OTL Extras logfile created on: 2012-07-08 12:43:43 - Run 4 OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Kruszewscy\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,92 Gb Total Physical Memory | 6,86 Gb Available Physical Memory | 86,68% Memory free 15,83 Gb Paging File | 14,87 Gb Available in Paging File | 93,91% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 654,69 Gb Total Space | 472,80 Gb Free Space | 72,22% Space Free | Partition Type: NTFS Drive D: | 29,00 Gb Total Space | 26,22 Gb Free Space | 90,42% Space Free | Partition Type: NTFS Drive F: | 662,90 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: LENOVEK | User Name: Kruszewscy | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1874C888-668F-42F7-9C42-C3D1D7D33D60}" = lport=2869 | protocol=6 | dir=in | app=system | "{26A783B0-62AD-432D-BEE1-9DA946B9A67E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2FE09499-8E96-4495-BE6A-EE84FC181A29}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{33E092A1-57C8-43E5-A1A0-0416DFE18D72}" = rport=445 | protocol=6 | dir=out | app=system | "{42753449-20FB-4301-946A-B957FF30C8D7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{46B22F71-31CA-42B2-924D-8404D5E5ED74}" = lport=445 | protocol=6 | dir=in | app=system | "{5B2BB372-6B79-45B5-96F9-3F31CA277B35}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5FABEFF7-B828-44FF-8E72-7FD186603784}" = rport=139 | protocol=6 | dir=out | app=system | "{6193D923-1F8F-4634-8C7E-CD3D64147F1E}" = lport=137 | protocol=17 | dir=in | app=system | "{6846129E-0782-45AB-9B1F-FE6F7DEE4462}" = rport=137 | protocol=17 | dir=out | app=system | "{6EA5E6F5-A8B1-4F79-9C59-E15A2914DBC9}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{7350A799-C76E-4D4D-B997-372E20CE4C89}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{AA23E8AD-BCC9-44FA-82D0-0E3E3B2723F9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B31FCB1B-1A79-4704-9CA2-8E4BADA720E2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C3F27EE7-F426-4BB4-A672-D802F57A16D1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CAA0CC1B-F32D-43BB-8A30-08DD5017EC01}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{D068461C-18E4-4963-95D1-90EEC8707FE3}" = rport=138 | protocol=17 | dir=out | app=system | "{D52A5D6C-5C4D-4679-9BA0-960FDDC675EA}" = lport=10243 | protocol=6 | dir=in | app=system | "{E4B2D91D-C3E7-4008-8130-0B3CC0597E20}" = lport=138 | protocol=17 | dir=in | app=system | "{E7F099E8-3D85-40F7-B101-A279E912C339}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{EFE95899-E31D-487B-9D35-0C8B0FF1A0AD}" = lport=139 | protocol=6 | dir=in | app=system | "{F1FA142E-4672-4319-8A62-53D71882977F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F85A0A5D-7205-4ED8-B232-43E2751DA783}" = rport=10243 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0137E1F1-5238-4FE2-90A6-B8BCBF0B1FB3}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battleforge\bootstrapper.exe | "{0652FE81-85A0-44BE-982C-9E3B5FE9E4E0}" = dir=in | app=c:\program files (x86)\intel corporation\intel wireless display\widiapp.exe | "{06B68F4F-6D74-4A88-BEE4-E2908B3111EF}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey (collector's edition)\launcher.exe | "{0739B91F-1649-481A-952C-30CFCA09CBA2}" = protocol=6 | dir=out | app=system | "{0945CB5A-7D1C-4D86-B2F9-6C727996CE5E}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{1BAD78F5-4DFC-469A-A9D0-EACEBDA742EF}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{1EE5E25F-3AB7-42F5-A281-791D005713CE}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{20C5D4B8-F8E8-46ED-B477-199F69481F38}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{2147BBE9-4637-423D-88E1-188B79279ACD}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battleforge\battleforge.exe | "{23C58A16-64CA-40DE-8B1A-AFEF827A76C0}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey (collector's edition)\acess.exe | "{2C113576-DD54-42AD-A2D6-BDC7232FC290}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{2E7BC07F-D18C-4B07-9319-54A24A758DF7}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{2EB8E2A3-7531-4FDE-9EC8-F376F0FF3E51}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{31325B7D-76B8-4621-8578-7ED20D17BD86}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{33D2DA45-B5C5-4613-907F-7D85265102B5}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "{345AAE96-B316-404C-982A-9D8C33C50217}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{347BCB68-C415-4F9D-B3E1-323F83995B1F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{36984FF0-42B4-4810-81F1-79123EFE1A27}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3B0953F2-6AE9-4A0F-8C74-D0FE7BB22D8D}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{4F21D04A-7663-417D-B5F9-C07BE392FCD9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{4F7C46F8-6364-4D3D-AE1B-FC0AE8A3D9F7}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey (collector's edition)\launcher.exe | "{4FCED455-285C-4AFB-892F-940767AE9B01}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{503FD809-7943-4303-A908-B42C5815430A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{57F927B0-DFFF-4EE4-BED1-8F5571417EE0}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battleforge\battleforge.exe | "{5C7525DD-920F-4AC7-A1D8-901029F17A3D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5E6B5AF0-0CD4-4A9F-89F8-F8386B908E92}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{6804AE5D-CFC5-4547-96AC-D7F79581A788}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{6BD89380-1422-42AC-ADBF-6B220D23A6C7}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{6BDF2CEF-8798-4FBE-B36D-1171C0E83186}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{7BF68C5E-D7C1-4D43-B05B-4DD0F0CF9C6F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{7FE328A7-52CD-4BB5-89BB-BA522C4A9FF0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe | "{86EF4867-6911-4971-BDF4-F381506CD2DF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe | "{93169980-198A-4A81-A85F-E783EE182607}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{93FC2E2C-85F0-4067-A528-837014FC41B9}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battleforge\bootstrapper.exe | "{96EF592B-9BA6-4B73-AA39-BED64F690A36}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey (collector's edition)\acess.exe | "{9AF60FED-2FFB-4BF3-9BDD-BC03A39273E4}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "{9DDB81D6-F506-45B8-90CA-3188D0B67A8C}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{9ED059A1-3C1C-404A-A34B-7E3EE94A9601}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey (collector's edition)\yuplay\yuplay.exe | "{A08CAEDD-A4D8-4528-AA67-23685C9B3CD3}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe | "{A268351A-7EFF-45F6-BD58-009171DF62E5}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe | "{A8D3ED31-8412-404B-8E86-A887C97C11E5}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey (collector's edition)\yuplay\yuplay.exe | "{ADBE1FA0-4F9C-4F82-B32A-BDE4B5B5FF93}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{B060CA1B-3463-41D0-9250-8BAC187C6E66}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{B5B9B0F2-5AEE-4486-A5E1-4454FFEBCDC2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{B60A1AED-1E70-40EC-B0CE-BE4FBDEC82E1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{BD34FFBC-6A2E-4886-BD93-ADC83DD13E04}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{C62E30A8-3F15-4E7A-B339-2CACA22ACD8C}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{CC287086-F803-4EB4-B67E-445A268A7B83}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{D2AE5FB2-0EFC-4854-9991-823341919A63}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{D5BA2863-4F2E-4E8C-A5EB-17304C434EF9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D9471943-C294-495A-84C2-5BE8E52A6099}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{DA5B1DB4-FA4A-4EB7-B819-257A2E091C38}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{DAA77456-CA28-4996-8E78-8F852AD91713}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.515\agent.exe | "{DB865D11-5E59-4E72-B5F1-51CA91BFCC3D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{DC692614-EDC3-4BE7-A71C-05234E502D42}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{E797FEF5-E90B-44E9-B65A-2D1537FE29C3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E8828B78-257B-4E37-A8C1-FA7B5C9F91B4}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe | "{EE5F37CF-1D8E-4683-8232-60142A5AAFB1}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\fifa 12\game\fifa.exe | "{F0FA24BE-EA06-4EB1-98DC-9F0111022C0A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{F1B4352C-0EA1-4589-8DC9-046A31E7E717}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{F731ABFD-14DC-44A5-9B3F-D7BB4615D2C8}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{FAFA7864-CC57-4F06-B03D-5C3348424878}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{03530249-96F4-4CCB-B05E-36EFF0C7568F}C:\users\kruszewscy\downloads\nail'd 2010 [pl] [.exe]\nail'd\naild_x86.exe" = protocol=6 | dir=in | app=c:\users\kruszewscy\downloads\nail'd 2010 [pl] [.exe]\nail'd\naild_x86.exe | "TCP Query User{24C12004-5E4E-4EF8-85E1-E7313CF32D97}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "TCP Query User{25E6D7D3-78AF-40A7-BD64-2EEA9479E298}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "TCP Query User{5B27B2D5-9DB4-4349-85F3-2838CE4DDCC2}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe | "TCP Query User{7AAA8FD6-079B-4926-A0F8-149AC15694B3}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "TCP Query User{7D0203FC-CF0B-4623-9AC7-3F711D463E5F}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "TCP Query User{86EBCFD3-A589-472E-AA36-DF780271EAC4}C:\program files (x86)\diablo iii\diablo iii.exe" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "TCP Query User{C1D47532-C6DA-426B-BCB7-B51A9B963F36}C:\program files (x86)\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | "TCP Query User{C6086348-2314-436C-9966-CBF2EFDB5749}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | "TCP Query User{CF209D8B-48A0-4DDC-806D-E1ABEF7B0B3C}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "TCP Query User{DB3FBB9C-BE03-413C-8110-1DCE3C97C292}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "TCP Query User{F7FDAFA4-2344-4E20-832A-DE872689CC21}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{02583056-DE2B-4701-9ACA-09B5D31BE35D}C:\users\kruszewscy\downloads\nail'd 2010 [pl] [.exe]\nail'd\naild_x86.exe" = protocol=17 | dir=in | app=c:\users\kruszewscy\downloads\nail'd 2010 [pl] [.exe]\nail'd\naild_x86.exe | "UDP Query User{0C57BE1D-FEC1-4042-BF35-CA6672DF35E6}C:\program files (x86)\diablo iii\diablo iii.exe" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "UDP Query User{0D0A2158-7A54-429D-A2C8-39B284FE3C88}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe | "UDP Query User{1729BC82-FA03-45FB-A05B-A16DF41419D2}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | "UDP Query User{35AE9255-EDE1-441B-85BC-B81932B559EB}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{44E7C2EB-9705-42D0-9AF9-F3016B91A4F3}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | "UDP Query User{6E4BC24F-A8D2-4420-ADF4-6996A79E35FC}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{78B3EC90-8AB0-4FB0-81B5-D6BD2AF302E7}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "UDP Query User{9722E723-F760-460C-B8FB-681902D35E52}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "UDP Query User{AE573A3B-12D7-4735-A8C0-3C00C9A792D2}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "UDP Query User{E05B61A2-7BC9-423D-819F-AC71230A6E39}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe | "UDP Query User{F5E42D0C-5C7A-4C08-800A-128196D748A4}C:\program files (x86)\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{26A24AE4-039D-4CA4-87B4-2F86417002FF}" = Java(TM) 7 Update 2 (64-bit) "{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display "{2998191E-A35E-47E2-BE38-7702C731D722}" = SRS Premium Sound Control Panel "{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = Lenovo Bluetooth with Enhanced Data Rate Software "{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{ACB6F4ED-835B-44EC-9EFD-AC8C83D28597}" = RtLED "{AF162E20-417F-4946-A06D-65734984957F}" = Oprogramowanie Intel(R) PROSet/Wireless WiFi "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 301.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 301.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.8.15 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.12.0213 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.8.15 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "EA12B1FB53CE4E387C31A85236C41EF559B5E392" = Pakiet sterowników systemu Windows - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) "Lenovo EE Boot Optimizer" = Lenovo EE Boot Optimizer "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "ProInst" = Intel PROSet Wireless "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.11 (64-bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1AD8819A-70E8-4380-92DA-F5B2421DAE35}" = G Data AntiVirus 2012 "{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{2006524B-91F8-4C6D-B961-397DC8132373}" = Królewna Śnieżka "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{51C15802-6F7A-4BCC-9D04-DAFB6D02FCD1}" = Bolek i Lolek - Letnia Olimpiada "{52334C99-D2C1-4AAA-991D-B2B06B139CF2}" = ABC z Reksiem "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71B8AD4E-5FDD-4B02-B7D3-E9118B36EA7C}" = Bolek i Lolek - tajemnicze zamczysko "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{83AA2913-C123-4146-85BD-AD8F93971D39}" = BabylonObjectInstaller "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B63540D-D942-4C38-B42E-A48AE0145970}" = Virtua Tennis 3 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AA8CAECD-8157-4C49-8F7D-DE82516ED42A}" = Bolek i Lolek - j. angielski dla dzieci cz.2 "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3) "{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}" = Lenovo EasyCamera "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych "{B2A81A85-0287-406b-9791-82E8F01A42B0}" = Reksio i Wehikuł Czasu "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{C580908C-B3BA-4C19-BD60-16F02F272201}" = BattleForge™ "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{CF5D5054-34F7-4A22-3594-29FF1D025029}_is1" = IHF Handball Challenge 12 "{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater "{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{EA8ADAA9-6671-4839-A51E-0C6792B78F3E}" = FIFA 12 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS "{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = Podręcznik użytkownika "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{F84906ED-BB54-4889-B131-FED9C9056FC8}" = Intel(R) Wireless Display "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{FE1D03A0-9687-449F-807E-FD7A3382FF0D}" = Śpiąca Królewna "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "BabylonToolbar" = Babylon toolbar on IE "DAEMON Tools Lite" = DAEMON Tools Lite "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "Diablo III" = Diablo III "Google Chrome" = Google Chrome "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "InstallShield_{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater "InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide "LiveVDO plugin" = LiveVDO plugin 1.3 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.61.0.1400 "Moja Lalka_is1" = Moja Lalka "OpenAL" = OpenAL "Origin" = Origin "Picasa 3" = Picasa 3 "PunkBusterSvc" = PunkBuster Services "SopCast" = SopCast 3.4.7 "Supermarket Mania 2 1.00" = Supermarket Mania 2 1.00 "uTorrent" = µTorrent "uTorrentControl2 Toolbar" = uTorrentControl2 Toolbar "VeriFace" = VeriFace "Wesołe_przedszkole_Reksia_Polish" = Wesołe przedszkole Reksia "WinLiveSuite" = Podstawowe programy Windows Live "WinRAR archiver" = WinRAR 4.11 (32-bitowy) [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{79A765E1-C399-405B-85AF-466F52E918B0}" = Sopcast Ask Toolbar Updater "TeamSpeak 3 Client" = TeamSpeak 3 Client [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-01 13:29:53 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = Error - 2012-07-01 15:50:39 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = Error - 2012-07-01 17:46:25 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = Error - 2012-07-02 01:00:30 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = Error - 2012-07-02 06:17:08 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = Error - 2012-07-02 22:36:02 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = Error - 2012-07-02 23:54:16 | Computer Name = Lenovek | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: BFP4f.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x4fedcb6d Nazwa modułu powodującego błąd: ntdll.dll, wersja: 6.1.7601.17725, sygnatura czasowa: 0x4ec49b8f Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00038dc9 Identyfikator procesu powodującego błąd: 0xc3c Godzina uruchomienia aplikacji powodującej błąd: 0x01cd58c6b28e25bc Ścieżka aplikacji powodującej błąd: C:\Program Files (x86)\EA Games\Battlefield Play4Free\BFP4f.exe Ścieżka modułu powodującego błąd: C:\windows\SysWOW64\ntdll.dll Identyfikator raportu: c242e2a1-c4c2-11e1-bf10-60d819e9f38d Error - 2012-07-03 08:35:13 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = Error - 2012-07-03 13:14:08 | Computer Name = Lenovek | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: nfsw.exe, wersja: 1.0.0.991, sygnatura czasowa: 0x4fea0bb4 Nazwa modułu powodującego błąd: nfsw.exe, wersja: 1.0.0.991, sygnatura czasowa: 0x4fea0bb4 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0024fcb0 Identyfikator procesu powodującego błąd: 0x291c Godzina uruchomienia aplikacji powodującej błąd: 0x01cd593f1045be64 Ścieżka aplikacji powodującej błąd: C:\ProgramData\Electronic Arts\Need For Speed World\Data\nfsw.exe Ścieżka modułu powodującego błąd: C:\ProgramData\Electronic Arts\Need For Speed World\Data\nfsw.exe Identyfikator raportu: 7f986cc8-c532-11e1-b9b3-60d819e9f38d Error - 2012-07-03 15:13:41 | Computer Name = Lenovek | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2012-07-07 22:37:37 | Computer Name = Lenovek | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Uruchomienie modułu rozszerzalności sieci WLAN nie powiodło się. Ścieżka modułu: C:\windows\System32\IWMSSvc.dll Kod błędu: 21 Error - 2012-07-07 22:37:40 | Computer Name = Lenovek | Source = DCOM | ID = 10005 Description = Error - 2012-07-07 22:37:40 | Computer Name = Lenovek | Source = DCOM | ID = 10005 Description = Error - 2012-07-08 06:29:59 | Computer Name = Lenovek | Source = sptd | ID = 262148 Description = Sterownik wykrył błąd wewnętrzny w swoich strukturach danych dla . Error - 2012-07-08 06:30:19 | Computer Name = Lenovek | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: BPntDrv discache GDMnIcpt gdwfpcd HookCentre spldr sptd Wanarpv6 Error - 2012-07-08 06:30:33 | Computer Name = Lenovek | Source = DCOM | ID = 10005 Description = Error - 2012-07-08 06:30:37 | Computer Name = Lenovek | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Uruchomienie modułu rozszerzalności sieci WLAN nie powiodło się. Ścieżka modułu: C:\windows\System32\IWMSSvc.dll Kod błędu: 21 Error - 2012-07-08 06:30:39 | Computer Name = Lenovek | Source = DCOM | ID = 10005 Description = Error - 2012-07-08 06:30:41 | Computer Name = Lenovek | Source = DCOM | ID = 10005 Description = Error - 2012-07-08 06:30:41 | Computer Name = Lenovek | Source = DCOM | ID = 10005 Description = < End of report >