OTL Extras logfile created on: 2014-12-27 15:31:52 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\otl 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17501) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 2,02 Gb Available Physical Memory | 50,50% Memory free 8,00 Gb Paging File | 5,71 Gb Available in Paging File | 71,37% Paging File free Paging file location(s): e:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 98,35 Gb Total Space | 20,61 Gb Free Space | 20,95% Space Free | Partition Type: NTFS Drive D: | 329,43 Mb Total Space | 24,92 Mb Free Space | 7,56% Space Free | Partition Type: NTFS Drive E: | 9,77 Gb Total Space | 5,69 Gb Free Space | 58,29% Space Free | Partition Type: NTFS Drive F: | 61,41 Gb Total Space | 9,96 Gb Free Space | 16,22% Space Free | Partition Type: NTFS Drive G: | 4,00 Gb Total Space | 2,92 Gb Free Space | 73,09% Space Free | Partition Type: FAT Drive H: | 390,57 Gb Total Space | 96,62 Gb Free Space | 24,74% Space Free | Partition Type: NTFS Drive M: | 54,65 Mb Total Space | 54,65 Mb Free Space | 100,00% Space Free | Partition Type: FAT Computer Name: KTOS7 | User Name: zbi | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\NOTEPAD.EXE (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software) .txt [@ = txtfile] -- C:\Windows\NOTEPAD.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-631475386-587308821-3710584268-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software) https [open] -- "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- C:\Windows\NOTEPAD.EXE %1 (Microsoft Corporation) Unknown [openas] -- Reg Error: Value error. Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [FarHere] -- "C:\Program Files\FAR\ConEmu.exe" /single /cmd "C:\Program Files\FAR\far.exe" "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software) https [open] -- "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- C:\Windows\NOTEPAD.EXE %1 (Microsoft Corporation) Unknown [openas] -- Reg Error: Value error. Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [FarHere] -- "C:\Program Files\FAR\ConEmu.exe" /single /cmd "C:\Program Files\FAR\far.exe" "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "9752:TCP" = 9752:TCP:*:Enabled:Remote Assistance Local "7110:TCP" = 7110:TCP:*:Enabled:Remote Assistance Remote [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0FDF8298-80F7-4771-8987-007388309C4C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{1290400B-8B93-4928-A1A6-A7CD39C66F2B}" = lport=137 | protocol=17 | dir=in | app=system | "{1D19F7E0-6D1D-4E49-AA93-02041ED7CF1B}" = rport=445 | protocol=6 | dir=out | app=system | "{2463BE43-0054-44A7-A737-3D4CECEAEB9E}" = lport=139 | protocol=6 | dir=in | app=system | "{30688E7A-62EE-4612-A5ED-43EBB8BAE60B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{30F26198-AA57-448C-9531-05BA7AD86F11}" = rport=10243 | protocol=6 | dir=out | app=system | "{61C60754-2738-48A8-9E01-AD869B5ABCFE}" = lport=10243 | protocol=6 | dir=in | app=system | "{67EEE161-3D11-4305-911A-C01EDCA20DE0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6BB4FEAA-D621-47F1-BDEB-90CB119585B2}" = rport=138 | protocol=17 | dir=out | app=system | "{7004F749-3E08-4634-8D73-1B65C8739053}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7486601D-484D-4B0D-ABF6-231A1ED37052}" = lport=138 | protocol=17 | dir=in | app=system | "{760A0880-9572-415A-B428-863145B03E7C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{83394F52-BBCB-47F1-B04F-4518BBA55E7B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{985885AA-040D-4E26-BF69-1A45DD4B1286}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{98639748-CF7C-4587-B6B2-7E51141E14B7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{9A268086-2952-4322-B5AB-902B85900388}" = lport=2869 | protocol=6 | dir=in | app=system | "{BD806298-B33B-40A4-B11D-6F9AEC9C1EC3}" = rport=139 | protocol=6 | dir=out | app=system | "{C0BAB55E-BBEB-4C33-933F-E35C7E673A62}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner | "{C4D3E71C-217B-414D-AF6D-82451E3A0539}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C918D0FB-B0F6-4989-B6C6-2C79E3606B25}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{CEA013F6-4424-4D08-9839-12F6CD49B77E}" = rport=137 | protocol=17 | dir=out | app=system | "{D67EA93C-062B-4DEE-886F-C8A44329966F}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{DC4FA140-DF1E-47E5-956E-FFD69681FCE9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DD88D6A6-705D-473C-AE36-0113EFBFF5E1}" = lport=445 | protocol=6 | dir=in | app=system | "{E021015F-74B0-4DCB-8550-0EA549B69890}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{F88A60F6-AC3A-4918-8A0E-116B56CA94DE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F804933-74B1-44DB-8D5B-6A4D698327D7}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{1649BC4E-59DE-4CEA-999D-2E578F3739AB}" = protocol=6 | dir=in | app=c:\program files\ultravnc\vncviewer.exe | "{16BE194B-6C72-42B3-95A4-94545062D864}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{18054FDC-9BE1-4C06-8AB0-9530E7DEFD2A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{24038BBE-5BF5-4EB8-A6C9-5AE927CB13CE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{2B663244-595A-4638-B2B3-6FB66CA67040}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{333E90BD-E116-4416-A3B3-B98388427BCF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{40F7DFFE-EE32-4540-B72E-8A1544B8D8C6}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{4BD8BF5E-E154-4AC9-B341-53505ECAFAC0}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{4C30D4E4-DAF0-44CE-978B-346F87FB9A0F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{4FEEC604-1E48-4288-AE7D-F7AB0302386F}" = protocol=17 | dir=in | app=c:\program files (x86)\easeus\todo backup\bin\tbconsoleui.exe | "{5ABAFE8A-14B2-4968-B603-C14DBE484553}" = protocol=17 | dir=in | app=c:\program files (x86)\easeus\todo backup\bin\agent.exe | "{5ECC1767-07D4-40EC-9436-5FC6DAB59E21}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{661B9F7A-2545-4363-BBED-40384AE1D624}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{859088A0-B964-4FD2-BC34-96AC314B1BE0}" = protocol=6 | dir=in | app=c:\program files (x86)\easeus\todo backup\bin\agent.exe | "{86FFDECD-8CE7-4F75-A20C-3FF26E9EE8FC}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{8D542D16-26B3-49EF-98C1-F162F46A76BF}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{8D574AD1-C418-4F81-8656-91C0BF19C0A1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{90229963-4FCA-4688-B659-363D5447B8C2}" = protocol=6 | dir=in | app=c:\windows\syswow64\svchost.exe | "{9A64C34D-834D-4EF5-A44E-DC64ED7E9D1A}" = protocol=17 | dir=in | app=c:\program files (x86)\easeus\todo backup\bin\tbservice.exe | "{9CDB7D5C-0F5B-4DBD-A249-EF1DDA0BF769}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9CF74B15-4999-42DA-B571-0D072DABACCB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{A027AC84-68E1-4714-B5F7-3EAF43290434}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{B80F8611-4DE1-4167-932F-FD2DD8F000CC}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{BAE8A2D5-B471-4D6A-9F5B-9BC059BC5A83}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{C2540041-860F-47F9-A725-8080B151B461}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{C671C61F-AEAC-43A1-86F2-8C23279241AF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CA638155-1DD8-4C9B-87C0-F488B8F70CDE}" = protocol=17 | dir=in | app=c:\windows\syswow64\svchost.exe | "{CFCFD25D-2BE6-4E3D-A1F5-726EF0DE34FB}" = protocol=6 | dir=in | app=c:\program files (x86)\easeus\todo backup\bin\tbservice.exe | "{D3915DF0-7F61-4BB9-B25F-D3A527E481C0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D44408A7-C067-48E1-884D-499F7772CFC9}" = protocol=6 | dir=out | app=system | "{D563DADB-B888-43A4-99BA-5AAF65D3639E}" = protocol=6 | dir=in | app=c:\program files (x86)\easeus\todo backup\bin\tbconsoleui.exe | "{E8F78CC9-70E7-4570-BD2B-E33F955A626B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{EAF39B1C-B49A-417F-98BC-BD7A4BBFA3E1}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{EE3FD15E-E8E8-48F5-885D-7A1DB6E7A2A0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{F46C439F-8551-4A64-B6F8-9BF858F79BF6}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{F52A7C27-2D87-44C8-832D-BDA4A6D8CE88}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{FBDE3CA5-DF6B-433E-9E5B-519EF5C54F1B}" = protocol=17 | dir=in | app=c:\program files\ultravnc\vncviewer.exe | "TCP Query User{13CE326C-C58A-43FB-B798-DA9CA9A52C26}C:\program files (x86)\microsoft games\age of empires ii\empires2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\empires2.exe | "TCP Query User{6FFA5CEB-0105-4809-BFD6-36CB4E76A94F}C:\users\zbi\appdata\local\far2_x64\far.exe" = protocol=6 | dir=in | app=c:\users\zbi\appdata\local\far2_x64\far.exe | "TCP Query User{7BA734D0-7E95-44E0-B9DB-07655E1685EF}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe | "TCP Query User{8438AEAA-6148-4999-B6B5-CEC7E4DFB196}C:\program files (x86)\zyxel\nsu\nsu.exe" = protocol=6 | dir=in | app=c:\program files (x86)\zyxel\nsu\nsu.exe | "TCP Query User{ADC2740A-DEF8-4FE9-ADD5-58ADADD8B949}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe | "TCP Query User{D6D67A5B-9C6F-4B62-ADA8-484AA2C31091}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | "TCP Query User{DD950D3A-E435-49CC-9E95-82707995DC91}C:\program files\bitcoin\bitcoin-qt.exe" = protocol=6 | dir=in | app=c:\program files\bitcoin\bitcoin-qt.exe | "TCP Query User{E0ED77DF-A0F5-46EC-B39A-252D12019BB4}C:\program files (x86)\microsoft games\age of empires\empires.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires\empires.exe | "TCP Query User{FDB85487-D296-402D-AC17-FD9D6FB4F713}C:\program files (x86)\zyxel\nsu\nsu.exe" = protocol=6 | dir=in | app=c:\program files (x86)\zyxel\nsu\nsu.exe | "UDP Query User{56AE461E-4876-4DB5-88D7-23CD9D5CC1CE}C:\program files (x86)\zyxel\nsu\nsu.exe" = protocol=17 | dir=in | app=c:\program files (x86)\zyxel\nsu\nsu.exe | "UDP Query User{9BCFB0D5-857B-4F0E-A789-F2D71F72113F}C:\program files\bitcoin\bitcoin-qt.exe" = protocol=17 | dir=in | app=c:\program files\bitcoin\bitcoin-qt.exe | "UDP Query User{B194B8BC-FE46-441A-A9B2-2C33B82A29D5}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe | "UDP Query User{D2894211-9D2C-44DC-8132-E5CA5EFAC5BE}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe | "UDP Query User{D63A9433-9080-42A9-8FB3-FBBF1DC8E6D2}C:\program files (x86)\zyxel\nsu\nsu.exe" = protocol=17 | dir=in | app=c:\program files (x86)\zyxel\nsu\nsu.exe | "UDP Query User{D65A1170-546D-4F1C-8BC6-13DB542B2278}C:\program files (x86)\microsoft games\age of empires ii\empires2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\empires2.exe | "UDP Query User{D94B2379-764F-4F8F-B3E7-126C0BA5E178}C:\program files (x86)\microsoft games\age of empires\empires.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires\empires.exe | "UDP Query User{E9A84371-A0C8-48E3-8833-7B7EB6B4BC9D}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | "UDP Query User{F375F7A4-8F1D-46EA-B8C7-D6FA71A24A87}C:\users\zbi\appdata\local\far2_x64\far.exe" = protocol=17 | dir=in | app=c:\users\zbi\appdata\local\far2_x64\far.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode "{143F0C11-D9F3-4F1E-9037-67BBFDD379AD}" = Far Manager 2 x64 "{17DEA095-8EE1-49A2-AC5A-9663DB098FA9}" = CSR Harmony Wireless Software Stack "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1DD03A94-C815-46EF-A43A-B36694002A7C}" = TortoiseSVN 1.6.16.21511 (64 bit) "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64 "{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition) "{23F2C78C-E131-4CA0-8F84-3473FB7728BA}" = Microsoft Security Client "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll "{43592B2E-C393-433F-8D0E-5A4B15A8C786}" = Microsoft Antimalware Service PL-PL Language Pack "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64 "{45F1F774-38B4-3CC3-BAAF-051E6D19E48E}" = Microsoft .NET Framework 4.5.1 (PLK) "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.9 "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64 "{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64 "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64 "{AB562530-921D-11DE-A208-005056C00008}" = Paragon Backup & Recovery™ 10.2 Free Edition "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 340.52 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Sterownik kontrolera 3D Vision 295.73 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.14.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64 "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D113D762-FC28-4B6F-A39E-DD9A037B04D4}" = Oracle VM VirtualBox 4.0.16 "{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client PL-PL Language Pack "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "BitBox" = Browser in the Box "CCleaner" = CCleaner "Defraggler" = Defraggler "FarHere" = Far Here Power Toy "GIMP-2_is1" = GIMP 2.6.10 "Microsoft Security Client" = Microsoft Security Essentials "NVIDIA Drivers" = NVIDIA Drivers "Process_Hacker_is1" = Process Hacker 1.11 "Recuva" = Recuva "SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set "Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "Shrew Soft VPN Client" = Shrew Soft VPN Client "Speccy" = Speccy "Ultravnc2_is1" = UltraVnc "Winflector_is1" = Winflector wersja 3.1.0.2 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{02C15B8C-26BE-479C-0001-7E31094C1376}" = MyTube 6 "{064A929A-4DE8-40CF-A901-BD40C14E4D25}" = PDF Architect "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control "{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.22 "{26A24AE4-039D-4CA4-87B4-2F03217072FF}" = Java 7 Update 72 "{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{2FF959E3-FFE4-46C4-96DA-03F26BCFEFCC}" = Brother MFL-Pro Suite DCP-J140W "{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth "{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1" = Data Lifeguard Diagnostic for Windows 1.24 "{6006089C-84B5-4F18-8113-D96792AED0DE}_is1" = ChrisPC Free Anonymous Proxy 5.40 "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7BBAEC47-1CC0-4CB8-ADB4-531B78DBD1DD}" = Adobe AIR "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{98613C99-1399-416C-A07C-1EE1C585D872}" = SeaTools for Windows "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A3EA81D6-07A2-4116-9EA3-60B741572FD6}" = NSU "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych "{B455E95A-B804-439F-B533-336B1635AE97}" = NVIDIA PhysX "{B5373BA3-BAD7-4EAC-A9D2-B66B41B82C57}" = OpenOffice 4.1.1 "{B7666229-351B-47D9-AA6F-DF777CF04BBF}" = Cezar IV "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{C3BDF1C8-66EF-4A0F-B427-A99E39706F45}_is1" = RMVB Converter 1.8 "{C43E4B9C-14C8-4EB0-998B-85211B6EDD61}" = Seagate DiscWizard "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27) "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX "Adobe Flash Player NPAPI" = Adobe Flash Player 16 NPAPI "Age of Empires" = Microsoft Age of Empires "Age of Empires 2.0" = Microsoft Age of Empires II "All Media Fixer_is1" = All Media Fixer 9.11 "Audacity_is1" = Audacity 2.0.3 "CDex" = CDex - Open Source Digital Audio CD Extractor "coverXP" = coverXP (remove only) "DC-Bass Source" = DC-Bass Source 1.3.0 "EaseUS Data Recovery Wizard 7.0_is1" = EaseUS Data Recovery Wizard 7.0 "EaseUS Partition Master_is1" = EaseUS Partition Master 10.2 "EASEUS Partition Recovery_is1" = EASEUS Partition Recovery 5.0.1 "EaseUS Todo Backup Free 6.1_is1" = EaseUS Todo Backup Free 6.1 "Easy Miner" = Easy Miner "EasyBCD" = EasyBCD 2.2 "Fakturowanie_is1" = Fakturowanie 1.1 "ffdshow_is1" = ffdshow v1.1.4399 [2012-03-22] "foobar2000" = foobar2000 v1.3.3 "Free Studio_is1" = Free Studio version 2013 "HaaliMkx" = Haali Media Splitter "ipla" = ipla 2.3.3 "iReboot" = iReboot 1.1.1 "IrfanView" = IrfanView (remove only) "LAME_is1" = LAME v3.99.3 (for Windows) "Mediator - Klient_is1" = Klient Mediator wersja 5.2 "Monkey's Audio_is1" = Monkey's Audio "Mozilla Firefox 34.0.5 (x86 pl)" = Mozilla Firefox 34.0.5 (x86 pl) "Mozilla Thunderbird 31.3.0 (x86 pl)" = Mozilla Thunderbird 31.3.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Odkurzacz 13.3_is1" = Odkurzacz "OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter 1.0.0.5 "Opera 12.17.1863" = Opera 12.17 "PDFMate PDF Converter_is1" = PDFMate PDF Converter 1.7.2 "PITy 2009_is1" = PITy 2009 dla Windows kompilacja:1.1.2.15 "PITy 2011_is1" = PITy 2011 dla Windows kompilacja:1.3.3.2 "PITy 2012_is1" = PITy 2012 dla Windows kompilacja:1.4.5.9 "PITy2013IPS_is1" = PITy2013 IPS 1.5.2.0 kompilacja:1.5.4.2 "qHarbour" = qHarbour "RadLight MPC DirectShow Filter" = RadLight MPC DirectShow Filter (remove only) "save2pc Light_is1" = save2pc Light 4.17 "SQLite Expert Personal 3_is1" = SQLite Expert Personal 3.3.7 "TeamViewer 9" = TeamViewer 9 "VLC media player" = VLC media player 2.0.1 "vsfilter_is1" = DirectVobSub 2.40.4209 "WinLiveSuite" = Podstawowe programy Windows Live "Xvid Video Codec 1.3.2" = Xvid Video Codec [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-631475386-587308821-3710584268-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Bitcoin Core (64-bit)" = Bitcoin Core (64-bit) "UnityWebPlayer" = Unity Web Player [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-631475386-587308821-3710584268-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-12-18 12:50:04 | Computer Name = ktos7 | Source = VSS | ID = 8194 Description = Error - 2014-12-18 13:14:54 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: CsrBtOBEXService.exe, wersja: 2.1.63.0, sygnatura czasowa: 0x4f68683b Nazwa modułu powodującego błąd: CsrBtOBEXService.exe, wersja: 2.1.63.0, sygnatura czasowa: 0x4f68683b Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000006f58 Identyfikator procesu powodującego błąd: 0xcc4 Godzina uruchomienia aplikacji powodującej błąd: 0x01d01ae4b64475f0 Ścieżka aplikacji powodującej błąd: C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe Ścieżka modułu powodującego błąd: C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe Identyfikator raportu: 61b318f0-86d9-11e4-970b-90e6ba43f68a Error - 2014-12-18 13:24:34 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x3a0 Godzina uruchomienia aplikacji powodującej błąd: 0x01d01ae67f936a00 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: bb5d1e40-86da-11e4-b683-90e6ba43f68a Error - 2014-12-19 03:35:39 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x3dc Godzina uruchomienia aplikacji powodującej błąd: 0x01d01b5ddc018520 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: a0ac4a40-8751-11e4-88a6-90e6ba43f68a Error - 2014-12-20 08:20:13 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x2b0 Godzina uruchomienia aplikacji powodującej błąd: 0x01d01c4f24cd68e0 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: 8bceb3a0-8842-11e4-b89f-90e6ba43f68a Error - 2014-12-21 11:35:01 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x448 Godzina uruchomienia aplikacji powodującej błąd: 0x01d01d2d94bafa80 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: ed2c6630-8926-11e4-b2a6-90e6ba43f68a Error - 2014-12-21 14:51:07 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x460 Godzina uruchomienia aplikacji powodującej błąd: 0x01d01d4edd95b940 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: 52233760-8942-11e4-a5c4-90e6ba43f68a Error - 2014-12-21 15:00:06 | Computer Name = ktos7 | Source = Windows Backup | ID = 4103 Description = Error - 2014-12-26 06:47:12 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x45c Godzina uruchomienia aplikacji powodującej błąd: 0x01d020f54c1e5120 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: 8baf8d50-8cec-11e4-87fc-90e6ba43f68a Error - 2014-12-26 11:36:53 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x45c Godzina uruchomienia aplikacji powodującej błąd: 0x01d021214f3d01e0 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: 03aba640-8d15-11e4-9477-90e6ba43f68a Error - 2014-12-27 08:45:18 | Computer Name = ktos7 | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: LogonUI.exe, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce79f70 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.18247, sygnatura czasowa: 0x521eaf24 Kod wyjątku: 0xc0000374 Przesunięcie błędu: 0x00000000000c4102 Identyfikator procesu powodującego błąd: 0x434 Godzina uruchomienia aplikacji powodującej błąd: 0x01d021d2ca1b9b40 Ścieżka aplikacji powodującej błąd: C:\Windows\system32\LogonUI.exe Ścieżka modułu powodującego błąd: C:\Windows\SYSTEM32\ntdll.dll Identyfikator raportu: 360a7ec0-8dc6-11e4-a8c0-90e6ba43f68a [ System Events ] Error - 2014-12-26 15:35:46 | Computer Name = ktos7 | Source = Application Popup | ID = 1060 Description = Ładowanie sterownika \SystemRoot\System32\Drivers\StarOpen.SYS zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Error - 2014-12-26 15:36:50 | Computer Name = ktos7 | Source = Service Control Manager | ID = 7023 Description = Usługa PDF Architect Service zakończyła działanie; wystąpił następujący błąd: %%-2147467259 Error - 2014-12-26 15:37:24 | Computer Name = ktos7 | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: sptd StarOpen Error - 2014-12-26 15:43:52 | Computer Name = ktos7 | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-12-26 16:04:12 | Computer Name = ktos7 | Source = Service Control Manager | ID = 7043 Description = Usługa Funkcja Audio CSR Bluetooth nie została poprawnie zamknięta po odebraniu kodu sterującego przed zamknięciem. Error - 2014-12-27 08:44:03 | Computer Name = ktos7 | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 21:03:46 na ?2014-?12-?26 było nieoczekiwane. Error - 2014-12-27 08:42:14 | Computer Name = ktos7 | Source = sptd | ID = 262148 Description = Sterownik wykrył błąd wewnętrzny w swoich strukturach danych dla . Error - 2014-12-27 08:43:43 | Computer Name = ktos7 | Source = Application Popup | ID = 1060 Description = Ładowanie sterownika \SystemRoot\System32\Drivers\StarOpen.SYS zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Error - 2014-12-27 08:44:45 | Computer Name = ktos7 | Source = Service Control Manager | ID = 7023 Description = Usługa PDF Architect Service zakończyła działanie; wystąpił następujący błąd: %%-2147467259 Error - 2014-12-27 08:45:15 | Computer Name = ktos7 | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: sptd StarOpen < End of report >