Anonim / 4 lata, 7 miesięcy temu | Download | Plaintext | Odpowiedz |

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
OTL Extras logfile created on: 2013-07-01 10:23:48 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\KOREK\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd
 
2,99 Gb Total Physical Memory | 2,01 Gb Available Physical Memory | 66,97% Memory free
6,21 Gb Paging File | 5,28 Gb Available in Paging File | 85,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 51,04 Gb Total Space | 4,48 Gb Free Space | 8,79% Space Free | Partition Type: NTFS
Drive E: | 172,08 Gb Total Space | 95,24 Gb Free Space | 55,35% Space Free | Partition Type: NTFS
Drive G: | 7,26 Gb Total Space | 2,96 Gb Free Space | 40,77% Space Free | Partition Type: FAT32
 
Computer Name: KOREK-PC | User Name: KOREK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== File Associations ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-298573157-274772125-329246348-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
[color=#E56717]========== Shell Spawning ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\PROGRAMY\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\PROGRAMY\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\PROGRAMY\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[color=#E56717]========== Security Center Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[color=#E56717]========== System Restore Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[color=#E56717]========== Firewall Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[color=#E56717]========== Authorized Applications List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\PROGRAMY\flashget\FlashGet universal\FlashGet.exe" = C:\PROGRAMY\flashget\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2
"C:\PROGRAMY\flashget\FlashGet universal\LiveUpdate.exe" = C:\PROGRAMY\flashget\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate
"C:\PROGRAMY\flashget\FlashGet universal\LiveUpdateEx.exe" = C:\PROGRAMY\flashget\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx
"C:\Users\KOREK\Downloads\facebook-pic000934519.exe" = c:\users\public\nvsvc32.exe:*:Enabled:NVIDIA driver monitor
 
 
[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{023E5945-6361-453F-BA7A-C7ABAD505692}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{025E04AA-2E56-4B03-B993-3523E4D4AE61}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{12239855-613C-427D-86CF-B431B36B3F1B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{14FFBBA0-400D-4621-85F8-88F7641F366C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{166A8D71-BFF0-4A09-96DF-2E98FC4EA04B}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{257CDC2D-ED93-4CE7-9201-FF6D1DD2DACC}" = rport=139 | protocol=6 | dir=out | app=system | 
"{2DC4E857-9EE0-4A5C-A41D-83896A1FCBE8}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{2F3FD5D4-CB41-4B40-8FA1-B931F8B81124}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{32B665ED-C9B4-4C12-BC00-988D14A08671}" = lport=445 | protocol=6 | dir=in | app=system | 
"{38902C09-6CD8-4F82-BEBF-0F8F713ADEA9}" = rport=2869 | protocol=6 | dir=out | app=system | 
"{418A2E1B-3FA7-4868-91D1-CCD683E1DE24}" = lport=137 | protocol=17 | dir=in | app=system | 
"{431DD8F5-3632-48C0-BA23-CAE273001626}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{565E7026-BC6A-4236-933B-349852B62684}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{70D69124-7115-4FE6-B519-D270A84D6E7D}" = rport=137 | protocol=17 | dir=out | app=system | 
"{7382D564-AC01-4E5B-B619-62574F17A66C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{79162B8D-4070-4E9B-84C6-8BF4F7D82A94}" = rport=445 | protocol=6 | dir=out | app=system | 
"{7E877EE0-CD2E-4B49-8057-26888326B1EF}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{878BC476-5682-485F-8BE7-4F2BC0B1898E}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{8D1856EF-33E0-4B96-A65C-230F34FDD640}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{90820AC6-54ED-43E7-945D-CCF721D6050D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{9EC5EDAB-A44F-4E1C-AE67-B6DABBE4A930}" = lport=138 | protocol=17 | dir=in | app=system | 
"{9FCAB203-C575-4B0E-A274-5C50AF2734EF}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{AA9BE5B9-679C-4E3B-9FB1-635B333B1B7D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{ACB3B08D-D200-4913-ABE3-14F4770BCD4B}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{B1AACAD1-ACEF-4DD4-B124-F15A8C318F13}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{BA379735-DF1C-4577-9839-1F4A63935C5A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{BC0B9C5C-E4D6-45A5-A5E2-24BC239DD488}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{BFD2EC5D-5721-4D02-98EF-FEB6BFB35DAF}" = rport=138 | protocol=17 | dir=out | app=system | 
"{C261726A-7C03-4412-9210-B3E0A680F83A}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{D60F55A6-003F-4041-A9F9-2C4F5B14CE72}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{DD2C54B1-8C56-4AF2-AB1B-98ECDEE5B147}" = lport=139 | protocol=6 | dir=in | app=system | 
"{DF7B0B69-E296-4A39-94D0-D40081811071}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{E044360B-0A32-474C-8C21-A6E0FE553891}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{E94BA6DA-66F7-41A3-AB0A-3F3F12A51D11}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{EA66FC16-0B70-4EEF-B12A-0ECCD4E61B20}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{EFD8FDA6-8471-47C5-86B9-0499E077E36B}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{F2DB06AB-6AD9-4278-822E-ADAF498DF195}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
 
[color=#E56717]========== Vista Active Application Exception List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05FDEF89-AEDC-43B3-B76C-4F36BEC3E93F}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{0CC54A1B-D94D-463D-AF94-1D9B10EE99D6}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{0D262842-6B80-43F9-B3D2-FE6FC0A77AA7}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{10B57119-C566-4610-9DE0-B4301C2C769B}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | 
"{1DD57858-637C-4D2E-93BC-020A8B7B851B}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | 
"{1DFEAA75-BC4B-4CFC-99C8-C02E6CD61C28}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | 
"{217A6C8E-169E-4814-A890-165831BB8E32}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{23B2BF96-68EF-4427-8B20-0F19F86CD518}" = protocol=6 | dir=in | app=c:\programy\bitcomet\bitcomet.exe | 
"{2BB16F13-1752-445B-98A9-EEF4CD82B741}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{2C59C9F0-BBE7-4F50-9247-A7F529A9CB41}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe | 
"{2E535AEA-C256-484A-8C7A-99295706A989}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{2F03B8BE-8144-4763-A459-D50C6B2788A1}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | 
"{328E1375-F3ED-4917-81C9-A7969C8AABBD}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{37B00CD3-4CCA-438E-B96D-039744BA2696}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{3ADD49D1-06BF-4291-9D09-73E5E6CCC4D0}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{3BD10423-1537-403E-84B7-852227C8473E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\football manager 2012 demo\fm.exe | 
"{3F902FE9-7BD5-4F75-AFE0-FB1D6A285D4F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{48FEFDEA-C310-4D86-A660-6F8690C6B09E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{4A898BBA-1B91-49C0-AD92-280D44BAEDC6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{54E5A893-8EBB-4E16-AF7B-FF62083BF5E0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{56E36042-F23F-482A-BE38-34B78B777774}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{581E036F-FA58-4CE8-A54F-370C23E2D3BD}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe | 
"{6075F454-72E2-41AC-9E58-9DC33C5D5B1F}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{66108639-30A8-4B6B-82F5-FBA16E63328E}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{67014DDC-BA22-4540-9AC7-08156E9B5AF2}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{674ED92E-F36B-46DD-A3E0-B867000E9F0A}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe | 
"{6770A85E-3CD2-4C34-9DAB-BBC52DD5EB73}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe | 
"{736577D2-46F3-45C6-9764-3D670A7DAE90}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{760D9C55-1CB1-4826-88D2-81ED5F44622C}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer_service.exe | 
"{7AF0509D-AAF9-44D3-9070-1A435A58418F}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{7BCB6B4F-BBAC-4258-87C4-C02CD5E7F34F}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{7DDA0B20-4E00-4AB6-A6CF-76EAE1133397}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{7EDCCC6D-CDC4-4318-B232-FA6574CADDA7}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{81199FC4-3ABF-4B2C-A498-D0072499B36D}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | 
"{8442B971-10F5-4FFC-B058-91D1D0A0B7C6}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{848FD939-2F3C-4AF2-8090-1BB0FF5597EB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{911C1102-C9A5-4E2F-AE6D-24A25EA3CC07}" = protocol=6 | dir=out | app=system | 
"{94E07C8F-F16C-45F5-ADF1-7E6A3E5C191A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{955C1B1B-24B7-4FA4-A6BC-9E7AEE9AB304}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{9706C606-7E4E-4A13-AA59-0CA78183E231}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | 
"{99173084-FC49-4D7A-B30E-837572F83FE0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{9A17E8B3-31B8-49EF-B0CA-471F99C0A064}" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | 
"{9A8942CC-43E3-44B0-B6CC-053DED02134D}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{9AA1933A-D0BF-4EA5-A855-3F85FBFDA199}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{9C2DC784-2F40-42E9-A7BF-D3C3BB8A01D9}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{9C9B238C-818B-401F-A81A-3099A3684CCB}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | 
"{9D05BC59-3EB7-47B3-BB0F-E55F78A61F5C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{9D23CA62-2C9A-4D9A-B82E-75EDFF1B280A}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe | 
"{9E8DF844-CBD8-4DFF-9A9A-EC46C92C77AB}" = protocol=17 | dir=in | app=c:\programy\bitcomet\bitcomet.exe | 
"{A0AB9AF9-CBB2-4F1E-B676-4F02EDF2C7E6}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe | 
"{A2580E7E-A08F-4A81-B6DF-31BA29629435}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{A5B2DFE2-F418-428E-B3D6-275D1BE0FAB7}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{A8CF8389-3B6B-4D60-A2D3-F38C1F82F3D2}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{A9F0B05A-EF34-4FF3-95C4-123AE3FED209}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{B24FD4D6-D7F8-4BB0-A1D2-099CC808BFF1}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe | 
"{B44CCDAD-387A-4916-8DD8-C97FD0CFD08C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{B8178060-1E86-461B-B4F0-8BBC3059E6C2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{BAC0A239-A31C-4466-ABAB-436F1851815C}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | 
"{BB337864-54E8-4081-B583-30E6ACB8DEA7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{BF8AFEFF-C708-41AB-9C5B-67232FA2A648}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe | 
"{C92B722A-C67B-4FEA-8038-C56A09FADCE2}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe | 
"{CA3CC46B-612E-43C3-980A-DDBF41BDA856}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | 
"{CE929037-5366-40F0-B088-81ACE465DE5F}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe | 
"{D14B6ACE-99D8-41EF-847B-104B6000BA17}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer_service.exe | 
"{D4616B53-0ED6-47DA-96BF-261386E1B1D9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{E339BCD5-0877-489A-936A-CD957CE086E6}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | 
"{E4057387-F914-4708-AB9E-652D8297661A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{E587F5FF-D9A7-4FA2-9D44-C45F7155FA0D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{E61B2744-2902-402B-AE0E-BAF6CA0BC945}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{EA21C42E-F0EE-4255-9C29-A63959FBE00C}" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | 
"{EBD50295-5B33-4706-8488-C8A25AF6C335}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | 
"{EEFCD2AD-F16C-4152-9D9C-D2A1E3137EAC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\football manager 2012 demo\fm.exe | 
"{F380C285-838D-4E30-9CDC-456172F0441F}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe | 
"{F7BF38F3-C741-46EB-BDA1-C3748FDD7DC5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"TCP Query User{002B8F16-2267-4060-A149-681D49FEB6F0}E:\gry\pes 2009\pes 2009\pes2009.exe" = protocol=6 | dir=in | app=e:\gry\pes 2009\pes 2009\pes2009.exe | 
"TCP Query User{03400898-605A-4655-BFC3-FCB3AD4E2EF0}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe | 
"TCP Query User{074D6095-57BB-4B7E-872D-1BDF253E6F1A}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | 
"TCP Query User{0B663A09-AB00-4B87-B61D-A3CB6CB0FFE9}E:\gry\ghiiipc\gh3.exe" = protocol=6 | dir=in | app=e:\gry\ghiiipc\gh3.exe | 
"TCP Query User{1DAF79E1-F6DF-4C4D-BE86-A0725C067EEE}C:\programy\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\programy\bitcomet\bitcomet.exe | 
"TCP Query User{2C6E3E5A-DD7A-4558-8509-706543D2CF68}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | 
"TCP Query User{2E1800F2-6C44-40AF-A2F9-F8BE0A8DD11B}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe | 
"TCP Query User{30A4F1F1-66F6-4230-97A8-09BE513D7C2D}E:\gry\kedal of honor\mohaa.exe" = protocol=6 | dir=in | app=e:\gry\kedal of honor\mohaa.exe | 
"TCP Query User{3D0ED628-D726-4F65-B209-ADD23F8E3F5B}E:\gry\kedal of honor\mohaa.exe" = protocol=6 | dir=in | app=e:\gry\kedal of honor\mohaa.exe | 
"TCP Query User{3E87A721-444B-4A1B-A409-892F152ECA05}C:\programy\gadu-gadu\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\programy\gadu-gadu\nowe gadu-gadu\gg.exe | 
"TCP Query User{5B8F9B94-27B7-461A-A8CC-6D9332690946}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"TCP Query User{5C57DFD3-01AB-4A11-908E-440DAF7D2B1B}C:\program files\rayv\rayv\rayv.exe" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.exe | 
"TCP Query User{61795DC4-94F6-4E80-B5DC-52C71CC74DFB}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe | 
"TCP Query User{6CAF5173-5285-40CF-AB50-80CE94526032}C:\programy\opera 10.0\opera.exe" = protocol=6 | dir=in | app=c:\programy\opera 10.0\opera.exe | 
"TCP Query User{710097BF-4AEC-49C7-9985-F27925E55488}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe | 
"TCP Query User{77BA7BAD-EC26-40E1-9B6F-5A71FA31358E}C:\programy\opera 10.0\opera.exe" = protocol=6 | dir=in | app=c:\programy\opera 10.0\opera.exe | 
"TCP Query User{79D1F749-5A57-4B33-A3E6-6D52710DDCD7}C:\programy\gadu-gadu\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\programy\gadu-gadu\nowe gadu-gadu\gg.exe | 
"TCP Query User{7C92F66A-CBE5-4797-B5D8-18A1F3B089E4}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe | 
"TCP Query User{A906D812-5225-4105-9A85-7597660C19C8}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | 
"TCP Query User{AEAD4A7E-D3FB-462F-B218-CC6604293B45}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | 
"TCP Query User{B80DB007-583C-4886-A429-F1049F15D6B0}E:\gry\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=e:\gry\counter-strike 1.6\hl.exe | 
"TCP Query User{BAA961C6-BF2C-4ED7-AECD-796F1FAEB083}E:\gry\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=e:\gry\counter-strike 1.6\hl.exe | 
"TCP Query User{C4152840-7F0E-475D-ACC4-1A0F9D0C4303}C:\program files\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | 
"TCP Query User{C6A37ECC-269D-420B-8BB7-07F6A9F7CDD8}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe | 
"TCP Query User{D8123FA7-5699-4A89-9BD7-5C9E16C9E732}F:\quake3\quake3.exe" = protocol=6 | dir=in | app=f:\quake3\quake3.exe | 
"TCP Query User{DF3C9388-C689-4193-B15D-0676D3725B67}E:\gry\pes 2009\pes 2009\pes2009.exe" = protocol=6 | dir=in | app=e:\gry\pes 2009\pes 2009\pes2009.exe | 
"TCP Query User{E83AEC6E-F1AB-49D3-8336-456CB2A287F3}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe | 
"UDP Query User{06473535-D58C-4538-ABEF-165D33ED8B60}E:\gry\ghiiipc\gh3.exe" = protocol=17 | dir=in | app=e:\gry\ghiiipc\gh3.exe | 
"UDP Query User{0C5AEB1C-687B-4B25-B11B-0286033A444E}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe | 
"UDP Query User{14EEE229-0E09-4E50-B751-5CEEFA67722C}C:\programy\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\programy\bitcomet\bitcomet.exe | 
"UDP Query User{24289E26-66E6-4603-871A-4D1DEC3C524B}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe | 
"UDP Query User{2BA8C34B-6250-4411-9A7F-7B1289DB45B8}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe | 
"UDP Query User{301ADE6A-C581-4143-8764-9336759086E2}C:\programy\gadu-gadu\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\programy\gadu-gadu\nowe gadu-gadu\gg.exe | 
"UDP Query User{3079EF13-C74A-4C3D-A425-1CEC12845BE6}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | 
"UDP Query User{42DECF93-1E7A-4F08-AAB3-11A4D024A059}E:\gry\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=e:\gry\counter-strike 1.6\hl.exe | 
"UDP Query User{4B5CFD6C-70A9-4EDD-9525-16FD21EE2C3D}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | 
"UDP Query User{4C1FC13F-0D93-47E7-8561-BE3E965F5A83}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe | 
"UDP Query User{522C403C-CD01-4F8D-AE0D-9418CBFECF14}E:\gry\pes 2009\pes 2009\pes2009.exe" = protocol=17 | dir=in | app=e:\gry\pes 2009\pes 2009\pes2009.exe | 
"UDP Query User{55F5EFE6-AF8A-41F7-A23F-66B4E8F0A05E}E:\gry\kedal of honor\mohaa.exe" = protocol=17 | dir=in | app=e:\gry\kedal of honor\mohaa.exe | 
"UDP Query User{5DE8088F-DB48-486C-ACEA-5FA331BC3CAA}C:\programy\gadu-gadu\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\programy\gadu-gadu\nowe gadu-gadu\gg.exe | 
"UDP Query User{694CBECB-0B36-4D93-9E99-3B3DACF8E9B5}C:\program files\rayv\rayv\rayv.exe" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.exe | 
"UDP Query User{8FAF06A6-ED2B-48B7-855B-CCD326FF2541}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe | 
"UDP Query User{9C156FE1-2BE6-4C0F-BF02-FC0F45B8EA83}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\adv\sopadver.exe | 
"UDP Query User{9F810CB0-6B75-4C4A-9D3F-A84CB5AAE308}C:\programy\opera 10.0\opera.exe" = protocol=17 | dir=in | app=c:\programy\opera 10.0\opera.exe | 
"UDP Query User{B75FFA18-60BF-4D6F-919E-A6ABFEC0861C}C:\program files\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | 
"UDP Query User{BB461FBC-0A01-4611-8EB9-20583FAF10D7}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | 
"UDP Query User{C36F9925-BAB2-40B4-A10A-704395B6CCA4}E:\gry\pes 2009\pes 2009\pes2009.exe" = protocol=17 | dir=in | app=e:\gry\pes 2009\pes 2009\pes2009.exe | 
"UDP Query User{C68E9377-DFA5-4D52-99B6-9819B3A8C9B9}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | 
"UDP Query User{CE2F6D32-2783-4087-94FB-9A3499D32535}C:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\programy\sopcast\sopcast-3.2.4-2009-7-9\sopcast\sopcast.exe | 
"UDP Query User{D494B0C5-B369-42A3-BD03-4F1963525AEB}F:\quake3\quake3.exe" = protocol=17 | dir=in | app=f:\quake3\quake3.exe | 
"UDP Query User{D632CD9B-C917-4530-9B8E-6F6DA31B50E8}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | 
"UDP Query User{E291BB9E-83DF-4AD4-9DB3-03736DCC2010}E:\gry\kedal of honor\mohaa.exe" = protocol=17 | dir=in | app=e:\gry\kedal of honor\mohaa.exe | 
"UDP Query User{EA5B9033-E645-4C28-9C5C-BD576D4D0D3D}E:\gry\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=e:\gry\counter-strike 1.6\hl.exe | 
"UDP Query User{ECF967C0-2063-43AF-B60B-6A1A54435199}C:\programy\opera 10.0\opera.exe" = protocol=17 | dir=in | app=c:\programy\opera 10.0\opera.exe | 
 
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{04441EE4-3631-43DB-813A-9D031380C8E5}" = MarketingReg
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 25
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer PowerSmart Manager
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = ADI USB ADSL Adapter
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype 6.5
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68301905-2DEA-41CE-A4D4-E8B443B099BA}" = MyWinLocker
"{6917A8F6-028C-4BA2-A70D-1A1BDA6BF227}" = easy SportsGraphics
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9AF0B106-56F1-461B-A270-95BC1682E282}" = Broadcom Gigabit NetLink Controller
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A8DB611A-D80E-450D-85F6-3ACDD164BE31}" = Pro Evolution Soccer 2009
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)
"{ACA85783-8EEA-4f0a-B2A3-A8173F30209F}" = C4200_doccd
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B09BCBF6-87EE-4403-A336-3A9510856535}" = HP Photosmart All-In-One Software 9.0
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BFDE4176-5DFE-4db9-AA00-8F30CB001BDA}" = c4200_Help
"{C353A9E3-27D5-4B1E-B21C-DA118EE2FD05}" = DV3300 Driver
"{C39E671D-0528-4c5e-A034-8470C5BC393A}" = C4200
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.74.216
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D1A339E0-A1AF-40BD-9D73-2C9DCEE896F9}" = STATISTICA PL 10
"{D8B7A682-20DA-4797-8415-B1FB14D4D32B}" = PS_AIO_Software
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}" = Acer Product Registration
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FD7F242B-9AA0-40c3-941E-3A9821D19C09}" = PS_AIO_ProductContext
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"A5C76F143DE85710B0FDBABC39480EC492EE05CF" = Windows Driver Package - Broadcom Bluetooth  (09/11/2009 6.2.0.9407)
"Acer Screensaver" = Acer ScreenSaver
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Ashampoo Burning Studio 9_is1" = Ashampoo Burning Studio 9.05
"avast" = avast! Free Antivirus
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800)
"BitComet" = BitComet 1.16
"DAEMON Tools Lite" = DAEMON Tools Lite
"Deluxe Ski Jump 3_is1" = Deluxe Ski Jump 3 v1.7.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Football Manager 2012_is1" = Football Manager 2012
"Free YouTube Download_is1" = Free YouTube Download version 3.2.4.622
"Gadu-Gadu 10" = Gadu-Gadu 10
"GridVista" = Acer GridVista
"Heroes III Armageddon's Blade" = Heroes III Armageddon's Blade
"Heroes III The Restoration of Erathia" = Heroes III The Restoration of Erathia
"Heroes III The Shadow of Death" = Heroes III The Shadow of Death
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"Kinovea" = Kinovea
"KLiteCodecPack_is1" = K-Lite Codec Pack 8.8.0 (Full)
"LManager" = Launch Manager
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 22.0 (x86 pl)" = Mozilla Firefox 22.0 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoScape" = PhotoScape
"Picasa 3" = Picasa 3
"RealAlt_is1" = Real Alternative 2.0.0
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SopCast" = SopCast 3.5.0
"STATNOVAPDF_is1" = STATNOVAPDF (novaPDF 7.4 printer)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 8" = TeamViewer 8
"Totalcmd" = Total Commander (Remove or Repair)
"VLC media player" = VLC media player 2.0.2
"Winamp" = Winamp
"WinAVI Video Converter 9.09.0" = WinAVI Video Converter 9.0
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Archiwizator WinRAR
"Worms Armageddon - New Edition" = Worms Armageddon - New Edition
 
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
 
[HKEY_USERS\S-1-5-21-298573157-274772125-329246348-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Video Converter Packages" = Video Converter Packages
"Winamp Detect" = Detektor Winampa
 
[color=#E56717]========== Last 20 Event Log Errors ==========[/color]
 
[ Application Events ]
Error - 2011-11-26 12:43:46 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 2011-11-26 13:43:24 | Computer Name = KOREK-PC | Source = Application Error | ID = 1000
Description = Faulting application fm.exe, version 12.0.3.35043, time stamp 0x4ea59480,
 faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
 0xc0000005, fault offset 0xfe74d7c8,  process id 0xfac, application start time 0x01ccac5c8739e711.
 
Error - 2011-11-27 05:00:52 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 2011-11-27 08:27:12 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 2011-11-27 09:18:32 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 2011-11-27 13:58:00 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 2011-11-27 16:54:58 | Computer Name = KOREK-PC | Source = Application Error | ID = 1000
Description = Faulting application POWERPNT.EXE, version 12.0.6545.5000, time stamp
 0x4c653ef1, faulting module ppcore.dll, version 12.0.6557.5001, time stamp 0x4db1d438,
 exception code 0xc0000005, fault offset 0x00039865,  process id 0x10bc, application
 start time 0x01ccad4602353e4e.
 
Error - 2011-11-28 04:26:19 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 2011-11-28 10:15:02 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 2011-11-28 15:39:48 | Computer Name = KOREK-PC | Source = WinMgmt | ID = 10
Description = 
 
[ OSession Events ]
Error - 2011-11-27 16:54:58 | Computer Name = KOREK-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application 
Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session 
lasted 350 seconds with 240 seconds of active time.  This session ended with a crash.
 
Error - 2012-06-05 14:03:07 | Computer Name = KOREK-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1884
 seconds with 900 seconds of active time.  This session ended with a crash.
 
Error - 2013-03-12 14:18:18 | Computer Name = KOREK-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 22643
 seconds with 9780 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 2013-06-30 16:05:16 | Computer Name = KOREK-PC | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.13,
 since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which 
addresses are being allocated to DHCP clients. To enable the DHCP allocator on this
 IP address, change the scope to include the IP address, or change the IP address
 to fall within the scope.
 
Error - 2013-06-30 16:05:22 | Computer Name = KOREK-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 2013-06-30 16:05:23 | Computer Name = KOREK-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 2013-07-01 03:55:50 | Computer Name = KOREK-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 2013-07-01 03:55:50 | Computer Name = KOREK-PC | Source = Service Control Manager | ID = 7000
Description = 
 
Error - 2013-07-01 03:56:50 | Computer Name = KOREK-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.13 for the Network Card with network
 address 00242BD7BB04 has been denied by the DHCP server 10.10.10.1 (The DHCP Server
 sent a DHCPNACK message).
 
Error - 2013-07-01 03:56:53 | Computer Name = KOREK-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
 may indicate that the system is low on virtual memory, or that the memory manager
 has encountered an internal error.
 
Error - 2013-07-01 03:56:57 | Computer Name = KOREK-PC | Source = ipnathlp | ID = 34001
Description = The ICS_IPV6 failed to configure IPv6 stack.
 
Error - 2013-07-01 03:56:57 | Computer Name = KOREK-PC | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 10.10.10.26, 
since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
 are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
 change the scope to include the IP address, or change the IP address to fall within
 the scope.
 
Error - 2013-07-01 03:56:59 | Computer Name = KOREK-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
 may indicate that the system is low on virtual memory, or that the memory manager
 has encountered an internal error.
 
 
< End of report >