OTL Extras logfile created on: 2013-02-21 19:02:01 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = D:\ 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,75 Gb Total Physical Memory | 2,11 Gb Available Physical Memory | 56,34% Memory free 3,75 Gb Paging File | 2,03 Gb Available in Paging File | 54,17% Paging File free Paging file location(s): [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 36,73 Gb Total Space | 2,53 Gb Free Space | 6,88% Space Free | Partition Type: NTFS Drive D: | 112,32 Gb Total Space | 20,39 Gb Free Space | 18,15% Space Free | Partition Type: NTFS Computer Name: TNR-PC | User Name: TNR | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [ChomikBox.Upload] -- "C:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( ) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [ChomikBox.Upload] -- "C:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( ) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 "C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01E2EE13-2F3E-497D-AD93-42BE6FBC4409}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{063EA3E6-686F-4FCF-B1CE-CD018A8345EC}" = rport=137 | protocol=17 | dir=out | app=system | "{096CC80B-89F4-49B4-A379-B010A109A0F7}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{0DED6DAA-2439-4FAB-A48F-05F09A2AFDC4}" = lport=137 | protocol=17 | dir=in | app=system | "{15B49D2F-3090-4ABA-B6A2-3BBBEEE7F9B6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{1951B534-954D-4837-9CE0-3F9AE1FDDDC7}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{2ACDE1A2-C6E1-49CE-93BF-FD604FC4FF70}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{40CE8137-D7BF-48DE-BECB-99566B48466F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4545AB18-7307-4407-84AA-D1F51B2CB5DF}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{47DC155B-3DD2-4F1A-A61C-036E6DC83EE6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4D3EAE67-21F6-4EDB-978D-86950351CA99}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{6374CD1A-9B00-4A3A-8DE2-BA3EE75A758E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{648A11AA-9D37-4804-9B16-032195F9FB8B}" = lport=138 | protocol=17 | dir=in | app=system | "{66A4C44E-1D26-4F41-A91D-F0D01C2F10F3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6BD46D85-3A45-451D-8F82-7BFE2E8918FA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6E26357F-9067-43E3-A1F9-C7B8DFE8832A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{75DEBBEB-321C-47A5-AA97-757B6AA59AC7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{75E7EEED-7EE1-4554-9B46-36A59908B2FA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{79008DDC-CBC1-42B4-8537-1176C4064182}" = lport=139 | protocol=6 | dir=in | app=system | "{80177A2F-0312-4F7D-962D-51AA2EC214CE}" = lport=2869 | protocol=6 | dir=in | app=system | "{8352A9D8-012A-4567-B006-6F63801A4E73}" = lport=10243 | protocol=6 | dir=in | app=system | "{901B8FE2-CD48-439F-B59F-5104D545B296}" = rport=10243 | protocol=6 | dir=out | app=system | "{98D847AD-6BEF-4657-81DE-C0A63E17B256}" = rport=138 | protocol=17 | dir=out | app=system | "{9B5A67F5-0535-49A9-B0C9-0AA1380C7727}" = rport=445 | protocol=6 | dir=out | app=system | "{A7116070-9962-482E-81CF-98432D66ED76}" = lport=445 | protocol=6 | dir=in | app=system | "{AC08B12E-CCB9-48DB-BCB3-D162AB42369C}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{B2926930-AF15-4226-BC75-D35A20E76504}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BBE337AE-0DD9-4221-B3E7-BF26B4D85B80}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{D0F002F1-29DF-4EE8-95FF-913A3094F360}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D87A05A7-593D-48BB-9F7C-EDB0637030BD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{EC1ACE53-91F0-47CF-9702-2EE9115B7F08}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F52C537C-FD83-42BC-9086-65E35D2530B7}" = rport=139 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00060E14-962E-44CB-B8D4-644B23375420}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{0649EE81-87A9-41B3-BC42-3215153845CD}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe | "{0C07D77A-7675-4787-A8CC-16229565D87C}" = protocol=17 | dir=in | app=c:\program files (x86)\yourfiledownloader\yourfile.exe | "{1696C28B-3B77-4008-820E-F54E98669172}" = protocol=6 | dir=in | app=d:\gry\starcraft ii\starcraft ii.exe | "{177CE33E-6D4C-4086-8343-93E81B1FB244}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1B0FA17F-50A4-4EB6-86DC-0785AA9F3C08}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{1CAD2BC4-5413-47C6-9E94-B850938ECE1D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{2ABCD1B3-D81C-408B-A5CD-90C2CA49D49D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{2B907F21-7B4A-46C9-B121-367B0DA6F888}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{2D8CEF51-2922-4C4D-A955-709586154B2E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe | "{2FAC17C9-4F73-4208-9BEC-43BA1E3933DF}" = protocol=6 | dir=in | app=d:\gry\earth 21600\earth 2160\earth2160_no_sse.exe | "{35488AED-A1E2-4789-AFBA-E4D4289B6CBB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{385B81DA-0DD0-4A5C-9F02-8092326AB170}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{3C192BE4-C80A-40DA-B09C-F313C4FADD1E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3F532603-1898-43C9-950F-0EBBAE0AACD4}" = protocol=6 | dir=in | app=d:\gry\diablo iii beta\diablo iii.exe | "{4ACF5CC2-54BF-40F3-A03D-21AD42B0BE81}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{4AFEE561-01E2-4A61-B7E2-98567A7705E0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | "{4FBF5E62-4CDE-458F-BA32-53012059127C}" = protocol=6 | dir=out | app=system | "{520A1F27-B8A5-4E5E-A094-0F61586ED3FF}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{525B4EB0-B65E-48F6-BD02-333C254B18DE}" = protocol=17 | dir=in | app=d:\gry\earth 21600\earth 2160\earth2160_sse.exe | "{56561E20-B58E-4AA6-9C31-9D6864A6D598}" = protocol=6 | dir=in | app=c:\program files (x86)\yourfiledownloader\downloader.exe | "{6250396E-5217-4E1F-8F68-705B853D2C89}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{64ED5CE6-2015-4048-B4B2-CCD6E61C51E2}" = protocol=6 | dir=in | app=d:\gry\earth 21600\earth 2160\earth2160_sse.exe | "{6E936020-5B82-48CF-B864-19EA091535C3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | "{727D9AE6-8FF4-4B37-A394-FDE119D182B8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{75C0820D-AA80-4539-8896-4950FD026D42}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{7755DA6A-E779-47B4-A794-65FF15389CD9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7E828635-63A7-4829-BB96-02B2FEF1CD83}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{7F1208BD-3C47-4A52-9438-D204AFA04FDA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{8336B604-1B6D-4171-845F-F1406CBECC76}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8389532A-6C63-467D-A13A-D8469F262892}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{9328EC0C-55F5-4C26-9F9A-F25E26FE6550}" = protocol=17 | dir=in | app=c:\program files (x86)\yourfiledownloader\downloader.exe | "{9A5788D7-CE42-459D-ADA2-119D24ED5892}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A097BB1A-8367-46AD-B01E-853D90F0E79F}" = protocol=6 | dir=in | app=d:\gry\starcraft ii\starcraft ii public test.exe | "{A26C6CB5-6F8B-48BB-9D71-F2E15F24F7CE}" = protocol=17 | dir=in | app=d:\gry\starcraft ii\starcraft ii public test.exe | "{A3875F34-5326-494F-87EE-61D158448EE2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A4DD751D-F6AA-436C-B63A-5B6CC98908D8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{B94BDD1F-673B-465D-B21C-62C6E2981122}" = dir=in | app=c:\users\tnr\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{C7B4D27D-7A37-4932-9196-9179022A24E9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{CF0C9663-023D-4C70-8453-EF6BF51DB7B2}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CF6317D5-BAC7-4830-AE3C-61421B5605F9}" = protocol=17 | dir=in | app=d:\gry\diablo iii beta\diablo iii.exe | "{D39AD7FA-DDA2-4C08-8346-9F2611366466}" = protocol=17 | dir=in | app=d:\gry\earth 21600\earth 2160\earth2160_no_sse.exe | "{D573EBF5-C4F2-4116-94DA-1B4D4A5A497F}" = protocol=17 | dir=in | app=d:\gry\starcraft ii\starcraft ii.exe | "{D82C33AF-14B7-4C5B-ABD8-F05F3C6D34A2}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{E34F3F96-8C19-43E7-95B4-5BBC2AFA0CD2}" = protocol=6 | dir=in | app=c:\program files (x86)\yourfiledownloader\yourfile.exe | "{EA20AD45-114E-435B-9569-B5A647D23E00}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{EE42EE10-DF89-4610-890D-3AD4C25730A7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{F396B68C-1AA2-42A8-9E39-A6AA8E987E3D}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{F4CC3941-1FBC-4288-8843-21E535ED4AF8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{F4EF1DD5-9BF5-435E-A549-9799D3CCF44C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{F4FC18B5-FBB4-4B9A-9300-568F20445D17}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{F78F0D1C-27D9-4252-8183-C0B0003BE10B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "TCP Query User{03DF32CA-43E3-467C-B961-47A0847E8507}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{05D068CF-25BD-4B33-8F87-C0F8E217F294}D:\gry\starcraft ii\versions\base23260\sc2.exe" = protocol=6 | dir=in | app=d:\gry\starcraft ii\versions\base23260\sc2.exe | "TCP Query User{190AD8A8-C1C0-410E-B6E0-15A427ACAA4D}C:\users\tnr\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\tnr\appdata\local\akamai\netsession_win.exe | "TCP Query User{278A64B0-00C3-428C-BCC5-A9D40BA63B19}C:\users\tnr\downloads\starcraft_2_eu_pl-pl.exe" = protocol=6 | dir=in | app=c:\users\tnr\downloads\starcraft_2_eu_pl-pl.exe | "TCP Query User{5C033506-70EF-4FD3-AC76-DAF0959FCBCF}D:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=d:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | "TCP Query User{5D82022D-719D-4D44-940F-6B16C62741C9}G:\quake 3\quake3\quake3.exe" = protocol=6 | dir=in | app=g:\quake 3\quake3\quake3.exe | "TCP Query User{725C5E15-6BBE-477A-8387-4E475024DC82}D:\gry\metin2\metin2client.bin" = protocol=6 | dir=in | app=d:\gry\metin2\metin2client.bin | "TCP Query User{8428112E-2ACC-4E57-9A4B-B48933421707}C:\programdata\battle.net\agent\agent.515\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe | "TCP Query User{9E60F6C8-228D-4B3E-9F1E-3C8420F8FBBF}C:\users\tnr\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\tnr\appdata\local\akamai\netsession_win.exe | "TCP Query User{ACBC2AE9-58EB-46FD-B3E3-05DDFE1C70F5}D:\85421124b4ldursee\baldurs gate enhanced edition-sg\bgee.exe" = protocol=6 | dir=in | app=d:\85421124b4ldursee\baldurs gate enhanced edition-sg\bgee.exe | "TCP Query User{B56ECCE6-016D-4270-9210-92E5BE9A654E}C:\program files (x86)\beamdog\beamdog.launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\beamdog\beamdog.launcher.exe | "TCP Query User{B6AD3738-336D-4A97-84EE-270F41144B49}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{C05B47D9-E615-4C5D-B77E-5516E777DCD3}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "TCP Query User{F80A2643-6B7E-4039-8E3E-CB5E16035D1D}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "UDP Query User{03E1A2D5-8489-44B1-81EF-1712DE07CCF4}C:\users\tnr\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\tnr\appdata\local\akamai\netsession_win.exe | "UDP Query User{08B4F4C6-CCC5-4DB7-B1BF-EDBB2C2CBFFC}G:\quake 3\quake3\quake3.exe" = protocol=17 | dir=in | app=g:\quake 3\quake3\quake3.exe | "UDP Query User{15CAD2C3-2760-4AB4-8EAF-56CD814F6F4B}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "UDP Query User{6215C865-32D3-4A42-B48D-186E90EF8F6A}D:\gry\metin2\metin2client.bin" = protocol=17 | dir=in | app=d:\gry\metin2\metin2client.bin | "UDP Query User{6A55C625-C679-42F0-99CB-DDBC15D712BA}C:\programdata\battle.net\agent\agent.515\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe | "UDP Query User{7A5EEB96-4368-406C-8099-DEECD88C7157}C:\users\tnr\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\tnr\appdata\local\akamai\netsession_win.exe | "UDP Query User{9F898BD2-52FA-4D7C-BB8C-352186CDA1F3}D:\85421124b4ldursee\baldurs gate enhanced edition-sg\bgee.exe" = protocol=17 | dir=in | app=d:\85421124b4ldursee\baldurs gate enhanced edition-sg\bgee.exe | "UDP Query User{A34117B3-89DA-4DFE-A1C2-1D7A4B35832D}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "UDP Query User{A8AF7445-97C2-47BD-B900-B0B2C2AC553C}C:\program files (x86)\beamdog\beamdog.launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\beamdog\beamdog.launcher.exe | "UDP Query User{B100CBE8-0499-4E5E-B720-F281C9D11532}D:\gry\starcraft ii\versions\base23260\sc2.exe" = protocol=17 | dir=in | app=d:\gry\starcraft ii\versions\base23260\sc2.exe | "UDP Query User{B95A3C44-FA8F-4B94-8C76-D2F9413337DA}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{C0E04B78-FEC9-4906-8108-29B9894379D0}C:\users\tnr\downloads\starcraft_2_eu_pl-pl.exe" = protocol=17 | dir=in | app=c:\users\tnr\downloads\starcraft_2_eu_pl-pl.exe | "UDP Query User{D1287578-8F01-43ED-834A-59A1D6BEB334}D:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=d:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | "UDP Query User{EFE5260A-8173-4C59-85E4-75C2FFBFB842}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1CC291E4-9288-4189-B02D-8E5A7E8CB550}" = Hex Workshop v6.7 "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{A7E19604-93AF-4611-8C9F-CE509C2B286E}_is1" = VDownloader 3.9.1326 "{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "CCleaner" = CCleaner "DriverAgent.exe" = DriverAgent by eSupport.com "DriverEasy_is1" = DriverEasy 3.11.3 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Microsoft Security Client" = Microsoft Security Essentials "NVIDIA Drivers" = NVIDIA Drivers "OptimizerPro" = OptimizerPro "WinRAR archiver" = WinRAR 4.01 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{204896C7-A116-4FC9-9DBC-7091B48AE25D}" = Aeria Ignite "{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13 "{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM "{4F7B7598-88EA-4442-A54E-65EADCF06D97}" = ChomikBox "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{71972D00-4596-11E2-B6EA-B8AC6F97B88E}" = Google Earth Plug-in "{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{89d77a73-062e-4f48-b165-da42c4ad74a3}" = Nero 9 Essentials "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A00000000002}" = Adobe Reader 6.0.2 "{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287 "{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter "{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}" = Browse2save "{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}" = Search-NewTab "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{DAC69A3A-89E6-4B70-B486-B974C2C95BE9}" = HD Writer AE 4.0 "{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade "{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9 "{F1100000-0009-0000-0003-074957833700}" = ABBYY FineReader 11 "1987 Bard's Tale" = 1987 Bard's Tale "Aeria Ignite" = Aeria Ignite "Aeria Ignite 1.9.1511" = Aeria Ignite "ALLPlayer_is1" = ALLPlayer V3.X "AVI Splitter_is1" = AVI Splitter version 1.12 "Beamdog Launcher" = Beamdog Launcher 1.9.4.0 "Browsers Protector" = Browsers Protector "DAEMON Tools Lite" = DAEMON Tools Lite "DivX Setup" = DivX Setup "ENTERPRISE" = Microsoft Office Enterprise 2007 "Gadu-Gadu" = Gadu-Gadu 7.7 "Gorky 17" = Gorky 17 "Icewind Dale II" = Icewind Dale II "ipla" = ipla 2.3.5 "KLiteCodecPack_is1" = K-Lite Codec Pack 9.2.0 (Full) "Manage Registry ActiveX Control DEMO 2.1_is1" = Manage Registry ActiveX Control DEMO 2.1 (Build 2.1.2.221) "NapiProjekt_is1" = NapiProjekt (2.1.0.2287) "OpenAL" = OpenAL "PLAY ONLINE" = PLAY ONLINE "RealAlt_is1" = Real Alternative 2.0.1 Lite "save2pc Ultimate_is1" = save2pc Ultimate 5.10 "SP_4e24eecb" = Search Assistant WebSearch 1.74 "SP_f2a323db" = BrowseToSave 1.74 "SpeedFan" = SpeedFan (remove only) "TeamSpeak 3 Client" = TeamSpeak 3 Client "TheBardsTale_is1" = The Bard's Tale: Opowieści Barda "UltraISO_is1" = UltraISO Premium V8.65 "uTorrent" = µTorrent "VLC media player" = VLC media player 2.0.1 "Winamp" = Winamp "WinPcapInst" = WinPcap 4.1.1 "YouTube Video Downloader_is1" = YouTube Video Downloader V2.0 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2808357160-679283154-414075850-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome "MyFreeCodec" = MyFreeCodec "Winamp Detect" = Detektor Winampa [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-02-21 03:55:41 | Computer Name = TNR-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika wydajności zdefiniowanych dla identyfikatora języka 015. Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu Win32. Error - 2013-02-21 03:55:41 | Computer Name = TNR-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika wydajności zdefiniowanych dla identyfikatora języka 015. Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu Win32. Error - 2013-02-21 10:25:05 | Computer Name = TNR-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji bieżącego zegara systemowego lub sygnatury czasowej. . Error - 2013-02-21 10:25:05 | Computer Name = TNR-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji bieżącego zegara systemowego lub sygnatury czasowej. . Error - 2013-02-21 10:25:07 | Computer Name = TNR-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji bieżącego zegara systemowego lub sygnatury czasowej. . Error - 2013-02-21 10:29:27 | Computer Name = TNR-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika wydajności zdefiniowanych dla identyfikatora języka 015. Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu Win32. Error - 2013-02-21 10:29:27 | Computer Name = TNR-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika wydajności zdefiniowanych dla identyfikatora języka 015. Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu Win32. Error - 2013-02-21 10:37:59 | Computer Name = TNR-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji bieżącego zegara systemowego lub sygnatury czasowej. . Error - 2013-02-21 10:39:53 | Computer Name = TNR-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika wydajności zdefiniowanych dla identyfikatora języka 015. Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu Win32. Error - 2013-02-21 10:39:53 | Computer Name = TNR-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika wydajności zdefiniowanych dla identyfikatora języka 015. Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu Win32. [ OSession Events ] Error - 2013-01-05 19:40:10 | Computer Name = TNR-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6689 seconds with 4860 seconds of active time. This session ended with a crash. [ System Events ] Error - 2013-02-21 10:25:00 | Computer Name = TNR-PC | Source = Application Popup | ID = 875 Description = Driver atksgt.sys has been blocked from loading. Error - 2013-02-21 10:25:00 | Computer Name = TNR-PC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%1275 Error - 2013-02-21 10:25:07 | Computer Name = TNR-PC | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą PLAY ONLINE. OUC. Error - 2013-02-21 10:25:07 | Computer Name = TNR-PC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi PLAY ONLINE. OUC z powodu następującego błędu: %%1053 Error - 2013-02-21 10:25:11 | Computer Name = TNR-PC | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: ASPI32 Error - 2013-02-21 10:25:17 | Computer Name = TNR-PC | Source = Microsoft-Windows-WHEA-Logger | ID = 18 Description = Wystąpił krytyczny błąd sprzętowy. Zgłoszone przez składnik: rdzeń procesora Źródło błędu: 3 Typ błędu: 256 Identyfikator procesora: 1 Widok szczegółów tego wpisu zawiera dodatkowe informacje. Error - 2013-02-21 10:25:17 | Computer Name = TNR-PC | Source = Microsoft-Windows-WHEA-Logger | ID = 18 Description = Wystąpił krytyczny błąd sprzętowy. Zgłoszone przez składnik: rdzeń procesora Źródło błędu: 3 Typ błędu: 256 Identyfikator procesora: 1 Widok szczegółów tego wpisu zawiera dodatkowe informacje. Error - 2013-02-21 10:25:17 | Computer Name = TNR-PC | Source = Microsoft-Windows-WHEA-Logger | ID = 18 Description = Wystąpił krytyczny błąd sprzętowy. Zgłoszone przez składnik: rdzeń procesora Źródło błędu: 3 Typ błędu: 10 Identyfikator procesora: 1 Widok szczegółów tego wpisu zawiera dodatkowe informacje. Error - 2013-02-21 10:25:17 | Computer Name = TNR-PC | Source = Microsoft-Windows-WHEA-Logger | ID = 18 Description = Wystąpił krytyczny błąd sprzętowy. Zgłoszone przez składnik: rdzeń procesora Źródło błędu: 3 Typ błędu: 256 Identyfikator procesora: 1 Widok szczegółów tego wpisu zawiera dodatkowe informacje. Error - 2013-02-21 12:39:30 | Computer Name = TNR-PC | Source = volsnap | ID = 393252 Description = The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. < End of report >