OTL Extras logfile created on: 2014-09-06 15:26:26 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = G:\ Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17239) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,10 Gb Available Physical Memory | 55,04% Memory free 4,00 Gb Paging File | 3,05 Gb Available in Paging File | 76,35% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 117,19 Gb Total Space | 21,50 Gb Free Space | 18,34% Space Free | Partition Type: NTFS Drive D: | 115,69 Gb Total Space | 45,10 Gb Free Space | 38,98% Space Free | Partition Type: NTFS Drive G: | 3,74 Gb Total Space | 3,57 Gb Free Space | 95,39% Space Free | Partition Type: NTFS Computer Name: AWWMIU-KOMPUTER | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\System32\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\System32\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [ChomikBox.Upload] -- "C:\Program Files\ChomikBox\\ChomikBox.exe" -u"%1" ( ) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01182BFF-EA31-4D9E-B05F-CD818FC1A4D1}" = rport=139 | protocol=6 | dir=out | app=system | "{29996F11-60B3-4449-8114-4C538FA044BB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2DEAABA8-DF4F-4E1D-992C-DAC784A5996A}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{2FDE1810-C5FD-4913-9383-7BEC328CA126}" = lport=443 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe | "{3BEAD859-D9BB-43E0-888A-186E3A6B53F5}" = rport=138 | protocol=17 | dir=out | app=system | "{3FEB6179-5FD1-4043-8C69-08FCB447D522}" = rport=10243 | protocol=6 | dir=out | app=system | "{42DFF9F6-346C-4E82-A1B8-1F01AA8C7679}" = lport=445 | protocol=6 | dir=in | app=system | "{48D93C0F-AC83-4C01-80F5-6260356E1AF3}" = lport=137 | protocol=17 | dir=in | app=system | "{4BD0069A-32D9-4D81-87A7-5184A7E3C4A5}" = rport=445 | protocol=6 | dir=out | app=system | "{4F37E265-0DCA-4510-AC9A-A7EA3104F318}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5147972A-DDE9-4BEC-A86F-4C2BB7EB7F6C}" = lport=138 | protocol=17 | dir=in | app=system | "{52245A77-C252-467B-82F8-30B9E94F2279}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{555FCC74-BC7E-4BC4-B9BF-B1FB3F4951C5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5AAD11AD-5394-4BF9-AD79-DB4F32B49F2C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5D94F624-EB07-4A2A-BD24-84D072AF8693}" = lport=10243 | protocol=6 | dir=in | app=system | "{6064CA6D-8ED8-4A8D-BCA1-2AD267CAD917}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{67EDBFDF-E6C3-4039-8025-2C58EBD8D97F}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{769507F8-5F16-4A71-8CEA-98EC95F46627}" = rport=137 | protocol=17 | dir=out | app=system | "{788BB230-09C2-4F43-9A26-73F55623376B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{8B162A89-B253-47BE-AAC1-70CD1A3277CE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A6BE55A4-C70A-40DD-9925-CC22DF24DA85}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{ACF8AF77-8F86-4365-82C0-8165C4FACA95}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B0A72972-4C01-4F2C-B844-AAA5EADE470E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{B57950C9-4DC1-44F5-8D1C-236A6768EC03}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{B96A1BDE-8D9C-4EFB-91C0-A74EA2A2A0BF}" = lport=2869 | protocol=6 | dir=in | app=system | "{D6AB05F7-80ED-4BF7-9DE7-1BD5DF8B41B7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E985F8F7-0571-49BE-B925-49180F38CE64}" = lport=139 | protocol=6 | dir=in | app=system | "{EB51DCB3-D3B5-48F2-B729-9D35345612C0}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{ED637991-BE9D-42A3-87D5-49EAE30A43AF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F4BD6EC7-7F70-412C-B150-9398A00FB8C2}" = lport=80 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0BD88B2C-B3AC-4BD1-A6FD-B1D8F5276364}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe | "{1175AE26-19F3-40BF-9984-C99645EAE643}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{15794210-0E96-4A3C-AD48-7A6E135EC115}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{1B547584-14F5-4DE2-816A-7EC00D1B5D46}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe | "{1F86B79A-4500-4AE4-9455-6973ECD9F08D}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe | "{2241C08B-8E3F-4379-B3A0-A20C2FC3B24B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{258ACFD1-E207-47C5-B48E-1397679CC422}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe | "{28C4629C-ED90-45D8-91FD-3F37E0F210EE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{293942E1-E0E7-4F4B-B790-4C79E2BD9618}" = protocol=58 | dir=in | app=system | "{29D4ADC5-543A-4CF2-9306-8BEF86E36305}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe | "{2E2A9733-6701-4093-B09B-6D6E60864B2E}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe | "{2E5131CC-875C-475B-8E5C-D3ED4D7508C0}" = protocol=6 | dir=out | app=system | "{2FCD35E0-1F65-4549-B216-72F889350CD7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{326649CC-A345-48F5-ACD3-A51A60AC96C4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe | "{3481D9F9-23A8-4B81-A087-2832199D4DEC}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe | "{39E7A7F9-4501-4CDF-8ED5-D2655D8BED49}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3AD5FD92-D0C0-43B3-990E-7CA088B2A7F1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{45640044-8CE8-401E-A8C8-F11AB0FF81BD}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe | "{4B84F5FA-F2D0-4FF4-9B40-FB9F0D26FA64}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe | "{531415D8-4F93-4731-9368-ECC70E8A29EA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{5C0D24F5-65CE-4366-A05E-D81AA02D95EF}" = protocol=6 | dir=in | app=c:\program files\webzen\c9\c9.exe | "{5C9A135E-D669-4CFE-8B36-8EFFC61030D0}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{644AE33A-F6A0-473D-83F2-40C89E134C6F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | "{68D5DFBD-DE1D-45FE-9635-87C22675E5FA}" = protocol=17 | dir=in | app=c:\users\awwmiu\appdata\roaming\utorrent\utorrent.exe | "{696B211A-22B6-4A1D-8B2F-568DBFCEB28F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe | "{74F33334-885F-49FA-B197-68C79252D6E1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe | "{77286950-A887-488A-AA86-B8E80C2DD35F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{775A44D7-AED2-4D52-B604-40987DF8D554}" = protocol=6 | dir=in | app=c:\program files\hearthstone\hearthstone.exe | "{7818240C-FC48-40E7-8E50-E4ADBD6B7FBE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{7A9FDFC2-DC48-42E7-ADD6-D3BF35D1C2ED}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe | "{7E7BB45F-FA5F-474B-A8EF-BC7BDE769130}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{807870F4-7889-4BDA-AF20-7A8B363CF495}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{80CD2C56-D941-4339-B2FF-90A3DCCAE6A9}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe | "{81627A75-691F-4219-9CB9-B3AA30D72AB7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe | "{818A58D7-BD87-4109-9E40-6633F2160239}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{81E76F0C-D855-40FF-9FC7-922F9CDEF2D6}" = protocol=17 | dir=in | app=c:\program files\hearthstone\hearthstone.exe | "{82E50EB9-AF86-4755-B7FD-068B74E326D9}" = protocol=17 | dir=in | app=c:\program files\battle.net\battle.net.exe | "{84DB438D-2FD4-481F-AFF8-170E5201DE03}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{85D9DDB8-9A7A-47D2-8122-C525D0FBF8AF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{86A7269D-3F44-472E-923F-E2D380033697}" = protocol=17 | dir=in | app=c:\program files\webzen\c9\c9.exe | "{959F6B3A-072D-4C66-B998-31D538AA9287}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe | "{96478982-BF1A-4BE8-91AF-282BD919D026}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{96A7024B-1087-4BF5-8EEE-A02FDA0DE324}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{AE2480C5-AD24-4F1B-BDD4-73D490F7F903}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{B288E9A6-DBB7-4135-A6CE-7A564222CF9B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{B7D76FF4-3C6F-4511-ADF1-48C68B509EC3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe | "{BF9EBD3E-7BF9-455B-8B9F-E43BB09E1042}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe | "{C13E7E79-D3DC-4B76-97E9-CDDC949B8C1A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | "{D09207CF-A821-4971-9115-83678EB878A5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D16CF999-4612-4B60-B73B-B376EB9E5DB1}" = dir=in | app=c:\program files\itunes\itunes.exe | "{D5509421-4811-4248-BF10-9B37F152E657}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe | "{D665155E-2E73-4D9F-BC97-55AAA4D06DAE}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe | "{D87AD774-BFFA-4A7E-8E75-6158F2A84178}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe | "{DD42AE3D-92EE-477D-9B82-877DADF1334F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe | "{DE52AAE9-E200-486C-BE21-43E17FC4A2DD}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe | "{E03E933B-A229-4D65-81B0-E46584A5F5DE}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe | "{E3859BC6-A3EA-4E96-9A62-1CF3F77CA82B}" = protocol=6 | dir=in | app=c:\users\awwmiu\appdata\roaming\utorrent\utorrent.exe | "{E3C58560-8C7D-4C17-8762-F04F9C869DD7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{E41A1E58-9994-474D-8259-3BE517EAF903}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{EFD1CFA2-5FEA-4757-A94E-F146DBBECA26}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe | "{F01F9023-2180-4C6D-8790-BE30CEC04784}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe | "{F2C98C9E-812B-467A-9FBB-A95999FBA7AE}" = protocol=6 | dir=in | app=c:\program files\battle.net\battle.net.exe | "{F4F687F7-F6EA-46A9-B5B8-4408EA8FEAD7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F6D3EC33-93BC-4A4A-80AE-A9DB51C96BAD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FD4F80BD-3681-4EE1-B87E-E79C6C2F07EF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{FF68C634-E6D6-4CB3-B27C-C695EDC5AAF2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe | "TCP Query User{02D5B0A5-B834-4235-8E49-C2A81ADAC209}C:\users\bartek\appdata\local\facebook\video\skype\facebookvideocalling.exe" = protocol=6 | dir=in | app=c:\users\bartek\appdata\local\facebook\video\skype\facebookvideocalling.exe | "TCP Query User{6EC5DC76-5EA4-42EC-886A-7D388EF09E35}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "TCP Query User{7ECB7A96-0B3E-4484-9424-823CCA4E59C8}C:\users\awwmiu\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\awwmiu\appdata\roaming\spotify\spotify.exe | "TCP Query User{9DA27E61-27B3-46BB-91EF-EDAFE1505D63}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe | "TCP Query User{9E3E63D8-FF00-4055-BBEC-EF308D8692B4}C:\users\awwmiu\desktop\4death.pl\4death.pl.exe" = protocol=6 | dir=in | app=c:\users\awwmiu\desktop\4death.pl\4death.pl.exe | "TCP Query User{CCD9CE1A-98CB-4039-841A-9CEAD2A2673C}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{E0592C36-BC1C-43CB-8893-CCCAF7266F70}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{EA5F3CA3-A803-413E-9EFC-34891FAA12F0}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "UDP Query User{0347E8D0-7804-4A1A-A06C-A165274BA5F8}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "UDP Query User{3F204866-638C-41D5-886F-C4C4C82AE467}C:\users\awwmiu\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\awwmiu\appdata\roaming\spotify\spotify.exe | "UDP Query User{40CA7A26-6A91-4805-A9BD-07D7BEB64384}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{47640AFB-4A26-4C7E-9EE7-FAC8916818F8}C:\users\awwmiu\desktop\4death.pl\4death.pl.exe" = protocol=17 | dir=in | app=c:\users\awwmiu\desktop\4death.pl\4death.pl.exe | "UDP Query User{479BD802-E841-4804-AF85-BA9DEC43D981}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "UDP Query User{A0F5F3B4-0644-456D-900F-848B6C2C15E5}C:\users\bartek\appdata\local\facebook\video\skype\facebookvideocalling.exe" = protocol=17 | dir=in | app=c:\users\bartek\appdata\local\facebook\video\skype\facebookvideocalling.exe | "UDP Query User{DA49B78E-08E9-4D33-A302-F2F85B969AA6}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe | "UDP Query User{E57ABC15-AFB8-4A25-A41C-DE54EBB4884C}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant "{1356E5A2-D867-4C4F-BC67-E468AF8410E0}" = J3600 "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{1A6A6531-08FC-47AD-BAC4-C41497E71045}" = Nero 7 Essentials "{2091F234-EB58-4B80-8C96-8EB78C808CF7}" = Facebook Video Calling 3.1.0.521 "{24F5EAD9-7D46-4ED6-9F61-085A76ADF523}" = ProductContext "{269402AB-D600-4961-80EF-779CB346D29E}" = HP OfficeJet J3600 "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{2965EB43-0543-459A-81D9-F4F7CD812075}" = BPDSoftware "{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1 "{4F7B7598-88EA-4442-A54E-65EADCF06D97}" = ChomikBox "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status "{5D6D605B-E4B7-490B-A794-9284BC3D2A8B}" = Driver Detective "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update "{78002155-F025-4070-85B3-7C0453561701}" = Obsługa programów Apple "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16 "{7C8C2AA5-FFD4-4A10-970D-152B2AB49C57}" = AVG 2013 "{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX "{83210FBF-5553-439F-AC94-AF5E55E068C1}" = AVG 2013 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{86D04316-F49A-4AF2-B3F1-A1E943886CE7}" = iTunes "{887868A2-D6DE-3255-AA92-AA0B5A59B874}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8CE4CB34-8187-42A1-B597-517760BEE8EC}" = BPD_Scan "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski) "{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}" = Apple Mobile Device Support "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A50DE037-B5C0-4C8A-8049-B0C576B313D1}" = Google+ Auto Backup "{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{AC76BA86-7AD7-1045-7B44-A95000000001}" = Adobe Reader 9.5.0 - Polish "{AFDAB4B7-E5CE-4277-9ABB-8D8C5E12853D}" = 3600_Help "{B022D7B2-5CC6-46A2-8972-8EFA2172DE3D}" = Gwiezdne Wilki 2 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 337.88 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 337.88 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 337.88 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Sterownik kontrolera 3D Vision 337.88 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.13.1220 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 14.6.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 14.6.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.23 "{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe 1.8.15.1 "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C83B8B35-C2C4-3302-9A6E-C2AF1A59E8D6}" = Microsoft .NET Framework 4.5.1 (PLK) "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch "{E593C3B6-6C5A-4AFC-A4F7-CCB94F60C888}" = BPDSoftware_Ini "{F04C4F83-D9C7-408C-9DEB-D5526E72108C}" = Linkury Smartbar "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "Adobe Flash Player ActiveX" = Adobe Flash Player 14 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin "Any Video Converter_is1" = Any Video Converter 5.5.3 "Audacity_is1" = Audacity 2.0.5 "AVG" = AVG 2013 "Battle.net" = Battle.net "CCleaner" = CCleaner "DAEMON Tools Lite" = DAEMON Tools Lite "ENTERPRISE" = Microsoft Office Enterprise 2007 "Gadu-Gadu 10" = Gadu-Gadu 10 "Hearthstone" = Hearthstone "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "HPOCR" = OCR Software by I.R.I.S. 14.0 "iFunBox 2014_is1" = iFunBox 2014 (v3.1.562.425), iFunbox DevTeam "Mozilla Firefox 31.0 (x86 pl)" = Mozilla Firefox 31.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "MP3 Cutter_is1" = MP3 Cutter 1.9 "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "PhotoScape" = PhotoScape "Picasa 3" = Picasa 3 "Shop for HP Supplies" = Shop for HP Supplies "Tongbu2" = Tongbu Assistant 2.1.4.0 "VLC media player" = VLC media player 2.0.5 "WinRAR archiver" = WinRAR 4.11 (32-bitowy) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ OSession Events ] Error - 2013-06-06 18:40:29 | Computer Name = AwwMiu-Komputer | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 142 seconds with 60 seconds of active time. This session ended with a crash. < End of report >