OTL Extras logfile created on: 2012-07-06 18:09:17 - Run 1 OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Aleksander\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,31 Gb Available Physical Memory | 65,35% Memory free 4,00 Gb Paging File | 3,40 Gb Available in Paging File | 84,94% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 298,08 Gb Total Space | 83,08 Gb Free Space | 27,87% Space Free | Partition Type: NTFS Computer Name: ALEKSANDER-PC | User Name: Aleksander | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_USERS\S-1-5-21-982888493-1902689212-848150227-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04FCD92A-80D0-4D13-B8CC-2970FE048B5B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{121ECC26-C960-4DD8-A97A-20EB2810B638}" = lport=138 | protocol=17 | dir=in | app=system | "{1F53711C-CA39-45EE-B293-AC8E656D3820}" = lport=2869 | protocol=6 | dir=in | app=system | "{1F565B66-A196-4273-B4A6-3E00119A4C47}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{210EF3B0-584F-4145-926F-372184604175}" = rport=138 | protocol=17 | dir=out | app=system | "{2F70D667-C1A7-45E9-8BB8-9631AE12090E}" = rport=10243 | protocol=6 | dir=out | app=system | "{441FF9DB-6963-4314-B6C4-F96633DC3552}" = lport=10243 | protocol=6 | dir=in | app=system | "{575DAD48-F6FA-4AB6-991A-F47E09CF8F76}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5A252280-8547-4611-908B-51FA4DCF94C9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{5FD12AEC-061D-4FCC-B2B9-A3404BD1102D}" = lport=139 | protocol=6 | dir=in | app=system | "{60D51BEA-AA87-4F06-8B36-F84029EBBE8E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{64F61DA2-F321-4F87-92FA-57AFAA275887}" = lport=137 | protocol=17 | dir=in | app=system | "{73F0E740-CA15-4685-9BE1-B40E943E0407}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{7CDA3A12-4F98-4EA4-A652-F5A22B356F2F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9365FE2C-B950-4384-866B-14100DE87B3E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{949B1CC8-D64C-4DD1-8565-3FC299EECF01}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{99EEDB82-D1B0-4428-97D6-04F14CDD8CA4}" = lport=445 | protocol=6 | dir=in | app=system | "{9D3273D9-B0D5-4056-AE26-079346298187}" = rport=137 | protocol=17 | dir=out | app=system | "{CFC08FFB-6C21-457B-9063-61391D8CD916}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D38BA3CA-7466-4E41-B1FD-416591000D09}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F2193409-96B9-4BF5-8C57-E2927CCA6A53}" = rport=139 | protocol=6 | dir=out | app=system | "{F61E02F4-F7AD-4DD3-8D54-59C0B26A299E}" = rport=445 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{065E2682-41A1-4BD4-B054-90DCF1D5054B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{0CF58205-C32B-4134-9DC4-1A320E5D911B}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{0E68BCE8-53DF-4848-83AA-91C20ACAC9E8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe | "{1173BBB6-3CA4-486F-ACC1-6E65F96FABB2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{12F0655E-5BD1-442F-B9AC-5647C0E00910}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\uplink\uplink.exe | "{19048924-4729-44FD-949F-7A637A61D633}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe | "{2773F89F-2CA3-4183-BC4D-56617E171B89}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe | "{348F5CEB-9665-4DC0-AA5A-324BD380EB99}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe | "{381CE452-B78F-456F-98DB-D7A9CC04D525}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{3825F505-386B-43B5-BB9D-05AB05241900}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\uplink\uplink.exe | "{3D1A8365-9545-446A-ACFF-0A9E46FBE5CA}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{40BA225D-C7CC-4292-9797-FE60E9C3EF99}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{40C08D2B-C944-44CA-80C8-612B70FBD54B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe | "{4B2B857F-6DCD-4C0F-BD0C-D5FA1FAD5A6C}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{4B5BF4B5-2B29-41F0-9081-8BA73ACD8086}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{4E282B23-82B5-4777-A779-CAD7DC5F6D68}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{4EC76D8C-426E-4C3C-8D0E-1F6AE6083CDE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe | "{527E3110-19A8-4625-AD97-A20E89B2B158}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{546A3CEC-BEBD-494B-99E7-91A8BA032A5C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe | "{54E19728-4D7B-48DF-AEA1-E18F72C58ABA}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{59352F0F-2EDD-464D-9A8C-2C71D79425F6}" = protocol=6 | dir=out | app=system | "{5E8D3AF7-BE33-4EB5-A04C-E0B1DE6C0B38}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{63428452-8B03-43E3-AAF7-AE1FF5B519BA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe | "{71816B45-85C4-41A6-9C2D-C1425553CD97}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{79C7F1B1-82A7-4473-BDC1-0DE3D8077C2C}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{7DD8B339-AAAB-401A-8CB1-D48B8369ED97}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{80C51FB9-3BDA-4417-8D81-6E12DC49448F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row 2\sr2_pc.exe | "{90B497BC-5E3C-468D-A8A5-39838437D4CE}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{94B62110-FEDE-45B4-B227-5B66A3025D68}" = protocol=6 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe | "{9562648F-95CD-45DE-B68F-B16B78780D52}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{A14C6DFD-B11C-4553-8A3E-8A89C1C215D4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A57C7F33-E3F4-4CAC-B08C-12DD551BE5BB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe | "{A990C49E-36B1-4A70-A0E0-B4E117DEA8BF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{AA315171-AFA1-4DA4-92DE-16C22EBF447F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe | "{B0422045-426D-4490-AF75-6B34A47512D4}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{B09D43C2-11BD-4C43-93A2-A32389D4D58E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe | "{B0C42AF4-85D6-4350-8D83-EBDDA447827C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{B62D6782-1852-4C26-811D-80AAAE0E0EC5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{B9694DF0-4409-4093-9DAB-250E11E97B67}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B9B5009E-DFD8-4DBC-BF73-C2619D2C5EEA}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B9E2717C-6269-48C1-B80B-8F7F06D507C2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{BA7D4DC9-45C6-4FD1-88F7-4E8044FFC9A8}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{BF517750-080F-40B1-8E45-7E6921518A0D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe | "{BFF8F590-42A4-477B-B627-812D6BB45E83}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{C046366F-BCBC-4EF2-8A89-77104AC3653F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe | "{C2E223F0-4F16-4F4F-A3D0-5561A7FFA92A}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe | "{CA97BB8A-2E17-4945-8802-9D20DF2CB885}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{CE152CD3-86C6-41C7-A28A-430C6DFF724C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{D24C0906-95C5-424D-8BA2-76E983C51CBA}" = protocol=17 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe | "{D530137C-BC4F-4DC1-AEBE-5AFEC6FB8012}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row 2\sr2_pc.exe | "{DB179086-C7DB-4AB1-8EEA-660D978177C2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{E2B63397-1051-4D47-B13B-29EF92A481CE}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{E72797AB-B0D0-4076-8706-2FB03BF2806F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E9FF81FE-F6E5-4F0F-A517-FCDE80FD7E44}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{EBD19B0E-9D52-4DC3-AEE0-202864C927F6}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EE698E18-76F9-4A27-B2F0-C800A714A386}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{F18315D8-D203-45D9-B31C-5E95949D9719}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{F267CB06-93AE-48C5-94F3-D3A60E832084}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{F4EB7723-4862-4ECE-B041-2DB800831116}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{050A768E-70EA-4578-94D0-9A742933FFCE}C:\users\aleksander\desktop\ntsd_2.4\ntsd2.4\ntsd.exe" = protocol=6 | dir=in | app=c:\users\aleksander\desktop\ntsd_2.4\ntsd2.4\ntsd.exe | "TCP Query User{2713C82A-38C8-4182-BFCA-EE9C9D30773D}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "TCP Query User{38CEAD22-2E65-4C04-B3D7-6F9198125764}D:\easysetupassistant\td-w8960n\fscommand\easysetupassistant.exe" = protocol=6 | dir=in | app=d:\easysetupassistant\td-w8960n\fscommand\easysetupassistant.exe | "TCP Query User{5FFEC5A0-D05D-4412-845A-B437BF01F4C2}C:\program files (x86)\turbine\ddo unlimited\dndclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\turbine\ddo unlimited\dndclient.exe | "TCP Query User{60C2F4E2-D43C-49F5-987A-F80CC7D43AE8}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "TCP Query User{61DE4894-8EEF-4B6C-9BB1-9785820FF2F6}C:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe" = protocol=6 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe | "TCP Query User{A30F21AA-53FD-4B25-906E-86E6841BEE2C}C:\users\aleksander\appdata\local\temp\rar$exa0.254\ntsd2.4\ntsd.exe" = protocol=6 | dir=in | app=c:\users\aleksander\appdata\local\temp\rar$exa0.254\ntsd2.4\ntsd.exe | "TCP Query User{A912EA5E-C871-41EC-8D84-B7B047C6ED76}C:\users\aleksander\appdata\local\temp\rar$exa0.952\ntsd2.4\ntsd.exe" = protocol=6 | dir=in | app=c:\users\aleksander\appdata\local\temp\rar$exa0.952\ntsd2.4\ntsd.exe | "TCP Query User{C7DA017D-D151-42BE-BE83-CD1BB66FF93E}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "TCP Query User{D5CBB243-15CF-4085-93DF-8D02A8F07681}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "TCP Query User{D5D12A87-77B1-402D-9F1A-2991FCEF161D}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "TCP Query User{E5428F71-2F9F-4A9C-9C4B-6E15296D6116}C:\program files (x86)\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe" = protocol=6 | dir=in | app=c:\program files (x86)\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe | "UDP Query User{0E8D1F65-C4D9-4832-A967-6AD997319101}C:\users\aleksander\appdata\local\temp\rar$exa0.254\ntsd2.4\ntsd.exe" = protocol=17 | dir=in | app=c:\users\aleksander\appdata\local\temp\rar$exa0.254\ntsd2.4\ntsd.exe | "UDP Query User{589DEF00-CD90-4514-8755-C22AE3567C9E}C:\users\aleksander\appdata\local\temp\rar$exa0.952\ntsd2.4\ntsd.exe" = protocol=17 | dir=in | app=c:\users\aleksander\appdata\local\temp\rar$exa0.952\ntsd2.4\ntsd.exe | "UDP Query User{5FA54D81-EFD2-4285-AD16-97DD576CA35E}C:\program files (x86)\turbine\ddo unlimited\dndclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\turbine\ddo unlimited\dndclient.exe | "UDP Query User{7C30B442-7438-4C20-B94E-7623A8F9DE74}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "UDP Query User{95DC9B15-A932-4DF2-8FBB-85BAD1303445}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "UDP Query User{9AFFF5DB-E8E2-4370-B9FE-1F3AB919F3E5}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "UDP Query User{A560FF94-650A-4EAF-8C5C-F695B36ACE18}C:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe" = protocol=17 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe | "UDP Query User{A5DC0F1D-1B3D-4E01-81F4-B2D935C68332}D:\easysetupassistant\td-w8960n\fscommand\easysetupassistant.exe" = protocol=17 | dir=in | app=d:\easysetupassistant\td-w8960n\fscommand\easysetupassistant.exe | "UDP Query User{AFEE6A8A-B18F-43D6-A98D-838A02BC6FFF}C:\program files (x86)\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe" = protocol=17 | dir=in | app=c:\program files (x86)\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe | "UDP Query User{B7444676-C9E7-4618-B3EF-930FC282ADDA}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe | "UDP Query User{E63F8AD5-FF59-4BFD-9C36-F70F91AB0CB0}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "UDP Query User{EFB36A90-9824-4C8B-AD4D-E74BA5789A75}C:\users\aleksander\desktop\ntsd_2.4\ntsd2.4\ntsd.exe" = protocol=17 | dir=in | app=c:\users\aleksander\desktop\ntsd_2.4\ntsd2.4\ntsd.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{26A24AE4-039D-4CA4-87B4-2F86417004FF}" = Java(TM) 7 Update 4 (64-bit) "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 296.10 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 296.10 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 296.10 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 296.10 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.11 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "WinRAR archiver" = WinRAR 4.11 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1 "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4 "{3647419E-C81D-411A-8013-7983F936A84A}" = S.T.A.L.K.E.R. - Clear Sky "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{534A31BD-20F4-46b0-85CE-09778379663C}" = Mass Effect™ 3 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Polish "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.9 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "avast" = avast! Free Antivirus "bc8a6440-918f-11dd-ad8b-0800200c9a66_is1" = Dungeons & Dragons Online ®: Eberron Unlimited ™ v01.17.01.801 "DAEMON Tools Lite" = DAEMON Tools Lite "ENTERPRISE" = Microsoft Office Enterprise 2007 "Europe MapleStory_is1" = Europe MapleStory "Google Chrome" = Google Chrome "Mafia II_is1" = Mafia II "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Mozilla Firefox 13.0.1 (x86 pl)" = Mozilla Firefox 13.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Origin" = Origin "pkslow_60_is1" = Profesor Klaus Słownictwo 6.0 "PunkBusterSvc" = PunkBuster Services "Saints Row The Third_is1" = Saints Row The Third "slow_12_60_is1" = Profesor Henry 6.0 Słownictwo poziom 1 i 2 "slow_34_60_is1" = Profesor Henry 6.0 Słownictwo poziom 3 i 4 "Smashmuck Champions" = Smashmuck Champions "StarCraft II" = StarCraft II "Steam App 1510" = Uplink "Steam App 209870" = Blacklight: Retribution "Steam App 22350" = BRINK "Steam App 28050" = Deus Ex: Human Revolution "Steam App 42910" = Magicka "Steam App 8930" = Sid Meier's Civilization V "Steam App 8980" = Borderlands "Steam App 9480" = Saints Row 2 "The Secret World_is1" = The Secret World "uTorrent" = µTorrent [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-982888493-1902689212-848150227-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "UnityWebPlayer" = Unity Web Player [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-06 10:48:41 | Computer Name = Aleksander-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-07-06 10:51:06 | Computer Name = Aleksander-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-07-06 10:52:05 | Computer Name = Aleksander-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-07-06 10:52:42 | Computer Name = Aleksander-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-07-06 10:56:47 | Computer Name = Aleksander-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-07-06 10:58:28 | Computer Name = Aleksander-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-07-06 11:04:02 | Computer Name = Aleksander-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-07-06 11:05:33 | Computer Name = Aleksander-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-07-06 11:12:40 | Computer Name = Aleksander-PC | Source = Winlogon | ID = 4103 Description = Windows license activation failed. Error 0x80070005. Error - 2012-07-06 11:21:17 | Computer Name = Aleksander-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2012-07-06 11:03:51 | Computer Name = Aleksander-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 17:02:26 on ?2012-?07-?06 was unexpected. Error - 2012-07-06 11:04:01 | Computer Name = Aleksander-PC | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: discache spldr Wanarpv6 Error - 2012-07-06 11:04:03 | Computer Name = Aleksander-PC | Source = DCOM | ID = 10005 Description = Error - 2012-07-06 11:04:12 | Computer Name = Aleksander-PC | Source = DCOM | ID = 10005 Description = Error - 2012-07-06 11:04:16 | Computer Name = Aleksander-PC | Source = DCOM | ID = 10005 Description = Error - 2012-07-06 11:04:16 | Computer Name = Aleksander-PC | Source = DCOM | ID = 10005 Description = Error - 2012-07-06 11:14:36 | Computer Name = Aleksander-PC | Source = Microsoft-Windows-Eventlog | ID = 106 Description = Corruption was detected in the log for the Security channel and some data was erased. Error - 2012-07-06 11:19:34 | Computer Name = Aleksander-PC | Source = Microsoft-Windows-Eventlog | ID = 106 Description = Corruption was detected in the log for the System channel and some data was erased. Error - 2012-07-06 11:19:35 | Computer Name = Aleksander-PC | Source = Microsoft-Windows-Eventlog | ID = 106 Description = Corruption was detected in the log for the Application channel and some data was erased. Error - 2012-07-06 11:19:50 | Computer Name = Aleksander-PC | Source = Microsoft-Windows-Eventlog | ID = 106 Description = Corruption was detected in the log for the Microsoft-Windows-Diagnosis-DPS/Operational channel and some data was erased. < End of report >