OTL Extras logfile created on: 2014-06-13 10:38:00 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Michał\Desktop\Viry Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17126) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,17 Gb Total Physical Memory | 1,28 Gb Available Physical Memory | 40,29% Memory free 3,73 Gb Paging File | 1,76 Gb Available in Paging File | 47,13% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 465,42 Gb Total Space | 399,15 Gb Free Space | 85,76% Space Free | Partition Type: NTFS Computer Name: MICHAL-PC | User Name: Michał | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04B2ADCF-2024-43A9-ABB1-7EF9E34FF178}" = rport=139 | protocol=6 | dir=out | app=system | "{0A11C619-E209-46CF-A79B-A54C44F7412B}" = rport=2869 | protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{0A322254-75F4-4113-A624-2397B7729596}" = lport=3389 | protocol=6 | dir=in | svc=termservice | app=%systemroot%\system32\svchost.exe | "{0AE51E4A-FF3D-4F98-B2F5-B7876A8233C2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{0B205650-83DC-43CF-9907-B9A53EA1CD88}" = lport=1689 | protocol=6 | dir=in | name=kms emulator port | "{1E40A9EE-676C-4D96-A40F-01B608D973B3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{25D26ED1-1EA0-4897-A444-9C4F6C9875DC}" = lport=1689 | protocol=6 | dir=in | name=kms emulator port | "{322DEC5A-00FD-417C-8CD1-F84B97712A79}" = lport=3389 | protocol=17 | dir=in | svc=termservice | app=%systemroot%\system32\svchost.exe | "{3808333A-C294-4504-B160-432AA52CCDBE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3E22A18F-8229-408D-9FAD-5F72BA5C22C7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{41ACD3F6-DAAC-42BA-9EEB-DCDBD8952B71}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{4EE03184-CE64-4341-A973-4EDF00DEB77A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{666A4A26-026D-4729-869E-26AFE9E5AF84}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{6FA776E4-0123-4675-83EC-7C55D51683A8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{72B02672-5CE8-4AAA-AC05-A0C3B1467E04}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{809AF591-DFBE-4319-B556-20BA68902BE5}" = rport=137 | protocol=17 | dir=out | app=system | "{96C86887-0190-472D-84E9-AD488AA4DC84}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{9F440374-D942-40F5-8804-029F9BBF4612}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A52A3DA1-1CD2-45C6-9A46-6AAE703F3E0B}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A6FD7A5C-7568-4BB4-BD35-54A23971EFD1}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\dashost.exe | "{BA6B7C39-8FC7-4082-A02F-662402DFDFE7}" = rport=138 | protocol=17 | dir=out | app=system | "{BBFAFABD-9C67-4F14-ACE0-FE7E74D1CBC5}" = lport=445 | protocol=6 | dir=in | app=system | "{C00D942A-A8B2-459F-8130-020180E18276}" = lport=137 | protocol=17 | dir=in | app=system | "{C1E3B867-44CD-4DC6-B8BF-FDF1C51CF617}" = lport=139 | protocol=6 | dir=in | app=system | "{C88FA4B0-8A20-4C1A-AA08-9838D88AE969}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{D3C47D15-0B7D-4ECC-A79E-8E065C6435D4}" = rport=445 | protocol=6 | dir=out | app=system | "{D8799E1F-42AA-4BEB-9FEB-1EB952B0A454}" = lport=138 | protocol=17 | dir=in | app=system | "{E1BCEB6C-273F-4DF0-97F7-CA44FB5B6970}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{EAB1DEAF-EB00-48DD-8E38-97F130D1750E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00D0007B-09D8-4E86-BC97-3C2AD17D0C21}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{015A65BD-E993-4D72-8DE8-628BC76D5E41}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | "{02D2A78F-A220-4082-9A2D-061DE0802268}" = dir=out | name=@{microsoft.bingnews_3.0.2.261_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{04216CFA-852A-4812-A509-615E3DE71C5E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{04AC3879-C06B-4C25-AC51-4D6824C71225}" = dir=out | name=@{microsoft.bingweather_3.0.2.258_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{0BA571D6-36AC-4E7D-A201-1DF87F36A737}" = protocol=17 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{0E63143A-DEBD-4F76-93B1-CA4878900AD8}" = dir=out | name=@{microsoft.bingfinance_3.0.2.258_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{0ECE32BA-1548-46BF-8C57-97B72FF8D9FF}" = protocol=17 | dir=in | app=c:\users\michał\appdata\roaming\dropbox\bin\dropbox.exe | "{0EDA3ED9-5DB8-4CFE-A945-A7A77002C0EE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{128BE73D-1393-4AE5-A579-7AEFB5C45A70}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe | "{14200419-7B92-4049-BEBD-898B5B8F65A8}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe | "{17F4B815-27D4-472A-972D-19E33A01CD44}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe | "{1AAF749C-703A-49FD-8862-C5D010109438}" = dir=out | name=@{microsoft.zunemusic_2.2.903.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{21C2FAAE-BE3B-46FE-94D6-4D5C47A4371D}" = protocol=17 | dir=in | app=c:\users\michał\appdata\roaming\dropbox\bin\dropbox.exe | "{2435629A-A206-49DD-9161-3D6E29A57BFA}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe | "{2563DD37-D064-4688-9D32-2F6726C9B0F0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe | "{26AC37A4-8C74-4F86-9FFA-4C071900CB4C}" = protocol=6 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{2DF2E2B0-A588-4810-90EB-4C394CAB983F}" = dir=in | name=junipernetworks.junospulsevpn | "{331D3F10-92E3-4211-9259-CAF9D02FCE86}" = dir=out | name=junipernetworks.junospulsevpn | "{3335B4D5-6865-4B93-81C9-808DF83C8429}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe | "{3816E650-8775-4671-93E2-3754DF4AC0F5}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe | "{3A1355F1-0516-4107-8481-EA7F2226B5B7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{3B53F7D8-B956-4C8A-8F68-9901D7E4966C}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | "{3D4B6253-88FE-4974-8DEC-82B03F1E307D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{41262A8B-FAE2-4367-9639-836C55A4A595}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{4536D664-BACA-4884-9C59-AB36439832FE}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{4DC8561B-AA6C-48F1-BA7C-273EC04167F7}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | "{4F821284-5D24-4214-A4D1-E027DC071146}" = protocol=17 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{50C326FD-9D1E-4268-B405-FB6AC3F631DB}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{51CF14A3-DAEA-46FD-8C59-870D3B333BBA}" = protocol=6 | dir=in | app=c:\users\michał\appdata\roaming\utorrent\utorrent.exe | "{5492F22A-2782-403F-ACF6-599E60828474}" = dir=in | name=hp all-in-one printer remote | "{55D6BC07-7BB2-44B2-A66B-49082554F630}" = protocol=6 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{57ABF4D0-9A58-4081-B131-06241CD31DBA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{5FF3CFD9-06EB-433E-A065-4D9068F9F4BD}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{60006329-0A83-4082-951A-3734A7B1E35E}" = protocol=6 | dir=in | app=c:\users\michał\appdata\roaming\dropbox\bin\dropbox.exe | "{606D4930-FF0D-4AD4-8E68-52636BB03024}" = dir=out | name=skype | "{6648775E-EDDF-4D0B-A499-FB8AE371776F}" = dir=out | name=@{microsoft.bingmaps_2.1.2922.2139_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{6E16B19A-ECB6-41F7-813A-755624A2B475}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe | "{6E938417-9088-4754-BE9A-A04A95EE74B0}" = dir=out | name=@{microsoft.zunevideo_2.2.902.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{70238E5A-6989-40D6-8797-A342B8E17232}" = protocol=17 | dir=in | app=c:\users\michał\appdata\roaming\utorrent\utorrent.exe | "{70B52BAD-07C8-48AF-AC05-C28883EB4D49}" = dir=out | name=hp all-in-one printer remote | "{7132F317-18F8-453C-9FF6-550189573F75}" = dir=out | name=@{microsoft.bingtravel_3.0.2.258_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{71C4B0A3-09A1-4016-AA94-2BFAD901C890}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | "{7B7B3B1D-0806-4C85-B2ED-29F00D7CDBE3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe | "{7C8BDE74-4EA4-4CC1-BBDA-31F8BA326241}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{835E0E77-65D1-4FAA-AA5E-AC67565A94FB}" = dir=out | name=sonicwall.mobileconnect | "{8B30A4D9-576B-43E2-9D29-002BA756F296}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{8EFEA156-7737-43A8-B3B4-671A40BFE115}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{9A91775A-83D3-4CF4-A127-0286A8D4CC12}" = protocol=17 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{A0BDF572-29AA-4909-9B50-E1D69C8C5A9D}" = protocol=17 | dir=in | app=c:\program files\kmspico\autopico.exe | "{A0D8948D-5338-46A2-9842-863E2E0FB71B}" = protocol=6 | dir=in | app=c:\program files\kmspico\autopico.exe | "{A2BC9BA1-FA68-4E49-9D64-A32B8E1119A5}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe | "{A3F3360A-EB0E-4F45-9B23-27621B01307E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe | "{A9080F4C-BE69-49F6-87CD-FAE444526D27}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{AAFF0B25-0F8D-4328-AC24-7135B34BDEC7}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{AE532EFC-842A-4756-B72B-742501A5E07C}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{AF2F4FA9-B47D-4462-AD2B-E432A1A92C5A}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | "{AF4CD98F-A6B6-4B1C-8D65-661A94CE0BDE}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{B5FC2F19-DC3A-432A-AA8C-DD12903B4714}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{B8ED0C80-DE63-4AA8-8037-11BEF5ED7F23}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.258_x86__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{BCD85D25-DCB0-4310-8BDD-957C1515ED77}" = dir=in | name=skype | "{BECBC565-8503-41F2-A034-48FBEF882F3E}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | "{BFACAF85-7271-4D8A-9D8B-23FAF7C060D0}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{C6182E4B-10FC-4083-A766-458080D68E73}" = dir=in | name=f5.vpn.client | "{C89661D5-D6DF-49EA-BE8D-907DC134CF2B}" = protocol=6 | dir=in | app=c:\users\michał\appdata\roaming\dropbox\bin\dropbox.exe | "{C9063C7A-2604-423E-B6F7-CFC736047D72}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | "{C9740969-A151-4056-8692-B83C1504F6C2}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | "{CBCE1455-135A-470C-8E32-73A6C13371C1}" = protocol=6 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{CD1355A9-717C-4DE6-9732-569861C211E1}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.258_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{CFDA0F09-30E6-4AA3-9BAF-5890B13EF1E3}" = protocol=6 | dir=in | app=c:\program files\kmspico\autopico.exe | "{E0200A4C-1C65-4823-B64F-9ADA0607B87E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe | "{E0C131D2-9837-4318-99BC-AC9AD0FBDA33}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | "{E20BB53A-3BDC-460D-BAEE-FFDC117AB485}" = dir=in | name=sonicwall.mobileconnect | "{E6A4BE21-4183-455E-8C07-84C78011B261}" = dir=out | name=checkpoint.vpn | "{E7BD3C1D-7801-4095-88E2-B1B705A9A5D6}" = protocol=6 | dir=in | app=%systemroot%\system32\rdpsa.exe | "{EEB0EDCF-820B-48FB-8E1A-4F398A01EA4C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe | "{F17EF2BE-77F2-420F-BCB4-0B102D116034}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F28CEDF3-A316-43B0-948B-829D68EB591D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{F41655E3-E7FD-4D8B-AB71-A849ED625BD0}" = protocol=17 | dir=in | app=c:\program files\kmspico\autopico.exe | "{F4DC08D9-79C5-4D36-9183-A1B23419BBC6}" = dir=out | name=@{microsoft.bingsports_3.0.2.258_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{FA35BA80-EA4B-48FD-9FEF-74E9E0B3FEC7}" = dir=in | name=checkpoint.vpn | "{FE5EA256-AD54-4FD8-B211-1263089653FF}" = dir=out | name=f5.vpn.client | "TCP Query User{E59724F5-F57A-4802-99C0-858D17390B5D}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe | "UDP Query User{D04954D7-06B1-457E-A561-0FC88410AA08}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{B6B75FB9-D1DB-491B-847D-144D9C580AA3}" = Corel Graphics - Windows Shell Extension "_{F49EE358-F23B-4D1C-9228-B6C155C938AE}" = CorelDRAW Technical Suite X6 "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{08B95186-14CB-4B39-8E78-7E9773416507}" = CorelDRAW Technical Suite X6 - PHOTO-PAINT "{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour "{0D39418C-FB21-49BB-A83F-ED97D0C84483}" = CorelDRAW Technical Suite X6 - IPM Content "{10290838-B697-4C48-84CD-45580DE5A340}" = Runtime VS2005 SP1 MFC 6195 "{10990BF5-C145-465D-830C-FF7BF3AFCE00}" = CorelDRAW Technical Suite X6 - Common "{11BF4215-81A1-4218-BD93-7ECE3A7C10AF}" = CorelDRAW Technical Suite X6 - Filters "{13B8AFC4-2AFC-4A82-BFB5-250EB4AD464D}" = CorelDRAW Technical Suite X6 - Designer "{1415243E-E8F2-4260-8779-5B136C06BF8F}" = HP Deskjet Ink Advant K209a-z All-in-One Driver Software 14.0 Rel. 6 "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{16F96835-25C8-4C13-981D-55A966371619}" = DJ_AIO_06_K209a-z_SW_Min "{17433C4D-B3BE-4FCE-9038-DD80D0227DCB}" = CorelDRAW Technical Suite X6 - FontNav "{1A27DB55-8B4B-4D37-A48E-5D16E7487425}" = CorelDRAW Technical Suite X6 - Custom Data "{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}" = System Requirements Lab for Intel "{2001B669-4E0D-4E5F-BF1E-86098B054D04}" = Runtime VS2005 SP1 OpenMP 762 "{219AD1C3-625D-4E3B-AD31-5D1475AEF3D7}" = CorelDRAW Technical Suite X6 - VideoBrowser "{26A24AE4-039D-4CA4-87B4-2F83217051FF}" = Java 7 Update 55 "{278EFD6F-86F2-41AF-BDE6-C961A0DFD4D2}" = CorelDRAW Technical Suite X6 - EN "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime "{2BACEEE5-7556-4FF4-B0BB-0F3EA8CD2CCA}" = Runtime VS2008 CRT 1 "{2D6E89AB-813C-4812-BC10-987F97B7AABF}" = G10_Multi-Mode "{337D0EDD-0E46-4F90-8E9F-95B7DECB3573}" = iSpy "{38FB60DD-69EC-4D6D-8F8E-EF5DDE6EA718}" = CorelDRAW Technical Suite X6 - Connect "{3CBE5580-B65E-48B0-B296-C0CB3A841351}" = K209a-z "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{51D0CD81-2A0F-4416-8BEC-4B72582B3F9A}" = GV IP Device Utility "{57697F92-56D3-4AFD-908D-5ED12D3D5FE0}" = Moxa ioSearch "{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status "{5D1E6A6A-1C4A-43FF-A4DF-5E94B9CA86A2}" = CorelDRAW Technical Suite X6 - VSTA "{5E119FD2-2A7B-414A-A4F2-C16B379DCA19}" = CorelDRAW Technical Suite X6 - Redist "{60870FA4-91AE-401B-9E33-A07612CB07DD}" = Virtual Serial Port Kit 5.4.3 "{69D14BA1-783B-4994-8427-9D4501B2587D}" = Virtual Serial Port Kit 5.4.3 "{6F6873E3-5C92-4049-B511-231A138DD090}" = Kaspersky Internet Security "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{77B75A66-40C0-4878-9CE9-C54FDA1F3DB5}" = CorelDRAW Technical Suite X6 - Core "{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16 "{82B37D39-FB69-48B2-A548-2085F460CC60}" = CorelDRAW Technical Suite X6 - Photozoom Plugin "{83298573-A6B6-42AB-A234-FE91CA2859C0}" = Microsoft SQL Server 2008 Native Client "{8889837C-CFFD-42CB-9436-7EC225F9B171}" = CorelDRAW Technical Suite X6 - Writing Tools "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8D99FA19-C2F9-4671-B707-04133EF4AC3D}" = CorelDRAW Technical Suite X6 - IPM "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{90120000-0070-0000-0000-4000000FF1CE}" = Microsoft Visual Basic for Applications 7.1 (x86) "{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-0054-0415-0000-0000000FF1CE}" = Microsoft Office Visio MUI (Polish) 2010 "{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{91140000-0057-0000-0000-0000000FF1CE}" = Microsoft Office Visio 2010 "{91B33C97-91F8-FFB3-581B-BC952C901685}_is1" = Ashampoo Burning Studio FREE v.1.12.0 "{947673AB-0683-42C3-A38B-5991B18B706B}" = XVL Studio 3D Corel Edition "{99B87886-CD77-4466-8002-96FD09B9B3DE}" = XVL Player / XVL Player Pro (Ver. 9 or later) "{99EEF5D1-7A88-4C5C-942D-420530EC1F64}" = Runtime VS2005 SP1 CRT 6195 "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer "{A8D93648-9F7F-407D-915C-62044644C3DA}" = MSI to redistribute MS VS2005 CRT libraries "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU "{ABE1617B-E44B-4AB7-80FA-C5E5695C4EDE}" = CorelDRAW Technical Suite X6 - VBA "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.07) - Polish "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update "{B574E8A6-0C66-4C6F-8DF6-8FB2356A9D44}" = CorelDRAW Technical Suite X6 - IPM Lattice "{B6A55FF8-71D7-406A-A4F1-D056164476D4}" = CorelDRAW Technical Suite X6 - Draw "{B6B75FB9-D1DB-491B-847D-144D9C580AA3}" = Corel Graphics - Windows Shell Extension "{BAB89D31-4C55-472B-8909-6CBE2CC276B1}" = Microsoft Visual Basic for Applications 7.1 (x86) English "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C643FF37-93E1-4079-A4EC-83DBEBDB6AFB}" = Runtime VS2005 SP1 "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{CE16D92B-50F3-4FC5-B29C-13FAFEE1A6C6}" = DYMO LabelWriter Drivers "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch "{E040B65B-8683-4228-8C33-D44A141E40EA}" = Secure Download Manager "{ED5CB552-FD01-4B3A-985B-13EA1F423294}" = Runtime VS2005 SP1 All 6195 "{EFFF4292-F672-41E8-9500-1DB91FDE9A4B}" = CorelDRAW Technical Suite X6 - Common Apps "{F0557823-56EC-4A1D-B34E-7A0B9E19B345}" = CorelDRAW Technical Suite X6 - Capture "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F49EE358-F23B-4D1C-9228-B6C155C938AE}" = CorelDRAW Technical Suite X6 - Setup Files "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "4MCAD 11 Standard_is1" = 4MCAD 11 Standard "Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin "ConfTrick_is1" = ConfTrick - (1.0.0.5) "DVP1410 SDK v1.1" = DVP1410 SDK v1.1 "DYMO Label v.8" = DYMO Label v.8 "FBDBServer_2_1_is1" = Firebird 2.1.1.17910 (Win32) "FT_Prog" = FT_Prog "Google Chrome" = Google Chrome "Greenshot_is1" = Greenshot 1.1.7.17 "GS Scrum_is1" = GS Scrum 1.0.0.0 "GSR_is1" = GSR 1.0.0.2 "GSW DB Synchr_is1" = GSW DB Synchr - UPDATE - 1.0.0.9 "GSW_is1" = GSW (4.0.5.0) "GSW-AXIS_is1" = GSW-AXIS 1.0.0.0 "HK-Software IBExpert Personal Edition_is1" = HK-Software IBExpert Personal Edition "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "InstallShield_{2D6E89AB-813C-4812-BC10-987F97B7AABF}" = G10 Multi-Mode "InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}" = Kaspersky Internet Security "KMSpico_is1" = KMSpico v9.2.3 "K-PZ SmartScale_is1" = K-PZ SmartScale 1.3.3.0 "LCD Programmer_is1" = LCD Programmer 1.0.0.0 "LDX Display Programmer_is1" = LDX Display Programmer 1.0.0.8 "Light control_is1" = Light control - (1.0.0.2) "MozBackup" = MozBackup 1.5.1 "Mozilla Thunderbird 24.6.0 (x86 pl)" = Mozilla Thunderbird 24.6.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Notepad++" = Notepad++ "NPort Administration Suite_is1" = NPort Administration Suite Ver1.19 "Office14.SingleImage" = Microsoft Office 2010 dla Użytkowników Domowych i Małych Firm "Office14.VISIOR" = Microsoft Visio Professional 2010 "Opera 12.17.1863" = Opera 12.17 "Rinstrum View300" = Rinstrum View300 "Shop for HP Supplies" = Shop for HP Supplies "SIL Editor_is1" = SIL Editor 6.0.1.56 "TAP-Windows" = TAP-Windows 9.9.2 "TCP/IP Builder" = TCP/IP Builder 1.9 "TeamViewer 8" = TeamViewer 8 "Totalcmd" = Total Commander (Remove or Repair) "Wave Editor_is1" = Wave Editor 3.3.2.0 "WinRAR archiver" = WinRAR 5.01 (32-bitowy) "winscp3_is1" = WinSCP 5.5.1 "X-Scale Axis_is1" = X-Scale Axis 1.0.2.1 "X-Scale_is1" = X-Scale 1.3.5.2 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1283838448-4104211232-2969665015-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-05-28 09:14:00 | Computer Name = Michal-PC | Source = MsiInstaller | ID = 11316 Description = Error - 2014-05-28 10:14:00 | Computer Name = Michal-PC | Source = MsiInstaller | ID = 11316 Description = Error - 2014-05-29 03:14:01 | Computer Name = Michal-PC | Source = MsiInstaller | ID = 11316 Description = Error - 2014-05-29 03:14:48 | Computer Name = Michal-PC | Source = Google Update | ID = 1 Description = Error - 2014-05-29 03:16:36 | Computer Name = Michal-PC | Source = Winlogon | ID = 4004 Description = Proces usługi logowania systemu Windows nie może zakończyć procesów obecnie zalogowanego użytkownika. Error - 2014-05-29 03:20:07 | Computer Name = Michal-PC | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: Service_KMS.exe, wersja: 13.1.0.0, sygnatura czasowa: 0x5313ef48 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0x00000000 Przesunięcie błędu: 0x009101a0 Identyfikator procesu powodującego błąd: 0x864 Godzina uruchomienia aplikacji powodującej błąd: 0x01cf7b0e59230dce Ścieżka aplikacji powodującej błąd: C:\Program Files\KMSpico\Service_KMS.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: a8e43352-e701-11e3-972e-000272354332 Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error - 2014-05-29 04:14:37 | Computer Name = Michal-PC | Source = MsiInstaller | ID = 11316 Description = Error - 2014-05-29 05:15:34 | Computer Name = Michal-PC | Source = MsiInstaller | ID = 11316 Description = Error - 2014-05-29 06:14:00 | Computer Name = Michal-PC | Source = MsiInstaller | ID = 11316 Description = Error - 2014-05-29 06:32:26 | Computer Name = Michal-PC | Source = Microsoft-Windows-LocationProvider | ID = 2006 Description = There was an error with the Windows Location Provider database [ System Events ] Error - 2014-06-12 04:17:29 | Computer Name = Michal-PC | Source = DCOM | ID = 10010 Description = Error - 2014-06-13 02:44:08 | Computer Name = Michal-PC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi ADVANTECH DVP USB Driver z powodu następującego błędu: %%1058 Error - 2014-06-13 02:44:46 | Computer Name = Michal-PC | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą DYMO PnP Service. Error - 2014-06-13 02:44:46 | Computer Name = Michal-PC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi DYMO PnP Service z powodu następującego błędu: %%1053 Error - 2014-06-13 02:44:59 | Computer Name = Michal-PC | Source = Service Control Manager | ID = 7034 Description = Usługa Service KMSELDI niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-06-13 02:49:05 | Computer Name = Michal-PC | Source = DCOM | ID = 10010 Description = Error - 2014-06-13 03:55:23 | Computer Name = Michal-PC | Source = DCOM | ID = 10010 Description = Error - 2014-06-13 03:56:15 | Computer Name = Michal-PC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi ADVANTECH DVP USB Driver z powodu następującego błędu: %%1058 Error - 2014-06-13 03:58:40 | Computer Name = Michal-PC | Source = Service Control Manager | ID = 7034 Description = Usługa Service KMSELDI niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2014-06-13 04:02:23 | Computer Name = Michal-PC | Source = DCOM | ID = 10010 Description = < End of report >