OTL Extras logfile created on: 2012-11-09 20:58:25 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jacek\Desktop 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,44 Gb Total Physical Memory | 2,15 Gb Available Physical Memory | 62,52% Memory free 6,87 Gb Paging File | 5,44 Gb Available in Paging File | 79,12% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 146,48 Gb Total Space | 119,12 Gb Free Space | 81,32% Space Free | Partition Type: NTFS Drive D: | 784,93 Gb Total Space | 702,35 Gb Free Space | 89,48% Space Free | Partition Type: NTFS Drive G: | 465,76 Gb Total Space | 386,96 Gb Free Space | 83,08% Space Free | Partition Type: NTFS Computer Name: JACEK-PC | User Name: Jacek | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0DFE48DE-C08D-4553-AB96-BE36B516C268}" = lport=10243 | protocol=6 | dir=in | app=system | "{134A13F3-66E7-44D3-B231-37776830FDF4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{157A8786-7818-4C3E-A3C3-D39B263B4BAA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{1DA6A2A1-AD17-42C4-AF80-928907594998}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{29FB53FC-7BC9-4B79-A9C1-ED90A2600D38}" = lport=2869 | protocol=6 | dir=in | app=system | "{37C119E0-19C9-4191-8FA0-12AADD1205B2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{38895425-F574-4B14-B232-04F327606DD3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3E22B50C-D4C1-41BA-828F-02F2C268EB39}" = rport=445 | protocol=6 | dir=out | app=system | "{4056CB6A-40A7-4336-BB30-B8AA1A1EF559}" = rport=139 | protocol=6 | dir=out | app=system | "{4A605EFB-3A10-4A15-B4BA-256E515D1D00}" = lport=445 | protocol=6 | dir=in | app=system | "{4D78C2F0-D1CC-45D6-AC1E-29269F637DFA}" = lport=139 | protocol=6 | dir=in | app=system | "{61291DE2-270B-4EA7-92DE-156F2FC820BC}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "{62822355-CC34-40C7-B71C-3A91CB56F15B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7DA8B006-D59B-41DD-92DD-F820789D2AE3}" = rport=10243 | protocol=6 | dir=out | app=system | "{8A0F4B64-3966-4702-8FEE-DC898A7BD52A}" = lport=137 | protocol=17 | dir=in | app=system | "{A10367BA-D3DA-4BDD-A7A1-D3C5492A76F3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{BC91CDDE-3D2B-461D-B235-08937C3CC8C0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C0A686A0-40B6-4177-B631-2AB0E4FC3262}" = rport=138 | protocol=17 | dir=out | app=system | "{C84DCC6E-6D33-468C-B723-35623F88ABEA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D9BD168C-D652-4DC2-A64A-287614D6CCAF}" = rport=137 | protocol=17 | dir=out | app=system | "{D9E9C009-7FE3-4B75-A030-1B08DB204FBB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E87646F0-7254-4D93-86E2-35D162C892E1}" = lport=138 | protocol=17 | dir=in | app=system | "{EB29F628-1DE1-4A58-9C63-64A8048FEEFC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{FCB6A231-6424-479C-BE4E-FD6F797A56E2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{002BFD94-15FB-424E-9ABF-150776B5A4B9}" = protocol=6 | dir=out | app=system | "{0154646D-E4A2-4511-8DAF-E613C74A1B6F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{020788D2-CA28-4163-9008-31F5EC883611}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{0867AB4B-A195-41BF-878E-59EFC5812480}" = protocol=6 | dir=in | app=d:\jacek\gry\borderlands 2\binaries\win32\borderlands2.exe | "{09A61446-6E10-4062-853A-6CA41A257DC8}" = protocol=6 | dir=in | app=d:\jacek\gry\borderlands 2\binaries\win32\borderlands2.exe | "{09F2E61E-DF84-4DE7-A606-53319BBBC916}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{19C44D85-91A9-4479-97F6-D38C90FCA177}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{1C29115A-6413-4EA8-9AEE-11C86B8D70A4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | "{213EFD83-7DCB-4632-9E8F-EF835067E080}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2337943C-751B-4A81-8087-5EFDE3A60C16}" = protocol=6 | dir=in | app=d:\jacek\steam\steamapps\common\dota 2 beta\dota.exe | "{25A45936-048C-4C82-BF1D-D8597D9DBA55}" = protocol=17 | dir=in | app=d:\jacek\steam\steamapps\common\dota 2 beta\dota.exe | "{28A007E3-D0CE-44D3-A533-DAB6B4CDDBD6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{298CF8EA-990E-4C44-9310-658895D0A0E5}" = protocol=17 | dir=in | app=d:\jacek\steam\steam.exe | "{2DE67CB9-E781-4CD4-A029-17189C567240}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{2F457BF4-ADD8-4B7D-B542-9A357767CFC0}" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\java.exe | "{3029641B-F9D2-41EC-8FB6-17EACBE5EE16}" = protocol=6 | dir=in | app=c:\windows\syswow64\javaw.exe | "{320B7EEF-5A65-41E5-8387-E111926BD1F0}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe | "{3723F3B8-534B-43D4-AF8A-30FDBA3E695F}" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\java.exe | "{37C59CE1-43CC-42C0-AEFA-B4D9782802FE}" = protocol=17 | dir=in | app=c:\windows\system32\java.exe | "{3B2003B0-AF05-4660-B01D-7902C9602A5A}" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "{3C452BB3-9826-4B7C-8889-D85BAD76DD94}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{3F42B6B1-4E3F-49ED-AF87-F815BA0460AC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | "{417F1207-DE37-403F-B9AF-E00CAA29540D}" = protocol=17 | dir=in | app=d:\jacek\steam\steamapps\common\c9\c9.exe | "{4CBFF5B7-0C00-4336-A5CE-7369F16BB76E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{52356DC1-9732-4B0A-8978-4978AAC42BED}" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "{5395B1FE-8013-4B92-8B74-F8511CB5B689}" = protocol=6 | dir=in | app=d:\jacek\steam\steamapps\common\c9\c9.exe | "{64C5D853-1DDC-4020-BCD2-3D1217709AB9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{663027CC-18D3-4886-942D-73CE89C77E8C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{6638FBA5-EC2A-421F-B4F6-A199CF87FA28}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{6D6939C8-B4B7-414D-9CC8-7D5F2724B063}" = protocol=17 | dir=in | app=d:\jacek\steam\steamapps\common\c9\c9mappingaccount.exe | "{6E83052C-41B5-466F-AC4F-FFCD5CC7D568}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{73A51F06-F5DA-4923-8434-595E975D3338}" = protocol=6 | dir=in | app=c:\windows\system32\java.exe | "{75028658-B104-494E-AEA8-B1BCD02B2FF6}" = protocol=6 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{75A7114F-C6C8-47DD-8898-52FCB01CE72C}" = protocol=6 | dir=in | app=d:\jacek\steam\steamapps\common\alien swarm\swarm.exe | "{7710C829-EA0E-44F8-8E34-5423A309645F}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe | "{7B884B95-DC74-40D7-A588-880BD00DBC13}" = dir=in | app=c:\program files (x86)\protected search\protectedsearch.exe | "{7F3DEFF0-705A-4B0E-9623-1B954989AD8A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{8167C62F-FC54-4563-A855-AB65E32BC518}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{81F71549-838C-4EE3-A5D9-84B4C555B8F1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{84746BAA-FB34-4A34-9984-F666A510333E}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{8490B2BF-9030-48A4-AC26-B933FFE4847F}" = protocol=17 | dir=in | app=d:\jacek\gry\borderlands 2\binaries\win32\borderlands2.exe | "{8D748A2E-76FE-47F7-8FF6-68C324846AB9}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{917EB4FA-A314-4F8B-A921-493205985B8B}" = protocol=17 | dir=in | app=d:\jacek\steam\steamapps\common\alien swarm\swarm.exe | "{93558727-2F48-4B6B-944D-225CCD372860}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{94DBCCAA-4F7B-4F06-8D55-1896EA3791E4}" = protocol=6 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{95A55EB9-EFC1-4433-8F5D-6B991772F29D}" = protocol=17 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{96445920-E98A-44E4-B533-FF8A899238DF}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{99D4A90E-0F05-4FC5-B4D3-39950B6A4BD7}" = protocol=6 | dir=out | svc=msiscsi | app=%systemroot%\system32\svchost.exe | "{9D915433-F6B1-435C-B139-02506B6BF938}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{A5C9BFEE-5B64-4AED-9611-525F36AED248}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A6D10DF6-EAE4-4AF5-8848-E7DCC161E951}" = protocol=6 | dir=in | svc=msiscsi | app=%systemroot%\system32\svchost.exe | "{AADA3D41-EA75-47A5-AECC-0B38E4A53B59}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe | "{AD1066EA-74BE-461E-8D75-825A0121956E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{ADB1033E-62A3-4D73-B387-73FAC782E9C8}" = protocol=17 | dir=in | app=d:\jacek\gry\l2 god\system\l2.bin | "{ADFF9309-03DE-4B5A-819B-E9E7993E8695}" = protocol=6 | dir=in | app=c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe | "{AF2C61F9-F7A3-484D-899A-C5277C5EFB67}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{AF67F936-7AFA-4593-A780-678C4F01FEEB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B167FD88-EF9B-48CE-8FBA-B7E5FBAB4366}" = protocol=17 | dir=in | app=d:\jacek\gry\borderlands 2\binaries\win32\borderlands2.exe | "{B4018E66-5EDF-4A2A-94DB-D3CD181B11EA}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe | "{B4477ADD-D406-43EC-9BF8-BD526BA35CE3}" = protocol=17 | dir=in | app=c:\windows\syswow64\javaw.exe | "{B503194C-0472-4540-B57F-970180C37499}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{B64A73CB-BF20-4AEB-8039-DED419DB3CA4}" = protocol=6 | dir=in | app=d:\jacek\steam\steam.exe | "{B9E06747-20DD-426B-982F-6E122BEFA9EC}" = protocol=6 | dir=in | app=d:\jacek\steam\steamapps\common\c9\c9mappingaccount.exe | "{BA056E1B-FF9E-41DB-91FC-C08B6396B9FB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BAE1DE43-383D-4310-B146-5ED9911E2A72}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe | "{BB9B40A7-B613-4997-A46B-4A7801E5C56E}" = protocol=17 | dir=in | app=c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe | "{C97883B4-8323-480B-89E5-8E6BF4D9E494}" = protocol=6 | dir=in | app=d:\jacek\gry\l2 god\system\l2.bin | "{C99B4FBE-EA7B-43D4-90C6-02A971DD8DE8}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{CD3C2C62-79CB-4CB2-AB8F-10D59ED824B6}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D94F714C-02ED-454B-A6F5-C667E914FFC6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{DD5F319A-139A-45EA-9BE2-AE2B06FBF8DA}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe | "{DFD82EC9-18AB-4251-B68B-22EEC9262D71}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | "{E675F3A1-77DC-47C3-A52D-325F2FBCE85E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{ECE55081-0F0F-4E63-AD9F-BAAC45D021C2}" = dir=out | app=c:\program files (x86)\protected search\protectedsearch.exe | "{EFA24504-53B0-4D6D-9028-5A4D0EDCAAB2}" = protocol=17 | dir=in | app=c:\program files\k2t\wtw\wtw.exe | "{F17B8F18-D4B5-4511-BE85-7DFA11C1F261}" = protocol=17 | dir=in | app=c:\program files (x86)\tunngle\tnglctrl.exe | "{F2003568-C47D-4622-8049-A6003DFAAFBA}" = protocol=6 | dir=in | app=c:\program files (x86)\tunngle\tunngle.exe | "{F3A3157A-B628-40F9-A549-A1A7FA01F7EF}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{F7926829-CD70-4730-9BB1-4941FD47794B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{F7CBB61C-20AC-4D21-8457-7790C4A9C559}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{F82F50C1-97FA-4AE1-8668-B3E3B9D506EA}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe | "{F85E33CD-0DEE-4B7C-AD1D-53E24DA262AE}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "TCP Query User{0648E387-E03E-4CD9-8C2D-77F7305F4E3D}D:\jacek\gry\l2 god\system\l2.bin" = protocol=6 | dir=in | app=d:\jacek\gry\l2 god\system\l2.bin | "TCP Query User{0BA5C973-459C-4DF4-83E3-9C464A5A24AE}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe | "TCP Query User{1D1642B8-F666-4445-86C0-BC821CA51C90}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "TCP Query User{520C3867-A207-4AE3-AF88-203276F90165}D:\jacek\steam\steamapps\common\c9\c9.exe" = protocol=6 | dir=in | app=d:\jacek\steam\steamapps\common\c9\c9.exe | "TCP Query User{61424FC4-927F-40B7-B02B-770C59136F65}C:\windows\syswow64\javaw.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\javaw.exe | "TCP Query User{C861EBC5-F2AF-468E-9DB3-47D2D689E79A}C:\program files\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\java.exe | "UDP Query User{3439D1BB-ED0A-464D-AA37-E6842E21C0DB}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | "UDP Query User{835D537D-8EDC-4F1A-BA1F-03D17E634633}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe | "UDP Query User{B190F5A1-43D1-48AF-A751-FF1DA7DD096E}C:\program files\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\java.exe | "UDP Query User{C19F5189-1BA0-4EA8-BFCA-3E06A2FE80C6}C:\windows\syswow64\javaw.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\javaw.exe | "UDP Query User{D3A92AFA-A658-438E-846D-4799D4556E60}D:\jacek\gry\l2 god\system\l2.bin" = protocol=17 | dir=in | app=d:\jacek\gry\l2 god\system\l2.bin | "UDP Query User{EBD4C42F-E4C1-4F9E-B6F6-630BCBE26C4A}D:\jacek\steam\steamapps\common\c9\c9.exe" = protocol=17 | dir=in | app=d:\jacek\steam\steamapps\common\c9\c9.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{18A5D014-E9AD-DEFE-FAFE-A409612F51B4}" = AMD Media Foundation Decoders "{1DF5019A-68B5-4ba1-8E59-E185C7B7FF11}" = Komunikator WTW 0.9.10.3377 "{26A24AE4-039D-4CA4-87B4-2F86417007FF}" = Java 7 Update 7 (64-bit) "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{50BD00DC-127E-BF00-FDD5-E1A93AB3507C}" = ccc-utility64 "{5972F3C3-5563-47D2-BEE3-1AFEBDD17DA2}" = ESET NOD32 Antivirus "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8BF6C901-8C9D-C663-F997-EC95A2CCA228}" = AMD AVIVO64 Codecs "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2010 "{A01AF425-8AF4-821B-3981-F608519CB1D2}" = AMD Drag and Drop Transcoding "{BB009B20-0BA0-ABDF-1947-4D56639214C7}" = AMD Accelerated Video Transcoding "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{E85D1C80-28C4-76B8-5A5A-2C8D8B38D5D9}" = AMD Catalyst Install Manager "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "CCleaner" = CCleaner "Creative VF0640" = Creative Live! Cam Socialize (VF0640) (1.00.05.00) "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "WinRAR archiver" = WinRAR 4.11 (64-bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR "{03AEAB60-A7B3-A8DB-468B-EB30FB4B40B0}" = CCC Help German "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{076A6FD8-EE45-4A83-B3C9-C7C34E7CAFDD}" = Lineage II "{162ABED6-E60C-6CFF-100E-43C16ABBC5BE}" = CCC Help Chinese Standard "{1CB724FF-D18C-8FFB-E7C9-0A09CF8EC066}" = CCC Help Japanese "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20C14CC3-5E3B-D39A-5B37-B15E59785063}" = CCC Help Chinese Traditional "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform "{2632A2C0-ECF4-7F79-7136-9FEA4C253A4C}" = CCC Help Turkish "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7 "{30F712DA-64FE-5DBE-AE76-3F8EA3F8223C}" = CCC Help French "{3C39B3CC-4EC8-C756-AF4B-72366504FCA5}" = CCC Help Hungarian "{46ED2B64-85C7-4E1F-920C-A555B21F2E4C}" = NVIDIA PhysX "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{4CC9D761-A9B6-D8EA-D2A9-B74B5A90B108}" = CCC Help Norwegian "{54B227A6-BDBE-69FA-D450-B99609063044}" = CCC Help Greek "{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{7C587778-C433-980E-F3C1-203890DC4FBE}" = CCC Help Polish "{7DC3EABF-66A2-6D79-B485-6328525CA387}" = CCC Help Swedish "{843603C6-75B7-BAB5-80DE-E76FB28DEEF2}" = CCC Help Finnish "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later "{887868A2-D6DE-3255-AA92-AA0B5A59B874}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{8BBC66FD-0195-29B4-5A58-E0B0554E8F42}" = Catalyst Control Center "{8D9EEAC7-42D5-3951-612A-EAA7B684C592}" = CCC Help Italian "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0015-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0016-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0018-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-0019-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001A-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001B-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-001F-0415-0000-0000000FF1CE}_Office14.PROPLUS_{1D751709-BA6C-49E2-844B-4F4F20F410C9}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0415-1000-0000000FF1CE}_Office14.PROPLUS_{0844B6E1-0A6F-4D81-8BCF-48F883F521FE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-002C-0415-0000-0000000FF1CE}_Office14.PROPLUS_{6606F321-8216-466E-981E-B75A14C46894}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-0044-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-006E-0415-0000-0000000FF1CE}_Office14.PROPLUS_{6AF8887A-72F7-4FA0-ABE4-396172B64550}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00A1-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{90140000-00BA-0415-0000-0000000FF1CE}_Office14.PROPLUS_{39EFF327-D2C4-4C4B-B8EE-37325DECE1A4}" = Microsoft Office 2010 Service Pack 1 (SP1) "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{9791DAED-B734-2835-988B-157BDA087496}" = CCC Help Dutch "{98B740C3-FAA4-C523-7478-4DBCAB7B27D1}" = Catalyst Control Center Graphics Previews Common "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9F0CAC6D-9B0D-A95F-CF61-6E88952D6181}" = CCC Help Thai "{A625DB70-98D5-16FD-C49D-4B8B1B2304A4}" = CCC Help Spanish "{A90214C3-3A0C-2F05-6083-E1A4BAD9E30D}" = CCC Help Danish "{AA123216-6DE0-E57C-DC57-4FECEACB482F}" = CCC Help Russian "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9 "{D0837A59-83E6-3392-1BD9-86D3445676DB}" = CCC Help Korean "{D70AB273-113B-D7DE-5C8D-82CABA7CB0AF}" = Catalyst Control Center Localization All "{D82BEF61-A0DA-4B2F-B53C-038310FB32EB}" = HydraVision "{DC8772D4-C75F-5235-63E2-BBC73F909B7A}" = CCC Help Czech "{DED7FD3C-DDD2-43BB-B0F5-B07F9D0430D3}" = CCC Help Portuguese "{E157F2EB-E06F-B57F-9105-68F348DB2EAD}" = CCC Help English "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{EF036F44-A287-BC23-3F6E-AAE6FDEF47EF}" = Catalyst Control Center InstallProxy "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable "{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}" = Sound Blaster X-Fi MB "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Afterburner" = MSI Afterburner 2.1.0 "AIMP3" = AIMP3 "ASRock IES_is1" = ASRock IES v2.0.15 "ASRock InstantBoot_is1" = ASRock InstantBoot v1.23 "ASRock OC Tuner_is1" = ASRock OC Tuner v2.2.65 "Borderlands 2_is1" = Borderlands 2 "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "DAEMON Tools Lite" = DAEMON Tools Lite "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platforma Menedżera urządzeń "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "Protected Search_is1" = Protected Search 1.1 "Raptr" = Raptr "Steam App 212390" = C9 "Steam App 570" = Dota 2 "Steam App 630" = Alien Swarm "TeamSpeak 3 Client" = TeamSpeak 3 Client "Tunngle beta_is1" = Tunngle beta [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1470513551-69500346-3861251064-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "NCsoft-Lineage2" = Lineage II [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-11-09 15:44:00 | Computer Name = Jacek-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-11-09 15:46:12 | Computer Name = Jacek-PC | Source = SideBySide | ID = 16842785 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195" could not be found. Please use sxstrace.exe for detailed diagnosis. Error - 2012-11-09 15:46:12 | Computer Name = Jacek-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-11-09 15:47:57 | Computer Name = Jacek-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-09 15:50:26 | Computer Name = Jacek-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2012-11-09 15:50:26 | Computer Name = Jacek-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error - 2012-11-09 15:54:51 | Computer Name = Jacek-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-11-09 15:56:21 | Computer Name = Jacek-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-09 16:00:39 | Computer Name = Jacek-PC | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error - 2012-11-09 16:00:39 | Computer Name = Jacek-PC | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. [ System Events ] Error - 2012-06-09 10:23:03 | Computer Name = Jacek-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error - 2012-06-09 15:01:01 | Computer Name = Jacek-PC | Source = DCOM | ID = 10001 Description = Error - 2012-06-10 08:52:49 | Computer Name = Jacek-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error - 2012-06-11 10:23:11 | Computer Name = Jacek-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error - 2012-06-12 10:21:32 | Computer Name = Jacek-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error - 2012-06-13 09:22:54 | Computer Name = Jacek-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error - 2012-06-13 17:17:19 | Computer Name = Jacek-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 23:16:24 on ?2012-?06-?13 was unexpected. Error - 2012-06-13 17:17:13 | Computer Name = Jacek-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. Error - 2012-06-14 02:01:59 | Computer Name = Jacek-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 00:55:43 on ?2012-?06-?14 was unexpected. Error - 2012-06-14 02:01:52 | Computer Name = Jacek-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6 Description = Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. < End of report >