OTL Extras logfile created on: 2014-09-13 12:58:31 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Daniel\Desktop 64bit- Professional (Version = 6.3.9600) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17278) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,96 Gb Total Physical Memory | 6,92 Gb Available Physical Memory | 86,92% Memory free 9,84 Gb Paging File | 8,90 Gb Available in Paging File | 90,44% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 119,24 Gb Total Space | 94,34 Gb Free Space | 79,12% Space Free | Partition Type: NTFS Drive X: | 465,41 Gb Total Space | 131,30 Gb Free Space | 28,21% Space Free | Partition Type: NTFS Computer Name: CORASIRPC | User Name: Daniel | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{039E23E6-056A-462A-B6BF-17FE33F2F5A7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{0697CDE7-2F18-4761-84C2-577931B8320F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{10F983D2-0564-4BDE-8C41-A929B5661369}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1D4613E0-EA3D-43C7-8251-73EA5D4983D7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3111D299-EEA6-42D6-A2AB-EFF3F3AC4993}" = lport=139 | protocol=6 | dir=in | app=system | "{51B1F675-4FCD-412F-9A7C-64866926D555}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{59F5CF7E-EA21-4F9C-A947-B3963C66DE79}" = rport=445 | protocol=6 | dir=out | app=system | "{68F64774-BCDD-4427-BF12-4E4C21B94935}" = rport=139 | protocol=6 | dir=out | app=system | "{6CAC652E-6548-4ECC-BDDE-9E44B87BE59A}" = lport=137 | protocol=17 | dir=in | app=system | "{71212E19-BD36-4E16-80BD-E54136A06296}" = rport=138 | protocol=17 | dir=out | app=system | "{7F478E58-9969-45F7-B59B-DCF9F95B6647}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{802880FE-67AA-4D14-92E6-0F0B0790F0BD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A0AD0A9E-CF8A-400C-A89E-E0E46C7663D8}" = lport=2869 | protocol=6 | dir=in | app=system | "{AE758FFD-BFF3-4BB5-A726-9112BA30E0E0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{AF3CCFAD-A580-40ED-B2AA-1DAD537DF10A}" = lport=445 | protocol=6 | dir=in | app=system | "{C150C286-71FE-46C9-9AD1-7F8CB493222A}" = rport=10243 | protocol=6 | dir=out | app=system | "{D15B6A69-400E-4FB5-976E-2E1E7C08D6DD}" = lport=10243 | protocol=6 | dir=in | app=system | "{DB6087AF-8D79-4E9A-BA20-6AE569CF79B6}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{EA63519C-6A10-4F99-A370-0B2AAE0EB7EF}" = lport=138 | protocol=17 | dir=in | app=system | "{F400EF6F-308A-4845-93B5-A3D2994DDBC5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{FDE393B8-CEFA-4F8C-8614-EEC1EBC230B2}" = rport=137 | protocol=17 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{064EFD4D-148F-4568-A505-76DBECC632BA}" = dir=in | app=x:\pliki programów (x64)\itunes\itunes.exe | "{079EE68C-EB79-47B7-AC11-33A417470FDE}" = protocol=6 | dir=in | app=x:\steam\steam.exe | "{0F731173-F324-4C86-AAD6-B79BCF2768C5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{10575DE7-8360-455D-B808-7F39EA73B0CE}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.315_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{12C33C96-E7BA-49EF-ADC0-66A5E3A4686A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{14A0C952-D578-46D5-AE2B-34EB282D5B8B}" = dir=out | name=@{microsoft.bingsports_3.0.2.317_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{1B78BE8A-E2E4-4BED-8776-3969AE8183DB}" = dir=in | name=onenote | "{1D0CB46B-AE91-4425-B169-602B8BDBA697}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{3730A996-CF6F-47ED-AC31-FC777873C7D7}" = dir=out | name=@{microsoft.bingtravel_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{39AE67ED-DBAB-4FF6-A41D-52E94F7A42C3}" = dir=out | name=@{microsoft.bingweather_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | "{3B8372F3-88B7-43B1-99A2-27336579C47C}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{3F03C7D1-043A-4FC2-8BCC-103125555738}" = dir=out | name=@{microsoft.bingfinance_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{48AC55C5-01CD-4DB5-9F7A-40793FEC77F8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{524E2C85-1C1D-4193-8797-7C2E7CB0A0E4}" = dir=out | name=onenote | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{551C463E-BAF1-4133-A0C1-75620FD98C3E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{5823494D-5EC8-436F-834F-F52F0887D4CF}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{5BCB968F-C093-4C4B-ABFE-2350D9F2C7FF}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{61A9054A-EFB0-4B05-88A1-58B6B4CF7DAA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{653D153B-3D3F-44A5-B7D0-E41CCEA50046}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{6B7EED23-EFFA-4252-AE4C-C7B72AEC0B2B}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{7B9321B5-A878-4133-A991-CD6F7C7E8721}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8003323C-51BB-4F8E-BE1E-1CC460A552C1}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{8E87BDA2-EC73-4EDE-92DF-776E694E2A2D}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{976ED9E3-AF8C-465E-8CC7-89098C8876AC}" = dir=out | name=windows_ie_ac_001 | "{9AA57CD5-8920-4CDD-BD98-AF69A80F86CB}" = dir=out | name=skype | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{A1A73CCD-8AF4-4C7C-A4A4-35B93CA23440}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A4D86932-9D90-49C9-B76D-815FE8172582}" = protocol=17 | dir=in | app=x:\steam\bin\steamwebhelper.exe | "{A6778694-0AEC-436E-9962-A97B888EC7B7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{AAD832CE-5F18-4DEB-AE9E-2DCBE0F476B8}" = dir=out | name=@{microsoft.zunemusic_2.2.931.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{AD10FF5A-0E5C-4EE2-BD38-9B4DF3C59E15}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{B161000D-4998-4559-B920-1B6A2EB8CF39}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{B40DDC29-F97B-4163-875F-23923B4820DA}" = protocol=6 | dir=out | app=system | "{B48C18D6-7F60-4226-9A7C-B60D242012B4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B58B9275-2124-4E93-ABDC-53DCD481784A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{B5A6542E-C20C-4603-839F-093E012C55A5}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{B96EEBDD-9105-4F37-9479-88B9CDF134FB}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{BA91FD98-0602-44BE-9ECC-D16F1A3E2C65}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BBF40576-DA47-416D-8DE6-CE1ADC5DDDB9}" = dir=out | name=@{microsoft.bingnews_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{BD4DD722-7889-4DB9-ACC4-7234F8B92BF0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{C45E8490-69BE-4B6F-8314-77B4EB668A04}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C7947E63-1802-4C1C-9026-BB0E17DEF6B8}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{CB49DD6C-F8D0-449A-A6C5-4D8746EA0298}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{D6696A90-D060-4E04-8177-3BCBDFA40653}" = protocol=6 | dir=in | app=x:\steam\bin\steamwebhelper.exe | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{D93CFA26-1855-4C60-B547-74918DF77463}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.313_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{E6D279C0-05B2-4C90-BF19-31ABAEEE71F9}" = dir=out | name=@{microsoft.zunevideo_2.6.283.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{E7727591-5841-41D2-B522-C6E41CF86069}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{EB8D51C5-220B-4EE3-858E-983B2914317B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{EE718CFF-756A-4439-8C23-0B6AEDB1CE94}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{EF0ADC26-6084-4111-B012-80BF3AB55222}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{F8B14FDE-40DE-4EFC-A4A6-D43F16CF947D}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{F9B32205-C1C2-428C-A903-2B1AB20DFE10}" = dir=in | name=skype | "{FABD7962-1E62-4090-B285-18245DF2C6EC}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FBA9D006-F86D-45BD-8300-1FA40C7DBCF0}" = protocol=17 | dir=in | app=x:\steam\steam.exe | "{FDEBC2E5-9047-4EC4-8B7A-0E6604811F87}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "TCP Query User{6827C6C5-10F1-4F74-A4AB-99595DD2D2CA}C:\windows\syswow64\rundll32.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\rundll32.exe | "TCP Query User{82C32622-D2A1-47A9-BB8B-55CFCB8DD968}C:\users\daniel\appdata\local\temp\low\i8w7.dll" = protocol=6 | dir=in | app=c:\users\daniel\appdata\local\temp\low\i8w7.dll | "UDP Query User{48BCBC2E-6939-4DDE-816A-B241E673E0A5}C:\windows\syswow64\rundll32.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\rundll32.exe | "UDP Query User{5F279C1A-C403-49EE-A188-2DE656AEA6FE}C:\users\daniel\appdata\local\temp\low\i8w7.dll" = protocol=17 | dir=in | app=c:\users\daniel\appdata\local\temp\low\i8w7.dll | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0D0F73C4-2DCE-4873-BC56-34E71BDAFEFA}" = ESET NOD32 Antivirus "{149FBD36-6E9E-2035-42B0-59D91714138D}" = AMD Fuel "{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.7.6 (64-bit) "{6119B3A6-3603-9695-0398-CDF2AF0A13F8}" = AMD Catalyst Install Manager "{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}" = Apple Mobile Device Support "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{77DE5105-D05E-448C-96CB-7FA381903753}" = iTunes "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{ABD878B8-E7E3-2BC4-5A95-478133DCFFC3}" = AMD Accelerated Video Transcoding "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{D3485211-6ACA-8BC3-1AAB-29FC5552C454}" = ccc-utility64 "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "WinRAR archiver" = WinRAR 5.11 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{031F80EB-1FE5-45EF-9DE2-E2F5AF01259F}" = CCC Help Spanish "{0B15A8C3-3B8A-F229-A880-82EA62908425}" = CCC Help Dutch "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{1A6752E1-966B-9D1F-F6B7-DDBCA6FC87ED}" = CCC Help Russian "{2058DA53-D5F2-D8D9-7325-39B0E367D1E1}" = CCC Help Swedish "{2090B6D0-E025-5A67-9838-8F1D5768E643}" = CCC Help Chinese Standard "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{25A3B953-1423-3F15-640E-B620DD0F419A}" = Catalyst Control Center - Branding "{2AD4FF67-43E9-77AD-D90C-584F950E2D12}" = CCC Help French "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{3A577334-7C90-55BC-1878-F5862FA268B2}" = CCC Help Korean "{3BF289E3-933B-F421-3B59-F6BB0D285B09}" = CCC Help Hungarian "{3CB6BA0C-6BC5-E543-221A-AA4DEBB6F4B5}" = CCC Help Polish "{430E2D32-6EA9-E6E4-80A1-84047694A45B}" = CCC Help Czech "{4A6A8D33-09CD-FD44-4BF0-999E8A6E93C8}" = CCC Help Italian "{6EBDE2A2-0CFB-9134-A859-68A0002B3FA6}" = CCC Help Thai "{71B53BA8-4BE3-49AF-BC3E-07F392008788}" = ASUS Xonar D2 Audio "{769E98DC-2BB0-83A7-51C9-306F30232345}" = Catalyst Control Center Graphics Previews Common "{78002155-F025-4070-85B3-7C0453561701}" = Obsługa programów Apple "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{80680785-2EE1-053F-9CD3-4B2C904596EE}" = Catalyst Control Center InstallProxy "{8181B50E-0E33-DE07-AAB2-E71BBBDBF288}" = CCC Help Portuguese "{83FB054C-7DA5-1C76-BFB2-423426DC35BB}" = AMD Catalyst Control Center "{8A640069-9784-701E-AC8E-84F62C42D1A3}" = CCC Help English "{93098E43-2743-1551-447F-2699E9591E9C}" = CCC Help Danish "{A3703A3B-FDCF-4349-4B2E-A189A2B90B51}" = CCC Help Chinese Traditional "{A619A488-A4BA-F2A0-72FA-4C484B93DC0F}" = CCC Help Greek "{C4799AAA-CE52-D2F1-63C8-E6D5106C78E0}" = CCC Help Norwegian "{C6182116-5F2D-9949-B42B-06073E86A98A}" = CCC Help German "{CC6C7F05-AF23-65BD-702D-705EAB723578}" = CCC Help Japanese "{D5B7F1A3-2CA6-4C5C-EFB6-4AA5772F5310}" = CCC Help Turkish "{DBA6B3EF-A8C0-4EB2-9554-3A7879838580}" = Catalyst Control Center Localization All "{F4A6308C-55E6-57DF-95BB-AEEF374B469A}" = CCC Help Finnish "{F543B0F9-D1F9-25D1-993C-8430BEC9D889}" = Catalyst Control Center InstallProxy "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin "Mozilla Firefox 32.0.1 (x86 pl)" = Mozilla Firefox 32.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "OpenAL" = OpenAL "Raptr" = Raptr "Steam" = Steam "Steam App 221100" = DayZ [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-09-12 11:16:32 | Computer Name = CorasirPc | Source = Software Protection Platform Service | ID = 1014 Description = Pozyskanie licencji użytkowania nie powiodło się. hr=0xC004C020 Identyfikator SKU=354d964a-56e7-43c5-a93f-287a7a750bd4 Error - 2014-09-12 11:16:32 | Computer Name = CorasirPc | Source = Software Protection Platform Service | ID = 8198 Description = Aktywacja licencji (slui.exe) nie powiodła się, kod błędu: hr=0xC004C020 Argumenty wiersza polecenia: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=354d964a-56e7-43c5-a93f-287a7a750bd4;NotificationInterval=1440;Trigger=TimerEvent Error - 2014-09-12 11:34:46 | Computer Name = CorasirPc | Source = Software Protection Platform Service | ID = 1062 Description = Przenoszenie identyfikatora potwierdzenia nie powiodło się. 0xC004F031 Identyfikator jednostki magazynowej = 354d964a-56e7-43c5-a93f-287a7a750bd4 Error - 2014-09-12 11:50:08 | Computer Name = CorasirPc | Source = Software Protection Platform Service | ID = 1062 Description = Przenoszenie identyfikatora potwierdzenia nie powiodło się. 0xC004F031 Identyfikator jednostki magazynowej = 354d964a-56e7-43c5-a93f-287a7a750bd4 Error - 2014-09-12 11:51:01 | Computer Name = CorasirPc | Source = Software Protection Platform Service | ID = 1062 Description = Przenoszenie identyfikatora potwierdzenia nie powiodło się. 0xC004F031 Identyfikator jednostki magazynowej = 354d964a-56e7-43c5-a93f-287a7a750bd4 Error - 2014-09-12 13:53:01 | Computer Name = CorasirPc | Source = Microsoft-Windows-RestartManager | ID = 10007 Description = Nie można ponownie uruchomić aplikacji lub usługi AMD FUEL Service. Error - 2014-09-12 14:09:18 | Computer Name = CorasirPc | Source = MsiInstaller | ID = 11935 Description = Error - 2014-09-12 18:42:42 | Computer Name = CorasirPc | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 2014-09-12 18:42:42 | Computer Name = CorasirPc | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1969 Error - 2014-09-12 18:42:42 | Computer Name = CorasirPc | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1969 [ System Events ] Error - 2014-09-13 07:00:13 | Computer Name = CorasirPc | Source = DCOM | ID = 10005 Description = Error - 2014-09-13 07:00:16 | Computer Name = CorasirPc | Source = DCOM | ID = 10005 Description = Error - 2014-09-13 07:00:16 | Computer Name = CorasirPc | Source = DCOM | ID = 10005 Description = Error - 2014-09-13 07:00:18 | Computer Name = CorasirPc | Source = DCOM | ID = 10005 Description = Error - 2014-09-13 07:00:25 | Computer Name = CorasirPc | Source = DCOM | ID = 10005 Description = Error - 2014-09-13 07:00:38 | Computer Name = CorasirPc | Source = Service Control Manager | ID = 7001 Description = Usługa Computer Browser zależy od usługi Server, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-09-13 07:00:38 | Computer Name = CorasirPc | Source = Service Control Manager | ID = 7001 Description = Usługa Computer Browser zależy od usługi Server, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-09-13 07:00:38 | Computer Name = CorasirPc | Source = Service Control Manager | ID = 7001 Description = Usługa Computer Browser zależy od usługi Server, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-09-13 07:01:17 | Computer Name = CorasirPc | Source = DCOM | ID = 10005 Description = Error - 2014-09-13 07:02:09 | Computer Name = CorasirPc | Source = DCOM | ID = 10005 Description = < End of report >