OTL Extras logfile created on: 2012-07-06 18:41:28 - Run 1 OTL by OldTimer - Version 3.2.53.1 Folder = D:\dysk c\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 3,22 Gb Available Physical Memory | 80,52% Memory free 8,00 Gb Paging File | 7,25 Gb Available in Paging File | 90,63% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 24,41 Gb Total Space | 1,45 Gb Free Space | 5,95% Space Free | Partition Type: NTFS Drive D: | 441,34 Gb Total Space | 221,46 Gb Free Space | 50,18% Space Free | Partition Type: NTFS Drive E: | 642,26 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive F: | 49,46 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: KOMPUTER_PAWLA | User Name: Pawel | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl[@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ChomikBox.Upload] -- "D:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( ) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ChomikBox.Upload] -- "D:\Program Files (x86)\ChomikBox\\ChomikBox.exe" -u"%1" ( ) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01A902B1-A9DE-409D-B6DD-60AD18A862FD}" = rport=445 | protocol=6 | dir=out | app=system | "{02CB4198-E786-45DA-9B04-C37F03ABB124}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{113E925B-0D73-4DDC-B0DB-5B791B38DA62}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{1B5139BE-C7A6-460C-BACA-042FD0F0918E}" = lport=2869 | protocol=6 | dir=in | app=system | "{1C8986DB-CED1-4CB1-BA5D-9388FC4E501F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{27AF922A-1B2B-4242-97C3-7B530521E7EA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2830BF62-9D7A-4BAB-AFDF-3EE3195DD9B7}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{29F8AC40-15C1-41A0-BCC7-19764BA9055D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2A966C3F-A453-404F-B796-B8A240AF3D14}" = lport=57141 | protocol=17 | dir=in | name=pando media booster | "{3068C455-4987-4F4A-B14C-800DC8227F17}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{4A728082-BD21-4FCE-8A79-FBC06D8B934E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4D153F23-0069-4206-BD1F-5D24862FEE53}" = rport=138 | protocol=17 | dir=out | app=system | "{4F24D3D3-C063-4041-A07E-5AA13E5DD621}" = lport=57141 | protocol=6 | dir=in | name=pando media booster | "{5F37F32E-DFD5-4328-85AB-64E7580A6995}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{62FEB0CF-0508-4875-A1EC-54F04820AE55}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{69D1F437-AAF3-457B-9F0C-859EEEA58C45}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{799F8F37-73CF-436C-B681-AEBEFBF1A394}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A11607EE-883F-47D2-BA9B-94A5ED637B80}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A847C512-4338-41CE-B8E7-5701B67BBD2B}" = lport=139 | protocol=6 | dir=in | app=system | "{B236D300-BECB-4B26-83CD-D44A5FAA5C9D}" = rport=139 | protocol=6 | dir=out | app=system | "{B28D99D1-A7CF-480A-8D6A-DB65CF1A82FD}" = lport=445 | protocol=6 | dir=in | app=system | "{BCDCF62A-BF3A-4E6A-9EF4-25996FA62FDB}" = lport=138 | protocol=17 | dir=in | app=system | "{C01D1180-F9A0-4F65-B24C-FE784FA8967E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CE542778-2402-4F85-8E4A-A0CC41FE6503}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CE79EABF-30B1-4BA6-9CDF-E9793EE5EC7A}" = rport=2869 | protocol=6 | dir=out | app=system | "{D83C098E-11C8-4434-8B70-F190CF203605}" = rport=137 | protocol=17 | dir=out | app=system | "{DC2BEE35-9F44-4C40-AD64-89AF8CB6CBB1}" = lport=57141 | protocol=6 | dir=in | name=pando media booster | "{DCC7A661-3734-48A9-A366-251536056D5A}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{E2C6FCBB-8EC1-42D3-927B-889AFF829982}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{EFD91E2C-4123-41B1-8B2B-F20E667F53AD}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{FB70AD55-B5A8-4213-989A-95B7ABCE4F79}" = lport=57141 | protocol=17 | dir=in | name=pando media booster | "{FCE124DF-3195-4F54-A359-2F60E6A43998}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{FE538982-A876-40E3-B9F0-B6108B20FAAA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FF9E54C5-6DF3-4A90-BA33-F942D7056321}" = lport=137 | protocol=17 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0240E1BA-042F-4FCF-9173-7A019003BB89}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{0433AFB8-D7D9-4810-8FE8-DC14B8609D47}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{07C2D082-2CED-4EF1-93C9-8F21D9C18871}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe | "{0B62905D-B975-4D7F-9AAE-9A11520441E0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{0C71C424-423F-4817-8045-8E5A584A6EF7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe | "{221B6C20-C8C2-411A-B077-0D02E84191CD}" = protocol=6 | dir=in | app=d:\program files\opera\pluginwrapper\opera_plugin_wrapper.exe | "{22D2469D-D4A2-44EC-9D19-28F3384A0002}" = protocol=58 | dir=in | app=system | "{26472865-AE5C-409F-A2B4-D2C286EDDD2C}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe | "{27DF500C-3E3B-43D8-9072-076A1E2B675B}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{32D0EFD5-7ABB-432D-B224-A444D999E225}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{34B69A32-B4D1-49A7-9590-8517ADE26366}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe | "{49980F1D-D3B1-40B3-A541-7B6198DA706C}" = protocol=6 | dir=in | app=d:\torrent\utorrent.exe | "{4E519D11-966B-4948-9B13-69A6DB25AEE3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{53D9B453-104B-4D07-A2DB-ED5CD8F5CC14}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{66481457-C065-4F42-A418-7741DC8B2FF1}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe | "{6A1FE790-598E-49AB-B6D8-FCEB522E7D3A}" = protocol=17 | dir=in | app=d:\program files\opera\pluginwrapper\opera_plugin_wrapper.exe | "{6E30EDA4-4D97-4EFC-93B7-CCC1EDBB1682}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{6ECEA23E-D7A2-49CF-920E-8DA4948575EB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{6F67E456-8B2B-44C9-A987-FAE637780F5B}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{734F0922-98C9-4E3F-8C03-18D439722094}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{77BA0C96-CEA6-483A-BF8F-366081DDF6C5}" = protocol=6 | dir=in | app=d:\program files (x86)\imesh applications\imesh\imesh.exe | "{7EF1223C-BD27-43FD-8F66-C1AA33B8FD58}" = protocol=6 | dir=in | app=d:\gry\diablo iii\diablo iii.exe | "{8165E0EC-D933-48E9-A97A-E11911481DC8}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{92642BB6-98F7-45E6-A157-6E7319A6EA75}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{98E7875D-1C68-4FE4-8D10-B756E90229F2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "{9F74FD29-EA25-40B3-B3CB-815501EA1EBB}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{A43F6C70-CE54-4F24-9B6F-18FEDF8EAC6F}" = protocol=17 | dir=in | app=d:\torrent\utorrent.exe | "{AA788732-1AEE-479F-92B5-245FCF4E17B0}" = dir=in | app=d:\program files (x86)\skype\phone\skype.exe | "{AAD0CB38-45E1-48F5-ABDA-AA9B21774A82}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{B9451878-F3E1-4F44-8094-29601F6E4050}" = protocol=6 | dir=in | app=d:\program files (x86)\imesh applications\imesh\imesh.exe | "{BB2E53B6-BC07-430D-9115-D9DC7EF23999}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{C96D52FC-134C-433D-879A-4A0EAD56712F}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{CD2FA702-797F-411F-9510-7B4CC12D5157}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{D026DC30-BA68-4EAC-83DC-A0A192E9449C}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe | "{D0BABD25-B8C2-4E4C-A0C7-18D9574F36A6}" = protocol=17 | dir=in | app=d:\gry\diablo iii\diablo iii.exe | "{DADF123C-3EC4-4DC8-A44F-C0C9A35A26BD}" = protocol=17 | dir=in | app=d:\program files (x86)\imesh applications\imesh\imesh.exe | "{E23B9A7E-35E9-4406-9A87-E4A4F724F9D3}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe | "{E5BED0D0-F741-471E-BFBD-ED187023E312}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EC30E29B-45A2-4E2E-9480-4D267733F69A}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe | "{EFCBD193-6E27-46B1-A58A-D40BE38E030E}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{F0B57D3D-AD76-4E47-9CF1-693618D054E3}" = protocol=17 | dir=in | app=d:\program files (x86)\imesh applications\imesh\imesh.exe | "TCP Query User{4D9AFB6F-91F2-4392-9A08-9A9970C27C7D}D:\program files\opera\opera.exe" = protocol=6 | dir=in | app=d:\program files\opera\opera.exe | "TCP Query User{5227A8F7-3BD2-48F8-9BED-7D22F626E96A}D:\program files\valve\hl.exe" = protocol=6 | dir=in | app=d:\program files\valve\hl.exe | "TCP Query User{72810454-55D9-4405-8FD8-182A93B0FC7B}D:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=d:\program files\gadu-gadu 10\gg.exe | "TCP Query User{74DF0FC9-8253-424D-9908-1242248940B5}D:\program files\opera\opera.exe" = protocol=6 | dir=in | app=d:\program files\opera\opera.exe | "TCP Query User{8CD62BC1-FFD3-4F76-B211-A8D3F3975248}D:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=d:\program files\gadu-gadu 10\gg.exe | "TCP Query User{9288EAB2-3EF5-4CC8-886D-8610AB38EB17}D:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=d:\program files (x86)\winamp\winamp.exe | "TCP Query User{96D8D7A0-FE99-43CE-B4AB-DB140757D4AB}D:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe" = protocol=6 | dir=in | app=d:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe | "TCP Query User{D78F04F3-7FE1-4559-ABC4-53ACA116439E}D:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe" = protocol=6 | dir=in | app=d:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe | "UDP Query User{0EAD761D-9B43-4D42-B8FC-1DABD3830221}D:\program files\opera\opera.exe" = protocol=17 | dir=in | app=d:\program files\opera\opera.exe | "UDP Query User{1034949C-3613-4899-8FCB-87902A72AC7F}D:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=d:\program files (x86)\winamp\winamp.exe | "UDP Query User{10A643A1-0E27-4EC9-8E24-0E0764000032}D:\program files\opera\opera.exe" = protocol=17 | dir=in | app=d:\program files\opera\opera.exe | "UDP Query User{17475F67-E27E-4EF7-AA81-F948AF0D93F5}D:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe" = protocol=17 | dir=in | app=d:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe | "UDP Query User{26A7AA2B-6D8D-4FE0-8700-E1420E97ACCD}D:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=d:\program files\gadu-gadu 10\gg.exe | "UDP Query User{6936F5AE-8E5E-4298-BF8E-DAFD7ED05439}D:\program files\valve\hl.exe" = protocol=17 | dir=in | app=d:\program files\valve\hl.exe | "UDP Query User{87E41339-EB48-4A3D-92DA-EBE67C684675}D:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe" = protocol=17 | dir=in | app=d:\gry\lucasarts\star wars jk ii jedi outcast\gamedata\jk2mp.exe | "UDP Query User{C9205BD8-574C-4447-943E-341402884257}D:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=d:\program files\gadu-gadu 10\gg.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{38D1C189-B133-401C-A729-3C47ED984B31}" = AVG 2011 "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A0377472-ED83-4A66-8B2E-0ECAEF190E47}" = AVG 2011 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 266.58 "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 266.58 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 266.58 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "AVG" = AVG 2011 "EPSON Stylus SX400 Series" = Odinstaluj drukarkę EPSON Stylus SX400 Series "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "WinRAR archiver" = Archiwizator WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = SAGEM F@st 800-840 "{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer "{6F23A5FE-CFE7-4340-A480-AA9AC196E9AB}" = ChomikBox "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8FB495A1-4A3F-4C1D-BD27-3F3AB2E66763}" = iMesh "{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{901C0415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Access 2003 Runtime "{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003 "{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C538746-C2DC-40FC-B1FB-D4EA7966ABEB}" = Skype™ 5.1 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A2804FE8-4101-48a0-AE1A-575B99014BF4}-Mio-7.30" = MioMore Desktop 7.30 "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2) "{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX "{BD8DA595-F501-4ABE-85A0-5C23E82472A0}" = Pomocnik Messenger "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CB4532F7-A1BD-46D2-9938-3E7D4656FB18}" = Razer Lachesis "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DD8D87E5-C372-462F-B168-94612B1D9451}" = HTC Sync "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{E9AD2143-26D5-4201-BED1-19DCC03B407D}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{F86B5FF0-E0C0-41AA-9FD3-5E9090FED323}" = Mumble 1.2.3 "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables "7-Zip" = 7-Zip 9.21beta "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Burn4Free CD & DVD_is1" = Burn4Free CD & DVD 5.4.0.0 "Burn4Free DB Toolbar" = Burn4Free DB Toolbar "CoreFLAC Audio Decoder+Source Filter" = CoreFLAC Audio Decoder+Source Filter (remove only) "Diablo III" = Diablo III "EPSON Scanner" = EPSON Scan "foobar2000" = foobar2000 v1.1.11 "Free Sound Recorder" = Free Sound Recorder "iMesh" = iMesh "LastFM_is1" = Last.fm 1.5.4.27091 "Messenger Plus!" = Messenger Plus! 5 "Messenger Plus! for Skype" = Messenger Plus! for Skype "Moja Matura - Matematyka Podstawowa1.0" = Moja Matura - Matematyka Podstawowa "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Odkurzacz 13.0_is1" = Odkurzacz "Opera 12.00.1467" = Opera 12.00 "PDF Editor 3" = PDF Editor 3 "SkanerOnline" = Skaner on-line mks_vir "Teachmaster 4.3" = Teachmaster 4.3 (remove only) "uTorrent" = µTorrent "Winamp" = Winamp "WinLiveSuite" = Podstawowe programy Windows Live [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "PhotoZoom Pro" = Shortcut PhotoZoom Pro 1.0.12 "Winamp Detect" = Detektor Winampa [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-06 12:02:17 | Computer Name = Komputer_PAWLA | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. Error - 2012-07-06 12:24:18 | Computer Name = Komputer_PAWLA | Source = VSS | ID = 18 Description = Error - 2012-07-06 12:24:18 | Computer Name = Komputer_PAWLA | Source = VSS | ID = 8193 Description = Error - 2012-07-06 12:24:18 | Computer Name = Komputer_PAWLA | Source = System Restore | ID = 8193 Description = Error - 2012-07-06 12:32:11 | Computer Name = Komputer_PAWLA | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-07-06 12:32:11 | Computer Name = Komputer_PAWLA | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-07-06 12:32:11 | Computer Name = Komputer_PAWLA | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. Error - 2012-07-06 12:38:52 | Computer Name = Komputer_PAWLA | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-07-06 12:38:52 | Computer Name = Komputer_PAWLA | Source = Microsoft-Windows-LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces wykonuje następującą operację na dostawcy licznika rozszerzeń: Performance. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-07-06 12:38:52 | Computer Name = Komputer_PAWLA | Source = Microsoft-Windows-LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Pierwszy wpis DWORD w sekcji danych (Data) zawiera kod błędu. [ System Events ] Error - 2012-07-06 12:35:06 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:36:50 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:36:50 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:36:50 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:41:50 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:41:50 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:41:50 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:43:58 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:43:58 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-07-06 12:43:58 | Computer Name = Komputer_PAWLA | Source = Service Control Manager | ID = 7001 Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie można uruchomić z powodu następującego błędu: %%1068 < End of report >