OTL Extras logfile created on: 2014-09-17 19:18:01 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = G:\Downloads 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17280) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 15,99 Gb Total Physical Memory | 13,05 Gb Available Physical Memory | 81,62% Memory free 31,98 Gb Paging File | 28,51 Gb Available in Paging File | 89,14% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 80,08 Gb Total Space | 17,92 Gb Free Space | 22,38% Space Free | Partition Type: NTFS Drive D: | 39,06 Gb Total Space | 23,20 Gb Free Space | 59,38% Space Free | Partition Type: NTFS Drive E: | 106,89 Gb Total Space | 106,88 Gb Free Space | 100,00% Space Free | Partition Type: exFAT Drive G: | 349,10 Gb Total Space | 111,31 Gb Free Space | 31,88% Space Free | Partition Type: NTFS Drive I: | 465,65 Gb Total Space | 220,88 Gb Free Space | 47,44% Space Free | Partition Type: FAT32 Computer Name: DESKTOP-PC | User Name: ctarx | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2349933241-316113571-2204629777-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [runas] -- cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [runas] -- cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{030CBA4A-94D7-41AE-9BC2-84E97D651A34}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{05F5B6F0-1FD9-453A-910A-F50CB1A82752}" = lport=57413 | protocol=6 | dir=in | name=pando media booster | "{0E7C215A-B779-458A-90DE-89716CDF9804}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{12CBFC7F-81B2-47C6-90F4-42E6D409A028}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{1500C335-11E6-4B31-936F-AAC77F5667F2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{1F783375-F1E6-4FCE-AC43-48EB04D4447F}" = lport=57413 | protocol=6 | dir=in | name=pando media booster | "{306678E0-F6D5-4C6D-A179-5B827BAD92FD}" = rport=137 | protocol=17 | dir=out | app=system | "{31EE771C-DCAC-4ACF-9E12-CBCE2786DD18}" = lport=138 | protocol=17 | dir=in | app=system | "{33D7CA39-5D56-4A87-8E83-187C719A5366}" = rport=139 | protocol=6 | dir=out | app=system | "{45C2789A-A0E7-47E5-81AC-5625180D52D2}" = rport=445 | protocol=6 | dir=out | app=system | "{486D489E-0523-4CC7-9458-7C6121E53BEE}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{58E43337-9AAE-4DF1-9F43-3A7F3526C6B6}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{65E672CC-1F05-4C6B-B02F-4EC9A62E784D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6BA77A9A-764C-4874-B5D1-E0EA8341A410}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{6C8B13FA-A439-4609-BBCD-9E6F141A0019}" = lport=2869 | protocol=6 | dir=in | app=system | "{6DAE56C6-679A-4E4A-85E4-CE1EC2F020E4}" = lport=445 | protocol=6 | dir=in | app=system | "{6E052DED-0716-4454-9754-A176DAB0B620}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6E7AC32C-92BA-49BA-996D-52AA2185BA2E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6E7CEBC0-B78A-43D7-9B64-74D8FE6B0BB5}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{76170FCA-2D5B-4FC7-A8AF-5AB5F6DBBE3B}" = rport=10243 | protocol=6 | dir=out | app=system | "{8E224B13-425E-41D1-B191-9FE1EE955E85}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{94C267B7-423E-455D-B3C4-EACF724F2BCA}" = lport=137 | protocol=17 | dir=in | app=system | "{9B7A98BC-55AA-4573-9015-4F42B3EBB166}" = lport=10243 | protocol=6 | dir=in | app=system | "{9DF45F4F-C0DD-43E3-A26F-6518D2F0A5CA}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{A343BBF1-CC30-4EBD-A854-D656BF4E97CE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{B65B1AC8-6A50-4FC2-B945-8B0FE76A1B94}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C4634D2B-95F2-4B97-B776-311C9FD3CB84}" = lport=139 | protocol=6 | dir=in | app=system | "{C677FF0D-5915-4A8C-B259-B523A06A0864}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{D0CEB2A9-E411-4AA6-86D4-02D99F222888}" = lport=57413 | protocol=17 | dir=in | name=pando media booster | "{E058B5DF-2ADF-4EC0-B002-CA05F4686EE0}" = lport=57413 | protocol=17 | dir=in | name=pando media booster | "{E43C9826-89DB-4EDA-BA5D-ECCA6DE9DC06}" = rport=138 | protocol=17 | dir=out | app=system | "{F2AB02EB-3495-4D07-9415-1F5420A378CF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FDD3152C-B99C-46D9-AD02-A14DD179AC41}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FE7770C9-0906-498C-AF10-B3071F8E9252}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{044BC37C-E864-4372-9FDE-BC2689D3A499}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{06FCA246-A299-45C5-9638-5057E1B0B04E}" = protocol=17 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{0DDCE24D-0FEF-46CB-9CA2-83058D31CEA1}" = protocol=6 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{0E6BB0BA-2794-4BD2-A765-BB7725973ADB}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3109\agent.exe | "{11B23657-13E5-4AE6-A30A-8D0B7DBD3153}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3109\agent.exe | "{15E8F302-755F-4013-8133-24D9B9A7A2FD}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | "{1FA956CA-DF16-452F-A664-4865B8D32FE2}" = protocol=6 | dir=out | app=system | "{214160FF-107D-4456-9CDB-B48298E3F55C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3016D238-D341-4C9B-83C4-C676262830D8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe | "{34C1D7F7-7639-41D2-B9FE-4DFA7940C5AF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe | "{369EBE23-9BD6-430A-9154-A5EC9A27E509}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | "{41A05EE1-9101-4CB1-8C01-E0916BBB7FBC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | "{41BF960F-EFAE-4537-A660-1BF9FF3B63C1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{450E3F1C-4457-41AE-8E1F-EDE76BF278B6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{4A158263-4EF7-4841-9EBA-97E3F0A98555}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{4BE46DEC-6E1E-43F1-A650-A02017A5F449}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4F70A3DA-0130-470F-928E-E138572433FE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{5C306D57-F931-434A-91D9-04DBDC658C89}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{6827C62E-E1CF-4EEE-BEEE-01EB0AD1D065}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | "{687DC275-E762-4209-9AF0-0AB49369ED19}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{68F45CF4-B655-417E-9684-12A2C6F158BE}" = protocol=17 | dir=in | app=g:\hearthstone\hearthstone.exe | "{6A351787-70BE-426F-AF8A-EA2ED2004E8F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe | "{6BD4FA50-6626-4465-8E09-B326CD3B204B}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{6CAABB78-34F3-4BC8-9CC2-591353D97EE9}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{6EBC8DEA-0923-40CF-8C5E-EE8A79F94438}" = protocol=6 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{7142195B-9803-4491-9625-F922F53C84BA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe | "{743FCF7E-E83C-4F34-AF52-0CB34D9F267B}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{7501BE2F-8320-422F-B35C-D0711F4A69E4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{7CBD5925-6B44-4059-AC51-8B1440530833}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{7E2B27B9-0AC5-4709-A839-8D375F8A61CE}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{802421B6-0877-4BDE-AFD1-D4BDE5358F56}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{847E4E08-BDE1-4EC5-B5D3-E9041A2B8E17}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | "{84D5BA1F-F752-4FA6-8675-D49287512FFB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{86E7DC90-345F-48C4-9A3B-7F72700B2164}" = protocol=6 | dir=in | app=g:\hearthstone\hearthstone.exe | "{8F9F45D6-9963-493C-9B62-39A57A49F6ED}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{9035049D-4D44-486C-8B81-5B3E60709E35}" = protocol=17 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{95B339CC-7032-4886-877D-F134CD6371E7}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe | "{A07FCCFE-1703-4404-B8E7-4D7A33195E04}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{A936954B-80FA-40FD-BBC6-5A4A09EFCB9E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{B1583D59-AD89-4CF6-B6FD-882B7D806AD1}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{B4C221DA-F914-4A16-A0F5-16BCFE736A1F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{B5B2FEAE-BEC5-481E-97BF-F0DED3AA7E2A}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "{BCA464B8-782E-4D68-8D22-C080A2D20236}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe | "{BD7A0B04-89C6-46C9-AA21-6C60DAB6E16E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{BEE83EC2-FF06-4661-9496-A57B60FCB259}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{C4C5D959-2B87-4462-95CE-35A628933BA7}" = protocol=6 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{C6AB0147-0059-4F21-A792-8A2C650DB92B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D134A2BA-BD28-4033-A695-6538CA3CED34}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | "{D328081D-3725-4398-8034-4FA16B7ACBAE}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{D84DDC4A-1020-44F6-96A2-F3EC55EAF376}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E1B89807-7CA9-4B7A-9DBD-2FB34B4795F2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{E55324EE-4AF4-4020-92C9-D08FC823EB38}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{E650918B-9BAE-4269-9938-8C8EF956A432}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{EC712FB3-8E62-43CE-B0B0-D59847DE8B26}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{ED301756-7380-4E03-A2BA-9FA2D990A20F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{EF0644ED-5AAB-47F1-AC42-E9FA4403F966}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{F0B33C78-D9BE-4D28-BAE1-E2833855CA3C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{F3318BA7-89A6-4564-8B16-214A0574B400}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe | "{F8729F2B-5755-4D13-8D97-A6269ACA903C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe | "{FB15DAD4-62B4-458E-B7A7-96EC7258B641}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "{FC57D6EE-589D-450A-A54C-A5D4D28D77E4}" = protocol=17 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{FC6CD18B-407C-42DB-892E-41C43EDB92E0}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "TCP Query User{76F1057B-8438-4370-9FD2-4CBE302D9D57}C:\program files\transmission\transmission-qt.exe" = protocol=6 | dir=in | app=c:\program files\transmission\transmission-qt.exe | "TCP Query User{893AD729-3EF3-433F-88AC-A304F3EB51E2}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "TCP Query User{B29FEE65-E4C6-46BF-B58E-B28B0403A017}C:\program files (x86)\libreoffice 4\program\soffice.bin" = protocol=6 | dir=in | app=c:\program files (x86)\libreoffice 4\program\soffice.bin | "TCP Query User{BC3B0A9C-736B-4DC9-8707-C69823627E44}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "UDP Query User{4F82DC5D-2D33-4467-86CF-D75AFBF4E98C}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "UDP Query User{C73E6045-E623-4CCE-A94E-88F7BF3C4E87}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "UDP Query User{D9E2436A-9538-4C12-AEDD-E481C656ABF4}C:\program files\transmission\transmission-qt.exe" = protocol=17 | dir=in | app=c:\program files\transmission\transmission-qt.exe | "UDP Query User{EBB48381-F993-4922-8029-1BDF56BC9954}C:\program files (x86)\libreoffice 4\program\soffice.bin" = protocol=17 | dir=in | app=c:\program files (x86)\libreoffice 4\program\soffice.bin | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1DF5019A-68B5-4ba1-8E59-E185C7B7FF11}" = WTW 0.9.18.3794 IM "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{23F2C78C-E131-4CA0-8F84-3473FB7728BA}" = Microsoft Security Client "{43B74FAB-FB58-447D-8D3A-5F638AF36FD1}" = Netzmanager "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{6E5159B4-A519-41EF-80EF-AD58371515DF}" = Eraser 6.0.10.2620 "{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64) "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 340.52 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 340.52 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 340.52 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.1.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 340.50 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.13.1220 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 15.3.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.30.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 15.3.33 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.23 "{B678797F-DF38-4556-8A31-8B818E261868}" = Apple Mobile Device Support "{F46AA0F1-E284-4878-A462-5F11B9166C0E}" = iTunes "CCleaner" = CCleaner "CPUID HWMonitor_is1" = CPUID HWMonitor 1.25 "EPSON SX430 Series" = EPSON SX430 Series Printer Uninstall "Microsoft Security Client" = Microsoft Security Essentials "Speccy" = Speccy "Totalcmd64" = Total Commander 64-bit (Remove or Repair) "Transmission-Qt" = Transmission-Qt [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1B2EC53E-FB7C-40E7-A4E8-504171771FC0}" = MechWarrior Online "{2BA9320D-E061-4C71-ACCB-AC0E9D4FC82B}" = Polar Daemon "{320453EE-6AEA-4E1A-8E64-72F33C0C928F}" = Polar WebSync "{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer "{3B35725F-C623-4A1E-B5CC-99C0868679E3}" = Smart 6 B10.0422.1 "{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B10.0427.1 "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print "{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B10.0521.1 "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1" = Panda USB Vaccine 1.0.1.4 "{65BC2BDA-D828-4596-99E4-A8799C45C84C}" = EMET 4.1 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{73bcb521-8936-42d7-ad00-ec2bb399e26c}" = MechWarrior Online "{78002155-F025-4070-85B3-7C0453561701}" = Obsługa programów Apple "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16 "{7D72DAFF-DCB2-437B-BC22-4B2ABF21462B}" = Private Internet Access Support Files "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7 "{8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}" = Epson Event Manager "{93AD8CBD-C32E-4318-90BB-A294BE2D712C}" = LibreOffice 4.2.5.2 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A02D7029-C4EF-44C1-9FD4-C0D3CA518113}" = Epson Easy Photo Print 2 "{A2F991E7-DDCD-42B7-AFEC-47789A099FDC}" = Browser Configuration Utility "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) "{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS "{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}" = Curse "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint "ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint "Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX "Battle.net" = Battle.net "CMUDPro" = CMUDPro 3.34 "EPSON Scanner" = EPSON Scan "Foxit Reader_is1" = Foxit Reader "Google Chrome" = Google Chrome "Hearthstone" = Hearthstone "InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B10.0521.1 "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "IrfanView" = IrfanView (remove only) "KeePassPasswordSafe2_is1" = KeePass Password Safe 2.27 "NapiProjekt_is1" = NapiProjekt (2.2.0.2399) "Netzmanager" = Netzmanager "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Rainmeter" = Rainmeter "Steam" = Steam "Steam App 570" = Dota 2 "TrueCrypt" = TrueCrypt "UltraUXThemePatcher" = UltraUXThemePatcher "VLC media player" = VLC media player "WinPcapInst" = WinPcap 4.1.3 "Wireshark" = Wireshark 1.12.0 (64-bit) [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2349933241-316113571-2204629777-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "101a9f93b8f0bb6f" = Curse Client [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-09-10 13:29:56 | Computer Name = desktop-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-09-14 11:51:36 | Computer Name = desktop-PC | Source = Application Error | ID = 1000 Description = Faulting application name: isuspm.exe, version: 4.10.100.25539, time stamp: 0x4213c5f3 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0018fce0 Faulting process id: 0x1528 Faulting application start time: 0x01cfd033c384c5ad Faulting application path: c:\program files (x86)\common files\installshield\updateservice\isuspm.exe Faulting module path: unknown Report Id: 01445b90-3c27-11e4-9e67-1c6f65374341 Error - 2014-09-14 11:52:03 | Computer Name = desktop-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-09-15 07:31:34 | Computer Name = desktop-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-09-15 07:59:59 | Computer Name = desktop-PC | Source = VSS | ID = 8194 Description = Error - 2014-09-16 08:24:15 | Computer Name = desktop-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-09-16 08:52:36 | Computer Name = desktop-PC | Source = VSS | ID = 8194 Description = Error - 2014-09-17 07:15:09 | Computer Name = desktop-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-09-17 07:43:29 | Computer Name = desktop-PC | Source = VSS | ID = 8194 Description = Error - 2014-09-17 13:02:30 | Computer Name = desktop-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2014-06-21 06:16:36 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-06-21 06:41:11 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-06-23 12:08:09 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-06-23 12:14:26 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-06-23 12:14:31 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-06-24 06:03:47 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-07-07 07:43:42 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-07-11 02:30:18 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-07-11 10:05:11 | Computer Name = desktop-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 2014-07-12 09:55:36 | Computer Name = desktop-PC | Source = Microsoft-Windows-Directory-Services-SAM | ID = 12291 Description = SAM failed to start the TCP/IP or SPX/IPX listening thread < End of report >