OTL Extras logfile created on: 2012-10-20 11:35:45 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = E:\Users\QWERTY\Documents 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,87 Gb Total Physical Memory | 1,67 Gb Available Physical Memory | 58,17% Memory free 5,73 Gb Paging File | 4,38 Gb Available in Paging File | 76,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive E: | 298,08 Gb Total Space | 184,28 Gb Free Space | 61,82% Space Free | Partition Type: NTFS Computer Name: QWERTY-NOTEBOOK | User Name: QWERTY | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url[@ = InternetShortcut] -- E:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- E:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- E:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "E:\Windows\System32\rundll32.exe" "E:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "E:\Windows\System32\rundll32.exe" "E:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "E:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "E:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [Winamp.Bookmark] -- "G:\muzyka\Winamp\winamp.exe" /BOOKMARK "%1" Directory [Winamp.Enqueue] -- "G:\muzyka\Winamp\winamp.exe" /ADD "%1" Directory [Winamp.Play] -- "G:\muzyka\Winamp\winamp.exe" "%1" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "E:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "E:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [Winamp.Bookmark] -- "G:\muzyka\Winamp\winamp.exe" /BOOKMARK "%1" Directory [Winamp.Enqueue] -- "G:\muzyka\Winamp\winamp.exe" /ADD "%1" Directory [Winamp.Play] -- "G:\muzyka\Winamp\winamp.exe" "%1" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{158FAB90-E58E-4C49-A8A0-59CA988644A3}" = lport=139 | protocol=6 | dir=in | app=system | "{17DB97F1-5ADD-49D8-B917-E0D4BB06D458}" = lport=137 | protocol=17 | dir=in | app=system | "{230AADD3-9DEE-4E06-ADE6-8CB6BC8EA4D1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{2BE7AAF0-AAE3-40EE-9F5A-BF7F85399141}" = rport=10243 | protocol=6 | dir=out | app=system | "{2D78A0EF-02D2-41D4-8190-9BFE1BE93DE8}" = rport=139 | protocol=6 | dir=out | app=system | "{2EF5065A-2E37-47CA-AAD5-2B36ED97FA60}" = rport=137 | protocol=17 | dir=out | app=system | "{30BB83C5-119B-48D0-AFAF-077B65526103}" = lport=10243 | protocol=6 | dir=in | app=system | "{4F7124CC-6A56-4099-9594-7A32DE76AE13}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5572C633-E20A-4AAA-85E8-3D931374C673}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6758EE1A-9FB5-471D-884A-760151131230}" = lport=2869 | protocol=6 | dir=in | app=system | "{7D39E739-1517-4AAA-AF55-560275B7180E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{816D3E24-E0F6-4B89-BE79-786D2231E671}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{965F8E6E-145E-44EB-B1A5-3811015328DD}" = lport=445 | protocol=6 | dir=in | app=system | "{A5BF68CA-908A-412D-912B-C5AFAF500CC0}" = rport=138 | protocol=17 | dir=out | app=system | "{AC1B5D93-296F-420D-BA45-377B87FB373F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B6797868-DF5C-4255-8492-F0F9D7BE8553}" = rport=445 | protocol=6 | dir=out | app=system | "{C72DAE82-8699-4B97-B7B9-4CA0C9DCCB22}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D418C69B-8960-4B0C-A44C-695F0A55096B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E8A29929-8C89-40DD-9402-D4B384423410}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{EADE9AA6-AF87-4E42-A7AA-2F38AE9E9265}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FAE3F5A2-8746-4191-A9A9-BD11E912B091}" = lport=138 | protocol=17 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{061C4213-7D2E-4A16-92C4-8AA40598137F}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{062B0572-C585-4580-84C5-F4BE0D353DF6}" = protocol=6 | dir=in | app=e:\program files (x86)\konami\pro evolution soccer 2012\pes2012.exe | "{06395A5E-49D7-4E32-B5CE-F4E466E87AAF}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hposfx08.exe | "{12012BBB-87DC-4C06-82B1-FC4E4FAA3765}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{15D04042-5220-4668-8C63-4C4B0E96221A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{15F5A914-5D1B-4B97-8890-6D563E22A79B}" = protocol=17 | dir=in | app=e:\program files (x86)\valve\steam\steamapps\digidigi360\counter-strike\hl.exe | "{1803E3E6-DDFE-4276-8E8F-C67CA67F20A1}" = protocol=6 | dir=in | app=e:\program files (x86)\valve\steam\steamapps\luki_matrix\counter-strike\hl.exe | "{191876DF-806C-4221-8BBF-B6AE90746EA0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{1CECB7DB-7DA7-4804-BAFB-EF90870DE17D}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{2897851E-7888-4674-BA7F-3AE40C47170A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{2AC75C26-F03B-441E-88B6-645DD4D48BC7}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{2BF5F8B2-B052-4583-B5D1-647DBEDE7FF5}" = protocol=6 | dir=in | app=e:\windows\syswow64\muzapp.exe | "{2E582480-C3D9-42A3-AE4A-E63C0C142D89}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe | "{37EAAA5A-DEFA-4C04-8AAF-F047E52FF835}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{38E41718-57E5-42A6-AD6B-265458B51196}" = protocol=6 | dir=in | app=e:\program files (x86)\valve\steam\steamapps\emenemsx253\counter-strike\hl.exe | "{3A25E65D-1D05-4FD1-A162-F8B574405821}" = protocol=6 | dir=in | app=e:\program files (x86)\valve\steam\steam.exe | "{3BE615C4-5CBD-47FB-A736-5C235D8F8FF0}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{420109A5-B06C-4171-8058-487950DFD158}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqpse.exe | "{45B60F96-96D0-4562-8BC6-CF3DDAEF1860}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{483E68C3-036F-4FDB-9535-966AA56C246B}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe | "{4C54102F-CCCB-4EFB-8B05-263E89DDCEE2}" = protocol=6 | dir=in | app=e:\program files (x86)\konami\pro evolution soccer 2011\pes2011.exe | "{4CA687E6-3B17-48BC-910A-9E13F1F30833}" = protocol=17 | dir=in | app=e:\program files (x86)\konami\pro evolution soccer 2011\pes2011.exe | "{51EB68FD-47DE-473C-9FE9-B16B3612FAA8}" = protocol=17 | dir=in | app=e:\program files (x86)\sony ericsson\update service\update service.exe | "{5ACA0B70-D310-42B2-A3EA-6FCBECC73636}" = protocol=17 | dir=in | app=e:\windows\syswow64\muzapp.exe | "{5BEA91AB-D491-4D17-843E-DA81B5E88136}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{6322DBAD-4187-4339-9874-A142D8128927}" = dir=in | app=e:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{694AD2AC-CEBB-46FA-B7BB-968FCD9E7D36}" = protocol=17 | dir=in | app=e:\program files (x86)\valve\steam\steam.exe | "{6B656302-E692-41B6-AC00-A8F5E678F8A4}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{718D7671-20A5-4CD7-BB8B-94BB95A86029}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{7788E89E-856F-4822-B608-C9ED9633D98F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{8200FDD6-5349-4444-A6EF-BD874100D998}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{92E68A2B-4B95-44CC-9855-86D06E80811E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{93F2D0A2-6E72-4CC1-944D-EBC2C4213E23}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{9609653B-A68A-4DE3-A2B4-281047F208B2}" = dir=in | app=e:\program files (x86)\skype\plugin manager\skypepm.exe | "{983E3C9E-EE71-4322-AED0-22F222E383CC}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{991BEFB6-1FC0-4552-AC02-A3ACB09F7A9A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A1B25808-2015-443D-B994-D965A6BF48A8}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqnrs08.exe | "{A2FB6488-D958-46E6-95EE-19DF41F15326}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe | "{A43301F9-35CA-453D-8C5E-F1D3031D921B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A6AA5839-A300-4080-8F65-CB1A56458228}" = protocol=17 | dir=in | app=e:\program files (x86)\valve\steam\steamapps\luki_matrix\counter-strike\hl.exe | "{C127AFA0-F0EF-4728-A84A-7C811DDFCA2E}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe | "{C3319D18-68B8-4193-A9DC-184615DBC1DA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{C5A937CB-89DF-4D29-89D3-BBA5D1749067}" = protocol=6 | dir=out | app=system | "{C5B013F2-EB69-484A-BE74-32CFC53D3995}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CB2290CD-10B4-4F1C-BCB8-3FE9187A531C}" = dir=in | app=e:\program files (x86)\skype\phone\skype.exe | "{CD4D2180-E3CC-459F-B368-50C18ED04FF0}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{CE285E7F-AFE2-488D-8262-34D698C17FD5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D0A31DB2-3D59-449B-A3F8-082A45D610B7}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{D30EA0D4-7B4D-4CFB-89C4-0E7AF3050756}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D6EBAA29-C1D4-40BE-AF8C-62E7720A2E03}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe | "{D968C2C3-C725-48D7-B7F6-CCF87E6ED580}" = protocol=17 | dir=in | app=e:\program files (x86)\konami\pro evolution soccer 2012\pes2012.exe | "{DA14F5BA-147D-4640-A5A4-101585534E51}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DA98B6C7-8BAC-4D92-A26F-B993BEF91337}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe | "{DD938469-C109-490B-9734-2D6CD99BB8DE}" = dir=in | app=e:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe | "{E240A433-F9CE-4CD0-9160-BE7BD9434B23}" = protocol=6 | dir=in | app=e:\program files (x86)\valve\steam\steamapps\digidigi360\counter-strike\hl.exe | "{E3FE8511-9163-491B-8E5D-2388A85C4056}" = protocol=6 | dir=in | app=e:\program files (x86)\sony ericsson\update service\update service.exe | "{EBFFBA95-1951-43F9-9E93-C1B6E262C9B2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{EF0EED57-74B6-451B-9F10-15422BD06F83}" = protocol=17 | dir=in | app=e:\program files (x86)\valve\steam\steamapps\emenemsx253\counter-strike\hl.exe | "{EF4055AF-D2A6-4FAC-9FE2-D86F439D2982}" = dir=in | app=e:\program files (x86)\hp\hp software update\hpwucli.exe | "{F5068A40-4D2D-40E2-B739-150AD1D1E50E}" = dir=in | app=e:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{FF1C9574-0DBC-491B-BAF7-79BABBAF7998}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "TCP Query User{06420C02-4EB3-409F-8D5E-71ABA0C988AE}E:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=e:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe | "TCP Query User{1715A051-7DB6-42D2-90A5-A8154D3A27E1}E:\gryy\nfs hotpursuit 2010\nfs hp full-rip dla exsite\nfs2010\nfs2010\nfs11.exe" = protocol=6 | dir=in | app=e:\gryy\nfs hotpursuit 2010\nfs hp full-rip dla exsite\nfs2010\nfs2010\nfs11.exe | "TCP Query User{1F1D8E19-8510-493B-B613-F0979983BB3D}G:\muzyka\winamp\winamp.exe" = protocol=6 | dir=in | app=g:\muzyka\winamp\winamp.exe | "TCP Query User{5A9EC03B-D564-4200-93D1-38518A7B8892}E:\program files (x86)\counter-strike\hl.exe" = protocol=6 | dir=in | app=e:\program files (x86)\counter-strike\hl.exe | "TCP Query User{711D80ED-65AF-4A69-8E01-9A5B2D0F6988}E:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=e:\program files (x86)\tmnationsforever\tmforever.exe | "TCP Query User{7ACDD637-CD78-408F-B82F-900B756991D5}E:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=e:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe | "TCP Query User{A6435A28-6E49-4380-B73F-F00B1FF32487}E:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=e:\program files (x86)\gadu-gadu 10\gg.exe | "TCP Query User{A8ADF349-9DC2-491C-B0B8-03A28A5245D7}E:\users\qwerty\documents\counter-strike nonsteam\hl.exe" = protocol=6 | dir=in | app=e:\users\qwerty\documents\counter-strike nonsteam\hl.exe | "TCP Query User{AB1EA8E4-8FE5-4C5C-8B46-6239494756E1}E:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=e:\program files (x86)\java\jre6\bin\java.exe | "TCP Query User{B5EFF8A5-A70E-401A-B489-785E96AFCBE7}E:\totalcmd\totalcmd64.exe" = protocol=6 | dir=in | app=e:\totalcmd\totalcmd64.exe | "TCP Query User{C9D1BCAB-BA51-4986-99C0-949227AA83E8}E:\program files (x86)\common files\nokia\tss\instrument api\bin\root.exe" = protocol=6 | dir=in | app=e:\program files (x86)\common files\nokia\tss\instrument api\bin\root.exe | "UDP Query User{2170861E-9409-4E32-B16C-F0B156A77968}E:\gryy\nfs hotpursuit 2010\nfs hp full-rip dla exsite\nfs2010\nfs2010\nfs11.exe" = protocol=17 | dir=in | app=e:\gryy\nfs hotpursuit 2010\nfs hp full-rip dla exsite\nfs2010\nfs2010\nfs11.exe | "UDP Query User{30F19B3A-79E9-4739-ADC1-07979079EA15}E:\program files (x86)\common files\nokia\tss\instrument api\bin\root.exe" = protocol=17 | dir=in | app=e:\program files (x86)\common files\nokia\tss\instrument api\bin\root.exe | "UDP Query User{31059D12-6ED4-404E-911B-D7B0434B8ACE}E:\program files (x86)\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=e:\program files (x86)\gadu-gadu 10\gg.exe | "UDP Query User{3DB1FDFD-ED75-40D6-A182-A78CE3D90902}E:\users\qwerty\documents\counter-strike nonsteam\hl.exe" = protocol=17 | dir=in | app=e:\users\qwerty\documents\counter-strike nonsteam\hl.exe | "UDP Query User{4CBCC233-C45B-4398-B2B6-3B6D2A0F2779}E:\totalcmd\totalcmd64.exe" = protocol=17 | dir=in | app=e:\totalcmd\totalcmd64.exe | "UDP Query User{5BBD7FFD-A62F-4516-86EF-74AC3714D1AB}E:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=e:\program files (x86)\tmnationsforever\tmforever.exe | "UDP Query User{B17483E1-7AEF-445E-BDE9-8065A3857D66}E:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=e:\program files (x86)\java\jre6\bin\java.exe | "UDP Query User{B42E774A-99E3-4BE2-95C6-410B4937E893}E:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=e:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe | "UDP Query User{BE791BE7-1DEE-4326-8294-BEAA3318D749}E:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=e:\program files (x86)\electronic arts\crytek\crysis 2\bin32\crysis2.exe | "UDP Query User{DE040E6D-DEFD-4E7F-94EF-4C3C343F872F}G:\muzyka\winamp\winamp.exe" = protocol=17 | dir=in | app=g:\muzyka\winamp\winamp.exe | "UDP Query User{E007AD04-91AA-48C5-97ED-7612174D3A02}E:\program files (x86)\counter-strike\hl.exe" = protocol=17 | dir=in | app=e:\program files (x86)\counter-strike\hl.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64 "{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer "{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{D2D77DC2-8299-11D1-8949-444553540000}_is1" = ZTE Handset USB Driver 5.2066.1.8B02 "{D7647425-7A6F-4DC6-9F9A-71148AB424CD}" = ESET NOD32 Antivirus "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Photosmart Essential" = HP Photosmart Essential 3.5 "HP Smart Web Printing" = HP Smart Web Printing 4.51 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "HPOCR" = OCR Software by I.R.I.S. 13.0 "Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software "Shop for HP Supplies" = Shop for HP Supplies "TNod" = TNod User & Password Finder "Totalcmd64" = Total Commander 64-bit (Remove or Repair) "WinRAR archiver" = Archiwizator WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam(TM) "{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp "{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24 "{2E87F4AB-99BF-421C-AF7B-365A9C08549A}" = F300 "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver "{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy "{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport "{519ACA84-2F7E-4482-8201-B0DCB6C8B3A5}" = Taksi Desktop Video Recorder v0.779 "{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.2 "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help "{6033673D-2530-4587-8AD0-EB059FC263F9}" = Crysis® 2 "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1 "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update "{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{9370105C-71BB-4FF9-A85B-36D79B95457A}_is1" = ALLConverter PRO 1.1 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software "{A29549FD-65F3-440C-A552-6B8114CF319D}" = Skype Toolbars "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1) "{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR "{B5A7081A-0C91-41C1-9EFF-5BD8696053A2}" = SIMCardReaderPro "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{D241D9B3-1A51-4E53-85CC-9AC754819015}" = Gregion 3.1 "{D31E6192-5790-4AB4-852B-1153205AE653}_is1" = Polski VAG 4.9 "{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential "{DAC0B889-5359-4FDC-893A-2B8EF6B71B6F}" = SIM MAX "{DB0A8A2A-4EA7-4FE3-802E-8A6DEE32696C}_is1" = Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0 "{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting "{DF5A03CC-D5AA-43D8-B948-D9903F2AF94A}" = Counter-Strike(TM) "{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext "{E737A098-F161-4B6F-AF22-86AAE34F6FBD}" = Pro Evolution Soccer 2012 "{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}" = PL-2303 Vista Driver Installer "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver "{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "ALLPlayer_is1" = ALLPlayer V5.X "Ashampoo Burning Studio Elements_is1" = Ashampoo Burning Studio Elements 10.0.9 "CS16 Full v32.1 Non-Steam" = CS16 Full v32.1 Non-Steam "DAEMON Tools Lite" = DAEMON Tools Lite "Data Doctor Recovery - SIM Card (Demo)" = Data Doctor Recovery - SIM Card (Demo) "Data Doctor Recovery - SIM Card 3.0.1.5" = Data Doctor Recovery - SIM Card 3.0.1.5 "EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 "facemoods" = Facemoods Toolbar "Fraps" = Fraps (remove only) "Free CD to MP3 Converter" = Free CD to MP3 Converter "Gadu-Gadu 10" = Gadu-Gadu 10 "GOM Player" = GOM Player "Gregion 3.1" = Gregion 3.1 "ImgBurn" = ImgBurn "LiveVDO plugin" = LiveVDO plugin 1.3 "MDI2PDF Converter_is1" = MDI2PDF 2.61 "Minecraft 1.2.0_02" = Minecraft 1.2.0_02 "Mozilla Firefox 16.0.1 (x86 pl)" = Mozilla Firefox 16.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Mp3 Knife_is1" = Mp3 Knife 3.2 "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151) "TmNationsForever_is1" = TmNationsForever "Update Service" = Sony Ericsson Update Service "vShare.tv plugin" = vShare.tv plugin 1.3 "WinGimp-2.0_is1" = GIMP 2.6.11 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-06-10 17:44:25 | Computer Name = QWERTY-Notebook | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: ALLPlayer.exe, wersja: 5.0.2.0, sygnatura czasowa: 0x4eebbb07 Nazwa modułu powodującego błąd: ALLPlayer.exe, wersja: 5.0.2.0, sygnatura czasowa: 0x4eebbb07 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x002818f4 Identyfikator procesu powodującego błąd: 0xbc4 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd474289b3e2d9 Ścieżka aplikacji powodującej błąd: E:\Program Files (x86)\ALLPlayer\ALLPlayer.exe Ścieżka modułu powodującego błąd: E:\Program Files (x86)\ALLPlayer\ALLPlayer.exe Identyfikator raportu: 72408a06-b345-11e1-b401-9dc5d461d007 Error - 2012-06-17 13:22:27 | Computer Name = QWERTY-Notebook | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "e:\program files (x86)\innovative solutions\drivermax\DPInst\ia64\dpinst.exe". Nie można odnaleźć zestawu zależnego Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-06-19 12:38:14 | Computer Name = QWERTY-Notebook | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "e:\program files (x86)\innovative solutions\drivermax\DPInst\ia64\dpinst.exe". Nie można odnaleźć zestawu zależnego Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-07-05 23:13:50 | Computer Name = QWERTY-Notebook | Source = SideBySide | ID = 16842785 Description = Nie można wygenerować kontekstu aktywacji dla "e:\program files (x86)\innovative solutions\drivermax\DPInst\ia64\dpinst.exe". Nie można odnaleźć zestawu zależnego Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0". Użyj narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę. Error - 2012-07-15 03:19:47 | Computer Name = QWERTY-Notebook | Source = Application Hang | ID = 1002 Description = Program iexplore.exe w wersji 8.0.7600.16385 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: c90 Godzina rozpoczęcia: 01cd6258ad97b801 Godzina zakończenia: 16 Ścieżka aplikacji: E:\Program Files (x86)\Internet Explorer\iexplore.exe Identyfikator raportu: 71eb9654-ce4d-11e1-bee8-b36b47d24f04 Error - 2012-07-15 03:22:38 | Computer Name = QWERTY-Notebook | Source = Application Hang | ID = 1002 Description = Program iexplore.exe w wersji 8.0.7600.16385 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 3a8 Godzina rozpoczęcia: 01cd625a397d9e07 Godzina zakończenia: 20 Ścieżka aplikacji: E:\Program Files (x86)\Internet Explorer\iexplore.exe Identyfikator raportu: d76aec07-ce4d-11e1-bee8-b36b47d24f04 Error - 2012-07-16 17:16:36 | Computer Name = QWERTY-Notebook | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: FlashPlayerPlugin_11_3_300_265.exe, wersja: 11.3.300.265, sygnatura czasowa: 0x4febd5ac Nazwa modułu powodującego błąd: NPSWF32_11_3_300_265.dll, wersja: 11.3.300.265, sygnatura czasowa: 0x4febd798 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x001d1e2f Identyfikator procesu powodującego błąd: 0xf88 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd639814ed6d54 Ścieżka aplikacji powodującej błąd: E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe Ścieżka modułu powodującego błąd: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll Identyfikator raportu: 85f64df5-cf8b-11e1-af7d-9f0824ef6207 Error - 2012-07-26 17:22:34 | Computer Name = QWERTY-Notebook | Source = Application Hang | ID = 1002 Description = Program iexplore.exe w wersji 8.0.7600.16385 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: fac Godzina rozpoczęcia: 01cd6b746b739838 Godzina zakończenia: 28 Ścieżka aplikacji: E:\Program Files (x86)\Internet Explorer\iexplore.exe Identyfikator raportu: fd2e4a1d-d767-11e1-bd9f-bd6a60e99202 Error - 2012-10-07 13:34:09 | Computer Name = QWERTY-Notebook | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: SopCast(12954).exe, wersja: 0.0.0.0, sygnatura czasowa: 0x506eb924 Nazwa modułu powodującego błąd: SopCast(12954).exe, wersja: 0.0.0.0, sygnatura czasowa: 0x506eb924 Kod wyjątku: 0x40000015 Przesunięcie błędu: 0x0003a7b5 Identyfikator procesu powodującego błąd: 0x258 Godzina uruchomienia aplikacji powodującej błąd: 0x01cda4b1e9840722 Ścieżka aplikacji powodującej błąd: E:\Users\QWERTY\Desktop\SopCast(12954).exe Ścieżka modułu powodującego błąd: E:\Users\QWERTY\Desktop\SopCast(12954).exe Identyfikator raportu: 32b78363-10a5-11e2-a142-87517770a005 Error - 2012-10-17 11:16:06 | Computer Name = QWERTY-Notebook | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: svchost.exe, wersja: 6.1.7600.16385, sygnatura czasowa: 0x4ce48736 Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7600.16385, sygnatura czasowa: 0x4a5bdb3b Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0002dffa Identyfikator procesu powodującego błąd: 0xe2c Godzina uruchomienia aplikacji powodującej błąd: 0x01cdac7909140aac Ścieżka aplikacji powodującej błąd: E:\Windows\SysWOW64\svchost.exe Ścieżka modułu powodującego błąd: E:\Windows\SysWOW64\ntdll.dll Identyfikator raportu: 924c7aa4-186d-11e2-8a6c-00266c765b4c [ System Events ] Error - 2012-10-20 04:24:30 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi eamonm z powodu następującego błędu: %%31 Error - 2012-10-20 04:24:36 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi epfwwfpr z powodu następującego błędu: %%31 Error - 2012-10-20 04:24:49 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: ehdrv sptd StarOpen Error - 2012-10-20 04:24:49 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi eamonm z powodu następującego błędu: %%31 Error - 2012-10-20 05:25:12 | Computer Name = QWERTY-Notebook | Source = sptd | ID = 262148 Description = Sterownik wykrył błąd wewnętrzny w swoich strukturach danych dla . Error - 2012-10-20 05:25:18 | Computer Name = QWERTY-Notebook | Source = Application Popup | ID = 1060 Description = Ładowanie sterownika \SystemRoot\SysWow64\Drivers\StarOpen.SYS zostało zablokowane z powodu niezgodności z tym systemem. Skontaktuj się z dostawcą oprogramowania w celu uzyskania zgodnej wersji sterownika. Error - 2012-10-20 05:25:36 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi eamonm z powodu następującego błędu: %%31 Error - 2012-10-20 05:25:41 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi epfwwfpr z powodu następującego błędu: %%31 Error - 2012-10-20 05:25:54 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: ehdrv sptd StarOpen Error - 2012-10-20 05:25:54 | Computer Name = QWERTY-Notebook | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi eamonm z powodu następującego błędu: %%31 < End of report >