OTL Extras logfile created on: 2010-12-14 00:24:49 - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Maria\Downloads Windows Vista Home Basic Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 40,00% Memory free 4,00 Gb Paging File | 2,00 Gb Available in Paging File | 57,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 465,76 Gb Total Space | 361,58 Gb Free Space | 77,63% Space Free | Partition Type: NTFS Computer Name: MARIA-FU | User Name: Maria | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-580308997-3297512381-3963118376-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AntiVirusOverride" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "FirewallOverride" = 1 "UpdatesDisableNotify" = 1 "UacDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "oobe_av" = 1 "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 1 "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Windows\system32\WTablet\Wacom_TabletUser.exe" = C:\Windows\system32\WTablet\Wacom_TabletUser.exe:*:Enabled:ipsec -- (Wacom Technology, Corp.) "C:\ComboFix\hidec.exe" = C:\ComboFix\hidec.exe:*:Enabled:ipsec -- File not found "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe" = C:\Program Files\PC Connectivity Solution\ServiceLayer.exe:*:Enabled:ipsec -- (Nokia) "C:\Windows\Explorer.exe" = C:\Windows\Explorer.exe:*:Enabled:ipsec -- (Microsoft Corporation) "C:\Windows\SYSTEM32\WISPTIS.EXE" = C:\Windows\SYSTEM32\WISPTIS.EXE:*:Enabled:ipsec -- (Microsoft Corporation) "C:\Users\Maria\AppData\Local\Temp\dcasrw.exe" = C:\Users\Maria\AppData\Local\Temp\dcasrw.exe:*:Enabled:ipsec -- () "C:\Users\Maria\AppData\Local\Temp\winkkdyr.exe" = C:\Users\Maria\AppData\Local\Temp\winkkdyr.exe:*:Enabled:ipsec -- File not found "C:\Windows\TEMP\winojpbgr.exe" = C:\Windows\TEMP\winojpbgr.exe:*:Enabled:ipsec -- () "C:\Windows\TEMP\xrpnl.exe" = C:\Windows\TEMP\xrpnl.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\w33cf8e.exe" = C:\Users\Maria\AppData\Local\Temp\w33cf8e.exe:*:Enabled:ipsec -- () "C:\Windows\TEMP\w34f009.exe" = C:\Windows\TEMP\w34f009.exe:*:Enabled:ipsec -- () "C:\Users\Maria\AppData\Local\Temp\winxlwp.exe" = C:\Users\Maria\AppData\Local\Temp\winxlwp.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\winlltjq.exe" = C:\Users\Maria\AppData\Local\Temp\winlltjq.exe:*:Enabled:ipsec -- File not found "C:\Windows\TEMP\fgbype.exe" = C:\Windows\TEMP\fgbype.exe:*:Enabled:ipsec -- File not found "C:\Windows\TEMP\dbjtg.exe" = C:\Windows\TEMP\dbjtg.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\winapspvt.exe" = C:\Users\Maria\AppData\Local\Temp\winapspvt.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\rdcq.exe" = C:\Users\Maria\AppData\Local\Temp\rdcq.exe:*:Enabled:ipsec -- File not found "C:\Windows\TEMP\kkesyx.exe" = C:\Windows\TEMP\kkesyx.exe:*:Enabled:ipsec -- File not found "C:\Windows\TEMP\ffrmm.exe" = C:\Windows\TEMP\ffrmm.exe:*:Enabled:ipsec -- File not found "C:\Program Files\Metin2 i priv\Spyware Doctor\pctsTray.exe" = C:\Program Files\Metin2 i priv\Spyware Doctor\pctsTray.exe:*:Enabled:ipsec -- (PC Tools) "C:\Users\Maria\AppData\Local\Temp\winnofhcf.exe" = C:\Users\Maria\AppData\Local\Temp\winnofhcf.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\winswmbv.exe" = C:\Users\Maria\AppData\Local\Temp\winswmbv.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\fixnma.exe" = C:\Users\Maria\AppData\Local\Temp\fixnma.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\cwnsrj.exe" = C:\Users\Maria\AppData\Local\Temp\cwnsrj.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\winhhfxwn.exe" = C:\Users\Maria\AppData\Local\Temp\winhhfxwn.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\wintbjhh.exe" = C:\Users\Maria\AppData\Local\Temp\wintbjhh.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\winokbmv.exe" = C:\Users\Maria\AppData\Local\Temp\winokbmv.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\winpidw.exe" = C:\Users\Maria\AppData\Local\Temp\winpidw.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\gtps.exe" = C:\Users\Maria\AppData\Local\Temp\gtps.exe:*:Enabled:ipsec -- File not found "C:\Users\Maria\AppData\Local\Temp\winubvbgx.exe" = C:\Users\Maria\AppData\Local\Temp\winubvbgx.exe:*:Enabled:ipsec -- File not found [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F250371-C8DA-4112-B8FC-D8C650D968F9}" = lport=139 | protocol=6 | dir=in | app=system | "{11595B93-3058-4782-8CBA-59A4A8FDD63A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{17FD6439-F906-45DF-A51F-0BBD10706FDD}" = rport=137 | protocol=17 | dir=out | app=system | "{1B8EB0CC-B0A9-49ED-90D7-62863914F8EB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{206EAC26-2877-43B1-8C99-AFEB71BAFAF9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2CB7F03D-74BA-49A8-9CA4-9205A13F37D0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3D0F9D0A-948C-48AF-A28C-235AD1F8A850}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service | "{436E24AD-6D6C-463C-BF25-19B1AC451AF9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4C3D6C4D-7EB5-42D8-AE13-6BA624339F9E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{62645DB1-891C-43ED-B9B2-DA403A648708}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{69AA21A0-F2E1-4FC6-A78C-7DFDA5FC580C}" = rport=138 | protocol=17 | dir=out | app=system | "{6A30EBDB-D31A-42B0-83B2-94D33B1C315E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{6CA5B5F6-2427-4E47-8449-F66D6AD6169A}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service | "{7361044C-0291-413A-A93D-369BFFFC4D98}" = rport=10243 | protocol=6 | dir=out | app=system | "{765BD1B5-19EB-4929-B514-7980B254B0FA}" = rport=445 | protocol=6 | dir=out | app=system | "{802B6C03-650E-4E4F-8C2D-F56CF0CE629B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{84FDF753-373F-480C-A10D-88ACF9A7068F}" = lport=445 | protocol=6 | dir=in | app=system | "{8DB0E6E3-571C-42B3-9718-62963DD73BF1}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{94DE1A87-0F8A-4BC7-A782-D4C38D3A6883}" = rport=139 | protocol=6 | dir=out | app=system | "{9F69A254-36F3-4DF3-8BA0-EB0541AF74A4}" = lport=2869 | protocol=6 | dir=in | app=system | "{ADB0CD37-6E1F-43E5-A2B9-4F868EC8FD21}" = lport=137 | protocol=17 | dir=in | app=system | "{AF7A7A90-601F-43EF-9F68-13006AB3EB66}" = lport=2869 | protocol=6 | dir=in | app=system | "{BB815688-5812-41F5-8AFA-CBB2B30D0F8C}" = lport=138 | protocol=17 | dir=in | app=system | "{D0B0891F-4A6D-4EEC-A5E8-F8388CA9E381}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DC717093-172C-4765-B430-F5996C7AA287}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F5BBE82A-9864-49CC-AA85-12AE532E26CA}" = lport=10243 | protocol=6 | dir=in | app=system | "{FC11FE63-0E7F-4FCE-A68C-2AD7EA6A47E9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{FE1F2855-EFC1-42BE-A3CA-40CA26C5EFF0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00902664-49A0-414B-AB8E-79014E3BDACF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{09197BC6-C700-4A1A-83C0-48414BA316E4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{095FA214-C024-4E6F-A027-14AAF03389F5}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{09C53597-9699-43EE-92C9-F94EA010A6EB}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{0DEC233F-B497-46A0-A5D1-BDC5CE848682}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{234CC0A4-4E85-4067-B5E5-0C5F11983794}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{2A04B30D-D2F7-47EE-918A-BBA170C6A6D3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2A07FB97-3969-4041-9652-16785AF9DCB0}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe | "{30D1829C-87ED-4C8B-81B7-8F1CC09FFDC0}" = protocol=6 | dir=out | app=system | "{31229094-FBD1-4BA3-BE93-40816D915429}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{350AAD17-B8DF-4ED2-BAC1-7539B69D6EE5}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{3E09273A-CE06-4195-A800-F5A7ADB79506}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{49082FC1-4E7A-4F64-9994-8EA9D84B733E}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{4AAC391B-1EC1-47B9-916F-77FDC8F7F2F5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{500F8F7B-9357-435F-AD55-EF1636269A69}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{50A5C85D-86B4-4590-A21B-1CDF89398701}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{53808C91-775E-4E8A-AFC3-129C7506C480}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{59469A0E-FC85-46FC-9815-C6BAAA32D49F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{5A414434-87F8-4DAF-9C25-985D8419F075}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{5F9ECFC0-B3FB-4B00-A1B7-808AF29861A9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{64AE4FE8-470F-4427-96EC-8085FABFD608}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{6A7B3059-FF08-4BD8-A250-2A65EFF5F743}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6B6B0967-F723-41A4-9AF7-3C80499B4178}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{6B8B2267-F29B-4C41-80FD-C0195398F187}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{6EBD80DC-5E52-418F-BD81-0362C6DA935A}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{6FC71981-9182-4051-826A-CACAE978F7F5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{705876F6-E80B-4369-8928-E0EB9E729FD4}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{7146AD81-F1BE-4655-9C26-EFE6E8DB5491}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{768E5A8A-79F3-4DFB-85D6-1CE9857EF0B8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{782FBDAE-4C57-4FC7-A13C-B5A72E65A26E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7DE6299D-7235-43D1-9986-1864DA704E08}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{82E8FC8C-3E34-4ECF-9941-B96D80FC4D71}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{8B9E6C59-5D78-4892-821F-A8C05E19BC13}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{8DBE9FE2-07B3-416C-B9F8-D5C0415C5F6E}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{997ACC9F-B8B8-414E-9B9D-EC57182C6F70}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe | "{A199C644-83B8-42A8-9E07-DD6B2D8E07CF}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{A3F469B3-4420-4D7A-841C-E1E8F6BBBA72}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{ADACC66B-A277-4FB8-B762-5B24B4DE918D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{B0677710-2366-4DD7-A605-561A6602D451}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{C3FCD341-14A3-45B4-999A-27B04DFA4664}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{C43D357B-019C-4906-86CB-874328D165C1}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{CDC2A246-FD29-4280-BCDD-21D56302067C}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{D467B325-0DF7-481C-BCFB-4E2E374EEBCC}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{D6465D35-7A14-4539-9203-214A2D36F33F}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe | "{D8D133E6-40D7-4AF9-B6E9-454DBDB8A65A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E4993A9C-7650-45CF-97E0-FD457CCA66D3}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{E99F4BF0-E0FE-40B0-8840-E481C7EFB2D6}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{F170E511-09EB-4167-8DD2-093D95C90D89}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{F5C07B9A-3E63-4B19-9DFE-5C354D9FA1BE}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{F6760EE2-77D9-4A05-A3E2-F61A67039803}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe | "{FA0BDDE2-3096-4331-BA29-64C55156BF05}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FB10493F-0F49-4E19-81D8-0196311E8166}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{FFEB0C56-03E5-4C48-BC06-C05099A34DD1}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "TCP Query User{0041345E-F048-4FEE-8095-69B7A61E380C}C:\users\cysia\appdata\local\temp\winlbvmgr.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winlbvmgr.exe | "TCP Query User{0115ADAD-4241-46F7-B9A1-0CFC547B2620}C:\users\cysia\appdata\local\temp\lgams.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\lgams.exe | "TCP Query User{02B56D24-134B-4F7E-9B5C-53BEEFC3EBBE}C:\program files\alcohol soft\alcohol 120\axautomntsrv.exe" = protocol=6 | dir=in | app=c:\program files\alcohol soft\alcohol 120\axautomntsrv.exe | "TCP Query User{04439F6B-4D64-4C89-B798-CCFBD37B7F01}C:\users\cysia\appdata\local\temp\winrado.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winrado.exe | "TCP Query User{07EAEB3A-F8DA-4C72-B02E-614596247E05}C:\program files\launch manager\hotkeyapp.exe" = protocol=6 | dir=in | app=c:\program files\launch manager\hotkeyapp.exe | "TCP Query User{08B15C1D-4E1C-4D16-AAF9-F08A5945B905}C:\users\cysia\appdata\local\temp\winhdokka.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winhdokka.exe | "TCP Query User{090D5B54-FCC9-412B-8CA7-A9A1037BAEED}C:\users\cysia\appdata\local\temp\winhlkx.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winhlkx.exe | "TCP Query User{0929B4C2-F286-44EA-8350-0F63779BB3A7}C:\users\cysia\appdata\local\temp\imky.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\imky.exe | "TCP Query User{096B3250-5076-4EDA-951B-6DE76447AC70}C:\na chwile!\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\na chwile!\metin2\metin2.bin | "TCP Query User{0A73F03F-0E8F-4D8F-9021-7F242AE9A653}C:\users\cysia\appdata\local\temp\gvfnch.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\gvfnch.exe | "TCP Query User{0C54526F-AB22-4C9C-B7C4-7F8957B9FC70}C:\users\cysia\appdata\local\temp\winiato.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winiato.exe | "TCP Query User{0C73A75B-E97C-43A9-A41A-147CC764B88E}C:\combofix\hidec.exe" = protocol=6 | dir=in | app=c:\combofix\hidec.exe | "TCP Query User{0D812E8D-EC5B-426A-B602-0527C97A5DA7}C:\users\cysia\appdata\local\temp\winlwghq.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winlwghq.exe | "TCP Query User{0ECCFB05-99F6-43E4-94D6-88F57110384F}C:\users\maria\appdata\local\temp\winxqinas.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\winxqinas.exe | "TCP Query User{0F277AD5-8703-4B4C-A935-25D632371B8D}C:\program files\linksys\linksys easylink advisor\linksys easylink advisor.exe" = protocol=6 | dir=in | app=c:\program files\linksys\linksys easylink advisor\linksys easylink advisor.exe | "TCP Query User{0FE0D413-0733-4CD0-9030-A512B5FBCA13}C:\users\cysia\appdata\local\temp\xikdk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\xikdk.exe | "TCP Query User{104227FE-3CE8-4FE3-9E50-F416D32BFC38}C:\users\cysia\appdata\local\temp\winnbvf.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winnbvf.exe | "TCP Query User{110653E5-C594-4B55-8941-96D2D7490C40}C:\users\cysia\appdata\local\temp\dyetk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\dyetk.exe | "TCP Query User{12A72EE1-3FA4-4F11-AF65-F1E09341AA8D}C:\na chwile!\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\na chwile!\metin2\metin2.bin | "TCP Query User{14F702CE-6EBF-4476-9443-DB5FF8966400}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{162311B9-ABE1-427C-8D3E-F6915C53B189}C:\windows\system32\wtablet\wacom_tabletuser.exe" = protocol=6 | dir=in | app=c:\windows\system32\wtablet\wacom_tabletuser.exe | "TCP Query User{16E36B1C-E662-4C23-8403-475D1D9B4BBC}C:\users\cysia\appdata\local\temp\winvmas.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winvmas.exe | "TCP Query User{175DCC76-1115-4A9B-A0E9-8E015C37BC15}C:\users\cysia\appdata\local\temp\winpjot.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winpjot.exe | "TCP Query User{1847B880-274C-4229-80D4-598242001F79}C:\users\cysia\appdata\local\temp\wingthsww.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\wingthsww.exe | "TCP Query User{1970B5BC-5BB3-46DF-AD9A-C0B745B14B1C}C:\users\cysia\appdata\local\temp\ufoptm.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\ufoptm.exe | "TCP Query User{19E8A030-50BF-45AA-A299-55630091EC8F}C:\windows\system32\hkcmd.exe" = protocol=6 | dir=in | app=c:\windows\system32\hkcmd.exe | "TCP Query User{1CAC8BF0-FB5E-4ACA-A601-30729B333666}C:\program files\itunes\ituneshelper.exe" = protocol=6 | dir=in | app=c:\program files\itunes\ituneshelper.exe | "TCP Query User{1F2D8AE4-3B75-41FD-AF1A-6735B81CC25C}C:\qeik\quake3.exe" = protocol=6 | dir=in | app=c:\qeik\quake3.exe | "TCP Query User{1FEC9B1B-8D4C-49F3-BB89-7A51659A383D}C:\users\cysia\appdata\local\temp\otkf.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\otkf.exe | "TCP Query User{2202011F-A84E-4778-9719-60625F5E2FCA}C:\users\cysia\appdata\local\temp\winptssr.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winptssr.exe | "TCP Query User{22DC69C8-B8C4-42D4-81E0-FF47FA72D5C7}C:\windows\system32\igfxtray.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxtray.exe | "TCP Query User{23595E8E-BE33-46E1-A7A0-941D56BA474B}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe | "TCP Query User{250B13F8-88CB-408B-A78E-417E33B08898}C:\windows\system32\wisptis.exe" = protocol=6 | dir=in | app=c:\windows\system32\wisptis.exe | "TCP Query User{2616CF70-47E2-4F22-85C8-BF96107B8FD8}C:\users\maria\appdata\local\temp\wineyuuh.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\wineyuuh.exe | "TCP Query User{2657BCC9-8081-48D4-B77A-ADD55127AC23}C:\users\cysia\appdata\local\temp\winkkuu.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winkkuu.exe | "TCP Query User{2716ECD7-3906-4D32-A74A-9F39566C47AE}C:\users\cysia\appdata\local\temp\abkk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\abkk.exe | "TCP Query User{280E6EF8-D576-495F-91D6-DB6299E47148}C:\users\cysia\appdata\local\temp\gsdsqy.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\gsdsqy.exe | "TCP Query User{282650A9-50AC-43F6-ADBB-AB2A7B4AAB3E}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe | "TCP Query User{2A31BDA1-CF3F-4AEF-81B8-D03E0FEE4959}C:\users\cysia\appdata\local\temp\winuucnob.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winuucnob.exe | "TCP Query User{2C4790FC-6190-4175-909C-0AF25F834F5F}C:\users\cysia\appdata\local\temp\winirrslb.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winirrslb.exe | "TCP Query User{2C9C1FAF-735D-497F-A525-E3B3F99481DA}C:\users\cysia\appdata\local\temp\winbcxs.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winbcxs.exe | "TCP Query User{2DFD0499-99FE-4A30-93CA-3E8C8CE2FA38}C:\users\cysia\appdata\local\temp\winhddsu.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winhddsu.exe | "TCP Query User{2E461A82-E8CE-439F-8F59-04100DC11C5F}C:\users\cysia\appdata\local\temp\fqomfj.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\fqomfj.exe | "TCP Query User{2F953528-564C-4B5D-99B7-DF848823171A}C:\users\maria\appdata\local\temp\rar$ex00.917\telewizja.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\rar$ex00.917\telewizja.exe | "TCP Query User{30E86E87-C016-4080-BC5F-E1BEF01FE566}C:\users\cysia\appdata\local\temp\gnkuvo.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\gnkuvo.exe | "TCP Query User{315A6136-55A7-4396-A2AF-D6148FDB258C}C:\users\cysia\appdata\local\temp\winxwgdt.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winxwgdt.exe | "TCP Query User{32AF272C-C026-4032-A538-60AF3B2AA824}C:\users\cysia\appdata\local\temp\winmsvebv.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winmsvebv.exe | "TCP Query User{332B7082-3A99-4E59-A78E-7314D349C1B1}C:\program files\metin2 i priv\spyware doctor\pctstray.exe" = protocol=6 | dir=in | app=c:\program files\metin2 i priv\spyware doctor\pctstray.exe | "TCP Query User{356F90B8-D050-4B9C-8652-14B9C7A2C537}C:\users\cysia\appdata\local\temp\winoxve.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winoxve.exe | "TCP Query User{359FBCE0-FFF4-4271-BDC3-317805F66495}C:\users\cysia\appdata\local\temp\winuqdwc.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winuqdwc.exe | "TCP Query User{3688C489-876A-4EC1-862B-1B7121B91A51}C:\windows\system32\userinit.exe" = protocol=6 | dir=in | app=c:\windows\system32\userinit.exe | "TCP Query User{3845E430-FF4D-4F09-907B-CCA675A01176}C:\users\cysia\appdata\local\temp\vryp.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\vryp.exe | "TCP Query User{38FEAFB0-074F-42D5-A632-8C2B6C800B01}C:\windows\system32\dwm.exe" = protocol=6 | dir=in | app=c:\windows\system32\dwm.exe | "TCP Query User{3921D26E-51AA-4878-9154-32C1A08E596E}C:\users\cysia\appdata\local\temp\winghhag.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winghhag.exe | "TCP Query User{39891019-DB11-454F-9454-EFBEAABB3730}C:\program files\windows defender\msascui.exe" = protocol=6 | dir=in | app=c:\program files\windows defender\msascui.exe | "TCP Query User{3CB7CB0F-A286-47C0-AC55-64EB8AF4955A}C:\users\cysia\appdata\local\temp\winyaji.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winyaji.exe | "TCP Query User{3CC1D661-F912-441F-A6C4-E509A9FBEFA2}C:\users\maria\appdata\local\temp\nfpmu.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\nfpmu.exe | "TCP Query User{3DC4126E-7C59-453E-A3FC-B7009C54F891}C:\program files\metin2 i priv\metin2\belenus.exe" = protocol=6 | dir=in | app=c:\program files\metin2 i priv\metin2\belenus.exe | "TCP Query User{41BCF137-3DA1-4511-9919-8B5296665CE3}E:\metin2client.bin" = protocol=6 | dir=in | app=e:\metin2client.bin | "TCP Query User{4506148A-77E8-4AA5-BAF0-83BBBCEC825D}I:\metin2\metin2.bin" = protocol=6 | dir=in | app=i:\metin2\metin2.bin | "TCP Query User{464DB1CF-B735-4D38-99DA-50668384FBAD}C:\users\cysia\appdata\local\temp\winouromk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winouromk.exe | "TCP Query User{46964A76-2F9B-4A95-BA5E-0A0E0500A67B}C:\program files\metin2 i priv\avalonmt2.exe" = protocol=6 | dir=in | app=c:\program files\metin2 i priv\avalonmt2.exe | "TCP Query User{471B22F4-1C17-43F7-8946-121777076EB5}C:\program files\metin2 i priv\metin2.bin" = protocol=6 | dir=in | app=c:\program files\metin2 i priv\metin2.bin | "TCP Query User{48812705-A549-4F27-AC57-E4E00DE57A03}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{4A215975-16B9-438B-BE60-73756B21B00D}C:\users\cysia\appdata\local\temp\winqgbv.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winqgbv.exe | "TCP Query User{4A8EA20F-3F56-401C-A33C-3360F00534C8}C:\users\cysia\appdata\local\temp\winaluvo.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winaluvo.exe | "TCP Query User{4D73A0E7-6E1D-4D42-A26C-D16A53D321B5}C:\users\cysia\appdata\local\temp\enovrc.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\enovrc.exe | "TCP Query User{4DC7301B-57AF-4558-B349-4ECDC91C6CAD}C:\users\cysia\appdata\local\temp\sxfn.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\sxfn.exe | "TCP Query User{4E5D41C7-919B-4B2A-9ED8-5B657D818D50}C:\users\cysia\appdata\local\temp\winafbgve.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winafbgve.exe | "TCP Query User{4EB6FE93-581A-4C72-B894-808A7D317449}C:\users\cysia\appdata\local\temp\winbxbbs.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winbxbbs.exe | "TCP Query User{4F5C5A3A-6E43-434A-B202-3C0EC5D0413A}C:\users\cysia\appdata\local\temp\pviu.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\pviu.exe | "TCP Query User{4FBB8599-C496-43CB-9836-ED868B180CF1}C:\users\cysia\appdata\local\temp\winoqatv.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winoqatv.exe | "TCP Query User{4FC8FA1A-06F0-4892-9F84-D0B72F26F2D0}C:\users\cysia\appdata\local\temp\winxtcyjt.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winxtcyjt.exe | "TCP Query User{51102517-94FE-455C-ABFD-CB468FB49A84}C:\users\cysia\appdata\local\temp\nvvba.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\nvvba.exe | "TCP Query User{519A5554-85A5-4ECF-9900-E1425A0B4E28}C:\program files\call of duty\codmp.exe" = protocol=6 | dir=in | app=c:\program files\call of duty\codmp.exe | "TCP Query User{527043F9-406A-4C8D-AFF8-0F8D52738EFB}C:\users\cysia\appdata\local\temp\winxcni.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winxcni.exe | "TCP Query User{5418D238-523E-417A-B5ED-AC496A1A9D77}C:\users\cysia\appdata\local\temp\winwahlju.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winwahlju.exe | "TCP Query User{55FB773E-16E4-4BFA-8EFE-714D7A1ABDA9}C:\users\cysia\appdata\local\temp\winphsog.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winphsog.exe | "TCP Query User{56771131-A2CF-4AA0-9F48-8C504456CEBB}C:\users\cysia\appdata\local\temp\winntkwek.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winntkwek.exe | "TCP Query User{58214921-0639-4643-B83A-D8A025334EA3}C:\users\cysia\appdata\local\temp\winmyle.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winmyle.exe | "TCP Query User{5A7801E9-E6A7-44A2-88D1-62E489450C47}C:\users\cysia\appdata\local\temp\wghpa.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\wghpa.exe | "TCP Query User{5AAFA6D6-F5C6-4C10-82E4-6D55D61DC6CF}C:\users\cysia\appdata\local\temp\etdo.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\etdo.exe | "TCP Query User{5BD5A2C0-DDDB-4B0D-8604-96EBE82909AB}C:\users\cysia\appdata\local\temp\winbvhai.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winbvhai.exe | "TCP Query User{5D4E5CB3-3962-46B9-9364-D1E4A1388E64}C:\users\cysia\appdata\local\temp\winojyr.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winojyr.exe | "TCP Query User{5FA56058-830B-483C-94A5-941B67F7CAF3}C:\users\cysia\appdata\local\temp\winbsif.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winbsif.exe | "TCP Query User{603405CD-E4CA-48ED-804E-821978CC312F}C:\windows\domino.exe" = protocol=6 | dir=in | app=c:\windows\domino.exe | "TCP Query User{606B37F0-50FA-4C03-BEAA-51A757AC367E}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe | "TCP Query User{61607A86-8D28-4281-BE73-2588E2F74E49}C:\users\cysia\appdata\local\temp\wintvuw.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\wintvuw.exe | "TCP Query User{6367CEF0-E2B6-4E82-A79D-EEC3AED33703}C:\users\cysia\appdata\local\temp\qphd.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\qphd.exe | "TCP Query User{63A4CE59-7EF7-4754-95B1-1A2E3794B585}C:\na chwile!\metin2\avalonmt2.exe" = protocol=6 | dir=in | app=c:\na chwile!\metin2\avalonmt2.exe | "TCP Query User{63D287F1-F597-4F26-B23E-B22F78F11E39}C:\program files\synaptics\syntp\syntpenh.exe" = protocol=6 | dir=in | app=c:\program files\synaptics\syntp\syntpenh.exe | "TCP Query User{64BEB54B-E6BC-407C-9ECA-D6F0B06C1719}E:\metin2.bin" = protocol=6 | dir=in | app=e:\metin2.bin | "TCP Query User{665A49AE-B6F6-4FBD-82E2-EE4A94B642DF}C:\users\cysia\appdata\local\temp\kmchtd.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\kmchtd.exe | "TCP Query User{670ED981-0C22-4C61-9825-0B58BEEFE146}C:\users\cysia\appdata\local\temp\hjmtcw.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\hjmtcw.exe | "TCP Query User{67CD412B-D741-440F-B487-F460115E18C2}C:\users\cysia\appdata\local\temp\xier.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\xier.exe | "TCP Query User{696EB92B-90B0-4B0F-B275-F14D905C642B}C:\users\cysia\appdata\local\temp\winhsxth.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winhsxth.exe | "TCP Query User{6A80E60B-09E4-4BA6-AF88-4AB2B08DB346}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe | "TCP Query User{6B5EB15D-EC41-4DE3-8055-D23B142A1A3A}C:\users\maria\appdata\local\temp\winragsng.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\winragsng.exe | "TCP Query User{6C4C8859-687A-4B1F-825B-1BFFD72AA071}C:\users\cysia\appdata\local\temp\slrpy.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\slrpy.exe | "TCP Query User{6FBB376B-A1A1-4E6D-AE6E-3614B6E0BE97}C:\users\cysia\appdata\local\temp\winfgxsk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winfgxsk.exe | "TCP Query User{71E5C0A1-A092-423A-98A9-973FF9617C1A}C:\users\cysia\appdata\local\temp\winmyyx.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winmyyx.exe | "TCP Query User{721D9590-9A31-406A-9545-FB7CFA201569}C:\users\cysia\appdata\local\temp\winpljxd.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winpljxd.exe | "TCP Query User{73E288D6-BF48-46C8-A11A-3D2075C8A172}C:\users\cysia\appdata\local\temp\winsibomy.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winsibomy.exe | "TCP Query User{776657D1-526A-4459-A399-4EE3C8FC5C87}C:\users\maria\appdata\local\temp\hugj.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\hugj.exe | "TCP Query User{7D4493C1-B050-40E6-8559-5452334E8C2C}C:\users\cysia\appdata\local\temp\rrpksp.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\rrpksp.exe | "TCP Query User{7DD259A0-51E1-4437-828C-6366FE985D54}C:\users\cysia\appdata\local\temp\cddo.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\cddo.exe | "TCP Query User{804110D4-0FA3-4D79-9B2B-B52CECFEEC80}C:\users\cysia\appdata\local\temp\winwybg.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winwybg.exe | "TCP Query User{80FE5F98-7F1A-4830-B8C1-0D008B5F9B45}C:\users\cysia\appdata\local\temp\winsiwm.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winsiwm.exe | "TCP Query User{81D3DA81-1AA8-4127-850F-9A5923791499}C:\program files\adobe\reader 8.0\reader\reader_sl.exe" = protocol=6 | dir=in | app=c:\program files\adobe\reader 8.0\reader\reader_sl.exe | "TCP Query User{82E78FF0-8840-458A-B198-FE9EE816353D}C:\users\cysia\appdata\local\temp\winmnerub.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winmnerub.exe | "TCP Query User{86F5D424-1BAC-4C8B-8783-3DF80268804B}C:\users\cysia\appdata\local\temp\wincdwd.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\wincdwd.exe | "TCP Query User{8766D2E4-5200-49F5-AE47-1CCB8CC9028A}C:\users\cysia\appdata\local\temp\winhrlnt.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winhrlnt.exe | "TCP Query User{8C84BA06-56CF-4514-80C2-1865E644A8C6}C:\windows\vmsnap3.exe" = protocol=6 | dir=in | app=c:\windows\vmsnap3.exe | "TCP Query User{8CB36C95-8A31-4FD9-94A7-0E06879B5476}C:\users\cysia\appdata\local\temp\onrnd.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\onrnd.exe | "TCP Query User{8D929D06-D2A0-4C4D-946C-72B942C66D17}C:\users\maria\appdata\local\temp\winjrtpu.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\winjrtpu.exe | "TCP Query User{8E61BDF1-C9FD-4B7D-9877-5A6EE1013C6B}C:\users\cysia\appdata\local\temp\ddviud.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\ddviud.exe | "TCP Query User{8F6F2F99-AC9E-47AC-9FAA-37BA4DBB673D}C:\users\cysia\appdata\local\temp\winleke.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winleke.exe | "TCP Query User{8FDB3099-57AD-45C0-AAA7-63CE42F16A9F}C:\users\cysia\appdata\local\temp\aedgk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\aedgk.exe | "TCP Query User{8FF4527F-3CC8-40E4-A484-14BA89BBC935}C:\users\cysia\appdata\local\temp\obqk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\obqk.exe | "TCP Query User{91E54D1F-0D58-4415-B13B-14C2B3FD6015}C:\users\maria\appdata\local\temp\winxyjt.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\winxyjt.exe | "TCP Query User{9206E666-13E7-45A3-822B-5E0DA62F147A}C:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe" = protocol=6 | dir=in | app=c:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe | "TCP Query User{92869445-EAB9-4CB3-A74E-AA373B74FB3B}C:\users\cysia\appdata\local\temp\winnaruf.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winnaruf.exe | "TCP Query User{92DF38D5-DBA5-4155-9397-A9ABB043E6C7}C:\users\cysia\appdata\local\temp\wincastjc.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\wincastjc.exe | "TCP Query User{93198601-17AA-44F3-8DE2-F3B87BB6029A}C:\users\cysia\appdata\local\temp\tnsyo.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\tnsyo.exe | "TCP Query User{93E141E4-F3D8-4130-8774-7F714AFD13F0}C:\users\cysia\appdata\local\temp\winggvk.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winggvk.exe | "TCP Query User{99CBB669-7726-4A81-9E39-F862DF1DA14C}C:\users\cysia\appdata\local\temp\winhpqvel.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winhpqvel.exe | "TCP Query User{99FAF287-9378-42D6-9FF6-8158F9DF9C32}C:\users\cysia\appdata\local\temp\windegwg.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\windegwg.exe | "TCP Query User{9A005C3E-5A2E-41C8-8696-2F53AEE48065}C:\users\cysia\appdata\local\temp\winsxue.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winsxue.exe | "TCP Query User{9B7BBFC7-58E8-4E12-B041-A284360B0C58}C:\users\cysia\appdata\local\temp\winwqua.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winwqua.exe | "TCP Query User{9CF795C3-9784-4DDD-9150-33EA86354758}C:\users\cysia\appdata\local\temp\aekkex.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\aekkex.exe | "TCP Query User{A1702FDF-9CDA-4321-8DC8-94A3BFD184BD}C:\program files\synaptics\syntp\syntpstart.exe" = protocol=6 | dir=in | app=c:\program files\synaptics\syntp\syntpstart.exe | "TCP Query User{A2ED5ADA-C7A7-44C9-9D5C-A44287B20CEA}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe | "TCP Query User{A3961C70-9D7B-4714-A275-BFE64EE355F5}C:\program files\common files\pure networks shared\platform\nmctxth.exe" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmctxth.exe | "TCP Query User{A4CB25C9-4BFC-48EE-89FF-0C2C9CE2F5B5}C:\users\cysia\appdata\local\temp\winxwjmr.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winxwjmr.exe | "TCP Query User{A563053B-247D-400B-B627-72ADDAE15F65}C:\users\cysia\appdata\local\temp\icte.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\icte.exe | "TCP Query User{A681D9CA-32BA-46A2-A5DB-BC4F2F69685A}E:\metin2\metin2client.bin" = protocol=6 | dir=in | app=e:\metin2\metin2client.bin | "TCP Query User{A798A65F-C17A-4E84-BFBE-2E7BDEEF9D89}C:\program files\z8games\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\program files\z8games\metin2\metin2.bin | "TCP Query User{A7EA85D7-E45A-484C-A61E-F583E224615E}C:\users\cysia\appdata\local\temp\winwuvx.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winwuvx.exe | "TCP Query User{A87B6A22-3D62-43C4-A1C1-EA995E04FC5B}C:\users\cysia\appdata\local\temp\winvtvlr.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winvtvlr.exe | "TCP Query User{AAB061C1-91FE-4400-9A95-6A236CEDB658}C:\users\cysia\appdata\local\temp\winnnoor.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winnnoor.exe | "TCP Query User{AB9126AE-F648-4D56-96F4-834FA34D9456}C:\users\cysia\appdata\local\temp\pdhgg.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\pdhgg.exe | "TCP Query User{AC7A142C-1EC8-4F8C-B5F3-22190749C588}C:\users\cysia\appdata\local\temp\winjkwqo.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winjkwqo.exe | "TCP Query User{AD148BEB-CEFC-4079-9737-D7169057ABCD}C:\users\cysia\appdata\local\temp\xmdjw.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\xmdjw.exe | "TCP Query User{ADB53D85-31C2-422E-B57C-8155E45AB12F}C:\users\cysia\appdata\local\temp\winyaps.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winyaps.exe | "TCP Query User{AF8EC932-A611-4DE7-B8B9-A6354724B398}C:\program files\pc connectivity solution\transports\nclmsbtsrv.exe" = protocol=6 | dir=in | app=c:\program files\pc connectivity solution\transports\nclmsbtsrv.exe | "TCP Query User{B78DCBE9-FF4E-48D1-922C-9B1D780E26E7}C:\users\cysia\appdata\local\temp\wintqygwh.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\wintqygwh.exe | "TCP Query User{B7BD55DA-6205-4F4D-9835-26907400B8DA}C:\users\cysia\appdata\local\temp\winwqaq.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winwqaq.exe | "TCP Query User{B8CA66D4-9D38-4E34-8A08-B31A8FA11F50}C:\program files\metin2 i priv\metin2mod.bin" = protocol=6 | dir=in | app=c:\program files\metin2 i priv\metin2mod.bin | "TCP Query User{BCE5C606-EF25-45CA-B7A6-4E8F05574898}C:\users\cysia\appdata\local\temp\winhpbfl.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winhpbfl.exe | "TCP Query User{BD9D2DF2-C742-482D-97A0-0BF30605BC63}C:\program files\common files\installshield\updateservice\issch.exe" = protocol=6 | dir=in | app=c:\program files\common files\installshield\updateservice\issch.exe | "TCP Query User{C07293F6-8B1D-449F-B2C8-6E28F50BE1FB}C:\program files\qprinter bookmaker\qprintmon.exe" = protocol=6 | dir=in | app=c:\program files\qprinter bookmaker\qprintmon.exe | "TCP Query User{C42511AB-7362-4886-844B-CB9A44D84EC9}C:\users\cysia\appdata\local\temp\wintouwlh.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\wintouwlh.exe | "TCP Query User{C6493BCE-9CB1-4FA9-9EF7-CE321656841C}C:\users\cysia\appdata\local\temp\winjdfe.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winjdfe.exe | "TCP Query User{C675B3B3-01C8-498C-9F36-C778968BBB0E}C:\users\cysia\appdata\local\temp\winadatr.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winadatr.exe | "TCP Query User{C6858188-92F5-4943-8C83-1EF1F2B3989D}C:\program files\skype\toolbars\shared\skypenames2.exe" = protocol=6 | dir=in | app=c:\program files\skype\toolbars\shared\skypenames2.exe | "TCP Query User{C7486EB8-523F-4718-B290-CC989316BFE2}C:\users\cysia\appdata\local\temp\dmlj.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\dmlj.exe | "TCP Query User{C792017B-7AA6-4652-BDB4-271C9222865D}C:\users\cysia\appdata\local\temp\pmicjj.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\pmicjj.exe | "TCP Query User{C7B29222-1009-46E8-99EF-036904F21A3A}C:\users\cysia\appdata\local\temp\winsgjjgc.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winsgjjgc.exe | "TCP Query User{CA880FB2-B7CA-4AC8-A5FC-C779EBA749FA}C:\users\cysia\appdata\local\temp\winbrbcpb.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winbrbcpb.exe | "TCP Query User{CABD90E3-5A0E-47D1-912A-F2F90B96BCE2}C:\users\cysia\appdata\local\temp\peach.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\peach.exe | "TCP Query User{CF04D3D8-CC6E-4DEF-ADF2-75A17A891564}C:\users\cysia\appdata\local\temp\winntrje.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winntrje.exe | "TCP Query User{CF24B0E7-615C-4304-9C16-23C4FCDD4AB9}C:\users\cysia\appdata\local\temp\winyqxnjm.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winyqxnjm.exe | "TCP Query User{D061D47E-26DB-4F5D-A748-407BD6420719}C:\users\cysia\appdata\local\temp\jukq.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\jukq.exe | "TCP Query User{D24F1836-7A47-4C09-96DA-79C0320D5788}C:\na chwile!\diablo ii\game.exe" = protocol=6 | dir=in | app=c:\na chwile!\diablo ii\game.exe | "TCP Query User{D4F5DBA7-C2B4-401A-9807-55E94264EECD}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{D612CD69-3488-490A-B449-5D0513585B91}C:\windows\system32\conime.exe" = protocol=6 | dir=in | app=c:\windows\system32\conime.exe | "TCP Query User{D7127B7D-1DE1-405E-BE59-11B4511A432B}C:\users\cysia\appdata\local\temp\uqij.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\uqij.exe | "TCP Query User{D7A797CE-1530-4525-B7D8-2CBFBBB9D26E}C:\users\cysia\appdata\local\temp\winfgvq.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winfgvq.exe | "TCP Query User{D7B60830-6EBE-447C-B90F-45EAAAE7481E}C:\users\cysia\appdata\local\temp\xfnux.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\xfnux.exe | "TCP Query User{D7BCF327-B8F0-4E89-9B02-B77AECDE3666}C:\users\maria\appdata\local\temp\cbrk.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\cbrk.exe | "TCP Query User{DBC4CDE3-23E0-4C27-BC16-8D09CE8586A4}C:\users\cysia\appdata\local\temp\windcyrjs.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\windcyrjs.exe | "TCP Query User{DE810604-54E9-4357-BF00-617FDFEC5BDA}C:\users\cysia\appdata\local\temp\gseopw.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\gseopw.exe | "TCP Query User{DE8D4013-12C0-46AA-97CF-F364D2095A28}C:\users\cysia\appdata\local\temp\brnds.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\brnds.exe | "TCP Query User{DEB58911-A8B1-4F36-9E97-39EDDE3689D4}C:\users\cysia\appdata\local\temp\vhiy.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\vhiy.exe | "TCP Query User{DEFB68D6-D05A-420D-8E58-41A0B6B747A8}C:\users\cysia\appdata\local\temp\cnbwe.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\cnbwe.exe | "TCP Query User{DF138F9B-2D3A-4CE7-AD2E-B8821CC42660}C:\users\cysia\appdata\local\temp\lkmmd.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\lkmmd.exe | "TCP Query User{E031BB26-F7B2-4011-816B-E75A85FFC2F6}C:\users\cysia\appdata\local\temp\winctnubl.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winctnubl.exe | "TCP Query User{E54908FB-BE63-4764-9E3A-FAF6A376BBD7}C:\users\cysia\appdata\local\temp\bwvvu.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\bwvvu.exe | "TCP Query User{E67BD624-7DB7-437D-9547-A97BD043D185}C:\users\maria\appdata\local\temp\winypij.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\winypij.exe | "TCP Query User{E7C8F8B3-9C5C-4926-8012-3B887AE483D5}C:\users\cysia\appdata\local\temp\winsopnle.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winsopnle.exe | "TCP Query User{EA42C8E2-966D-4AC6-811D-DC54653CFCE7}C:\users\cysia\appdata\local\temp\winloxm.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winloxm.exe | "TCP Query User{EA8247BB-6B5A-476A-AC65-94ED77E68002}E:\metin2\metin2.bin" = protocol=6 | dir=in | app=e:\metin2\metin2.bin | "TCP Query User{EA8E781F-D8B0-48CD-A67F-90AF6ADF48EA}C:\program files\common files\installshield\updateservice\isuspm.exe" = protocol=6 | dir=in | app=c:\program files\common files\installshield\updateservice\isuspm.exe | "TCP Query User{EBE3F48F-C0B2-474B-B87A-F19EB7DA4312}C:\windows\system32\igfxpers.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxpers.exe | "TCP Query User{ED423481-8BAC-492B-A7AA-7E5B14FD5AE0}C:\users\cysia\appdata\local\temp\winqlvow.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winqlvow.exe | "TCP Query User{EE2A5FD2-81CB-44BD-9BC4-ABA1B0FC68F1}C:\users\cysia\appdata\local\temp\winujgakm.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winujgakm.exe | "TCP Query User{EEF604D5-1E82-423F-A294-99B1CA2F5013}C:\users\cysia\appdata\local\temp\winolbd.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winolbd.exe | "TCP Query User{F0ABF1F0-7A44-43D9-9660-83E312623C85}C:\users\cysia\appdata\local\temp\winxxduhj.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winxxduhj.exe | "TCP Query User{F0EBF688-C371-4D6F-A65D-57F1169AF179}C:\users\maria\appdata\local\temp\winriqv.exe" = protocol=6 | dir=in | app=c:\users\maria\appdata\local\temp\winriqv.exe | "TCP Query User{F10A018E-CA63-44BB-8E34-ABF84C3310BD}C:\program files\adobe\reader 8.0\reader\adobecollabsync.exe" = protocol=6 | dir=in | app=c:\program files\adobe\reader 8.0\reader\adobecollabsync.exe | "TCP Query User{F271C524-0DF0-46E4-BD85-276D0BBD3BD6}C:\users\cysia\appdata\local\temp\xpuu.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\xpuu.exe | "TCP Query User{F31B1F65-F00A-49F3-BDC1-6DB10AFE1D4D}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe | "TCP Query User{F35B38DA-5301-4592-8212-4F01D241F94E}C:\program files\metin2 i priv\metin2client.bin" = protocol=6 | dir=in | app=c:\program files\metin2 i priv\metin2client.bin | "TCP Query User{F43FF9C6-2BFF-4A75-A3A0-5D8434677D30}C:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe" = protocol=6 | dir=in | app=c:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe | "TCP Query User{F446573F-875F-4862-A453-8F69C08627E3}C:\users\cysia\appdata\local\temp\maqs.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\maqs.exe | "TCP Query User{F7948BC1-448F-4B81-A14B-E2A9249F6AFB}C:\users\cysia\appdata\local\temp\winvsets.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winvsets.exe | "TCP Query User{F7ED561F-DC9D-47A5-91B8-4557C2AACF9F}C:\users\cysia\appdata\local\temp\winevew.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winevew.exe | "TCP Query User{F8546160-0085-4348-B0CD-33FFB4697F87}C:\program files\snajper elite\sniper elite\sniperelite.exe" = protocol=6 | dir=in | app=c:\program files\snajper elite\sniper elite\sniperelite.exe | "TCP Query User{F86ADEA8-6080-496F-BC34-43D82ED893F1}C:\users\cysia\appdata\local\temp\winpxelsr.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winpxelsr.exe | "TCP Query User{F9BFFAB9-6F0E-4717-B197-D126CE205ED2}C:\users\cysia\appdata\local\temp\winqqrnq.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winqqrnq.exe | "TCP Query User{FA23ECF7-52FF-47DB-A164-2B657E6841CA}C:\users\cysia\appdata\local\temp\jticih.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\jticih.exe | "TCP Query User{FB63F96C-5CDC-4BAA-92E4-86C4F41301DE}I:\metin2\metin2client.bin" = protocol=6 | dir=in | app=i:\metin2\metin2client.bin | "TCP Query User{FBE7234F-4AA0-4E83-A46E-81BD148466F9}C:\users\cysia\appdata\local\temp\winrgro.exe" = protocol=6 | dir=in | app=c:\users\cysia\appdata\local\temp\winrgro.exe | "TCP Query User{FD435BB6-5C8D-49BE-87C9-BC0E70B003DB}E:\metin2\metin2.bin" = protocol=6 | dir=in | app=e:\metin2\metin2.bin | "TCP Query User{FE4A7A4C-3084-4B2C-BB50-C9F617A4BBF1}C:\na chwile!\metin2\avalonmt2.exe" = protocol=6 | dir=in | app=c:\na chwile!\metin2\avalonmt2.exe | "UDP Query User{0475EF54-DD06-4BDF-AF26-487AA420041F}C:\program files\adobe\reader 8.0\reader\adobecollabsync.exe" = protocol=17 | dir=in | app=c:\program files\adobe\reader 8.0\reader\adobecollabsync.exe | "UDP Query User{04C24164-C175-495B-86AE-2AF0DEA549DD}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe | "UDP Query User{0601F1DB-1D7A-4A88-B770-6C6757B1021E}E:\metin2\metin2.bin" = protocol=17 | dir=in | app=e:\metin2\metin2.bin | "UDP Query User{078FFF2A-7E44-4B98-A3ED-E2DECA399822}C:\users\cysia\appdata\local\temp\winuqdwc.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winuqdwc.exe | "UDP Query User{07FD8A81-D475-4FF7-95D5-3F27178F0879}E:\metin2\metin2client.bin" = protocol=17 | dir=in | app=e:\metin2\metin2client.bin | "UDP Query User{0804901D-669E-4CC0-B672-9ED1DFEAD0C8}C:\program files\z8games\metin2\metin2.bin" = protocol=17 | dir=in | app=c:\program files\z8games\metin2\metin2.bin | "UDP Query User{09E3829F-C02C-45D5-A43C-29E44C7D7413}C:\users\cysia\appdata\local\temp\winouromk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winouromk.exe | "UDP Query User{10153920-CB72-412F-B751-B1A424D27B0B}C:\users\cysia\appdata\local\temp\winyaps.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winyaps.exe | "UDP Query User{1035A383-CE5D-49B4-8688-C7484C0D53C5}C:\users\cysia\appdata\local\temp\dyetk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\dyetk.exe | "UDP Query User{10CD3E01-3FC2-499A-ADEC-177761F6302B}C:\program files\metin2 i priv\metin2mod.bin" = protocol=17 | dir=in | app=c:\program files\metin2 i priv\metin2mod.bin | "UDP Query User{12BFF06E-D96B-4B57-A4B5-B1E0781B1317}C:\users\cysia\appdata\local\temp\winvmas.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winvmas.exe | "UDP Query User{12FEF8BF-9C39-4ED3-A4D6-3FDC872F2AB1}C:\users\cysia\appdata\local\temp\winxcni.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winxcni.exe | "UDP Query User{159C051C-689C-4007-8154-B72FF745B4E8}C:\users\cysia\appdata\local\temp\winnnoor.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winnnoor.exe | "UDP Query User{15E490A7-C463-4A09-B5E8-56524B5FA891}C:\users\cysia\appdata\local\temp\winsibomy.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winsibomy.exe | "UDP Query User{16304183-F1FB-4D54-ACB9-D01BF4D594E7}C:\program files\call of duty\codmp.exe" = protocol=17 | dir=in | app=c:\program files\call of duty\codmp.exe | "UDP Query User{16F35B3B-E553-4BA9-BE98-E51F8D873115}C:\users\cysia\appdata\local\temp\winbxbbs.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winbxbbs.exe | "UDP Query User{180D9B76-A413-44E6-B08F-1AB2938AD1AE}C:\users\cysia\appdata\local\temp\abkk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\abkk.exe | "UDP Query User{182BBB9F-5109-4382-8B8B-D6C8CFF79B6A}C:\users\cysia\appdata\local\temp\aedgk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\aedgk.exe | "UDP Query User{1A9AF2FD-038A-40C9-A354-49E263C401A6}C:\users\cysia\appdata\local\temp\winkkuu.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winkkuu.exe | "UDP Query User{1D16F32A-04EF-45C9-9D4F-D1CBF2074CF7}C:\users\cysia\appdata\local\temp\wintvuw.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\wintvuw.exe | "UDP Query User{1FA2557F-548F-4F61-B30F-3647BBE15766}C:\users\cysia\appdata\local\temp\winpxelsr.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winpxelsr.exe | "UDP Query User{20E4108D-6C73-4F63-808D-2EE757FC1B64}C:\users\cysia\appdata\local\temp\vhiy.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\vhiy.exe | "UDP Query User{21B68F9F-B8E5-4653-BE96-447B97836957}C:\users\cysia\appdata\local\temp\wingthsww.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\wingthsww.exe | "UDP Query User{235A5C40-DEA9-4EE4-A035-9EEAACC0F322}C:\users\cysia\appdata\local\temp\winptssr.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winptssr.exe | "UDP Query User{24A57CC6-9381-4F04-A5F2-C960E302BDB2}C:\users\maria\appdata\local\temp\rar$ex00.917\telewizja.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\rar$ex00.917\telewizja.exe | "UDP Query User{2523D11F-2A43-4E2F-9159-1F4FFA84AA5E}C:\users\maria\appdata\local\temp\winriqv.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\winriqv.exe | "UDP Query User{26A63333-BC96-4A2C-AEB3-7FBAEC20D3EC}C:\users\cysia\appdata\local\temp\winevew.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winevew.exe | "UDP Query User{2789FCC4-072C-46B5-A5F1-CFC3D35C0CE7}C:\users\cysia\appdata\local\temp\winoxve.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winoxve.exe | "UDP Query User{2796F56D-B6D8-492B-AB43-F739ACBDB38D}C:\users\maria\appdata\local\temp\nfpmu.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\nfpmu.exe | "UDP Query User{280FBCB1-07B7-496B-A897-2F4741C01565}C:\na chwile!\metin2\avalonmt2.exe" = protocol=17 | dir=in | app=c:\na chwile!\metin2\avalonmt2.exe | "UDP Query User{28A1E9C3-D45D-40F1-82F0-6F9B42F61202}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe | "UDP Query User{295254BD-E377-4DA6-B80D-24CC767C8E00}C:\users\maria\appdata\local\temp\hugj.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\hugj.exe | "UDP Query User{2C261EB2-A2CB-44E8-8AD7-F415AFBA4AD7}C:\users\cysia\appdata\local\temp\winbrbcpb.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winbrbcpb.exe | "UDP Query User{2CE66986-03AF-4387-9F39-0FD00A1A6FAE}C:\windows\system32\hkcmd.exe" = protocol=17 | dir=in | app=c:\windows\system32\hkcmd.exe | "UDP Query User{2DC76225-A5C5-4825-B4EA-790782E142FB}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{2E5D2713-012F-4A07-B21E-FF86F48BE5A6}C:\users\cysia\appdata\local\temp\winojyr.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winojyr.exe | "UDP Query User{30C5AFC8-DB21-4C24-A051-60D094630021}C:\users\cysia\appdata\local\temp\hjmtcw.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\hjmtcw.exe | "UDP Query User{3272ABEE-6D23-4A64-8C47-7AAD5E2BB4B2}C:\users\cysia\appdata\local\temp\winwuvx.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winwuvx.exe | "UDP Query User{328DBA3B-5F85-4B6B-8939-183A46453D5C}C:\program files\windows defender\msascui.exe" = protocol=17 | dir=in | app=c:\program files\windows defender\msascui.exe | "UDP Query User{3326313D-54F6-4DA9-867B-3C843CF8B00A}C:\users\cysia\appdata\local\temp\winjkwqo.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winjkwqo.exe | "UDP Query User{33804681-E17D-4B8D-8D3B-7FD1F3400B54}C:\program files\common files\installshield\updateservice\isuspm.exe" = protocol=17 | dir=in | app=c:\program files\common files\installshield\updateservice\isuspm.exe | "UDP Query User{3478DB0C-8E60-4F7B-81FB-9926F41D8136}C:\users\cysia\appdata\local\temp\winsiwm.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winsiwm.exe | "UDP Query User{349BA783-0181-49B5-AB3C-16F63348A82C}C:\users\cysia\appdata\local\temp\jticih.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\jticih.exe | "UDP Query User{36679272-E2C3-4089-97A6-1082C827B2F5}C:\users\cysia\appdata\local\temp\jukq.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\jukq.exe | "UDP Query User{37165DE8-7A7C-4AE8-8D7A-55DEDA84B522}C:\users\cysia\appdata\local\temp\pmicjj.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\pmicjj.exe | "UDP Query User{376AC2EE-8CE9-4A50-ACAA-63679DE5EEDD}C:\users\cysia\appdata\local\temp\winmsvebv.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winmsvebv.exe | "UDP Query User{3B035481-2CA1-4B3B-9008-33852BD93628}C:\users\cysia\appdata\local\temp\winyaji.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winyaji.exe | "UDP Query User{3F6FB66D-0B8D-4ADA-9F13-2C8EB0B4846A}C:\users\maria\appdata\local\temp\winxqinas.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\winxqinas.exe | "UDP Query User{3F9A31AB-6231-49FB-B354-50C90C069E7B}C:\windows\system32\dwm.exe" = protocol=17 | dir=in | app=c:\windows\system32\dwm.exe | "UDP Query User{41B8D911-94C5-49D1-9CD0-0B7B953594EC}C:\users\cysia\appdata\local\temp\winphsog.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winphsog.exe | "UDP Query User{427CDBC9-FE65-47D0-ADDB-2E3C08FA201A}C:\users\cysia\appdata\local\temp\winqlvow.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winqlvow.exe | "UDP Query User{42F883A0-B995-4DE4-956E-B404C061533F}C:\users\cysia\appdata\local\temp\wincdwd.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\wincdwd.exe | "UDP Query User{433B1686-BB66-4491-98BB-4D50102C0243}C:\na chwile!\diablo ii\game.exe" = protocol=17 | dir=in | app=c:\na chwile!\diablo ii\game.exe | "UDP Query User{43418FA6-1E86-4157-9274-160AA5DA1DB0}C:\users\cysia\appdata\local\temp\winntrje.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winntrje.exe | "UDP Query User{46AA9DD7-3968-4788-B2D6-02B4E8CF2F65}C:\users\maria\appdata\local\temp\winxyjt.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\winxyjt.exe | "UDP Query User{4950510C-F6C1-4BDA-B440-B1C109D6107B}C:\users\cysia\appdata\local\temp\winfgvq.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winfgvq.exe | "UDP Query User{4B388A08-CF5B-4E0D-9132-C553D9E1B868}C:\users\cysia\appdata\local\temp\winolbd.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winolbd.exe | "UDP Query User{4BA6335D-A3EC-4D2C-BD50-7F69D16C2989}C:\users\cysia\appdata\local\temp\winnaruf.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winnaruf.exe | "UDP Query User{4BF16A19-AC5F-4AEC-812C-FB0D82B1B10C}C:\users\cysia\appdata\local\temp\gvfnch.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\gvfnch.exe | "UDP Query User{4CC62252-2C2E-4688-860A-AD7F693457E3}C:\users\cysia\appdata\local\temp\pdhgg.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\pdhgg.exe | "UDP Query User{502938A0-4C68-47AE-859F-742EA7A8880B}C:\program files\adobe\reader 8.0\reader\reader_sl.exe" = protocol=17 | dir=in | app=c:\program files\adobe\reader 8.0\reader\reader_sl.exe | "UDP Query User{50FAE17A-2C09-40F5-9B7F-50836CC6F918}C:\program files\common files\pure networks shared\platform\nmctxth.exe" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmctxth.exe | "UDP Query User{52AD4BB8-E967-4108-BDB1-5965A9F47989}C:\users\cysia\appdata\local\temp\windcyrjs.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\windcyrjs.exe | "UDP Query User{54196A5B-597F-4748-A9AF-781306972AA5}C:\users\cysia\appdata\local\temp\winhpbfl.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winhpbfl.exe | "UDP Query User{550175F9-50D1-4614-A089-EE2AE7EC3BA3}C:\windows\system32\igfxtray.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxtray.exe | "UDP Query User{555580BB-EAB9-489C-9EB1-FE9D142288C8}C:\users\cysia\appdata\local\temp\cddo.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\cddo.exe | "UDP Query User{55E5EE22-40AC-4511-AEAA-27628789511C}C:\program files\qprinter bookmaker\qprintmon.exe" = protocol=17 | dir=in | app=c:\program files\qprinter bookmaker\qprintmon.exe | "UDP Query User{5800E84A-BFB3-495D-96B3-EE4C9C7E9C20}C:\windows\system32\wtablet\wacom_tabletuser.exe" = protocol=17 | dir=in | app=c:\windows\system32\wtablet\wacom_tabletuser.exe | "UDP Query User{581E3365-4996-4576-B1EB-329F9379088A}C:\program files\synaptics\syntp\syntpenh.exe" = protocol=17 | dir=in | app=c:\program files\synaptics\syntp\syntpenh.exe | "UDP Query User{58E92A8C-FC1B-4F07-B30E-5F36CFC2DDC5}C:\users\cysia\appdata\local\temp\winwahlju.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winwahlju.exe | "UDP Query User{58EA8280-8500-4B30-88B6-4F28C57AECA2}C:\qeik\quake3.exe" = protocol=17 | dir=in | app=c:\qeik\quake3.exe | "UDP Query User{591C6E5C-21EC-4E73-ABC8-9D2923407EDB}C:\windows\domino.exe" = protocol=17 | dir=in | app=c:\windows\domino.exe | "UDP Query User{5BBB15D5-E762-4AA8-B08D-D3CD51F8137C}C:\users\cysia\appdata\local\temp\xpuu.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\xpuu.exe | "UDP Query User{5C33DBD5-CF97-4C14-A39D-6D6613D92443}C:\users\cysia\appdata\local\temp\winxwgdt.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winxwgdt.exe | "UDP Query User{5E4476BB-A340-43AD-B2E4-94936620C5AB}C:\users\cysia\appdata\local\temp\winmyyx.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winmyyx.exe | "UDP Query User{5F456EFA-6BF3-41DA-8F3A-85799A2F8F54}C:\users\cysia\appdata\local\temp\winxwjmr.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winxwjmr.exe | "UDP Query User{5FAF3527-21CA-489E-A0C9-C7B241845334}C:\users\cysia\appdata\local\temp\winyqxnjm.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winyqxnjm.exe | "UDP Query User{60B521E6-4293-43F4-AA62-F5DDD941ECF3}C:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe" = protocol=17 | dir=in | app=c:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe | "UDP Query User{61344CDF-8510-44A5-83BA-3EF4D8F1BF42}C:\users\cysia\appdata\local\temp\winadatr.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winadatr.exe | "UDP Query User{660F4813-2EA1-4FC2-A4E3-168E1482714C}C:\users\cysia\appdata\local\temp\winvsets.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winvsets.exe | "UDP Query User{66100453-F2FE-4485-B2C4-B5AA06BB0114}C:\users\cysia\appdata\local\temp\winctnubl.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winctnubl.exe | "UDP Query User{669148C5-69DE-4A06-AC7D-16E12950F9A9}C:\users\cysia\appdata\local\temp\xmdjw.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\xmdjw.exe | "UDP Query User{66A19574-7E86-40BD-B1EF-B92DAF867DBC}C:\users\cysia\appdata\local\temp\winsxue.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winsxue.exe | "UDP Query User{677C2F34-55C9-458F-B224-56C0243E372E}I:\metin2\metin2.bin" = protocol=17 | dir=in | app=i:\metin2\metin2.bin | "UDP Query User{683EB557-605B-4E09-89DD-1785E8E103A9}C:\users\cysia\appdata\local\temp\bwvvu.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\bwvvu.exe | "UDP Query User{69D17946-DB50-4425-B922-2DA887093316}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe | "UDP Query User{6C0A36E5-E841-42DB-BAD6-447B6C15D7BF}C:\users\cysia\appdata\local\temp\winhlkx.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winhlkx.exe | "UDP Query User{6D412EA2-0BCF-4113-A0C5-96D51C59E446}C:\users\cysia\appdata\local\temp\xikdk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\xikdk.exe | "UDP Query User{6D9C9CDC-7B48-40EC-AECE-1DC298A61D96}C:\windows\system32\userinit.exe" = protocol=17 | dir=in | app=c:\windows\system32\userinit.exe | "UDP Query User{6F3FE341-6FDC-44CA-A4C4-7825A2AD1537}C:\users\cysia\appdata\local\temp\ddviud.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\ddviud.exe | "UDP Query User{6F847431-DFF2-4CC6-A06C-C42495F3EB18}C:\users\cysia\appdata\local\temp\etdo.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\etdo.exe | "UDP Query User{6FD450F1-3F92-43E3-881F-1D2FA80EA8C0}C:\users\cysia\appdata\local\temp\fqomfj.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\fqomfj.exe | "UDP Query User{71139A95-C935-4051-AB76-3B3EB4C5D182}C:\program files\itunes\ituneshelper.exe" = protocol=17 | dir=in | app=c:\program files\itunes\ituneshelper.exe | "UDP Query User{72BACFFF-F075-4E3D-87E6-632FBD6C8C73}C:\users\cysia\appdata\local\temp\winmnerub.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winmnerub.exe | "UDP Query User{72E014F8-015A-4E4E-A3BF-E5A78E20231C}C:\users\cysia\appdata\local\temp\winsopnle.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winsopnle.exe | "UDP Query User{72F20E76-3A26-47EF-9AE9-CC85DC2F1263}C:\users\cysia\appdata\local\temp\winntkwek.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winntkwek.exe | "UDP Query User{731752CB-C55F-43E0-A244-EBD174B2ECBB}C:\windows\system32\conime.exe" = protocol=17 | dir=in | app=c:\windows\system32\conime.exe | "UDP Query User{76EC2D80-088B-461C-969A-C598304D9264}C:\users\cysia\appdata\local\temp\enovrc.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\enovrc.exe | "UDP Query User{771BFA6E-CCB3-4A64-893C-4EB61F941D58}C:\users\cysia\appdata\local\temp\winsgjjgc.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winsgjjgc.exe | "UDP Query User{77818B54-5879-48B2-85E0-59209D4CA1E7}C:\users\cysia\appdata\local\temp\winleke.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winleke.exe | "UDP Query User{7937F64A-46BC-4C1D-8325-B95BACBC9AA2}C:\users\cysia\appdata\local\temp\winirrslb.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winirrslb.exe | "UDP Query User{7CEA5E40-B857-4008-8BD4-52485B7B2152}C:\program files\synaptics\syntp\syntpstart.exe" = protocol=17 | dir=in | app=c:\program files\synaptics\syntp\syntpstart.exe | "UDP Query User{7D9D7956-9D49-4CF8-B73C-F2D5897B7C84}C:\program files\metin2 i priv\avalonmt2.exe" = protocol=17 | dir=in | app=c:\program files\metin2 i priv\avalonmt2.exe | "UDP Query User{7E037C85-04BC-4F84-A67A-3642425F7AEE}C:\users\cysia\appdata\local\temp\kmchtd.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\kmchtd.exe | "UDP Query User{7ED56DB4-6699-40DF-874C-A3F7EB4BF3CC}C:\users\cysia\appdata\local\temp\nvvba.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\nvvba.exe | "UDP Query User{7F20ECC9-DA4B-4427-A244-EACAF8F0AA75}C:\users\maria\appdata\local\temp\wineyuuh.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\wineyuuh.exe | "UDP Query User{808D2E90-1E64-40D6-8743-6456186062D6}C:\users\cysia\appdata\local\temp\winxxduhj.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winxxduhj.exe | "UDP Query User{819A14CE-346F-4796-A322-8C5470EA0690}C:\users\cysia\appdata\local\temp\vryp.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\vryp.exe | "UDP Query User{81F3F216-6831-4AB6-8A39-40263CD1A558}C:\users\cysia\appdata\local\temp\winwybg.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winwybg.exe | "UDP Query User{83FEC109-4422-4DFF-9DA3-3CE1D087B8F8}E:\metin2client.bin" = protocol=17 | dir=in | app=e:\metin2client.bin | "UDP Query User{865CE3D1-B9FF-4471-91F2-6E1C800D6AEF}C:\users\cysia\appdata\local\temp\winhsxth.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winhsxth.exe | "UDP Query User{88100558-5E77-4CB6-996D-715B48113954}C:\users\cysia\appdata\local\temp\icte.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\icte.exe | "UDP Query User{88F9CAD9-17C1-48B5-8FF4-5E5443BDE3F8}C:\users\cysia\appdata\local\temp\rrpksp.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\rrpksp.exe | "UDP Query User{89EEFBF7-5A09-4043-82E6-D5B832E21EB8}C:\users\cysia\appdata\local\temp\winnbvf.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winnbvf.exe | "UDP Query User{903106A8-704C-4BB2-86E8-794DB1E79464}C:\users\cysia\appdata\local\temp\uqij.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\uqij.exe | "UDP Query User{90FF05F9-D565-4844-A1E6-DE220085A024}C:\program files\metin2 i priv\metin2.bin" = protocol=17 | dir=in | app=c:\program files\metin2 i priv\metin2.bin | "UDP Query User{93BBE1B8-C2AC-4E45-AF15-27E7B8EFBA9E}C:\users\cysia\appdata\local\temp\wintqygwh.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\wintqygwh.exe | "UDP Query User{9406D15E-6FAE-4FB9-9F63-AB60BB74461C}C:\users\cysia\appdata\local\temp\winpjot.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winpjot.exe | "UDP Query User{94677C45-4949-4288-9E70-8BB13DCA5318}C:\users\cysia\appdata\local\temp\xier.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\xier.exe | "UDP Query User{965FF1D4-A7BE-4360-AD70-DBEF3EBD4978}C:\users\cysia\appdata\local\temp\aekkex.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\aekkex.exe | "UDP Query User{99828646-2E47-4E98-923C-1A07FF2409E4}C:\users\cysia\appdata\local\temp\otkf.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\otkf.exe | "UDP Query User{99CA678F-60B0-45F7-8189-275E88F35A1F}C:\users\maria\appdata\local\temp\winragsng.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\winragsng.exe | "UDP Query User{9A0B3C43-D980-4F87-BAB9-73394793BE57}C:\users\cysia\appdata\local\temp\windegwg.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\windegwg.exe | "UDP Query User{9B00C36B-B05D-4569-ABCA-5CFB4609FF56}C:\program files\snajper elite\sniper elite\sniperelite.exe" = protocol=17 | dir=in | app=c:\program files\snajper elite\sniper elite\sniperelite.exe | "UDP Query User{9BB3A23F-F1FB-4DA9-8693-AA6729841584}C:\users\cysia\appdata\local\temp\winwqaq.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winwqaq.exe | "UDP Query User{9CB99EBC-43C0-4087-A78F-A957C4C39866}C:\users\cysia\appdata\local\temp\peach.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\peach.exe | "UDP Query User{9D345CAA-29F8-435A-A4CD-A69709CA3C5E}C:\users\cysia\appdata\local\temp\tnsyo.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\tnsyo.exe | "UDP Query User{9ED2AC2E-1AE1-45C6-86B4-CBB93A54CA42}C:\users\cysia\appdata\local\temp\gseopw.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\gseopw.exe | "UDP Query User{A06143E8-43B6-4425-AF7A-94F8948DE40F}C:\users\cysia\appdata\local\temp\winaluvo.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winaluvo.exe | "UDP Query User{A2EA06E5-9A42-4EA4-A314-F11AB3C5C7CE}E:\metin2\metin2.bin" = protocol=17 | dir=in | app=e:\metin2\metin2.bin | "UDP Query User{A3AE2C55-406B-4BD9-8313-B4AEC359EB11}C:\users\maria\appdata\local\temp\winypij.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\winypij.exe | "UDP Query User{A4BFE562-A91A-4AC0-9028-596B55763DCA}C:\na chwile!\metin2\avalonmt2.exe" = protocol=17 | dir=in | app=c:\na chwile!\metin2\avalonmt2.exe | "UDP Query User{A591FA6F-127B-4240-BB98-9E351E25261B}C:\users\cysia\appdata\local\temp\winmyle.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winmyle.exe | "UDP Query User{A85616BF-0104-4D8C-AAA6-DFE0507C8753}C:\users\cysia\appdata\local\temp\winbsif.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winbsif.exe | "UDP Query User{A8BBB147-5CA8-4252-BB0A-0B026C33D269}C:\users\cysia\appdata\local\temp\wincastjc.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\wincastjc.exe | "UDP Query User{AB7A6613-9BAA-4AA3-A376-3A40DA65DB61}C:\program files\common files\installshield\updateservice\issch.exe" = protocol=17 | dir=in | app=c:\program files\common files\installshield\updateservice\issch.exe | "UDP Query User{AB834D16-5FCD-4409-ACE5-2FDF668CAC36}C:\users\maria\appdata\local\temp\cbrk.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\cbrk.exe | "UDP Query User{ABE817FE-7C1C-4C12-AD4B-E61DC8580ACF}C:\users\cysia\appdata\local\temp\gnkuvo.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\gnkuvo.exe | "UDP Query User{AC1C57A7-3F82-4831-8CDB-F00C7D121F06}I:\metin2\metin2client.bin" = protocol=17 | dir=in | app=i:\metin2\metin2client.bin | "UDP Query User{AEE53E18-C36F-4DBA-BB86-A778D019A014}C:\users\cysia\appdata\local\temp\winjdfe.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winjdfe.exe | "UDP Query User{AFDE3AF6-7D95-4F6E-91FF-175E7F4EAF1D}C:\users\cysia\appdata\local\temp\winqqrnq.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winqqrnq.exe | "UDP Query User{B048804B-3F2A-4BA8-885F-2EAE7271B7E4}C:\users\cysia\appdata\local\temp\winggvk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winggvk.exe | "UDP Query User{B14A03E5-6F00-4233-AAD4-BA2070E2F9DB}C:\users\cysia\appdata\local\temp\winpljxd.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winpljxd.exe | "UDP Query User{B29BE65E-2F7D-4235-810E-4C8DF4E42A9E}C:\users\cysia\appdata\local\temp\wintouwlh.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\wintouwlh.exe | "UDP Query User{B33FD59F-C58A-4610-A5E9-15467AE1FB9D}C:\users\cysia\appdata\local\temp\ufoptm.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\ufoptm.exe | "UDP Query User{B37562DD-DB41-4FF9-B908-1AC0F7DC86C6}C:\users\cysia\appdata\local\temp\winiato.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winiato.exe | "UDP Query User{B4B8B1C8-05BD-4A2B-82B0-32B6E981C321}C:\combofix\hidec.exe" = protocol=17 | dir=in | app=c:\combofix\hidec.exe | "UDP Query User{B4E030E9-FA2C-450C-83D6-810CBBB4349B}C:\users\cysia\appdata\local\temp\obqk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\obqk.exe | "UDP Query User{B85A2362-E243-4E33-90CF-BC19F62C35DB}C:\users\cysia\appdata\local\temp\qphd.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\qphd.exe | "UDP Query User{B9F74E95-718D-4A72-949F-30F88E55FAE5}C:\users\cysia\appdata\local\temp\winafbgve.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winafbgve.exe | "UDP Query User{BAE671D1-578D-4E7D-BB01-98C4A21200A7}C:\users\cysia\appdata\local\temp\cnbwe.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\cnbwe.exe | "UDP Query User{BF6F838A-B8F4-48A6-9668-B2E7D8535CF9}C:\users\cysia\appdata\local\temp\lgams.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\lgams.exe | "UDP Query User{C02CE452-2F1B-426C-8BB6-99433B6CD717}C:\users\cysia\appdata\local\temp\pviu.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\pviu.exe | "UDP Query User{C466E51D-7F87-49C6-B583-41217C4BA410}C:\users\cysia\appdata\local\temp\dmlj.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\dmlj.exe | "UDP Query User{C606E41B-3DAC-41A2-BA3A-4E76921A36C0}C:\users\cysia\appdata\local\temp\brnds.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\brnds.exe | "UDP Query User{C6546893-123C-48BC-A219-50C39B65CEFB}C:\users\cysia\appdata\local\temp\winlbvmgr.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winlbvmgr.exe | "UDP Query User{C702FEDA-6F86-4269-ACFB-AB1D22656E69}C:\users\cysia\appdata\local\temp\maqs.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\maqs.exe | "UDP Query User{C73C3BE6-C741-4100-9ED9-0A232913D046}C:\users\cysia\appdata\local\temp\winbcxs.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winbcxs.exe | "UDP Query User{C7745ED6-BC80-4B1B-A1D3-29D3E0EB6537}C:\users\cysia\appdata\local\temp\xfnux.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\xfnux.exe | "UDP Query User{C90E1FCC-5159-48D6-A95A-1B0293F3ED90}C:\program files\metin2 i priv\metin2\belenus.exe" = protocol=17 | dir=in | app=c:\program files\metin2 i priv\metin2\belenus.exe | "UDP Query User{C990D086-528A-4425-8C57-A82AC1CB2DBA}C:\users\cysia\appdata\local\temp\gsdsqy.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\gsdsqy.exe | "UDP Query User{CAC4E810-3FFF-495C-91B9-58F5DC48045F}C:\users\cysia\appdata\local\temp\winbvhai.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winbvhai.exe | "UDP Query User{CB8A311E-A6CE-4647-8138-6095FC1EE0ED}C:\users\cysia\appdata\local\temp\slrpy.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\slrpy.exe | "UDP Query User{CBB6F66E-75D3-464E-86C3-E40F8EA111E3}C:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe" = protocol=17 | dir=in | app=c:\program files\corel\coreldraw graphics suite 13\programs\corelpp.exe | "UDP Query User{CC7ECC8D-02D0-442F-8D34-A24331C574C3}C:\users\cysia\appdata\local\temp\onrnd.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\onrnd.exe | "UDP Query User{CDBB2171-3A11-442D-84AD-D06B84582057}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{D0D1640E-24FF-4EBA-96AE-63E785D85A50}C:\users\cysia\appdata\local\temp\winhdokka.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winhdokka.exe | "UDP Query User{D0D40286-EC7C-4B8B-8B56-1E5E6AAEDAC8}C:\users\cysia\appdata\local\temp\winhrlnt.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winhrlnt.exe | "UDP Query User{D14528AA-2E0F-4025-B5E1-98C1E50AACA4}C:\program files\alcohol soft\alcohol 120\axautomntsrv.exe" = protocol=17 | dir=in | app=c:\program files\alcohol soft\alcohol 120\axautomntsrv.exe | "UDP Query User{D1C567DD-62F2-4119-A611-45FC729F7E47}C:\users\cysia\appdata\local\temp\winloxm.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winloxm.exe | "UDP Query User{D26E43CA-CD4C-4843-8D0F-13AE70DF036B}C:\users\cysia\appdata\local\temp\winhddsu.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winhddsu.exe | "UDP Query User{D39F78CB-316A-438A-9D70-120B83897D57}C:\program files\pc connectivity solution\transports\nclmsbtsrv.exe" = protocol=17 | dir=in | app=c:\program files\pc connectivity solution\transports\nclmsbtsrv.exe | "UDP Query User{D63C41B7-3F9D-4AEF-9048-D08AA4FAB6AB}C:\users\cysia\appdata\local\temp\winxtcyjt.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winxtcyjt.exe | "UDP Query User{D7139340-0BB7-4B2D-B4CB-C954F6000EF6}C:\users\cysia\appdata\local\temp\winqgbv.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winqgbv.exe | "UDP Query User{D7159FA6-81C5-44A4-A921-E7A7DE3BBD14}C:\program files\metin2 i priv\spyware doctor\pctstray.exe" = protocol=17 | dir=in | app=c:\program files\metin2 i priv\spyware doctor\pctstray.exe | "UDP Query User{D73B426F-A2F5-4597-AA65-43DC8F252221}C:\na chwile!\metin2\metin2.bin" = protocol=17 | dir=in | app=c:\na chwile!\metin2\metin2.bin | "UDP Query User{D7B61679-0D4D-444A-9388-E7383669CA0A}C:\users\cysia\appdata\local\temp\winoqatv.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winoqatv.exe | "UDP Query User{DA1E4C15-EB62-40AB-97BE-91FF328F5FC3}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe | "UDP Query User{DA8DB17B-487D-47DE-8B8B-52B9C895DC97}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{DAC5B420-B290-465A-9976-E535F186908C}C:\users\cysia\appdata\local\temp\sxfn.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\sxfn.exe | "UDP Query User{DBFCB55A-45CE-4C0E-B662-E3858378325F}C:\users\cysia\appdata\local\temp\winrado.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winrado.exe | "UDP Query User{DD29E939-2F16-40EF-8FDA-D0D7F6CF607E}C:\users\cysia\appdata\local\temp\winrgro.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winrgro.exe | "UDP Query User{DEF00862-1023-45C7-963B-4A3DE51BE630}C:\program files\linksys\linksys easylink advisor\linksys easylink advisor.exe" = protocol=17 | dir=in | app=c:\program files\linksys\linksys easylink advisor\linksys easylink advisor.exe | "UDP Query User{DFF1D77E-FA65-4D21-831F-03B13BDAAB7E}C:\users\cysia\appdata\local\temp\wghpa.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\wghpa.exe | "UDP Query User{E080CD79-E361-4CCD-B4DE-9AB53566113C}C:\na chwile!\metin2\metin2.bin" = protocol=17 | dir=in | app=c:\na chwile!\metin2\metin2.bin | "UDP Query User{E4284010-1042-44E0-8B32-38F76BCFD6E1}E:\metin2.bin" = protocol=17 | dir=in | app=e:\metin2.bin | "UDP Query User{E5582017-0BD3-4467-9410-174E746ED236}C:\users\cysia\appdata\local\temp\imky.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\imky.exe | "UDP Query User{E755BDFD-DA36-4DA2-9BCE-F8D192C06179}C:\users\cysia\appdata\local\temp\winhpqvel.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winhpqvel.exe | "UDP Query User{E8BCAE07-A593-44A6-B3DB-352ED86171CA}C:\users\cysia\appdata\local\temp\winuucnob.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winuucnob.exe | "UDP Query User{E9973ECD-F9FE-46CC-97E5-904340E6174E}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe | "UDP Query User{EA2B7338-6438-4480-AA0D-A9FE9CFD24DE}C:\users\cysia\appdata\local\temp\winghhag.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winghhag.exe | "UDP Query User{ED4FEC55-A448-440F-86D9-9A1229B5A5EC}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe | "UDP Query User{ED5117A2-7831-4B6C-8D83-63D52CD8D37A}C:\users\cysia\appdata\local\temp\lkmmd.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\lkmmd.exe | "UDP Query User{EF891F1D-5405-4530-9962-B2292B9B1840}C:\users\cysia\appdata\local\temp\winlwghq.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winlwghq.exe | "UDP Query User{EFC8EE29-7D8F-4357-B1E8-90856C0B379D}C:\users\cysia\appdata\local\temp\winvtvlr.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winvtvlr.exe | "UDP Query User{EFE3784F-5D7F-411E-986F-05EE9C25DDC3}C:\users\cysia\appdata\local\temp\winwqua.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winwqua.exe | "UDP Query User{F05CDED1-6660-4DD5-89D9-E38B23422732}C:\program files\launch manager\hotkeyapp.exe" = protocol=17 | dir=in | app=c:\program files\launch manager\hotkeyapp.exe | "UDP Query User{F1F74BA2-41E7-4596-B99E-E602394F57BD}C:\program files\skype\toolbars\shared\skypenames2.exe" = protocol=17 | dir=in | app=c:\program files\skype\toolbars\shared\skypenames2.exe | "UDP Query User{F3E86BA5-B884-47F1-880C-765413FC9D72}C:\windows\system32\igfxpers.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxpers.exe | "UDP Query User{F5256D9F-BE6F-48DE-86A0-93996E4A9F3A}C:\program files\metin2 i priv\metin2client.bin" = protocol=17 | dir=in | app=c:\program files\metin2 i priv\metin2client.bin | "UDP Query User{F7D4D351-0C58-4733-95B8-8F610DA86793}C:\users\cysia\appdata\local\temp\winujgakm.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winujgakm.exe | "UDP Query User{FBBDE0D9-76CF-44A9-AFF7-06C6A41848D0}C:\windows\vmsnap3.exe" = protocol=17 | dir=in | app=c:\windows\vmsnap3.exe | "UDP Query User{FC732D42-4C62-4A3E-831E-D4D35D919CAF}C:\users\cysia\appdata\local\temp\winfgxsk.exe" = protocol=17 | dir=in | app=c:\users\cysia\appdata\local\temp\winfgxsk.exe | "UDP Query User{FE4D8CEA-2807-47BB-876D-534F25A639F8}C:\users\maria\appdata\local\temp\winjrtpu.exe" = protocol=17 | dir=in | app=c:\users\maria\appdata\local\temp\winjrtpu.exe | "UDP Query User{FE76E65C-93EA-4B3A-A222-5415FAA1792A}C:\windows\system32\wisptis.exe" = protocol=17 | dir=in | app=c:\windows\system32\wisptis.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{05381030-963D-4779-BECA-0D7D49268EDB}" = Płatnik 8.01.001 "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution "{108FAA6F-DEEE-48EA-B3A9-1C5EB2605A6B}" = PL "{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Narzędzie do przekazywania usługi Windows Live "{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}" = Nokia PC Suite "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18 "{284BD984-6E5C-4586-80A8-14D85E233497}" = Linksys EasyLink Advisor "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support "{44C29075-93A3-4B7F-8208-021DBB65E3B3}_is1" = QPrinter Bookmaker 2 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}" = FontNav "{4ECA710C-B818-4751-A3B8-42C2D93922A8}" = Nokia Software Updater "{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService "{616E8966-0574-4E9E-A9CD-9CB819EBC162}" = KONICA MINOLTA TWAIN Ver.3 "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}" = CorelDRAW Graphics Suite X3 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{85F411A3-2C4F-4CDE-B848-EA3E243AF23E}" = OpenOfficeT7 2.3.1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_SMALLBUSINESSR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_SMALLBUSINESSR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_SMALLBUSINESSR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_SMALLBUSINESSR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_SMALLBUSINESSR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_SMALLBUSINESSR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_SMALLBUSINESSR_{E9EA2604-8AC9-47D2-8F4B-6BF60787A357}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_SMALLBUSINESSR_{D45F91DE-F0FC-4D5F-9A0C-FDE5B251AAC6}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007 "{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars "{9862473C-E063-4C68-A161-2CDE0E8048A5}" = Podstawowe programy Windows Live "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support "{AC76BA86-7AD7-1045-7B44-A80000000000}" = Adobe Reader 8 - Polish "{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D303B}" = A4 TECH PC Camera H "{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR "{C09B6CDD-E34E-4735-9B54-A8000A26E46B}_is1" = Video Download Studio 3.3.5 "{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer "{C94E45B0-6AA6-4FB9-9AAE-22085F631880}" = VBA "{C9507D0D-1A9C-486E-91D6-33A71CCA55F2}" = Pure Networks Platform "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE3B8E96-B0AF-4871-9178-1519B58E3A93}" = A4 TECH PC Camera H "{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager V1.4.9 "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D1803CD4-0CE7-4484-98E3-88D7A2D629A4}" = Windows Live Messenger "{D85E93D8-BF44-4BE5-962D-EB8EFDACC073}" = KONICA MINOLTA HDD TWAIN Ver.3 "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F1FDAA01-988C-423F-AC12-0D8F333943FD}" = Nokia Connectivity Cable Driver "{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager "{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = VideoStudio "504244733D18C8F63FF584AEB290E3904E791693" = Pakiet sterowników systemu Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0) "9CF25B327FC690237C04DD3EAD264E80564C757F" = Windows Driver Package - Summa (SUMMAUSB) USB (11/11/2008 6.3) "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Audacity_is1" = Audacity 1.2.6 "Cucusoft Ultimate Video Converter_is1" = Cucusoft Ultimate Video Converter 8.03 "ESET Online Scanner" = ESET Online Scanner v3 "GAMEFORGE Nostale(UK)_is1" = Nostale Online UK (Remove) "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallShield_{284BD984-6E5C-4586-80A8-14D85E233497}" = Linksys EasyLink Advisor "InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = Ulead VideoStudio 11 "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13) "Nokia PC Suite" = Nokia PC Suite "Notowania OnLine 3 BM Alior Bank_is1" = Notowania OnLine 3 BM Alior Bank "Nowe Gadu-Gadu" = Nowe Gadu-Gadu "openclipart" = Open Clip Art Library "PhotoScape" = PhotoScape "PITy 2009_is1" = PITy 2009 dla Windows kompilacja:1.1.0.1 "Redirection Port Monitor" = RedMon - Redirection Port Monitor "SMALLBUSINESSR" = Microsoft Office Small Business 2007 "SubEdit - Vista WMP Patch_is1" = SubEdit - Vista WMP Patch "SubEdit-Player_is1" = SubEdit-Player "SynTPDeinstKey" = Synaptics Pointing Device Driver "Visa Widget" = Visa Widget 2.14 "Wacom Tablet Driver" = Wacom Tablet "Windows Media Encoder 9" = Windows Media Encoder 9 Series "WinLiveSuite_Wave3" = Podstawowe programy Windows Live "WinPcapInst" = WinPcap 4.1.1 "WinRAR archiver" = Archiwizator WinRAR "Zestaw Klipartów dla OpenOfficePL Eplus" = Zestaw Klipartów dla OpenOfficePL Eplus 1.0 [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2010-12-13 05:59:07 | Computer Name = Maria-fu | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd nmsrvc.exe, wersja 10.0.8093.0, sygnatura czasowa 0x47f3f7af, moduł powodujący błąd DLink.dll_unloaded, wersja 0.0.0.0, sygnatura czasowa 0x4896241a, kod wyjątku 0xc0000005, przesunięcie błędu 0x6660f47b, identyfikator procesu 0x3b20, godzina rozpoczęcia aplikacji 0x01cb9aac3db6734e. Error - 2010-12-13 07:05:57 | Computer Name = Maria-fu | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd SniperElite.exe, wersja 0.0.0.0, sygnatura czasowa 0x4316e528, moduł powodujący błąd binkw32.dll, wersja 6.0.6000.16386, sygnatura czasowa 0x4549bdc9, kod wyjątku 0xc0000135, przesunięcie błędu 0x00008fc7, identyfikator procesu 0x4d64, godzina rozpoczęcia aplikacji 0x01cb9ab5b1e47d8e. Error - 2010-12-13 08:44:44 | Computer Name = Maria-fu | Source = Application Hang | ID = 1002 Description = Program FontNav.exe w wersji 6.0.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania raportami i rozwiązaniami problemów. Identyfikator procesu: 521c Godzina rozpoczęcia: 01cb9ac346a2e08e Godzina zakończenia: 33 Error - 2010-12-13 08:45:52 | Computer Name = Maria-fu | Source = Application Hang | ID = 1002 Description = Program FontNav.exe w wersji 6.0.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania raportami i rozwiązaniami problemów. Identyfikator procesu: 5124 Godzina rozpoczęcia: 01cb9ac39387534e Godzina zakończenia: 41 Error - 2010-12-13 12:53:44 | Computer Name = Maria-fu | Source = WinMgmt | ID = 10 Description = Error - 2010-12-13 13:19:35 | Computer Name = Maria-fu | Source = SecurityCenter | ID = 3 Description = Usługa Centrum zabezpieczeń systemu Windows nie może ustanowić kwerend dotyczących zdarzeń z usługi WMI, aby monitorować program antywirusowy, program antyszpiegowski i zaporę innej firmy. Error - 2010-12-13 13:21:37 | Computer Name = Maria-fu | Source = WinMgmt | ID = 10 Description = Error - 2010-12-13 13:31:36 | Computer Name = Maria-fu | Source = WinMgmt | ID = 10 Description = Error - 2010-12-13 14:11:21 | Computer Name = Maria-fu | Source = SecurityCenter | ID = 3 Description = Usługa Centrum zabezpieczeń systemu Windows nie może ustanowić kwerend dotyczących zdarzeń z usługi WMI, aby monitorować program antywirusowy, program antyszpiegowski i zaporę innej firmy. Error - 2010-12-13 14:23:51 | Computer Name = Maria-fu | Source = WinMgmt | ID = 10 Description = [ OSession Events ] Error - 2010-04-22 09:29:06 | Computer Name = Maria-fu | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4397 seconds with 720 seconds of active time. This session ended with a crash. [ System Events ] Error - 2010-03-13 12:25:29 | Computer Name = Maria-fu | Source = bowser | ID = 8003 Description = Error - 2010-03-13 16:54:05 | Computer Name = Maria-fu | Source = DCOM | ID = 10010 Description = Error - 2010-03-13 16:59:56 | Computer Name = Maria-fu | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 21:58:53 na 2010-03-13 było nieoczekiwane. Error - 2010-03-13 18:13:53 | Computer Name = Maria-fu | Source = bowser | ID = 8003 Description = Error - 2010-03-13 18:17:51 | Computer Name = Maria-fu | Source = bowser | ID = 8003 Description = Error - 2010-03-13 18:21:51 | Computer Name = Maria-fu | Source = bowser | ID = 8003 Description = Error - 2010-03-13 18:29:53 | Computer Name = Maria-fu | Source = bowser | ID = 8003 Description = Error - 2010-03-13 18:33:46 | Computer Name = Maria-fu | Source = DCOM | ID = 10010 Description = Error - 2010-03-13 19:01:38 | Computer Name = Maria-fu | Source = bowser | ID = 8003 Description = Error - 2010-03-14 09:21:40 | Computer Name = Maria-fu | Source = Dhcp | ID = 1002 Description = Serwer DHCP 192.168.1.1 odmówił dzierżawy adresu IP 192.168.1.104 dla karty sieciowej o adresie 0016441EE268. (Serwer DHCP wysłał komunikat DHCPNACK). < End of report >