OTL Extras logfile created on: 14/11/2011 18:20:14 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Wojtek\Downloads\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000809 | Country: Wielka Brytania | Language: ENG | Date Format: dd/MM/yyyy 2.99 Gb Total Physical Memory | 1.79 Gb Available Physical Memory | 59.71% Memory free 6.18 Gb Paging File | 5.04 Gb Available in Paging File | 81.58% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 105.82 Gb Total Space | 79.07 Gb Free Space | 74.73% Space Free | Partition Type: NTFS Drive E: | 106.83 Gb Total Space | 2.24 Gb Free Space | 2.10% Space Free | Partition Type: NTFS Computer Name: WOJTEK-PC | User Name: Wojtek | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\S-1-5-21-699923459-1462160667-771819599-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [ChomikBox.Upload] -- "C:\Program Files\ChomikBox\\ChomikBox.exe" -u"%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02E9682D-8572-4CDA-8AE2-F658A5545DDD}" = lport=138 | protocol=17 | dir=in | app=system | "{31A0CB40-7D15-490E-9028-C002D8C63EBB}" = lport=139 | protocol=6 | dir=in | app=system | "{4EE15E93-A4FA-4784-BCAB-78846AFBFEB5}" = lport=2869 | protocol=6 | dir=in | app=system | "{4F0BD5CB-F7F5-4C91-A3A7-3C943C640EF0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{51105851-4BB5-4BF8-82DB-E914A9FC54C4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{5A0A8CE6-0CEC-4477-ABAF-CA6C43D7AD28}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{63B5BC70-70D2-40CB-8B9C-EB894398E279}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{68858F9E-43B8-4B53-9D62-1E0844EF78A2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{74E4800F-4549-407B-867A-71800C08A417}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{8FC82C0D-D23F-4843-BEEB-1507066191B4}" = rport=138 | protocol=17 | dir=out | app=system | "{975EBDB1-CAC9-496E-88EE-A96CD28FE108}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{9D9F9B67-8598-4FF2-B10E-268339C1173E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A203747E-B267-4A4B-8BCE-717991D19B36}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A78D3B7B-6994-465E-B1A0-AF492F8D4D3A}" = rport=445 | protocol=6 | dir=out | app=system | "{CD9DD0E0-82F0-4C80-8CF3-D3B68C6F41C5}" = rport=137 | protocol=17 | dir=out | app=system | "{DC8FDA8F-1E1B-4C20-A416-95A2C3892558}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E124D850-254A-433A-9DCF-E3AC47B7A6BA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F4ED6EB9-D726-4CF1-B92F-EA1C2C5CC839}" = lport=445 | protocol=6 | dir=in | app=system | "{F59A4683-0F47-41AA-903D-53555AA77861}" = lport=137 | protocol=17 | dir=in | app=system | "{FF3333E8-117A-43E4-A58B-2A187CA1EA61}" = rport=139 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0016ED8B-5313-4770-BA3E-BCD6DF80471A}" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.exe | "{01A22914-655D-4432-8CFF-713A9070BD64}" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.exe | "{04354F46-2EB0-4839-8043-CA65F8E29516}" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.exe | "{05AC4CCC-9BDA-427A-9A6B-88C98BC6636E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{0E96ADAD-BAB1-4C4F-B7E5-41CD16A079CC}" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.dll | "{115C0709-8492-405E-B107-974E8088A40E}" = protocol=6 | dir=in | app=c:\users\wojtek\appdata\local\temp\~os3588.tmp\rlvknlg.exe | "{1D72076D-84EA-4901-85DD-C6065CA5C267}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{210F279B-A8F1-4232-B368-120D66F11AC6}" = protocol=6 | dir=in | app=c:\users\wojtek\appdata\local\temp\~os7a1c.tmp\rlvknlg.exe | "{29D8B033-E1A8-4C40-9E2F-759E457161BF}" = protocol=6 | dir=in | app=c:\users\wojtek\appdata\roaming\rayv\viewer\rayv.dll | "{35909997-0B9D-4CE0-9E51-DDDCB17C7371}" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.exe | "{3B975825-8B6D-4792-A3FC-6DE1598F1A3D}" = protocol=6 | dir=in | app=c:\users\wojtek\downloads\desktop\facemoods.exe | "{3F28D3B2-8C7A-43AF-BFA2-ED79C15CAABC}" = protocol=17 | dir=in | app=c:\program files\relevantknowledge\rlvknlg.exe | "{3F7745DF-AE9B-45A0-83D7-F797E225FCF4}" = protocol=17 | dir=in | app=c:\program files\relevantknowledge\rlvknlg.exe | "{40EF7245-FE80-484E-9E1A-FB6D09193410}" = dir=in | app=c:\program files\msn messenger\livecall.exe | "{4589B037-BFA1-4E91-AF47-C6BE6C5B18A0}" = protocol=6 | dir=in | app=c:\users\wojtek\appdata\local\temp\~osc5cf.tmp\rlvknlg.exe | "{49493968-659C-4433-855F-174BEF87F6F2}" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.dll | "{4AE6E1E5-9D6E-4522-AFD5-954433C1BA93}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{4C7745C8-783F-4687-9D1A-3168A107D067}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{533760A7-8C92-4D38-95B8-2E12DC79168B}" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.dll | "{5CE52EA8-F10A-41E0-BA40-B7245E4DB41D}" = protocol=17 | dir=in | app=c:\users\wojtek\appdata\roaming\rayv\viewer\rayv.dll | "{5DFBE27B-2D5F-44C1-BA73-E0BDC9296C02}" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.dll | "{6314D38B-33F3-452E-8750-85EE9318F990}" = protocol=6 | dir=in | app=c:\users\wojtek\appdata\roaming\rayv\viewer\rayv.dll | "{6D6D0DED-D7EA-4C66-AB67-F3DA2A16CF2A}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{7F859D29-1E07-40A6-87BB-1F4E6E428AEC}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe | "{7FDC1456-2CF4-4D98-8F0E-22BD3836F691}" = protocol=6 | dir=in | app=c:\users\wojtek\appdata\local\temp\~os8e40.tmp\rlvknlg.exe | "{830A153F-E2FA-49F3-98E9-D3B41B18BA5C}" = protocol=6 | dir=in | app=c:\windows\temp\~os9ab9.tmp\rlvknlg.exe | "{939D98A0-7940-47FC-8DD8-F098617D1FD7}" = protocol=6 | dir=in | app=c:\program files\veetle\player\veetlenet.exe | "{94B1FA49-8D59-4EAF-A3EC-526C448BD9ED}" = protocol=17 | dir=in | app=c:\users\wojtek\downloads\desktop\facemoods.exe | "{A1AABD9C-AFF0-4937-9555-8DFC767FE18C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{A8A71137-1C41-42E4-B70C-7E28F0CF1B65}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{B7FF46FB-98A0-445A-A563-0BE98EC08173}" = protocol=6 | dir=in | app=c:\program files\relevantknowledge\rlvknlg.exe | "{CC5C5D36-086F-41D1-96C1-FB15DF0775CB}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe | "{D020880E-226D-4808-8BFF-77E74C99521C}" = protocol=6 | dir=in | app=c:\windows\temp\~os44fc.tmp\rlvknlg.exe | "{D5268D17-FEC2-4F4D-839D-95070DADF940}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{D5B14E7E-4EEF-4722-A322-12D289E61598}" = protocol=17 | dir=in | app=c:\users\wojtek\appdata\roaming\rayv\viewer\rayv.dll | "{D66EEB3A-E6DB-44EF-B09F-54A04ABDF101}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{DBAFFF99-B26C-4FD5-A6D2-A70ECFC121BF}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{E7A052A1-E83A-41CA-B470-74DDDFB85F0D}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{EA70DB71-250C-4B0F-83AF-66089120DAD4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{EBCE8A61-45DE-40CF-A869-B282EBA6EAA9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{ED3CEB8B-49A0-4E4E-8375-C55AFFA7976E}" = protocol=6 | dir=in | app=c:\program files\relevantknowledge\rlvknlg.exe | "{F1E973AC-2D20-4462-920D-F528F06D9D43}" = dir=in | app=c:\program files\skype\phone\skype.exe | "TCP Query User{0B88D1EC-A198-4386-9D58-00A84CCC9408}C:\program files\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=c:\program files\counter-strike 1.6\hl.exe | "TCP Query User{28572969-AA2B-4CBF-A8D3-BB672076FF42}C:\program files\counter strike 1.6 hd nonsteam\hl.exe" = protocol=6 | dir=in | app=c:\program files\counter strike 1.6 hd nonsteam\hl.exe | "TCP Query User{29E5D428-DADE-4C7A-B964-8A4C0EC612DB}C:\program files\gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu\gg.exe | "TCP Query User{36286C09-007E-4DEE-A010-0DE0C6900909}C:\program files\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=c:\program files\counter-strike 1.6\hl.exe | "TCP Query User{37CF65FD-9A48-4159-A1DC-0BB14141C79D}C:\program files\dap\dap.exe" = protocol=6 | dir=in | app=c:\program files\dap\dap.exe | "TCP Query User{4054B67A-5518-4C0D-A041-439A99877E8D}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{4909433D-E419-43BC-97A2-644813309234}C:\program files\konnekt\konnekt.exe" = protocol=6 | dir=in | app=c:\program files\konnekt\konnekt.exe | "TCP Query User{577F42DD-B8EC-40F7-B9D7-9F54F7B74ADC}C:\program files\ea games\mohaa\mohaa.exe" = protocol=6 | dir=in | app=c:\program files\ea games\mohaa\mohaa.exe | "TCP Query User{64B7474D-05B5-4F8E-94A1-4BFCC5B3647A}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "TCP Query User{6E87D654-2B99-4CE5-B498-83CD7C2F5972}C:\program files\miranda im\miranda32.exe" = protocol=6 | dir=in | app=c:\program files\miranda im\miranda32.exe | "TCP Query User{94C372D2-AFCD-4CF4-95B2-2E6701EF6353}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "TCP Query User{B99DA73C-F173-4CF0-9779-2F9780CB3933}C:\program files\dap\dap.exe" = protocol=6 | dir=in | app=c:\program files\dap\dap.exe | "TCP Query User{C2554907-8249-4CCB-A8D1-5EA1D17AFA50}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe | "TCP Query User{D816D8E2-0215-4AB6-85D4-8CC22E889689}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "TCP Query User{D941CAE6-7429-4143-857B-54AF3419B3C7}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{D973E938-A47D-4B8D-9420-870436CBC53E}C:\program files\luckywire\luckywire.exe" = protocol=6 | dir=in | app=c:\program files\luckywire\luckywire.exe | "TCP Query User{E035C9ED-B3BB-4DCF-8E75-E485976ABFF3}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe | "TCP Query User{E6A252FC-0517-4373-A9B8-31DC8C2D7109}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe | "TCP Query User{E76DAEA1-8795-434C-8B9A-6D72CF05B59C}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "TCP Query User{E9C23C1E-13C6-4B18-9323-AEC0E2EF1C18}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "TCP Query User{F1AA4134-563A-4DCA-B5F2-CF1569E8F3E4}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{FEE2FADC-AC17-4052-AF8B-51494A1559A7}C:\program files\gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu\gg.exe | "UDP Query User{0C79659D-776F-48A1-BD90-F6908BB062BE}C:\program files\dap\dap.exe" = protocol=17 | dir=in | app=c:\program files\dap\dap.exe | "UDP Query User{20E1BED8-064F-4DC8-9873-8FB6EBB524DD}C:\program files\konnekt\konnekt.exe" = protocol=17 | dir=in | app=c:\program files\konnekt\konnekt.exe | "UDP Query User{2393B262-2576-41B0-8A96-08CDA5EBB65A}C:\program files\miranda im\miranda32.exe" = protocol=17 | dir=in | app=c:\program files\miranda im\miranda32.exe | "UDP Query User{2531D4BE-9915-442A-9BAF-9DEBBEC3D974}C:\program files\counter strike 1.6 hd nonsteam\hl.exe" = protocol=17 | dir=in | app=c:\program files\counter strike 1.6 hd nonsteam\hl.exe | "UDP Query User{28A599B6-27DE-4AC8-828D-0C1072DD21BA}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "UDP Query User{2BCD9147-B9F4-4A2A-9AD2-F33560EE9112}C:\program files\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=c:\program files\counter-strike 1.6\hl.exe | "UDP Query User{318E2866-978E-4505-9569-F57C1858C0EC}C:\program files\dap\dap.exe" = protocol=17 | dir=in | app=c:\program files\dap\dap.exe | "UDP Query User{67EB859B-306A-4172-8227-4954AAFE9E33}C:\program files\gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu\gg.exe | "UDP Query User{6865A45C-AA67-4993-A7A2-8B2AB273808F}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{703F1D34-424F-4449-8680-0DC4AB090300}C:\program files\luckywire\luckywire.exe" = protocol=17 | dir=in | app=c:\program files\luckywire\luckywire.exe | "UDP Query User{70B2912B-34F7-4E7B-A16F-CF40D7DB05F0}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "UDP Query User{8270DC49-C659-4E50-9962-6FB8102555D0}C:\program files\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=c:\program files\counter-strike 1.6\hl.exe | "UDP Query User{95C137B1-3ED6-48BB-B12A-D5EBEE17A02E}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe | "UDP Query User{AC4AD9FF-5926-4DF4-B585-0C6A4A281463}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe | "UDP Query User{B46E5BC4-411D-4D2A-86DD-79BC188B1E49}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{C1D16E9F-DA4F-4967-A7F2-B162138AE021}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "UDP Query User{C6221F49-6EA8-46EF-AD71-8539B77E42FB}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "UDP Query User{D405A7C3-67C6-4809-A856-F1E591F5A8A6}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe | "UDP Query User{E34A915D-C15D-4495-86C8-2E9B751049EC}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{E8C95A9C-6870-49D1-BD46-E5003FDD8026}C:\program files\ea games\mohaa\mohaa.exe" = protocol=17 | dir=in | app=c:\program files\ea games\mohaa\mohaa.exe | "UDP Query User{E9A335FA-C365-410E-A393-32C2CBE130B7}C:\program files\gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu\gg.exe | "UDP Query User{FD018716-7CF2-40C2-B915-5F7BDCE1AB30}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07D8511D-C9FE-4A93-933F-EAA5C8F20095}" = IDT Audio "{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 21 "{2BC21CD2-8053-406A-80F6-9AB61717B49D}" = ODF Add-in for Microsoft Office "{34FF0741-EC67-4C05-AC2A-6D257123DF2E}" = BigFix "{39098402-3F7A-4257-A4AE-FC1181D1B40B}" = Camera Assistant Software for Gateway "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{4E86E575-2B04-4FEC-ADA3-72D47CB4777C}" = Cortona3D Viewer "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features "{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{5F00DF7E-418B-4CD9-8EC5-781156BCC49E}" = Microsoft Money Shared Libraries "{64CAA486-3CA5-4C81-8DAE-5D7D18E1956C}" = ChomikBox "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{75E9A522-65D2-4200-A95F-C3EF89703263}" = Lyrics Plugin for Winamp "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine "{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{d08d9f98-1c78-4704-87e6-368b0023d831}" = RelevantKnowledge "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable "{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Agere Systems Soft Modem" = Agere Systems HDA Modem "Audio Manager_is1" = Audio Manager 3.10 "BitTorrent" = BitTorrent "CCleaner" = CCleaner "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP) "EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 9.1.0 Home Edition "Gadu-Gadu" = Gadu-Gadu 7.1 "Google Desktop" = Google Desktop "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0 Demo "ipla" = ipla 2.3.3 "LastFM_is1" = Last.fm 1.5.4.27091 "LuckyWire" = LuckyWire "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Miranda IM" = Miranda IM 0.9.22 "Money2007b" = Microsoft Money Essentials "Mozilla Firefox (3.6)" = Mozilla Firefox (3.6) "PDF2Word v1.6_is1" = PDF2Word v1.6 "RayV" = PL-IPTV "RealAlt_is1" = Real Alternative 2.0.2 "SopCast" = SopCast 3.2.4 "SynTPDeinstKey" = Synaptics Pointing Device Driver "Veetle TV" = Veetle TV "VLC media player" = VLC media player 1.0.5 "WildTangent gateway Master Uninstall" = Gateway Games "Winamp" = Winamp (remove only) "WinRAR archiver" = Archiwizator WinRAR [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-699923459-1462160667-771819599-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 07/07/2011 10:54:47 | Computer Name = Wojtek-PC | Source = Application Error | ID = 1000 Description = Faulting application update.tmp, version 0.0.0.0, time stamp 0x424c1096, faulting module LIBEAY32.dll, version 6.0.6001.18000, time stamp 0x4791a7a6, exception code 0xc0000135, fault offset 0x00009cac, process id 0x4c0, application start time 0x01cc3cb5d04dea00. Error - 07/07/2011 13:01:24 | Computer Name = Wojtek-PC | Source = WinMgmt | ID = 10 Description = Error - 07/07/2011 13:46:11 | Computer Name = Wojtek-PC | Source = Application Error | ID = 1000 Description = Faulting application gg.exe, version 7.1.0.6, time stamp 0x43f5c9bd, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00cfe6b2, process id 0xaf0, application start time 0x01cc3ccb5b80ede7. Error - 07/07/2011 14:25:49 | Computer Name = Wojtek-PC | Source = WinMgmt | ID = 10 Description = Error - 07/07/2011 15:40:00 | Computer Name = Wojtek-PC | Source = Application Error | ID = 1000 Description = Faulting application gg.exe, version 7.1.0.6, time stamp 0x43f5c9bd, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00c5e6b2, process id 0xd34, application start time 0x01cc3cdd632b70a0. Error - 07/07/2011 16:14:33 | Computer Name = Wojtek-PC | Source = Application Error | ID = 1000 Description = Faulting application gg.exe, version 7.1.0.6, time stamp 0x43f5c9bd, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00e8e745, process id 0xa28, application start time 0x01cc3cdda8cb3b40. Error - 07/07/2011 17:33:20 | Computer Name = Wojtek-PC | Source = WinMgmt | ID = 10 Description = Error - 07/07/2011 17:33:27 | Computer Name = Wojtek-PC | Source = Application Error | ID = 1000 Description = Faulting application update.tmp, version 0.0.0.0, time stamp 0x424c1096, faulting module LIBEAY32.dll, version 6.0.6001.18000, time stamp 0x4791a7a6, exception code 0xc0000135, fault offset 0x00009cac, process id 0xa88, application start time 0x01cc3ced81a2b762. Error - 08/07/2011 04:45:33 | Computer Name = Wojtek-PC | Source = WinMgmt | ID = 10 Description = Error - 08/07/2011 04:45:57 | Computer Name = Wojtek-PC | Source = Application Error | ID = 1000 Description = Faulting application update.tmp, version 0.0.0.0, time stamp 0x424c1096, faulting module LIBEAY32.dll, version 6.0.6001.18000, time stamp 0x4791a7a6, exception code 0xc0000135, fault offset 0x00009cac, process id 0x9d8, application start time 0x01cc3d4b73c1e32b. [ Media Center Events ] Error - 17/01/2011 10:43:07 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 30/01/2011 05:42:31 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 22/02/2011 07:10:17 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 22/02/2011 09:22:06 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 19/03/2011 05:18:17 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 01/05/2011 04:11:35 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 16/07/2011 06:03:59 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide Error - 16/08/2011 13:13:41 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide Error - 11/11/2011 12:49:31 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide Error - 13/11/2011 11:34:32 | Computer Name = Wojtek-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide [ System Events ] Error - 14/11/2011 11:31:36 | Computer Name = Wojtek-PC | Source = HTTP | ID = 15016 Description = Error - 14/11/2011 11:32:07 | Computer Name = Wojtek-PC | Source = Service Control Manager | ID = 7000 Description = Error - 14/11/2011 11:38:56 | Computer Name = Wojtek-PC | Source = Service Control Manager | ID = 7031 Description = Error - 14/11/2011 12:36:25 | Computer Name = Wojtek-PC | Source = HTTP | ID = 15016 Description = Error - 14/11/2011 12:36:51 | Computer Name = Wojtek-PC | Source = Service Control Manager | ID = 7000 Description = Error - 14/11/2011 12:38:21 | Computer Name = Wojtek-PC | Source = VDS Dynamic Provider | ID = 16908298 Description = Error - 14/11/2011 12:50:50 | Computer Name = Wojtek-PC | Source = HTTP | ID = 15016 Description = Error - 14/11/2011 12:51:09 | Computer Name = Wojtek-PC | Source = Service Control Manager | ID = 7000 Description = Error - 14/11/2011 13:14:13 | Computer Name = Wojtek-PC | Source = HTTP | ID = 15016 Description = Error - 14/11/2011 13:14:52 | Computer Name = Wojtek-PC | Source = Service Control Manager | ID = 7000 Description = < End of report >