF419B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{926F8742-C1BD-4F76-A861-227C6B7688AC}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{9BC2A1EE-4A74-4044-AF73-73690607F5DD}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{9F5E0D50-5C4D-4346-BAFB-7CB03CDE941F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A63060FD-4EFE-4155-B735-7A1325532423}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{AB465ECE-FCE7-457F-A06C-5D41142FA034}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{AF9F5097-A96B-4D1A-B156-17E1672B2554}" = protocol=6 | dir=in | app=c:\program files (x86)\atube\dtuser.exe | "{AFB4B5D9-6FCB-429F-8F37-612C4004AA55}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{B027EE70-6442-46CB-8EC4-FC15CBA8EBCC}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B2AF3A52-9DD1-4314-8FDE-175CBB33CBE1}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{B2F44E0E-B485-4974-BB29-6AB094EF1E99}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B39F43DE-5472-4B19-AAB8-60180B25972E}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{B70592B4-84EE-4D49-9D44-8B8F83EBB8B6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{C6EC7EC7-4F99-41D9-9504-D26BC49502DF}" = protocol=6 | dir=in | app=c:\program files (x86)\bitcomet\bitcomet.exe | "{DAA345D5-0BB0-470B-BF22-B42C3D3BE14B}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{FA3790AA-A480-422B-AD86-8D9A8DFA45A0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{8C674B4C-658C-4238-B778-D16625CC54AF}C:\users\michał\appdata\roaming\syokp\eskeo.exe" = protocol=6 | dir=in | app=c:\users\michał\appdata\roaming\syokp\eskeo.exe | "TCP Query User{8E6E6B6B-CF40-4A32-B494-A9D0D100C04F}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "TCP Query User{A023AE8E-BE24-4BAF-8CAF-75FA82555E20}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "TCP Query User{E4E01EF1-7B5C-4CB2-9F14-5B5DD2EEBF50}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "UDP Query User{B9AA5735-8F43-4AF7-9BE0-C9F70192FD3A}C:\users\michał\appdata\roaming\syokp\eskeo.exe" = protocol=17 | dir=in | app=c:\users\michał\appdata\roaming\syokp\eskeo.exe | "UDP Query User{BC999845-4138-42DD-BC52-C59203B15CF0}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | "UDP Query User{CE6C71E0-F915-467D-B0DE-870297DD573C}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "UDP Query User{F3DFD361-8857-4466-B81B-78F515106C7C}C:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gadu-gadu 10\gg.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder "{27D28586-BEF1-4E06-8787-3B1FC3A41489}" = Internet Manager "{90140000-006D-0415-1000-0000000FF1CE}" = Moduł Szybka instalacja pakietu Microsoft Office 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9EA64B79-30A1-F52E-D801-B07CF05FFFAF}" = ccc-utility64 "{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller "{C78D3032-9DFD-41D0-9DE9-58EAE750CBA4}" = Microsoft Security Client "{D8DACA27-C2D9-9E8E-A8A5-A10E0C670D01}" = ATI Catalyst Install Manager "CCleaner" = CCleaner "Microsoft Security Client" = Microsoft Security Essentials "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{016095EE-5BB3-791C-A558-06412FF78691}" = CCC Help Russian "{0BF1DE3D-31B9-417F-A915-4BCC5AAEE3CD}_is1" = Sothink SWF Editor "{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker "{10F4A085-EA81-594B-C0B8-ADF013D26B8E}" = CCC Help Turkish "{14EC371D-145C-9AC3-B3A8-EA90C6B0325E}" = PX Profile Update "{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2 "{1942E836-414C-4414-672B-93FCC8CC18AB}" = CCC Help Danish "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Narzędzie do przekazywania usługi Windows Live "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2367FAB6-057A-4973-875F-F57F7BBBA363}_is1" = DreamScene Seven version 1.2 "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 "{284AE43C-30E4-B57E-A234-05496D05AB68}" = Catalyst Control Center Graphics Previews Vista "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{2E522ED6-01E2-4207-82D5-B3BFB31B8BD4}" = Windows Live Sync "{32354BAB-8BAE-7189-6E3F-922D47292D3D}" = CCC Help Czech "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{49273419-5179-4866-9F71-5CF346F302CF}_is1" = Sothink SWF Catcher "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E242AB2-86A7-4231-82A9-1E4226D23CA8}" = Catalyst Control Center - Branding "{51958BA7-21E4-4A8B-9098-CD8375BD17B2}" = Asystent rejestracji usługi Windows Live "{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI "{5735A865-CD31-5788-DA38-AAB06EAED9F4}" = CCC Help Hungarian "{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1" = Acer GameZone Console "{5901E428-EC91-71EE-BA56-9417E40BE182}" = ccc-core-static "{6053FE9B-5473-41D6-AEBF-AD6F98138191}" = Windows Live Movie Maker "{60AA5155-39C7-14AA-FB4B-489B1C8DE9A1}" = CCC Help Chinese Traditional "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{72449E65-4852-2FD9-F603-D77E39DD3CF6}" = CCC Help Finnish "{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic "{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite "{7703542C-3842-C5EE-2452-B006F441A162}" = CCC Help Polish "{774C0434-9948-4DEE-A14E-69CDD316E36C}" = Internet Explorer Toolbar 4.6 by SweetPacks "{7760D94E-B1B5-40A0-9AA0-ABF942108755}" = Acer Crystal Eye Webcam "{7F529418-344D-3792-F7B6-04EB805F5931}" = CCC Help English "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}" = Spin & Win "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}" = Poker Pop "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}" = Amazonia "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}" = Heroes of Hellas "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11505173}" = Airport Mania First Flight "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{888DEFB8-CFCE-43FE-A7C8-9B18C4450719}_is1" = Sothink Flash Downloader for Browser "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{91F29ED6-6C82-F83D-BF8D-3E67D18E7249}" = Catalyst Control Center Localization All "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9862473C-E063-4C68-A161-2CDE0E8048A5}" = Podstawowe programy Windows Live "{990EEE1A-4D64-16AF-A944-AD97AE080D26}" = CCC Help German "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9A98031B-0A1A-AFDC-87F4-AAFDC1E97B7D}" = CCC Help Portuguese "{9AB614A6-719C-4A6E-A63E-831E0A35F62A}" = Windows Live Writer "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9CDEAEC9-2F14-4D39-8541-C1EEC4B5D1CB}" = Galeria fotografii usługi Windows Live "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Polish "{ADE37EC4-B96C-4903-9BEB-FAE1DDE27E39}" = Snap.Do "{AEAA9D8A-A347-0FC4-5CAF-D9F2236FCF49}" = CCC Help French "{AEB43F42-8F9D-DBD8-0B11-941CC27C174A}" = CCC Help Norwegian "{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1" = Sothink SWF Decompiler "{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder "{C2EE73BE-CD73-6EC9-A5A0-0E080A60A00E}" = CCC Help Chinese Standard "{C35FE07E-24B5-410F-85B7-122087A0C7DD}" = Poczta usługi Windows Live "{CFCF4223-BC7B-110C-4E19-5FF025721C4B}" = CCC Help Spanish "{D1803CD4-0CE7-4484-98E3-88D7A2D629A4}" = Windows Live Messenger "{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9 "{E17D581A-6949-6A53-7A18-E80C6BDCC800}" = CCC Help Italian "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{E96D1A04-B0B4-0788-D70F-0A9BB9C503BD}" = CCC Help Korean "{EB5E21BC-AC56-A45D-5593-A1C55A380677}" = CCC Help Swedish "{ECEDC447-3EED-6F90-CB39-0A49BD2D63DE}" = CCC Help Thai "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater "{EF45FBBD-3CE8-698B-AC44-C693468F53D3}" = CCC Help Greek "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F47BEA79-07F3-5602-76B4-B9B9042269A1}" = Catalyst Control Center InstallProxy "{F73D3B6A-4E5F-E93D-C7C3-65DE80BEE0E7}" = CCC Help Dutch "{F9D7691A-E3CD-EF15-DE38-EDF0BB1E345F}" = CCC Help Japanese "Acer Registration" = Acer Registration "Acer Screensaver" = Acer ScreenSaver "Acer Welcome Center" = Welcome Center "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Advanced SystemCare 6_is1" = Advanced SystemCare 6 "Age of Sail 2" = Age of Sail 2 "Alligator Flash Designer 8 PL" = Alligator Flash Designer 8 PL (8.0.24) "AVG Secure Search" = AVG Security Toolbar "BitComet" = BitComet 1.28 "BurnAware Home_is1" = BurnAware Home 3.0.6 "CoffeeCup GIF Animator" = CoffeeCup GIF Animator "DMX5_is1" = DriverMax 6 "FastStone Image Viewer" = FastStone Image Viewer 4.6 "GOM Player" = GOM Player "Google Chrome" = Google Chrome "HyperCam 2" = HyperCam 2 "Identity Card" = Identity Card "InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2 "InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager "InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9 "LManager" = Launch Manager "Mozilla Firefox 8.0 (x86 pl)" = Mozilla Firefox 8.0 (x86 pl) "MpcStar" = MpcStar 5.3 "NAV" = Norton AntiVirus "NST" = Norton Identity Safe "Office14.Click2Run" = Moduł Szybka instalacja pakietu Microsoft Office 2010 "Opera 12.10.1652" = Opera 12.10 "Opera 12.11.1661" = Opera 12.11 "TeamSpeak 3 Client" = TeamSpeak 3 Client "WinLiveSuite_Wave3" = Podstawowe programy Windows Live "WinRAR archiver" = WinRAR 4.01 (32-bitowy) [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3542797096-4280232732-1929941010-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "GG" = GG "Video Converter" = Video Converter Error encountered while reading event logs. < End of report >