OTL Extras logfile created on: 2014-12-08 23:51:38 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\user\Desktop\Wszystkie te syfy 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17420) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,89 Gb Total Physical Memory | 5,10 Gb Available Physical Memory | 64,58% Memory free 15,78 Gb Paging File | 12,60 Gb Available in Paging File | 79,84% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 169,70 Gb Total Space | 111,34 Gb Free Space | 65,61% Space Free | Partition Type: NTFS Drive E: | 390,62 Gb Total Space | 263,48 Gb Free Space | 67,45% Space Free | Partition Type: NTFS Drive F: | 371,09 Gb Total Space | 370,53 Gb Free Space | 99,85% Space Free | Partition Type: NTFS Computer Name: USER-KOMPUTER | User Name: user | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3871900662-1698721075-3235340947-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0A4AFF27-8AA6-4851-8B01-8359EA65E127}" = rport=139 | protocol=6 | dir=out | app=system | "{15093307-747F-482E-A109-AC0DF75ECDD7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{178B8358-0699-4CB5-ACFC-645F716F4B56}" = rport=137 | protocol=17 | dir=out | app=system | "{2170DDD3-6CE6-403A-81B5-744B9E950D8D}" = rport=445 | protocol=6 | dir=out | app=system | "{21FDBD05-A91C-4686-A45B-7CD49962598D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3A29F754-11C0-4EC1-9A0B-118272388F1D}" = rport=138 | protocol=17 | dir=out | app=system | "{503F6AF3-5982-48FE-AC0D-6F359DD57A19}" = lport=138 | protocol=17 | dir=in | app=system | "{749886A0-DC88-4DA7-BC25-17057FEE9E9E}" = rport=10243 | protocol=6 | dir=out | app=system | "{77DAA7A2-131B-4122-8BCB-17B0CE275179}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{7A8D9EA9-773A-4B12-9EE7-75DE102554F3}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{7C55BE98-1EEC-4F36-9301-CD8A9D0A1F33}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8B2BEA87-C9BC-403F-AEC9-128935062153}" = lport=2869 | protocol=6 | dir=in | app=system | "{8BDD816A-6780-4E23-9FF9-88C647A6DF30}" = lport=137 | protocol=17 | dir=in | app=system | "{95D3AABC-7C78-4384-AD75-C37A111D4A7B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A18A8ED3-6AAA-4A51-B783-B538C608E603}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A86A5D8A-75A6-416A-8E2C-B85A8274ADD7}" = lport=445 | protocol=6 | dir=in | app=system | "{AC1D5C0A-B2AD-4339-A727-6B79A70BDEDF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B9AC4E25-1E6F-44EB-85CE-95A9AE385DB4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D4DE6A75-7B9D-4CC3-A29A-153077E36F48}" = lport=139 | protocol=6 | dir=in | app=system | "{E5425523-5325-4A3C-8740-858A6BF4653B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E94C7114-3473-4070-97D2-E3CF38C569DE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{EA8AEB52-4608-487A-97EB-9724954250F3}" = lport=10243 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00CA162E-0E90-4BD3-A8E8-68A5B5E3655C}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{0BB84FC1-28A8-40EC-B61B-A079DCF47035}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{12538D5C-E1DC-4BAC-9A18-D3D3472A115D}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | "{13F9E94B-89D8-4616-95FE-CD4B4A653357}" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\bittorrent\bittorrent.exe | "{162F7DEF-F2A1-4CEA-85B6-DA9A441A358D}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steamapps\common\the war z\warzlauncher.exe | "{184361CD-A9AB-45A7-A192-E7D6D4B922E5}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{1BA16B58-43C4-426F-9AD5-6C43DD378B50}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe | "{1BFBB9DF-BA7D-4DEF-9CCB-F8F2C0ED7EB2}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steam.exe | "{1EFE7B8D-FD79-4F59-AB67-ACF24249D415}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{23461999-613F-4E18-A4A1-9159DB82FED8}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{242A335D-7C47-4985-9DF7-619C8F1B483F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{273AD6FE-9BF9-4EEC-A0A3-CCB0AD5F0901}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{29818D03-35B6-477F-BE05-33132E99039A}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steamapps\common\the war z\warzlauncher.exe | "{2E08603E-CE64-4F15-BB8A-98E90DBE785D}" = protocol=6 | dir=in | app=e:\program files (x86)\battle.net\battle.net.exe | "{2E5C9D31-B9B2-4D85-B1D7-109C0557476A}" = protocol=17 | dir=in | app=e:\program files (x86)\origin games\fifa 15\fifasetup\fifaconfig.exe | "{3065726B-98E4-4C5C-B1F4-7336F39E2D3F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{36B3FABF-A1A4-4984-ADFB-C3F2D758FF88}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{3B3D7E78-90EF-44B8-B06B-8318CEA54C4B}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{4F90347E-ADD0-4B34-8479-BE8FD2FF1393}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{5386949E-DB0E-4ABC-BFCB-9D985E66DF08}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{55CD807B-8FFB-4D9F-BEF8-ECA34CBBFA1D}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | "{5BFC1726-B0F8-4D88-ADF5-245306095D78}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{6334BA36-CA42-4C96-A84F-D4E54E98BBE1}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{66CC942B-C1CF-467B-B2A7-05413A789682}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{68B579F5-855C-494B-B266-D81FCB562A6D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{6CF700C7-C6ED-44EC-8746-7AC8411E32AC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{6E2AA6AF-F16E-43BC-8098-A509AE5899ED}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{70B43998-C7DD-467D-91A7-01898D16B2D5}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{71C83433-3F87-4F54-8385-520668102E02}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{7258A423-9BC1-41C7-A67E-32F99ACEBE1A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{75D7C178-BC11-40E2-AFD0-334E2DE7E44D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe | "{7D990CB3-85A0-4321-AF9B-EF012928D684}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{8513A73B-70D5-4E58-B5AB-A7D7C2823B97}" = protocol=17 | dir=in | app=e:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe | "{8517A66B-6B63-44BC-9D05-63411ABB628C}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | "{89E79114-95E1-4621-9835-B04B49EBAA5E}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{8B4AE737-0ECD-4A10-A4A2-E7D1473DA0B6}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{8BE5A120-F836-430E-BE56-FC5BC3F5AD55}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\bin\steamwebhelper.exe | "{90FEC5D3-4073-4207-9487-A9FE570EE9FD}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{969234C1-33F5-4D18-B2B6-13745B6064A0}" = protocol=6 | dir=in | app=e:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe | "{97D10F3C-7B53-4409-9748-9C91DE78F3AE}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe | "{9A464AF8-DB08-4FE8-8C91-03A61F0F2452}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{9B824AFF-1664-4674-B4D0-2790342FA806}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | "{9F0B8187-EFAB-424C-A69E-521ADDE7DCA1}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steam.exe | "{9FFB68F6-63C3-4C6C-B68E-1CC7512E94D2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{A109B1D1-C93B-4889-A4E7-2A514C04A0B1}" = protocol=6 | dir=in | app=e:\program files (x86)\origin games\fifa 15\fifasetup\fifaconfig.exe | "{A1C3F2E8-A2E9-4325-8CAD-E982E62A168D}" = protocol=6 | dir=out | app=system | "{AC795A98-A585-4B75-AAAB-CBB429DBBCAD}" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\bittorrent\bittorrent.exe | "{B3717A1C-B60E-47A3-BEFE-41209BC2BAF5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe | "{B6608B8B-989A-478A-8A43-9A39D902F4D0}" = protocol=17 | dir=in | app=e:\program files (x86)\battle.net\battle.net.exe | "{BBA023F0-F496-4569-A90B-58968AFAD051}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D2A7502C-4C0D-45FF-8DFE-38727DCAF0B3}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{D6A96725-42FA-42A5-AD9D-433828EF2BC9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D9359733-57EF-43FB-8431-D61EE266035B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{E647FB95-55F0-4017-8C98-3AA57A37C9E7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{EF37D7F4-A9EB-4979-ABB9-AC0F1DB3DFE0}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\bin\steamwebhelper.exe | "TCP Query User{098D9745-FF35-48E2-B0E4-B447D0300DC5}E:\program files (x86)\steam\steamapps\common\the war z\infestation.exe" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steamapps\common\the war z\infestation.exe | "TCP Query User{0F5ED81A-DDE2-4C09-BC92-95A87097FCB9}E:\program files (x86)\origin games\fifa 15\fifa15.exe" = protocol=6 | dir=in | app=e:\program files (x86)\origin games\fifa 15\fifa15.exe | "TCP Query User{2CADEEED-755F-4E19-AD3E-3BDE7E386D1C}E:\program files (x86)\r.g. mechanics\far cry 4\bin\farcry4.exe" = protocol=6 | dir=in | app=e:\program files (x86)\r.g. mechanics\far cry 4\bin\farcry4.exe | "TCP Query User{A63D3233-DA03-48CE-83B2-A709297A8E3A}E:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=e:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe | "TCP Query User{B4A50534-DBDE-45A4-87C2-B1DEB361451A}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | "TCP Query User{C1E4C099-6A61-472D-9C33-871915C96D9C}C:\users\user\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\spotify\spotify.exe | "UDP Query User{06F4CA90-9DC6-4E03-8977-6D285DD97633}E:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=e:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe | "UDP Query User{0B7BA5E4-939A-4394-86EA-BA46E732BBF1}E:\program files (x86)\r.g. mechanics\far cry 4\bin\farcry4.exe" = protocol=17 | dir=in | app=e:\program files (x86)\r.g. mechanics\far cry 4\bin\farcry4.exe | "UDP Query User{57160A79-BF1E-4CD3-87D1-6989DA627D3C}C:\users\user\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\spotify\spotify.exe | "UDP Query User{578ADDF1-492E-4C6C-9987-5E1839909F36}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | "UDP Query User{731AB8AD-5C5D-44CE-9A19-2470005B7AC3}E:\program files (x86)\steam\steamapps\common\the war z\infestation.exe" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steamapps\common\the war z\infestation.exe | "UDP Query User{F7C71B5F-6918-43C2-9B65-91103625DD87}E:\program files (x86)\origin games\fifa 15\fifa15.exe" = protocol=17 | dir=in | app=e:\program files (x86)\origin games\fifa 15\fifa15.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00653D04-04AF-3606-DADE-002DC26C0732}" = AMD Media Foundation Decoders "{0A2E1907-D0DE-0D01-CA64-CB0AB0BFE539}" = AMD Wireless Display v3.0 "{1CEAC85D-2590-4760-800F-8DE5E91F3700}" = Intel(R) Management Engine Components "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 "{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}" = iTunes "{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 "{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy Gamepad tool 0.7.1001 "{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology "{4E7F7C0A-4DE9-791C-61D4-9A5952DF5801}" = AMD Drag and Drop Transcoding "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{A6A04D70-ADF1-3FE6-3A79-577C284AC9D4}" = AMD Wireless Display v3.0 "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B7CC660E-F31D-490C-BD2A-2CB2EC5A5E3A}" = Intel(R) Chipset Device Software "{B9C27F57-AB84-425F-9D00-E18C5D65C18D}" = Intel(R) Rapid Storage Technology "{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}" = Apple Mobile Device Support "{C12C2297-65A4-4E64-9AE1-29F0D947FDA0}}_is1" = MegaDownloader 0.7 "{C16CD4C0-48EE-0F40-C9FD-0778EAF73FBD}" = AMD Wireless Display v3.0 "{C2956908-53A3-88FC-B795-B16508296FC4}" = AMD Catalyst Install Manager "{C3ECDE27-BD89-71E3-254D-DF32AF7C389D}" = AMD Wireless Display v3.0 "{D33CB107-E697-4CAD-8511-3B7C543743D7}" = Intel(R) Management Engine Components "{F7CD07B2-565B-D770-0388-9C16A8FA5B1D}" = AMD Accelerated Video Transcoding "{FD67BFA0-E205-47AA-BA09-123B3B72DB5E}" = 3DMark 11 "CCleaner" = CCleaner "HWiNFO64_is1" = HWiNFO64 Version 4.48 "TeamSpeak 3 Client" = TeamSpeak 3 Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{032DC00A-51D1-4D28-BFB7-1D0E85291E11}" = Futuremark SystemInfo "{1110A014-1471-4B66-BFDC-E8EED120CC59}" = System Requirements Lab CYRI "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{151AE945-AA23-3834-D5C7-C60832B71B15}" = CCC Help Czech "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.21 "{25A3B953-1423-3F15-640E-B620DD0F419A}" = Catalyst Control Center - Branding "{26A24AE4-039D-4CA4-87B4-2F03217071FF}" = Java 7 Update 71 "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{3D4ADA2B-F028-4307-ADF4-6F9AA44725DA}" = EA SPORTS™ FIFA 15 "{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX "{44A6C11C-D744-6B2C-D5A1-E32CB1DB0088}" = AMD Catalyst Control Center "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4DC7C1AB-4389-B736-082D-1BFA6BC10293}" = CCC Help Greek "{51307F85-BD05-1938-8440-E88FD13585CA}" = CCC Help Chinese Traditional "{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV "{5454083B-1308-4485-BF17-1110000D8302}" = Grand Theft Auto IV "{5454083B-1308-4485-BF17-1110000D8303}" = Grand Theft Auto IV "{5454083B-1308-4485-BF17-1110000D8304}" = Grand Theft Auto IV "{5454083B-1308-4485-BF17-1110000D8305}" = Grand Theft Auto IV "{5454083B-1308-4485-BF17-1110000D8306}" = Grand Theft Auto IV "{5454083B-1308-4485-BF17-1110000D8307}" = Grand Theft Auto IV "{5454083B-1308-4485-BF17-1110000D8308}" = Grand Theft Auto IV "{5565E164-9928-CEDD-5011-9EE073D797B9}" = CCC Help Japanese "{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV "{5947D004-A315-F50D-D24F-4C9D5B8413A5}" = CCC Help Spanish "{5AAF27C9-51C1-DEF1-230F-9F348E2DF885}" = CCC Help Russian "{5BBF2F0E-8891-0E74-83D3-0DBDB750EDC6}" = CCC Help Norwegian "{5C89D6B4-C8C4-08B9-4381-4E6C9BA3C094}" = CCC Help Italian "{5DE67937-45D5-45E4-923C-0B7F7EC929A7}" = League of Legends "{5FD7B6B3-08C7-4FEE-9C37-A2134C699885}}_is1" = This War of Mine "{64A47A55-1E5E-82F1-26A6-8157D34739A4}" = CCC Help Chinese Standard "{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}" = Microsoft Games for Windows Marketplace "{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call "{6EFD0C42-4CC1-4716-A0CA-21C1A062CF34}" = AMD System Monitor "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{755C6015-01B7-475D-448A-CE4D35E68F38}" = CCC Help Dutch "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}" = Obsługa programów Apple "{86CF0325-7921-55A6-16B2-254E77C40FE4}" = CCC Help French "{877AB8B2-9D11-D640-7B11-730699E0C9A2}" = CCC Help Swedish "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{89CE7F9B-B4DF-8585-638B-6BD807ADE9C7}" = HydraVision "{8B743AA0-53B2-11D2-808A-00600895FB43}" = Heroes of Might and Magic III - Złota Edycja "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9A974568-D4D5-EED2-1976-132C28211A82}" = CCC Help Korean "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A0ED9B46-5B37-616A-FDCC-3F713BC2972D}" = CCC Help German "{A11D86BF-B950-759B-3DBF-1575B76BF974}" = CCC Help Polish "{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 "{A3790827-8F55-4120-9D7A-8A0A894C4AEB}" = System Requirements Lab Detection "{A5457401-D56A-43F2-9524-78E54A7FC07A}" = SlimDrivers "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA14530E-3EF6-92AB-B39F-DB96F852BBBC}" = CCC Help Portuguese "{ABAD2544-D794-E1B1-2763-55A9BB811D5A}" = CCC Help Thai "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.09) - Polish "{B3BE2947-BB03-6079-60DD-41B388BBC74A}" = Catalyst Control Center Graphics Previews Common "{B89357B0-C12E-F21E-7E8D-CA13BFED19C7}" = CCC Help Hungarian "{C5BE5386-0A43-32DD-9F2B-934B8CCCAC41}" = Catalyst Control Center Localization All "{C70E8FBB-10F3-1DFF-E35F-6D62264D7A80}" = CCC Help Finnish "{e48a2f61-851a-4155-82f9-af1b04db8c3b}" = Oprogramowanie mikroukładu Intel® "{EC43C902-EF4F-0BF6-FA5F-897D2E450858}" = CCC Help Turkish "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2AB797F-31A3-A376-736B-9E0533BAB530}" = CCC Help English "{F3220B5E-9395-F557-8DB9-1E0F29D32026}" = CCC Help Danish "{f9e83b9c-ab7e-4005-8f32-4ea69703a5e4}" = 3DMark 11 "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX "Avast" = avast! Free Antivirus "Battle.net" = Battle.net "EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 "Far Cry 4_R.G. Mechanics_is1" = Far Cry 4 "Google Chrome" = Google Chrome "HD Tune_is1" = HD Tune 2.55 "Hearthstone" = Hearthstone "League of Legends 3.0.1" = League of Legends "Łatka polonizacyjna GTA IV v0.99" = Łatka polonizacyjna GTA IV v0.99 "Mafia II_is1" = Mafia II "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 2.0.4.1028 "Mozilla Firefox 30.0 (x86 pl)" = Mozilla Firefox 30.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "OCCT" = OCCT 4.4.1 "Open Broadcaster Software" = Open Broadcaster Software "Origin" = Origin "PunkBusterSvc" = PunkBuster Services "Raptr" = Raptr "screenSHU" = screenSHU - the fastest screen capture ever. "Steam" = Steam "Steam App 226700" = Infestation: Survivor Stories "Steam App 440" = Team Fortress 2 "TechPowerUp GPU-Z" = TechPowerUp GPU-Z "WinRAR archiver" = Archiwizator WinRAR [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3871900662-1698721075-3235340947-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "BitTorrent" = BitTorrent "Spotify" = Spotify [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-12-07 10:06:34 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-07 13:09:39 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-07 19:04:43 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-08 08:36:04 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-08 11:10:38 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-08 13:45:14 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-08 14:17:12 | Computer Name = user-Komputer | Source = VSS | ID = 8194 Description = Error - 2014-12-08 14:19:26 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-08 14:28:44 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2014-12-08 15:46:43 | Computer Name = user-Komputer | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2014-11-08 09:37:10 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0 z powodu następującego błędu: %%1053 Error - 2014-11-09 09:11:22 | Computer Name = user-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 02:29:53 na ?2014-?11-?09 było nieoczekiwane. Error - 2014-11-09 19:02:47 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0. Error - 2014-11-09 19:02:48 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0 z powodu następującego błędu: %%1053 Error - 2014-11-09 19:46:20 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0. Error - 2014-11-09 19:46:20 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0 z powodu następującego błędu: %%1053 Error - 2014-11-09 19:46:44 | Computer Name = user-Komputer | Source = WMPNetworkSvc | ID = 866300 Description = Error - 2014-11-10 08:26:14 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0. Error - 2014-11-10 08:26:14 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Usługa buforowania czcionek platformy Windows Presentation Foundation, wersja 3.0.0.0 z powodu następującego błędu: %%1053 Error - 2014-11-10 11:22:16 | Computer Name = user-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 15:45:17 na ?2014-?11-?10 było nieoczekiwane. < End of report >