OTL Extras logfile created on: 2014-05-25 20:50:45 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Daniel\Downloads 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17031) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1013,49 Mb Total Physical Memory | 96,04 Mb Available Physical Memory | 9,48% Memory free 2,68 Gb Paging File | 0,80 Gb Available in Paging File | 30,04% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 50,11 Gb Total Space | 11,80 Gb Free Space | 23,55% Space Free | Partition Type: NTFS Drive D: | 11,93 Gb Total Space | 4,10 Gb Free Space | 34,33% Space Free | Partition Type: NTFS Drive E: | 804,20 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Drive F: | 12,48 Gb Total Space | 0,01 Gb Free Space | 0,10% Space Free | Partition Type: NTFS Computer Name: SERWISDANIEL | User Name: Daniel | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3221662640-3026500274-3220262054-1001\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0C7BD139-7C56-4265-89E7-A2B6B7ECB545}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{1D67A3F1-38D1-4171-BFF5-9BCD413DC117}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{23330BE2-CA12-4F0E-8E70-2CB52BDBF7FB}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{29BF90A5-A06F-4789-BB95-DD2052A0AAEE}" = rport=137 | protocol=17 | dir=out | app=system | "{3370158E-6370-4589-AEEC-E21608B30960}" = lport=139 | protocol=6 | dir=in | app=system | "{342B2697-E44D-4089-95F6-0557BB9C95D9}" = rport=445 | protocol=6 | dir=out | app=system | "{3F3A5C69-11B0-463B-A39A-300C58621286}" = lport=2869 | protocol=6 | dir=in | app=system | "{4429A092-8AE8-4C48-9077-C1323459CACC}" = lport=10243 | protocol=6 | dir=in | app=system | "{44E4C25E-129B-4A65-85A1-9DB69E2462E5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{4E6BBA38-5750-47FC-B3F1-00E35D5D121A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5BFA4AA3-DF7F-4C4F-B934-A6269C1019BB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7F1C5FEF-B878-45D0-9DE4-B5BEB21DCF5E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{8848354B-C444-45ED-88B0-C422E402535E}" = rport=139 | protocol=6 | dir=out | app=system | "{8B0116C9-AD5F-4B61-81A3-E706E2F28FE0}" = lport=137 | protocol=17 | dir=in | app=system | "{9CEE2773-45EF-41C3-BC90-33DF4FB58E97}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A6FD0A0F-E5E3-45A5-8695-3D0D74D0B221}" = lport=138 | protocol=17 | dir=in | app=system | "{BC8F1CA1-5007-4FF7-8EA8-AF525AFE3CDB}" = lport=6004 | protocol=17 | dir=in | app=f:\office15\outlook.exe | "{C1B02972-0D2B-4ABC-B1ED-F980319F3365}" = rport=10243 | protocol=6 | dir=out | app=system | "{CFB90198-1042-4216-8180-063B40D1D2E4}" = rport=138 | protocol=17 | dir=out | app=system | "{D35CCD94-32C4-4B1E-AEE4-07FCE7F47962}" = lport=445 | protocol=6 | dir=in | app=system | "{EAD8A91C-D7A3-4D2D-B3D3-87C5693DF956}" = lport=6004 | protocol=17 | dir=in | app=e:\office15\outlook.exe | "{EDDF2862-7BAF-4C68-AA7D-2ECCBB125D16}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F150166D-B1EC-4545-B02C-2E14DC3B538D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | "{F2BFCF83-CB32-4D67-9505-FF5AE66A4A4D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F41FAA41-9096-4DE2-AD83-8C777FE68406}" = lport=1688 | protocol=6 | dir=in | name=kms emulator port | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0436626A-2EE9-45E2-9A04-629362CD54FC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{062CA90F-3867-4877-B91C-15237B9693CD}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{09059144-3048-4EC1-ABF9-978A50E4B2D6}" = dir=out | name=ipla | "{0BAC3E9B-3B55-431F-934C-EB5BC6F69B7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0BAED3AB-5C4A-4B77-9C41-52F979E5FD7D}" = dir=out | name=radio zet | "{152A93DA-EB95-4F8E-90A7-520EEAAED995}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{15E57E12-6131-46AF-9192-ACDE0AE339D9}" = protocol=17 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{167DBE47-2524-4439-8DC4-F75E1C4E6CE3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{16EE71BF-DD2B-4968-8BF6-99C4F6FDCB5E}" = dir=out | name=hill climb racing | "{1C64872D-1679-4F69-BB5B-6F2EF58A5635}" = dir=out | name=@{microsoft.bingsports_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{1FC1EF4A-B07F-47F2-B3E9-BBF645715BEF}" = dir=out | name=@{hugogames.hugotrollwars_1.4.0.2_x64__t3zmq3hm5qps4?ms-resource://hugogames.hugotrollwars/resources/rflib_gamesettings_text_title} | "{248D07F3-5602-4D6A-B4CC-EDA4FEEC2915}" = protocol=6 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{26E87CED-6FF5-4F9C-B398-ED381E925CC2}" = protocol=6 | dir=in | app=c:\program files\kmspico\autopico.exe | "{291B2E22-B8EF-4D8C-B7E9-0327D8BAAC63}" = protocol=17 | dir=in | app=c:\program files\kmspico\kmsserver.exe | "{2BBC76C4-A6F9-4720-A26E-163CE0F7F383}" = dir=out | name=rayman jungle run | "{2C3C478E-1E80-4AE8-B9A3-84AF1A45607C}" = dir=out | name=internet speed tester | "{31153F0E-0688-4A30-8CB4-61A7332B9806}" = dir=out | name=youtube bookmarks | "{331ABF5F-A76B-49AD-92BD-364A22692C1A}" = protocol=17 | dir=in | app=c:\program files\kmspico\autopico.exe | "{36AB003A-AFAF-494A-8465-0E333D4CC9DF}" = dir=out | name=krzyżówki | "{36EC491E-229D-454B-8470-64F72333BC2B}" = dir=out | name=@{microsoft.zunemusic_2.2.886.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{3DFE6249-26A7-48B8-A334-D369963A3E06}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{423F7F8F-F982-474E-B9EA-95AD10FE1487}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{451F1D88-6C54-4FB9-ABE9-99639E5C1F6D}" = protocol=6 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{47B92534-3608-46A2-8D3C-0B3FB56C51E2}" = dir=out | name=google search | "{49220AF7-B450-4134-B20F-262AF6B8BBA8}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{4BC8EAC2-FCC2-4D20-8DE7-ADF278D2DDBA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{4BE590D6-BF91-4784-874F-2661577108F3}" = protocol=17 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{4F74E4FE-A931-4711-AE80-B8821E9ACFD8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{5332BEFE-3384-4388-AD60-30543DFB0FBD}" = protocol=17 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{55599883-1AD9-4EDF-83F7-BD61FF479C28}" = protocol=6 | dir=in | app=e:\office15\ucmapi.exe | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{574EAFFA-2A22-48F4-B8A0-8D6767B46F1F}" = protocol=17 | dir=in | app=f:\office15\ucmapi.exe | "{58308BED-955D-4CB4-8F3C-FDB66599BAB9}" = protocol=6 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{5A7679F2-F661-4926-94F4-C6BEFC8CE89F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{60750404-3935-4F43-98EE-7D2C95CF8607}" = dir=out | name=@{hugogames.hugotrollwars_1.6.0.3_x64__t3zmq3hm5qps4?ms-resource://hugogames.hugotrollwars/resources/rflib_gamesettings_text_title} | "{65DB8995-9CA5-4DE5-A07B-96F1627AA1F0}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{6BC596A4-40DB-4248-A6FD-BFB9A897C8A3}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{6E8872AD-AC1A-4425-9E14-471FB37089B6}" = dir=out | name=mzip | "{6F0ECF69-A4C5-4FE4-8E9C-D6C978FEDBD6}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{6F48642C-286B-43DF-BA57-02B3EDBF9386}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{70CE0621-7599-4D62-BA5B-C79FCBE57A85}" = dir=out | name=@{microsoft.bingweather_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{75A4A10A-2A6A-42B1-B5C1-447C1FBF953D}" = protocol=17 | dir=in | app=c:\program files\kmsnano\data\qemu-system-i386.exe | "{7993ED6A-CD2A-4C71-82B2-C00B65E42B46}" = protocol=6 | dir=in | app=f:\office15\lync.exe | "{80CF9AB7-45F9-40CD-A134-D7A59668E7CE}" = protocol=6 | dir=in | app=c:\program files\kmspico\kmsserver.exe | "{82A1E06F-8166-4694-AEF8-E4CCBD08E781}" = protocol=6 | dir=in | app=c:\program files\kmsnano\data\qemu-system-i386.exe | "{87200688-F39D-4D60-B2F5-85C27841CCB6}" = dir=out | name=@{f4a14ebd.speedchecker_2.0.2.2_neutral__520nysfwyaqs0?ms-resource://f4a14ebd.speedchecker/resources/applicationname} | "{8D201A42-B66B-4258-BB11-87165DBF85E7}" = dir=in | name=skype | "{90D30702-F037-4FB7-A3A9-6E4C970A4919}" = protocol=17 | dir=in | app=c:\program files\kmsnano\data\qemu-system-i386.exe | "{9511A750-1B5F-4C31-8D97-C87D87CD6598}" = dir=out | name=przepisy.pl | "{9932A4E3-383F-4EC4-B1CF-F7F11B95066D}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{A5A019F9-79E4-47DB-94DB-0C07B82059A3}" = protocol=17 | dir=in | app=f:\office15\lync.exe | "{A6A701DB-4BA4-431A-8933-2F82B123F02D}" = protocol=17 | dir=in | app=e:\office15\ucmapi.exe | "{A6B7ECCA-276F-4241-B248-D512D3E98A98}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{A773D16D-FE30-483E-8DF9-840C19213C89}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A96E042D-F32F-41D6-8AB7-DA00BF827AEE}" = protocol=6 | dir=in | app=c:\windows\system32\kmsserver.exe | "{AE2DA30A-F272-49A9-A4E3-079D9020EEE1}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{B2C53AC5-06AF-4881-9FC8-12295BC6586A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{B49D4644-326C-4EAE-AFEC-C846AFD9EDD8}" = protocol=6 | dir=in | app=f:\office15\ucmapi.exe | "{B61FA9CE-E351-460C-94E6-07D27947C95C}" = dir=out | name=@{microsoft.bingmaps_2.0.2530.2317_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{B6238B4A-11E8-46FD-B7CF-7870F7EE9607}" = protocol=6 | dir=in | app=c:\program files\kmspico\autopico.exe | "{B6AD9397-26D8-4B7D-93D4-77204548739D}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{B6E102C8-327B-4924-93AD-047AAA156444}" = protocol=6 | dir=out | app=system | "{BBA7506A-1B42-465C-8FC0-E5D508636C54}" = dir=out | name=allegro.pl | "{BE2CDFC0-663F-4168-930F-4FC617F113CB}" = dir=out | name=@{microsoft.zunevideo_2.2.886.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{BEE4B2B8-7240-46C5-9480-23456BF934A7}" = protocol=6 | dir=in | app=c:\program files\kmsnano\data\qemu-system-i386.exe | "{BF8F6536-E6D5-4F56-BE1F-5D16E2CE4365}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{C12072CC-6E33-48BA-AD28-1553DDA4CF30}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{C1F51D89-A885-4670-844A-E00A1799BC7A}" = dir=out | name=@{61908richardwalters.calculator_3.0.0.0_neutral__486nvj664v5b0?ms-resource://61908richardwalters.calculator/resources/apptitle} | "{C2D742FE-F3E2-46CA-938E-816A109B393F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C41EBEDC-25C9-42B9-9D04-7757E58FA98F}" = dir=out | name=@{microsoft.bingtravel_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{C4CFC43C-D326-4D3D-9CDD-CFB9BE6343F5}" = protocol=6 | dir=in | app=e:\office15\lync.exe | "{CB0CC781-1561-4B00-9DE9-51F61B38A75A}" = protocol=6 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{CEA1F21A-DD2F-4DFD-A53C-04923C60E0E0}" = dir=out | name=@{microsoft.bingnews_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{CF9CD600-FF16-445C-A241-912F972BAD56}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D1A123A5-FD6B-4264-BF05-B9C553B784CB}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D2071808-BBF0-428F-AE95-1AF5A8C4A8EC}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{D6186435-3CB8-47A4-B4F5-74A48BEC6D80}" = dir=out | name=wsop: full house pro | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{D6BAF880-BFC2-406B-AE31-301BB27EA67C}" = dir=out | name=skype | "{D8C10818-B2F2-4D82-83E9-82B255DE9D3C}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{E2E4754D-9DCF-4B54-A539-43E9B7C0B96E}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{E56E7A28-9734-44B2-9FBB-A37EA80B55F8}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{E8227F06-E468-4C2A-B04D-C90F6D5AC91B}" = protocol=17 | dir=in | app=c:\windows\system32\kmsserver.exe | "{EB6BC97B-FFCA-47CD-800E-6F3FE0695EC5}" = protocol=17 | dir=in | app=c:\program files\kmspico\autopico.exe | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{ECACA6D2-65B3-47B1-916A-A16B44689EF9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{EED221A4-7953-48C0-9F8F-BE719A7A0733}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{F23A1CBC-1E04-442D-998B-AF2ACB4F8ED3}" = dir=out | name=@{microsoft.bingfinance_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{F315DE5F-52AA-4BE9-BBB7-0952F6269A47}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{F54DEE61-F57D-4610-8079-AD0E11987882}" = protocol=17 | dir=in | app=e:\office15\lync.exe | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{FD75DCAE-4102-43A7-9530-BDE13B37DD8C}" = protocol=17 | dir=in | app=c:\program files\kmspico\service_kms.exe | "TCP Query User{927EACFC-F759-4A9D-A128-30DEDF5393A1}C:\users\daniel\appdata\local\temp\kmsnano\qemu-system-i386.exe" = protocol=6 | dir=in | app=c:\users\daniel\appdata\local\temp\kmsnano\qemu-system-i386.exe | "UDP Query User{9A0A838E-26C1-4C0F-9CB9-BE9C236CC8E1}C:\users\daniel\appdata\local\temp\kmsnano\qemu-system-i386.exe" = protocol=17 | dir=in | app=c:\users\daniel\appdata\local\temp\kmsnano\qemu-system-i386.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{345841F8-F9F9-9910-134E-49162B7FDDAD}" = ccc-utility64 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90150000-0015-0415-1000-0000000FF1CE}" = Microsoft Access MUI (Polish) 2013 "{90150000-0016-0415-1000-0000000FF1CE}" = Microsoft Excel MUI (Polish) 2013 "{90150000-0018-0415-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (Polish) 2013 "{90150000-0019-0415-1000-0000000FF1CE}" = Microsoft Publisher MUI (Polish) 2013 "{90150000-001A-0415-1000-0000000FF1CE}" = Microsoft Outlook MUI (Polish) 2013 "{90150000-001B-0415-1000-0000000FF1CE}" = Microsoft Word MUI (Polish) 2013 "{90150000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch "{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English "{90150000-001F-0415-1000-0000000FF1CE}" = Narzędzia sprawdzające pakietu Microsoft Office 2013 — polski "{90150000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2013 "{90150000-0044-0415-1000-0000000FF1CE}" = Microsoft InfoPath MUI (Polish) 2013 "{90150000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2013 "{90150000-0090-0415-1000-0000000FF1CE}" = Microsoft DCF MUI (Polish) 2013 "{90150000-00A1-0415-1000-0000000FF1CE}" = Microsoft OneNote MUI (Polish) 2013 "{90150000-00BA-0415-1000-0000000FF1CE}" = Microsoft Groove MUI (Polish) 2013 "{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013 "{90150000-00C1-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2013 "{90150000-00E1-0415-1000-0000000FF1CE}" = Microsoft Office OSM MUI (Polish) 2013 "{90150000-00E2-0415-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (Polish) 2013 "{90150000-012B-0415-1000-0000000FF1CE}" = Microsoft Lync MUI (Polish) 2013 "{91150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013 "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{AFB70FA9-7C73-4DB9-8689-4A3DA1891B02}" = WD SmartWare "HDMI" = Intel(R) Graphics Media Accelerator Driver "KMSpico_is1" = KMSpico v9.1.3 "Office15.PROPLUSR" = Microsoft Office Professional Plus 2013 "SynTPDeinstKey" = Synaptics Pointing Device Driver "TAP-Windows" = TAP-Windows 9.9.2 "WinRAR archiver" = WinRAR 4.00 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{15F5403E-C8AF-4FEC-893D-BA96D6063270}" = WD Quick View "{1812E293-E2D1-3072-0ED4-C15163533D7E}" = CCC Help Swedish "{1ec9e03a-452b-48fb-8e1b-27ee0477985f}" = WD SmartWare Installer "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{25087F13-EBE7-C817-CA31-08C196F73B23}" = CCC Help Hungarian "{29043AAA-3A1A-D36B-C1CB-E201FA72C16A}" = CCC Help Dutch "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{3C7F465C-765F-A038-60BE-03B7301B0161}" = CCC Help Norwegian "{42321261-5D40-644C-1235-927141D4FA20}" = CCC Help Portuguese "{446CF7B3-EE4D-1C10-E2B7-87C1C8517FE8}" = CCC Help Korean "{450BED09-F405-87EE-CD52-5055B1EF8F72}" = CCC Help Chinese Standard "{4D628C2E-D9F7-2D3A-E610-00F4D52F219F}" = CCC Help Polish "{553B5DE6-496A-4328-DE0B-D1C83F7FE4D8}" = CCC Help Turkish "{5EA2099A-0249-1D98-5387-0BEF207D72AA}" = AMD Catalyst Control Center "{632396AA-8A78-A9A4-0945-7E24DF3F5B6C}" = CCC Help French "{64592305-22DF-6756-FD51-1B7234D4C6AB}" = CCC Help Russian "{7BC48761-EE54-AA23-5607-0D11B7550CFB}" = CCC Help Italian "{7C58E0C8-89FB-7E36-158C-5DC0B57027D9}" = CCC Help Czech "{87270A4A-EDE9-BFDF-AE0C-0FBDEEA5D4BD}" = CCC Help Thai "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8B1A559A-FB9D-42F5-A8A7-2F132CF28414}" = Catalyst Control Center "{8EFB7927-48AD-4E6D-91B7-6B2BD6C3F380}" = Acronis Disk Director 11 Home "{8F1ABC89-3D34-1D8B-DF69-EC9198604283}" = CCC Help Spanish "{91B33C97-7BCF-CDFE-4321-58EBF3E8641C}_is1" = Ashampoo Burning Studio 14 v.14.0.1 "{96DAF3C6-C2D4-5804-E219-86C034A02355}" = CCC Help Japanese "{9BB69BDB-FE40-24D2-3822-828FB6DF6DE2}" = CCC Help German "{A71019D0-8C9D-DB8D-2801-CBFC736FF307}" = CCC Help Danish "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{B99E1A30-E349-FA3B-80F7-FB55EBC40996}" = CCC Help Chinese Traditional "{C28E9DF6-C68D-18DF-076C-7E92B9F30A96}" = CCC Help English "{C68D4599-2D2A-2060-39D0-0B3DEA861657}" = Catalyst Control Center Localization All "{CB79256B-C0E0-40C6-8EB7-BDD796203581}" = Catalyst Control Center - Branding "{DADC7AB0-E554-4705-9F6A-83EA82ED708E}" = Realtek Ethernet Diagnostic Utility "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F940E929-2FFF-1F4E-7ECB-DE1B0377D627}" = CCC Help Finnish "{FB8AF07B-42FB-4746-058A-B6A063472452}" = CCC Help Greek "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "Driver Booster_is1" = Driver Booster "Google Chrome" = Google Chrome "Mozilla Firefox 27.0.1 (x86 pl)" = Mozilla Firefox 27.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "SpeedFan" = SpeedFan (remove only) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-05-25 09:10:28 | Computer Name = SERWISDANIEL | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Service_KMS.exe, wersja: 11.0.0.0, sygnatura czasowa: 0x52a8d15d Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0x00000000 Przesunięcie błędu: 0x00007ffb5bbb1aa5 Identyfikator procesu powodującego błąd: 0x598 Godzina uruchomienia aplikacji powodującej błąd: 0x01cf781a5455b176 Ścieżka aplikacji powodującej błąd: C:\Program Files\KMSpico\Service_KMS.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: f0861835-e40d-11e3-82d3-d0ecc2d0b014 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2014-05-25 09:10:31 | Computer Name = SERWISDANIEL | Source = .NET Runtime | ID = 1026 Description = Error - 2014-05-25 09:14:21 | Computer Name = SERWISDANIEL | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2014-05-25 09:14:21 | Computer Name = SERWISDANIEL | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2014-05-25 09:14:21 | Computer Name = SERWISDANIEL | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error - 2014-05-25 10:06:25 | Computer Name = SERWISDANIEL | Source = Microsoft-Windows-Immersive-Shell | ID = 2486 Description = Aplikacja Microsoft.WindowsAlarms_6.3.9654.20335_x64__8wekyb3d8bbwe+App nie została uruchomiona w wyznaczonym czasie. Error - 2014-05-25 14:26:28 | Computer Name = SERWISDANIEL | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Service_KMS.exe, wersja: 11.0.0.0, sygnatura czasowa: 0x52a8d15d Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0x00000000 Przesunięcie błędu: 0x00007ffb1d340565 Identyfikator procesu powodującego błąd: 0x600 Godzina uruchomienia aplikacji powodującej błąd: 0x01cf78464236f68f Ścieżka aplikacji powodującej błąd: C:\Program Files\KMSpico\Service_KMS.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: 159e5e57-e43a-11e3-82d4-e2972968d715 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2014-05-25 14:28:45 | Computer Name = SERWISDANIEL | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2014-05-25 14:28:45 | Computer Name = SERWISDANIEL | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2014-05-25 14:28:45 | Computer Name = SERWISDANIEL | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. [ System Events ] Error - 2014-05-25 09:07:36 | Computer Name = SERWISDANIEL | Source = BugCheck | ID = 1001 Description = Error - 2014-05-25 09:07:56 | Computer Name = SERWISDANIEL | Source = Service Control Manager | ID = 7003 Description = Usługa Aktywator programu Acronis OS Selector zależy od następującej usługi: ProtectedStorage. Ta usługa może nie być zainstalowana. Error - 2014-05-25 09:10:32 | Computer Name = SERWISDANIEL | Source = Service Control Manager | ID = 7034 Description = Usługa Service KMSELDI niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-05-25 09:31:40 | Computer Name = SERWISDANIEL | Source = cdrom | ID = 262151 Description = W urządzeniu \Device\CdRom0 wystąpił zły blok. Error - 2014-05-25 09:52:17 | Computer Name = SERWISDANIEL | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-05-25 14:22:04 | Computer Name = SERWISDANIEL | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 15:47:35 na ?2014-?05-?25 było nieoczekiwane. Error - 2014-05-25 14:21:37 | Computer Name = SERWISDANIEL | Source = cdrom | ID = 262151 Description = W urządzeniu \Device\CdRom0 wystąpił zły blok. Error - 2014-05-25 14:22:17 | Computer Name = SERWISDANIEL | Source = BugCheck | ID = 1001 Description = Error - 2014-05-25 14:22:24 | Computer Name = SERWISDANIEL | Source = Service Control Manager | ID = 7003 Description = Usługa Aktywator programu Acronis OS Selector zależy od następującej usługi: ProtectedStorage. Ta usługa może nie być zainstalowana. Error - 2014-05-25 14:26:41 | Computer Name = SERWISDANIEL | Source = Service Control Manager | ID = 7034 Description = Usługa Service KMSELDI niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. < End of report >