OTL Extras logfile created on: 2011-03-13 23:31:52 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Krystyna\Desktop Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 7.0.6002.18005) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free 6,00 Gb Paging File | 4,00 Gb Available in Paging File | 71,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 288,09 Gb Total Space | 186,20 Gb Free Space | 64,63% Space Free | Partition Type: NTFS Drive D: | 9,00 Gb Total Space | 1,93 Gb Free Space | 21,43% Space Free | Partition Type: NTFS Drive F: | 1021,00 Mb Total Space | 1018,74 Mb Free Space | 99,78% Space Free | Partition Type: FAT32 Computer Name: KRYSTYNA-PC | User Name: Krystyna | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\S-1-5-21-1234806826-2403135869-279979013-1004\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AntiVirusOverride" = 1 "AntiVirusDisableNotify" = 1 "FirewallOverride" = 1 "FirewallDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1234806826-2403135869-279979013-1004] "EnableNotifications" = 0 "EnableNotificationsRef" = 3 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 1 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\windows\system32\igfxdkp32.exe" = C:\windows\system32\igfxdkp32.exe:*:Enabled:VLAN [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{003B375D-608E-48A0-B9E2-2607903315D1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{02082CB1-A643-43E5-B678-FBD896351E70}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{0216E459-13FE-42F4-A370-4CFE904FD2FB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{074390EF-09DC-4F20-A8F5-84547ECECB39}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{476EE289-B149-4489-8E55-449D598A5055}" = lport=2869 | protocol=6 | dir=in | app=system | "{49FF3245-F5B9-4460-A6B0-3E1E986542C1}" = rport=10243 | protocol=6 | dir=out | app=system | "{4F30AFD3-7CEB-41D8-9A13-DE1FE4813A4D}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{5ECCC17B-6EBB-4755-930A-FFB385B331C6}" = rport=445 | protocol=6 | dir=out | app=system | "{63109F59-7B3F-492C-B754-5353B8F586E7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{70795F64-29F2-4011-B790-50282537E2DB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7AECAF13-DEE3-49E0-BEB6-17D43AC5BF5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{916DC5A2-6D13-4844-993A-67D4046B0F24}" = lport=139 | protocol=6 | dir=in | app=system | "{9404D69B-6ED0-46F6-B3EF-E484466FB44C}" = lport=2869 | protocol=6 | dir=in | app=system | "{971BC495-F5A8-41B1-815C-3041816EE8F8}" = lport=138 | protocol=17 | dir=in | app=system | "{98261ACE-F1AC-4B6B-B67F-A3BE5158A3E4}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{9BA4B386-A910-4D0C-9CFD-B1E59B8B96CC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9C91412E-8633-403C-8306-28D64B4E428B}" = rport=139 | protocol=6 | dir=out | app=system | "{AD838837-269F-4BBF-87D2-9E3333CDFCFB}" = lport=137 | protocol=17 | dir=in | app=system | "{B14021DD-D443-4007-BC13-67AD8790E54C}" = rport=137 | protocol=17 | dir=out | app=system | "{B73470B8-1D47-4B47-BF91-95F6E4BBAA0A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CFF68C51-A84A-4CBC-959A-67D7BB16A418}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D79FAA30-4FAE-49BC-A5CC-C87F20586AD2}" = lport=445 | protocol=6 | dir=in | app=system | "{DDA2FF12-85C4-4E6B-BE26-2D1F99E117D3}" = rport=138 | protocol=17 | dir=out | app=system | "{DE250E5A-EFA3-458B-BC3D-FC62E00C7785}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{E4DB5752-D6A2-4DCD-8A59-088CB6F05979}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{ECE8586C-94FD-473E-A73A-F6E7F0F618B9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{F515D0ED-3DC7-484B-9C97-473FA8A0B172}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{FB43A6C1-962D-4167-8753-CC819E0B27A4}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{FDCAE68C-8C0B-4798-BC6F-7B9855857B07}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FF4A439F-2FC5-43E1-8821-2FC1C328CAFA}" = lport=10243 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03F73AAA-2454-4846-ACCA-F273F33CE15B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{0DCA808B-4F25-43E2-A45E-C48BB772A251}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{2508D20B-FC6B-4B7E-848B-7C84AAEC6FE2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{27A6070E-2CA1-478B-854A-16DA473E2909}" = dir=in | app=c:\program files\msn messenger\livecall.exe | "{2B83E502-04A2-4488-8AE1-C55F1A4490DF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3054C7A4-5DBA-4EAD-8359-2F979B07A4C9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3578FCFD-2B08-4AD5-8E8D-B1342FD584C8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{505B43EB-067A-427E-8CE0-5738E8550FFD}" = protocol=17 | dir=in | app=c:\program files\mcafee\managed virusscan\agent\myagtsvc.exe | "{50FD83A2-AA06-4269-99B6-07ED6FC0F199}" = protocol=6 | dir=in | app=c:\program files\mcafee\managed virusscan\agent\myagtsvc.exe | "{514185B2-2FE8-4D4A-A7BD-36F33667E736}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{6067B8CC-6D9C-4D08-A978-2C0CAA895B40}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6AB4F18E-D1FA-42D1-8A1B-0E1745ED6D54}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{700EF9EE-621D-4C46-99CD-7739112BA4A1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{780C1C3B-7978-4AED-B448-2FE6C82AC9FD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{823FBBFC-5B84-4309-9FD1-79FA9882350E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{829B41AF-7FB9-40C0-B49D-5E523266A9FC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8F974552-602D-4B13-98F4-87AC99FDE958}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe | "{96073F4A-081D-438A-B0AC-B8FAE50622D6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{9AA24DFC-6E01-410E-9825-237C081A81C8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{AFD8169D-810C-4EAB-83FA-9B0FB1A2B95D}" = protocol=17 | dir=in | app=c:\users\krystyna\appdata\roaming\dropbox\bin\dropbox.exe | "{BC93048C-64D1-40F0-A11C-61CC18B59D7E}" = protocol=6 | dir=in | app=c:\users\krystyna\appdata\roaming\dropbox\bin\dropbox.exe | "{C1D78776-617F-4B81-96B8-05C666280F80}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{CC903B45-5E58-4776-B427-C60F5071412A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{D3B4A561-F3F9-49F4-844F-B87EBEB117AA}" = protocol=6 | dir=out | app=system | "{EE4ADC29-DC91-4CE1-83D6-4F376D5CABD9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{F3DAEFF3-65FD-4C54-AC0F-B2CDB2489C9F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F79DA120-F1A9-4230-B557-85D2F86EA3C1}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{FA806DC6-625F-4779-BCF9-C6FD5BF54A03}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "TCP Query User{202830BA-AD60-4DD6-B386-2BEBF0EAC4D2}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{30E59278-3F38-430C-8A39-BFFD24F964C9}C:\program files\metin2_pl\pandoramt2.exe" = protocol=6 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "TCP Query User{38DE92F7-A5AD-45FB-BBBA-FEB9221C0B38}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{3A556E32-D871-4D19-913A-5149C694E506}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "TCP Query User{3CF20FD1-E9E4-498C-9202-009C0ADEBFAA}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{3F2B2638-E199-40BC-AEA7-9AE82D829AF7}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=6 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "TCP Query User{50127F44-5D1F-4486-9876-A631B65D94FC}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "TCP Query User{54BE1B22-C1E1-44A0-BDD7-50B365667F29}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "TCP Query User{5F9995FF-F2C0-4CCB-95E0-C1A32D2D8AFB}C:\program files\cavalos\cavalos.exe" = protocol=6 | dir=in | app=c:\program files\cavalos\cavalos.exe | "TCP Query User{865920BA-7BD5-4766-9271-01111BA4661F}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "TCP Query User{990AB7D6-9D13-47D9-A105-C929B58F1E8C}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | "TCP Query User{A2BE5F47-560A-42E8-84D4-AAE805961ABC}C:\program files\metin2_pl\metin2.bin" = protocol=6 | dir=in | app=c:\program files\metin2_pl\metin2.bin | "TCP Query User{A3D365BE-68E0-4AA8-A0A6-D7487C5E75D2}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{A9731401-AD78-4BC1-917C-D8E67B20B593}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=6 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "TCP Query User{D9A6F8E9-BAA7-4052-AC51-B404097D0103}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | "TCP Query User{F5388CA7-F35A-402A-9AE2-EAC8B352D321}C:\program files\metin2_pl elitemt2\elitemt2.exe" = protocol=6 | dir=in | app=c:\program files\metin2_pl elitemt2\elitemt2.exe | "TCP Query User{F79E4C50-1020-48AE-A60F-7F47D32F1737}C:\program files\metin2_pl\pandoramt2.exe" = protocol=6 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "UDP Query User{1033F9F2-8153-4592-AF5A-D5013A9ACB89}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "UDP Query User{1420CEEC-B1E9-49E4-BF60-4656E5AB9D2C}C:\program files\metin2_pl\pandoramt2.exe" = protocol=17 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "UDP Query User{41087A50-D9D4-4E17-A487-37DF1D4AE2C7}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{42BB121F-1074-4D68-9616-F67DBF96DF46}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=17 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "UDP Query User{52CFAC34-3B6B-4D3F-8434-74A2BEA46BAE}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{5CB0A0FF-7489-47DE-A72B-77DDDECFCD39}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{8AECF8D5-7362-4F06-9648-7602403EAD13}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=17 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "UDP Query User{99024D85-0A33-4E70-A121-79BD025E8B78}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=17 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "UDP Query User{9953823A-0780-4E1C-A614-D928F9F4756E}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "UDP Query User{A5AC7D65-C762-45B8-8E35-F86AF255D19E}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | "UDP Query User{C363B555-1A95-4DC4-B8C9-2A8A0FCDE589}C:\program files\metin2_pl elitemt2\elitemt2.exe" = protocol=17 | dir=in | app=c:\program files\metin2_pl elitemt2\elitemt2.exe | "UDP Query User{CD244F23-52C1-4B26-B54E-1029B29CA8C0}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=17 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "UDP Query User{D256E151-BB0E-4B16-A98F-BA361F4B7516}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{E5DB6D25-0640-4E0D-9C6A-EE8222B3627F}C:\program files\cavalos\cavalos.exe" = protocol=17 | dir=in | app=c:\program files\cavalos\cavalos.exe | "UDP Query User{E6B49B31-8E0C-439A-8A63-1B65B57B8A8C}C:\program files\metin2_pl\metin2.bin" = protocol=17 | dir=in | app=c:\program files\metin2_pl\metin2.bin | "UDP Query User{ECCE0872-3B48-4EA5-9935-B72F8C6C0F51}C:\program files\metin2_pl\pandoramt2.exe" = protocol=17 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "UDP Query User{F913577A-F1C9-4B1B-96C9-B7832B2DED61}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1 "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6200 "{06CB77AB-CDE1-EF6B-175D-85FA59C7F0EE}" = Catalyst Control Center Core Implementation "{07D78C7B-2AA8-5C02-4238-EE3F39279221}" = Catalyst Control Center Localization Thai "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{0AF9C2B7-2E98-8D77-3892-F8512305C6CE}" = CCC Help Turkish "{0F98662A-EA83-414F-8766-3FCE46A32641}" = Credential Manager for HP ProtectTools "{154E4F71-DFC0-4B31-8D99-F97615031B02}" = HP Webcam Application "{164280AB-98C2-FD02-EC0B-5DFBB98E89C1}" = Catalyst Control Center Localization Chinese Standard "{173317B8-D99E-F58E-CAAE-924D8F26C435}" = CCC Help Czech "{1779522E-BFC6-738C-E97E-39405E196FA6}" = Catalyst Control Center Localization Spanish "{1871FE54-36AA-478F-B374-A46BA54474CC}" = ESET NOD32 Antivirus "{1DB44CB7-D68E-9F09-D656-0FBC7D4D9C00}" = Catalyst Control Center Localization Norwegian "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FD3DF19-EF58-2A29-222B-A4B6E237D3DD}" = Catalyst Control Center Graphics Previews Vista "{207A8D54-51C9-48B6-80E6-CBA5403B3ED4}" = Vista Default Settings "{2086797F-A4BA-4CD3-8104-09B8D39DA5D8}" = HP JavaCard for HP ProtectTools "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library "{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 24 "{2EC294E6-2E8C-23A7-C174-4E59532B0E06}" = Catalyst Control Center Localization Korean "{30BF4E6C-D866-46F7-A4F6-81A45E97706E}" = Catalyst Control Center - Branding "{311BF3BF-6AAB-7859-1E5A-EB46644A6011}" = CCC Help French "{32063923-8066-18D5-BF07-2B692547AEF5}" = CCC Help Korean "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{323C15C3-6DE1-05E6-B202-6F1D90BB1B06}" = Catalyst Control Center Localization Turkish "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 E1 "{3848DCD1-E356-ACB9-93AF-FB93485E1598}" = CCC Help Thai "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = HP Webcam "{3A76F96A-637B-9A0E-F65B-AE595A49DEDA}" = ccc-core-static "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3FCFB6B6-B5DE-C5B8-825F-5998C220C24E}" = Catalyst Control Center Localization Russian "{420BBA1D-B275-4891-838C-EA88FE87A632}" = HP Customer Experience Enhancements "{45BA0F82-FC61-828B-A188-49A24B7B39F4}" = Catalyst Control Center Localization Swedish "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4ADB08ED-A385-21BA-3511-00EB170C9CCA}" = Catalyst Control Center Localization Greek "{4C203E35-B5C7-4E35-9834-619668C0FFEE}" = HP 3D DriveGuard "{500CAC18-1509-AC6C-3E91-A437F9457D5E}" = CCC Help Japanese "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features "{5B5494F7-FD30-AFAB-ACD5-345F26B6AAF4}" = Catalyst Control Center Graphics Full Existing "{5BF2EC0B-2A01-DDEA-5645-E700BCE9CDA6}" = CCC Help Spanish "{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check "{5EF644FA-3703-3253-7372-AE46FD862588}" = ccc-utility "{63BABF5E-B142-02F9-85E1-F0A1DBEC6D5D}" = Catalyst Control Center Localization Chinese Traditional "{647ED1EC-1D53-9886-B5A1-234CE9D7BE3F}" = Catalyst Control Center Localization Danish "{64F561F5-17B7-0721-8D08-78777BB91382}" = CCC Help Italian "{65E63D8F-F763-940E-38FA-1A6B2C30ADB2}" = Catalyst Control Center Graphics Light "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library "{69333A04-5134-40A5-A055-9166A7AA1EC8}" = "{6B4591DF-C531-255E-BDE6-25226A5AE115}" = Skins "{6C4592F5-A803-1740-A708-84F3578DC083}" = Catalyst Control Center Localization German "{6DF8EB4D-F5E5-369C-38B2-4F7CD0F02AC3}" = Catalyst Control Center Localization Italian "{70CEFEBA-F757-4DBE-8A21-027C326137CE}" = HP Software Setup 5.00.A.7 "{75D7BB3A-9AB7-4ad1-AD5E-0059B90C624B}" = HP ProtectTools Security Manager Suite "{789C97CE-9E17-4126-BDF4-11FF458BF705}" = File Sanitizer For HP ProtectTools "{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8BB128BE-2670-485D-A221-B00715BCEBCF}" = HP Easy Setup - Frontend "{8BEA3254-8719-4815-9312-69AF21B8D779}" = CCC Help Chinese Traditional "{8BF85A3B-C2EE-2A32-DF54-B565062FBEC9}" = Catalyst Control Center Localization Japanese "{8DD39028-8B90-88D8-781A-AB82A9AE6662}" = CCC Help English "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD "{91B26C13-34A4-36FA-E1F0-22664915EED1}" = Catalyst Control Center Localization Dutch "{926F4D5F-C8FC-4FB7-8E09-BCB8A997D1C7}" = HP ProtectTools Security Manager "{968933D6-A9FC-891C-6292-F7E68DB2C7EA}" = CCC Help Finnish "{96DB55D1-E21F-126C-1ADD-35EAAC852C7C}" = Catalyst Control Center Localization Finnish "{988B865E-CC06-7B3D-FBC0-52093DB75C9A}" = CCC Help Dutch "{997F39AA-6CDC-2E23-F9C3-D59AACABAB8F}" = Catalyst Control Center Localization French "{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant "{9DBD8BEE-B3EC-4D82-A81C-0F6250176DCC}" = Drive Encryption for HP ProtectTools "{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A1410161-F615-4B91-A019-FA33833EF00D}" = BIOS Configuration for HP ProtectTools "{AC194855-F7AC-4D04-B4C9-07BA46FCB697}" = ActivClient 6.1 x86 "{AC76BA86-7AD7-1045-7B44-AA0000000001}" = Adobe Reader X (10.0.1) - Polish "{B0704448-6681-607E-D97F-A148C2E2F763}" = CCC Help Danish "{B79DB290-9F72-4B20-9776-848D7832705B}" = HP User Guides 0108 "{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX "{BABEDC2E-5718-1D6D-9E76-93C7EC76BBC4}" = CCC Help Greek "{BC1DC565-8B34-4B29-9DB2-BF281C2FB56E}" = ESU for Microsoft Vista SP1 "{BD5DE09E-3C1C-1DCE-E98D-7B7BBDBE15AD}" = CCC Help Portuguese "{BFCBCC48-9027-17B7-BD08-5214898494CC}" = CCC Help German "{C3036710-8564-ECEA-0E19-1B7880111167}" = CCC Help Swedish "{C7D03B2F-5B3A-A6D8-1C6C-AFCA02DDD3EC}" = Catalyst Control Center Localization Czech "{C8A33E2B-5DDB-BF2E-24A9-95DFA1CDF56D}" = Catalyst Control Center Localization Polish "{CA144572-CEAD-5A14-A338-D28B35D9C7FF}" = Catalyst Control Center Localization Hungarian "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE3020D2-1742-19F4-EFB4-4D76097C81D0}" = Catalyst Control Center Localization Portuguese "{CF755AAE-7801-359C-E9D3-FE8572F8C760}" = Catalyst Control Center Graphics Full New "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 "{DC04644B-C7B3-AF77-610C-7F0AF59AC44D}" = ATI Catalyst Install Manager "{DE80F89F-6132-42A9-1A47-542F6C60E1A2}" = CCC Help Russian "{E333CA5F-00ED-4EEF-90E5-6A33A8FE969F}" = HP Help and Support "{E979B690-80A7-8E8B-1281-C68DBEDDB491}" = CCC Help Norwegian "{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "{F173C2B3-296F-458C-98FF-1676A42EBA02}" = HP Wallpaper "{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager "{F23DFEB2-A5D1-3B97-FBF3-30DC859411C0}" = CCC Help Hungarian "{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner "{FBE38124-B7F0-3EEE-98C5-D8C3AE353FF5}" = CCC Help Chinese Standard "{FD9FAE60-2BF1-C877-9843-AABA9DA06A2B}" = CCC Help Polish "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Advanced SystemCare 3_is1" = Advanced SystemCare 3 "Agere Systems Soft Modem" = Agere Systems HDA Modem "ALLPlayer V2.2" = ALLPlayer V2.2 "AQQ" = WapSter AQQ "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "ENTERPRISE" = Microsoft Office Enterprise 2007 "IrfanView" = IrfanView (remove only) "JDownloader" = JDownloader "KLiteCodecPack_is1" = K-Lite Codec Pack 5.0.5 (Full) "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3) "NapiProjekt_is1" = NapiProjekt 1.0.6.9 "Nero8Lite_is1" = Nero 8 Lite 8.3.6.0 "RealAlt_is1" = Real Alternative 1.9.0 "Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "Smart Defrag 2_is1" = Smart Defrag 2 "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = Archiwizator WinRAR [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1234806826-2403135869-279979013-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2011-03-12 13:54:51 | Computer Name = Krystyna-PC | Source = WinMgmt | ID = 10 Description = Error - 2011-03-12 14:00:55 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-12 14:00:55 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-12 14:00:55 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3011 Description = Error - 2011-03-12 18:53:19 | Computer Name = Krystyna-PC | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd mplayerc.exe, wersja 1.2.1008.0, sygnatura czasowa 0x49ff6112, moduł powodujący błąd ntdll.dll, wersja 6.0.6002.18327, sygnatura czasowa 0x4cb73436, kod wyjątku 0xc0000005, przesunięcie błędu 0x00024484, identyfikator procesu 0x1564, godzina rozpoczęcia aplikacji 0x01cbe1083c7fd0f3. Error - 2011-03-12 18:53:22 | Computer Name = Krystyna-PC | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd mplayerc.exe, wersja 1.2.1008.0, sygnatura czasowa 0x49ff6112, moduł powodujący błąd ntdll.dll, wersja 6.0.6002.18327, sygnatura czasowa 0x4cb73436, kod wyjątku 0xc0000005, przesunięcie błędu 0x00024484, identyfikator procesu 0x1564, godzina rozpoczęcia aplikacji 0x01cbe1083c7fd0f3. Error - 2011-03-13 05:27:30 | Computer Name = Krystyna-PC | Source = WinMgmt | ID = 10 Description = Error - 2011-03-13 05:33:16 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-13 05:33:16 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-13 05:33:16 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3011 Description = [ System Events ] Error - 2011-03-12 18:53:30 | Computer Name = Krystyna-PC | Source = Dhcp | ID = 1002 Description = Serwer DHCP 192.168.1.1 odmówił dzierżawy adresu IP 192.168.1.3 dla karty sieciowej o adresie 002100AB02EC. (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2011-03-13 01:45:01 | Computer Name = Krystyna-PC | Source = Dhcp | ID = 1002 Description = Serwer DHCP 192.168.1.1 odmówił dzierżawy adresu IP 192.168.1.3 dla karty sieciowej o adresie 002100AB02EC. (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2011-03-13 05:26:04 | Computer Name = Krystyna-PC | Source = volmgr | ID = 262190 Description = Inicjowanie zrzutu awaryjnego nie powiodło się! Error - 2011-03-13 05:26:18 | Computer Name = Krystyna-PC | Source = volmgr | ID = 262190 Description = Inicjowanie zrzutu awaryjnego nie powiodło się! Error - 2011-03-13 05:27:02 | Computer Name = Krystyna-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 2011-03-13 05:27:11 | Computer Name = Krystyna-PC | Source = Print | ID = 64 Description = Próba instalacji drukarki Microsoft XPS Document Writer 6.0.6002.18005 w obrazie systemu operacyjnego w trybie offline nie powiodła się z powodu następującego błędu systemu Win32: 1797 (0x705). Może to występować, jeśli sterownik drukarki wymaga wprowadzenia danych przez użytkownika lub wyświetla interfejs użytkownika podczas instalacji. Error - 2011-03-13 05:27:30 | Computer Name = Krystyna-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2011-03-13 05:27:30 | Computer Name = Krystyna-PC | Source = Service Control Manager | ID = 7001 Description = Error - 2011-03-13 08:35:48 | Computer Name = Krystyna-PC | Source = Dhcp | ID = 1002 Description = Serwer DHCP 192.168.1.1 odmówił dzierżawy adresu IP 192.168.1.3 dla karty sieciowej o adresie 002100AB02EC. (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2011-03-13 08:52:40 | Computer Name = Krystyna-PC | Source = Dhcp | ID = 1002 Description = Serwer DHCP 192.168.1.1 odmówił dzierżawy adresu IP 192.168.1.3 dla karty sieciowej o adresie 002100AB02EC. (Serwer DHCP wysłał komunikat DHCPNACK). < End of report >