Avira antywirus chce usunąć plik należący do systemu


(karton16) #1

Witam,

Podczas skanowania przez antywirus Avira odnalał mi virusa w folderze BitGuard,

mam windows 7 home premium 64 bit

Co to jest za progrm ten bitguard i czy mogę go usunąć


(Acorus) #2

Usuń.Pokaż logi z OTL analiza-dezynfekcja-zestaw-narzedzi-nieingerencyjnych-t485632.html


(karton16) #3

Log z extras.txt:

OTL Extras logfile created on: 2013-10-13 16:50:29 - Run 1

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Albert\Desktop\Adrian\Downloads

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7601.17514)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd


1,93 Gb Total Physical Memory | 0,85 Gb Available Physical Memory | 43,95% Memory free

3,87 Gb Paging File | 2,11 Gb Available in Paging File | 54,52% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 213,72 Gb Total Space | 147,09 Gb Free Space | 68,82% Space Free | Partition Type: NTFS

Drive D: | 18,86 Gb Total Space | 2,74 Gb Free Space | 14,51% Space Free | Partition Type: NTFS


Computer Name: ALBERT-HP | User Name: Albert | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days


[color=#E56717]========== Extra Registry (All) ==========[/color]



[color=#E56717]========== File Associations ==========[/color]


[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)

.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)

.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)

.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)

.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

.js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)

.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)

.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

.bat [@ = batfile] -- "%1" %*

.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)

.cmd [@ = cmdfile] -- "%1" %*

.com [@ = comfile] -- "%1" %*

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

.exe [@ = exefile] -- "%1" %*

.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)

.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)

.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)

.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)

.js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

.pif [@ = piffile] -- "%1" %*

.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

.scr [@ = scrfile] -- "%1" /S

.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)

.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)


[HKEY_CURRENT_USER\SOFTWARE\Classes\]

.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)


[color=#E56717]========== Shell Spawning ==========[/color]


[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]

batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)

batfile [open] -- "%1" %*

batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)

cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)

cmdfile [open] -- "%1" %*

cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)

htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)

htmlfile [edit] -- Reg Error: Key error.

htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"

http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)

https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)

inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)

inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)

jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)

jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)

jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)

jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)

jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)

regfile [open] -- regedit.exe "%1" (Microsoft Corporation)

regfile [merge] -- Reg Error: Key error.

regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)

txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)

vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)

vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)

vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)

vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)

wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)

wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)

wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [ChomikBox.Upload] -- "C:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( )

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]

batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)

batfile [open] -- "%1" %*

batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)

cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)

cmdfile [open] -- "%1" %*

cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)

htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)

htmlfile [edit] -- Reg Error: Key error.

htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"

http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)

https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)

inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)

inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)

jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)

jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)

jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)

jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)

jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)

regfile [open] -- regedit.exe "%1" (Microsoft Corporation)

regfile [merge] -- Reg Error: Key error.

regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)

txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)

txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)

vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)

vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)

vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)

vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)

wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)

wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)

wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [ChomikBox.Upload] -- "C:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( )

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)


[color=#E56717]========== Security Center Settings ==========[/color]


[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1


[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]


[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0


[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]


[color=#E56717]========== Firewall Settings ==========[/color]


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1


[color=#E56717]========== Authorized Applications List ==========[/color]



[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{034E9CFB-AE60-44A5-8DF8-008E82E4F0DB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 

"{2315ED0B-EF2E-4121-8509-10A24FA8E022}" = lport=139 | protocol=6 | dir=in | app=system | 

"{2A730F5C-6113-4165-B6DD-40C776BE516D}" = lport=137 | protocol=17 | dir=in | app=system | 

"{33F7ABF8-6F56-456A-B79C-88189989EE61}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 

"{38F548BA-6E9F-4B1D-BD55-C503BEB0F54D}" = lport=10243 | protocol=6 | dir=in | app=system | 

"{41D247F6-DF7B-4B2F-A8F8-1874AFFC953E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 

"{65FB755B-DAE6-4C45-8989-B288A7B9C64A}" = rport=10243 | protocol=6 | dir=out | app=system | 

"{67D7BD62-5684-4D6C-B25D-8DCAFB29ECC1}" = lport=2869 | protocol=6 | dir=in | app=system | 

"{7ADB1B00-5445-465F-9F7C-57093880771D}" = rport=445 | protocol=6 | dir=out | app=system | 

"{892891F1-56D6-4ED4-AF3A-71822AA3A1AF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 

"{94DD743F-CD7B-40A2-B8EA-8B07981BDEE7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 

"{A0ECD028-6C42-4DE6-8439-9AC05A1EF23D}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 

"{A7214A4C-5DB9-4BA5-A991-DA06DEEC93EC}" = lport=138 | protocol=17 | dir=in | app=system | 

"{A9910EDD-E16B-4F09-A470-A9377F9DF895}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 

"{ADA7AD70-E809-4D37-8E4F-BD2E4E709181}" = lport=445 | protocol=6 | dir=in | app=system | 

"{AFB7C9D4-1592-41CA-A13E-189FFA49B5D4}" = rport=138 | protocol=17 | dir=out | app=system | 

"{AFE5FFEE-E87F-450E-A8BF-493BF86816F5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 

"{BC9F31F6-A417-4C69-95B3-32C1411C7653}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 

"{C36A32C7-EE29-48C8-B875-8BE52B06E05C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 

"{C5CC1E6D-56AF-4D4A-95BD-3A75A0C4A2B0}" = rport=137 | protocol=17 | dir=out | app=system | 

"{C978DE75-10D9-43C7-A089-A5575A46187D}" = rport=139 | protocol=6 | dir=out | app=system | 

"{D5597F2A-53D9-4343-8BC1-32A8042C970D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 

"{FEA09D98-ABEE-4D30-B693-88547529D362}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 


[color=#E56717]========== Vista Active Application Exception List ==========[/color]


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{060041CC-155C-4487-9E3D-63C5B3A88681}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe | 

"{08CD7D83-6671-430C-B3AC-4AFA25BA97CB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 

"{0C94D22C-1A8D-4A7E-861E-85FE7243B0EC}" = protocol=17 | dir=in | app=c:\users\albert\appdata\roaming\utorrent\utorrent.exe | 

"{1B963F57-16F5-4806-BAEF-8C88DED3C5AD}" = protocol=6 | dir=out | app=system | 

"{2035856D-D84E-4EB6-8E04-E12491162565}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe | 

"{20AAC863-EF43-4FCA-A185-C10038965CA4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 

"{2F029B36-00F8-4324-8597-AC9B5B61FE8D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 

"{488CE25D-AEF1-4329-A3CC-CB0E4C482C2D}" = protocol=6 | dir=in | app=c:\users\albert\appdata\roaming\utorrent\utorrent.exe | 

"{5940F3C0-FB0E-49DE-9B9C-AD3CE4F84618}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 

"{6B6EF8C1-48AF-4C0C-B789-ED2E058719FF}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 

"{6BA11F97-F3F6-42A4-B49A-CF0D4518D86F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 

"{6CB5FF9F-9742-455D-8B3D-87D5D93082D2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 

"{733B6D2A-5F16-4879-9BD7-09A60D906317}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 

"{7BCCC164-925E-402D-880B-C1BD1CD841D8}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe | 

"{83C6DC54-001A-4457-9FEA-8E166144A6E8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 

"{88AE36F7-6E50-4E72-8EA3-0D3E2779DD52}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe | 

"{A1371BB5-B5CE-40FC-9661-8F952F669759}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 

"{A2A8E773-EBB7-4F4D-982A-84D0A380BAD7}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 

"{AC320F63-7E7D-4FDA-AD63-18413B32F352}" = dir=out | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe | 

"{AF0FDBEE-99DE-4DB7-8604-1D3F724450FA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 

"{B6317BFD-C46D-4E32-8882-8D78F4452F08}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 

"{BA6938F8-2869-4790-9A70-41FB5D8CD8B5}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe | 

"{BB0E4AC6-F4DB-46C8-B010-D2777AC70FCB}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe | 

"{C491AA02-2962-47DF-8883-544813BCAB4E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 

"{C53C8A7F-D263-4845-986A-408BEA111104}" = protocol=6 | dir=in | app=c:\programdata\esafe\egdpsvc.exe | 

"{CB82B098-6547-41D0-BA40-FA4954F4CE18}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 

"{CE6D3C3D-4746-4796-96DE-D7381FC562B1}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 

"{D114BBA9-F80F-4915-94B3-55D9D7F0DD06}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 

"{D13B42D9-67B7-476C-9339-76F1EE9DE345}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 

"{D78BA3E5-B972-4484-BD4B-667D31676DCF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 

"{DC7CB7AA-0C8D-44A3-B18C-44A04B0D62FF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 

"{DFCDE3DC-5F31-405C-B6E7-7D7B2F7106C6}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe | 

"{E420A840-4B6E-493C-822E-52D0126E7FFB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]


64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{091A0130-A82F-4A6D-9C61-3BBBB3289030}" = RtVOsd

"{13DCC2C7-454D-42F0-A892-E0E9A5DE4E67}" = HP Wireless Assistant

"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant

"{26A24AE4-039D-4CA4-87B4-2F86416021FF}" = Java(TM) 6 Update 21 (64-bit)

"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services

"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector

"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570

"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010

"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting

"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto

"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter

"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile

"Blender" = Blender

"CCleaner" = CCleaner

"GIMP-2_is1" = GIMP 2.8.6

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"SynTPDeinstKey" = Synaptics Pointing Device Driver

"Whilokii" = Whilokii 1.0.0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements

"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar

"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player

"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore

"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = BitGuard

"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker

"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 4.0

"{1AF23A65-F2B5-469C-AA51-DA5FB74CA856}" = HP Documentation

"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update

"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite

"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library

"{26050F54-3928-4D9C-849A-C48A9E831E6F}" = ChomikBox

"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22

"{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 40

"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery

"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery

"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7

"{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}" = Adobe Shockwave Player 11.5

"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology

"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go

"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3

"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager

"{491ADA37-04EE-2ECE-9F86-DDC0106047AC}" = Times Reader

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform

"{504CC891-B140-4E1B-860B-5E4C1DFBA9E3}" = Blio

"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3

"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup

"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer

"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library

"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack

"{6B114F59-6732-4EA5-A33E-ACC6DEC49B61}" = HP Software Framework

"{705B639E-FAAF-40D7-AD58-C445321C7C3F}" = LightScribe System Software

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform

"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger

"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow

"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}" = Ralink RT5390 802.11b/g/n WiFi Adapter

"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore

"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English

"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack

"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker

"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail

"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer

"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer

"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer

"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.3.3 MUI

"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = Compaq Setup Manager

"{AF306BD8-F9D1-4627-89B9-246E59074A05}" = HP Power Manager

"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR

"{B1A4A13D-4665-4ED3-9DFE-F845725FBBD8}" = HP Support Assistant

"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars

"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo

"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint

"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail

"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector

"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86

"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64

"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!

"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common

"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources

"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

"{E3723A04-A894-4036-A78E-282E18F43C0A}_is1" = Tinypic 3.16

"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime

"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger

"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = PC Camera-UA0072

"{EF682D1C-591D-48B5-9803-628DA622C281}" = HP Quick Launch

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials

"7-Zip" = 7-Zip 9.22beta

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Avira AntiVir Desktop" = Avira Free Antivirus

"Bonanza Deals" = Bonanza Deals (remove only)

"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader

"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)

"Dia" = Dia (remove only)

"Google Chrome" = Google Chrome

"HP Photo Creations" = HP Photo Creations

"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite

"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go

"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow

"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9

"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint

"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector

"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!

"Mozilla Firefox 24.0 (x86 en-US)" = Mozilla Firefox 24.0 (x86 en-US)

"MozillaMaintenanceService" = Mozilla Maintenance Service

"My HP Game Console" = HP Game Console

"Office14.Click2Run" = Microsoft Office Click-to-Run 2010

"Power Sound Editor Free" = Power Sound Editor Free

"searchgol" = searchgol toolbar  

"Search-Gol Chrome Toolbar" = Search-Gol Chrome Toolbar

"uTorrent" = µTorrent

"WildTangent hp Master Uninstall" = HP Games

"WinLiveSuite" = Windows Live Essentials

"WsysControl" = Wsys Control 10.2.1.2652

"WT087328" = Blackhawk Striker 2

"WT087330" = Bounce Symphony

"WT087335" = Build-a-lot 2

"WT087343" = Dora's World Adventure

"WT087360" = Escape Rosecliff Island

"WT087361" = FATE

"WT087362" = Final Drive Nitro

"WT087372" = Heroes of Hellas 2 - Olympia

"WT087379" = Jewel Quest Solitaire 2

"WT087394" = Penguins!

"WT087395" = Poker Superstars III

"WT087396" = Polar Bowler

"WT087397" = Polar Golfer

"WT087414" = Virtual Families

"WT087415" = Wheel of Fortune 2

"WT087428" = Bejeweled 2 Deluxe

"WT087453" = Chuzzle Deluxe

"WT087501" = Plants vs. Zombies

"WT087533" = Zuma Deluxe

"WT087536" = Diner Dash 2 Restaurant Rescue

"WT089299" = Mystery P.I. - The London Caper

"WT089307" = Virtual Villagers 4 - The Tree of Life

"WT089308" = Blasterball 3

"WT089328" = Farm Frenzy

"WT089359" = Cake Mania

"WT089362" = Agatha Christie - Peril at End House

"ZumoDrive" = HP CloudDrive


[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"GG" = GG

"UpdaterEX" = Extended Update


[color=#E56717]========== Last 20 Event Log Errors ==========[/color]


[Application Events]

Error - 2013-10-10 19:21:39 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-10 19:23:55 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-10 19:25:58 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-10 19:25:58 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-10 19:25:58 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-10 19:25:58 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-11 00:56:15 | Computer Name = Albert-HP | Source = MsiInstaller | ID = 11316

Description = 


Error - 2013-10-11 00:56:27 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-11 14:44:52 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


Error - 2013-10-11 14:44:52 | Computer Name = Albert-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107

Description = Nie mozna wyodrebnic listy glównej innych firm z pliku cab automatycznej

 aktualizacji z: ,

 wystapil blad: A required certificate is not within its validity period when verifying

 against the current system clock or the timestamp in the signed file. .


[Hewlett-Packard Events]

Error - 2013-03-25 15:42:01 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\031325084152.xml

 File not created by asset agent


Error - 2013-03-25 16:38:42 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = en-US Object reference not set to an instance of an object. HPSF at

 HPAssistant.Pages.MaintainTuneUpProgress.bgScan_RunWorkerCompleted(Object sender,

 RunWorkerCompletedEventArgs e) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(RunWorkerCompletedEventArgs

 e) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(Object arg)


   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback,

 Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object

 source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)



Error - 2013-03-25 16:38:43 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = en-US Object reference not set to an instance of an object. HPSF at

 HPAssistant.Pages.MaintainTuneUpProgress.bgScan_RunWorkerCompleted(Object sender,

 RunWorkerCompletedEventArgs e) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(RunWorkerCompletedEventArgs

 e) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(Object arg)


   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback,

 Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object

 source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)



Error - 2013-03-25 16:38:44 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = en-US Object reference not set to an instance of an object. HPSF at

 HPAssistant.Pages.MaintainTuneUpProgress.bgScan_RunWorkerCompleted(Object sender,

 RunWorkerCompletedEventArgs e) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(RunWorkerCompletedEventArgs

 e) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(Object arg)


   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback,

 Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object

 source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)



Error - 2013-03-25 16:38:44 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = en-US Object reference not set to an instance of an object. HPSF at

 HPAssistant.Pages.MaintainTuneUpProgress.bgScan_RunWorkerCompleted(Object sender,

 RunWorkerCompletedEventArgs e) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(RunWorkerCompletedEventArgs

 e) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(Object arg)


   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback,

 Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object

 source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)



Error - 2013-03-25 16:38:44 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = en-US Object reference not set to an instance of an object. HPSF at

 HPAssistant.Pages.MaintainTuneUpProgress.bgScan_RunWorkerCompleted(Object sender,

 RunWorkerCompletedEventArgs e) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(RunWorkerCompletedEventArgs

 e) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(Object arg)


   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback,

 Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object

 source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)



Error - 2013-03-25 16:38:44 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = en-US Object reference not set to an instance of an object. HPSF at

 HPAssistant.Pages.MaintainTuneUpProgress.bgScan_RunWorkerCompleted(Object sender,

 RunWorkerCompletedEventArgs e) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(RunWorkerCompletedEventArgs

 e) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(Object arg)


   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback,

 Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object

 source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)



Error - 2013-03-25 16:38:44 | Computer Name = Albert-HP | Source = Hewlett-Packard | ID = 0

Description = en-US Object reference not set to an instance of an object. HPSF at

 HPAssistant.Pages.MaintainTuneUpProgress.bgScan_RunWorkerCompleted(Object sender,

 RunWorkerCompletedEventArgs e) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(RunWorkerCompletedEventArgs

 e) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(Object arg)


   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback,

 Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object

 source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)



[HP Wireless Assistant Events]

Error - 2011-05-10 22:05:53 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2011-05-10 22:05:58 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2011-05-10 22:06:03 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2011-05-10 22:06:08 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2011-05-10 22:06:13 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2011-05-10 22:06:18 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2011-05-10 22:06:23 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2011-05-10 22:06:28 | Computer Name = Albert-HP | Source = HP WA Service | ID = 0

Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.

 (Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32

 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object

 o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean

 getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String

 propertyName) at HPPA_Service.CurrentConfiguration.b__c()


Error - 2013-10-12 11:35:31 | Computer Name = Albert-HP | Source = HP WA Application | ID = 0

Description = System.Exception HardwareAccess hasn't been instantiated properly.  

  at PAProgramAccess.Impl.UpdatePowerSchemeInformation(PowerScheme powerScheme)


Error - 2013-10-12 16:58:31 | Computer Name = Albert-HP | Source = HP WA Application | ID = 0

Description = System.Exception HardwareAccess hasn't been instantiated properly.  

  w PAProgramAccess.Impl.UpdatePowerSchemeInformation(PowerScheme powerScheme)


[System Events]

Error - 2013-10-12 07:02:10 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7022

Description = Usluga Wsys Service zawiesila sie podczas uruchamiania.


Error - 2013-10-12 07:03:51 | Computer Name = Albert-HP | Source = DCOM | ID = 10005

Description = 


Error - 2013-10-12 07:03:51 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7009

Description = Uplynal limit czasu (30000 ms) podczas oczekiwania na polaczenie sie

 z usluga HP Software Framework Service.


Error - 2013-10-12 07:03:51 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7000

Description = Nie mozna uruchomic uslugi HP Software Framework Service z powodu 

nastepujacego bledu: %%1053


Error - 2013-10-12 07:04:27 | Computer Name = Albert-HP | Source = DCOM | ID = 10005

Description = 


Error - 2013-10-12 07:04:27 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7009

Description = Uplynal limit czasu (30000 ms) podczas oczekiwania na polaczenie sie

 z usluga Windows Search.


Error - 2013-10-12 07:04:27 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7000

Description = Nie mozna uruchomic uslugi Windows Search z powodu nastepujacego bledu:

   %%1053


Error - 2013-10-12 07:05:58 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7009

Description = Uplynal limit czasu (30000 ms) podczas oczekiwania na polaczenie sie

 z usluga BonanzaDealsLive-Dienst (bonanzadealslive).


Error - 2013-10-12 07:05:58 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7000

Description = Nie mozna uruchomic uslugi BonanzaDealsLive-Dienst (bonanzadealslive)

 z powodu nastepujacego bledu: %%1053


Error - 2013-10-12 07:06:29 | Computer Name = Albert-HP | Source = Service Control Manager | ID = 7009

Description = Uplynal limit czasu (30000 ms) podczas oczekiwania na polaczenie sie

 z usluga Microsoft .NET Framework NGEN v4.0.30319_X86.



< End of report >

(Acorus) #4

Dałeś tylko extras.Użyj AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner z funkcji Skan a następnie Clean (w przypadku Visty/Windows7 uruchom z prawokliku jako Administrator).

Pokaż nowy OTL.txt umieszczony na wklej.org


(karton16) #5

http://http://wklej.org/id/1149190/

-- Dodane 13.10.2013 (N) 18:30 --

To jest ten log z Otl


(Acorus) #6

Loga tam nie ma.


(karton16) #7

http://wklej.org/id/1149190/

Teraz jest pomyliłem się


(Acorus) #8

Log wykonaj na prawidłowych ustawieniach. http://obrazki.elektroda.pl/4338219300_1364652821.png


(karton16) #9

Ok zrobię to, a co to właściwie jest za program, bo od wczoraj mam laptopa, włąśnie z tym programem, i po przeinstalowaniu antywirusa zacza mi pokazywać, że w tym pliku mam wirusa