OTL Extras logfile created on: 2012-07-15 17:45:35 - Run 1 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Piotr\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19019) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,24 Gb Available Physical Memory | 62,16% Memory free 4,25 Gb Paging File | 3,57 Gb Available in Paging File | 84,13% Paging File free Paging file location(s): ?:\pagefile.sys %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 101,00 Gb Total Space | 29,93 Gb Free Space | 29,63% Space Free | Partition Type: NTFS Drive D: | 197,09 Gb Total Space | 112,93 Gb Free Space | 57,30% Space Free | Partition Type: NTFS Drive F: | 18,78 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: PIOTR-PC | User Name: Piotr | Logged in as Administrator. Cannot determine boot mode. | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Przeglądaj za pomocą programu h Corel PaintShop Photo Pro X3] -- "c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05275D86-2BFC-4D9A-A001-5A8AA02421C2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{33609D71-BED8-411C-8EA1-468D4E203459}" = lport=138 | protocol=17 | dir=in | app=system | "{369FDB46-B104-4F63-9867-57B2C481E4ED}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{4044DF46-2E8D-455C-BE4A-100498098139}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{47C8CD65-317A-4E69-9522-5E1209F528BA}" = lport=445 | protocol=6 | dir=in | app=system | "{4DBEC52A-0CD3-4F33-BFEA-1A2B703C4A3E}" = lport=139 | protocol=6 | dir=in | app=system | "{52F9E9A3-543F-48C9-92E9-D73DB1094DF4}" = lport=2869 | protocol=6 | dir=in | app=system | "{538FBF4C-B8CA-431E-8546-2210CB7055A3}" = lport=2869 | protocol=6 | dir=in | app=system | "{575E166C-AF35-4299-BDBC-CC2580DECC9B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{61194F77-CCD0-403E-BDB5-2E26F5D904E4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{7058545F-0DB7-4C0A-BB13-0184AE03CF15}" = rport=139 | protocol=6 | dir=out | app=system | "{7430CA23-906A-4453-AB99-E9A0F45DD9A1}" = rport=445 | protocol=6 | dir=out | app=system | "{856F38AD-054C-4B80-866D-ED54B9B860AC}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{85BD0B1C-77E9-44E4-BAA2-FC223EB0DB78}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{98A1AFA3-1A8D-4632-8461-961D376AF5E0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C06B446A-80CB-420F-B7A4-F9D9F8F447A5}" = rport=137 | protocol=17 | dir=out | app=system | "{C8C4F20D-7829-47A6-A4BA-8CAAA57F8D05}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{D9660003-F69C-441D-B831-B17946A04F19}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{DA80FB51-51E2-4E7B-9222-860B6EBCE500}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E4D184B8-564F-42F3-8B85-B7961F499059}" = lport=137 | protocol=17 | dir=in | app=system | "{EC7AA6BA-C679-4796-8AE8-BFF988AC8B28}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{F35A16FE-5EF3-418D-A6E2-5DFECFC9E560}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F9BC8852-EC0B-471C-B0C7-0E012519DAE0}" = rport=138 | protocol=17 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{08784C33-1EB8-4E70-94D2-A63029B88785}" = protocol=6 | dir=in | app=c:\program files\electronic arts\król nazguli\game.dat | "{0974A772-B777-4FA5-844F-9724DC3E2C00}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{11EC448B-4BDA-4EA6-A904-B7A416125290}" = protocol=6 | dir=in | app=c:\program files\reality pump\two worlds ii\twoworlds2.exe | "{1C2ADA0B-F07C-4A83-A4B4-834F3A2DE011}" = protocol=6 | dir=in | app=c:\program files\electronic arts\bitwa o śródziemie ii\game.dat | "{22E9A16D-09D8-41CA-BA18-FD728A53E0FC}" = protocol=6 | dir=in | app=d:\program files\mass effect 2\masseffect2launcher.exe | "{2CD87EEC-3933-4CD4-B285-00C45AFF8679}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{3162ED69-5DD6-4CAA-BE1D-762DC8D05E8E}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{317592FE-7489-44B6-89ED-039641BB3125}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\skyrim\skyrimlauncher.exe | "{332E7B67-4ADD-42B1-AB28-ECA8D20DFB5B}" = protocol=6 | dir=in | app=d:\program files\reality pump\two worlds\twoworlds.exe | "{36CEE675-A4E4-4F69-8FB7-B0B6A5E0A7F5}" = protocol=6 | dir=in | app=c:\program files\reality pump\two worlds ii\twoworlds2.exe | "{3A981548-1A68-4763-B58B-408B72DA1B67}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{3ABF1F77-8CD0-48AA-B718-003ADEF625C0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mountblade warband\mb_warband.exe | "{42ACD8E9-4203-4970-A46C-FA7C702A9F78}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe | "{45894772-7473-45A0-9DAF-E30F591D35FF}" = protocol=17 | dir=in | app=d:\program files\reality pump\two worlds\twoworlds_radeon.exe | "{4822C32A-FA20-4710-AA94-B6DEE5D7A307}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{49DF1BF8-55B3-4F92-896F-6A937463F9E7}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{5DC26CEE-5C38-41D4-B631-6DF8277F36FD}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe | "{5F5B18D8-B464-4503-B5C7-CE2692A7F358}" = protocol=17 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe | "{677DD9DE-42A2-4863-A9F0-3E40240D014E}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{6C575759-A444-4E3A-845F-C1B30135FB6D}" = protocol=6 | dir=in | app=d:\program files\mass effect 2\binaries\masseffect2.exe | "{6DCF7ACA-BFD1-4270-BFC8-6915968189FB}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe | "{7024F779-56E7-4B7C-94D5-2CC42537B5E1}" = protocol=17 | dir=in | app=c:\program files\electronic arts\król nazguli\game.dat | "{7171D2DF-FB04-450B-B449-A57284E22D7E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\skyrim\skyrimlauncher.exe | "{79C406B9-ADCB-48FC-BB1D-F2D0D6CE8BCE}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{7A1A1CA6-39E6-42A8-A773-4E414A7C5731}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed brotherhood\acbmp.exe | "{7CC0D8FC-142E-444A-A456-B42645A2FAB5}" = protocol=17 | dir=in | app=d:\program files\mass effect 2\masseffect2launcher.exe | "{8CDF3ED8-A8F4-439D-A01B-6A856762663E}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{8F52E9C9-2F6A-4222-BCBF-D140160210F5}" = protocol=17 | dir=in | app=c:\program files\reality pump\two worlds ii\twoworlds2.exe | "{917027A4-E8A3-464A-B337-2803FB600C01}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{9867D2BF-6D6C-4C24-A345-0C6B54714162}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{99F0A91E-2546-475D-BC1A-A6FE3680DB0C}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{9B09F8E2-25AB-4DD6-BD72-855B0C5FAA84}" = protocol=6 | dir=in | app=c:\program files\cyanide\gamecenter\gamecenter.exe | "{9D3BA1FD-245D-426D-9342-9C9031488210}" = protocol=17 | dir=in | app=c:\program files\cyanide\gamecenter\gamecenter.exe | "{9E2178D3-3E09-48AB-9DFC-D041A3220B8D}" = protocol=17 | dir=in | app=c:\program files\reality pump\two worlds ii\twoworlds2.exe | "{A2D51BF6-48FF-488F-B27E-3063BB17FBA5}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{A3714218-FE0B-4A12-A6E2-FA28725595D3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{AA70660A-7254-42C7-81D0-196E1CE2F1D9}" = protocol=6 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe | "{B0E6A1A8-33F3-409B-B866-5665F25E3C8A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{C1E5C521-4849-4151-9268-22D2D28764E4}" = protocol=17 | dir=in | app=c:\users\piotr\desktop\sweetimsetup.exe | "{CF4A7BBF-5A31-4A40-B9A3-50B3317BB0CF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mountblade warband\mb_warband.exe | "{D5332FC9-2EC8-4E1A-8B1F-F06BDC9652CC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{DA7574A8-4BDD-461E-8BE0-AD8ABC28B212}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe | "{DF7A59E8-B975-42DC-A2E1-DB0A16683A31}" = protocol=6 | dir=in | app=d:\program files\reality pump\two worlds\twoworlds_radeon.exe | "{E10F5298-A08C-4943-83A4-E6B7DC6000FE}" = protocol=6 | dir=in | app=c:\users\piotr\desktop\sweetimsetup.exe | "{E3910709-14F7-46A4-B9B7-06B23314340D}" = protocol=17 | dir=in | app=d:\program files\mass effect 2\binaries\masseffect2.exe | "{E67C2E86-E334-414C-8686-60C625D574CF}" = protocol=17 | dir=in | app=c:\program files\ea games\bitwa o śródziemie\game.dat | "{E8CCF83A-E7D2-410B-8F50-FD9D98194863}" = protocol=6 | dir=in | app=c:\program files\ea games\bitwa o śródziemie\game.dat | "{EACF40EE-BBBE-491F-99C1-619DF6BFB13C}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed brotherhood\acbmp.exe | "{F24E49B1-5F53-489D-B564-903A60B74327}" = protocol=17 | dir=in | app=c:\program files\electronic arts\bitwa o śródziemie ii\game.dat | "{F6D14F1B-4934-43DD-83A7-18C3E30E4CD6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{FC10AAB2-ECD6-48F5-939C-ED5644C32AED}" = protocol=17 | dir=in | app=d:\program files\reality pump\two worlds\twoworlds.exe | "{FC27C8FB-CBD5-442A-94D8-740D31563072}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "TCP Query User{14E40484-8925-4BE4-AB3F-35D9417B1B6E}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "TCP Query User{199793D1-05CF-4234-AF4F-A5FA6C32D712}D:\program files\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe" = protocol=6 | dir=in | app=d:\program files\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe | "TCP Query User{309AB4CD-68CB-4555-9340-63FAB0F7DE13}C:\users\piotr\desktop\yuleech-runes_of_magic_3_0_8_2349_slim_eu.exe" = protocol=6 | dir=in | app=c:\users\piotr\desktop\yuleech-runes_of_magic_3_0_8_2349_slim_eu.exe | "TCP Query User{312BB5AC-CBBF-4893-9B55-4256FE6AD985}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "TCP Query User{5052FE1F-797A-4F33-96AF-01E7579B12B6}E:\rom\yuleech-runes_of_magic_3_0_0_2130.exe" = protocol=6 | dir=in | app=e:\rom\yuleech-runes_of_magic_3_0_0_2130.exe | "TCP Query User{51955B18-2C20-45A3-AB27-C0552E82EC0E}D:\program files\wiedźmin 2\bin\witcher2.exe" = protocol=6 | dir=in | app=d:\program files\wiedźmin 2\bin\witcher2.exe | "TCP Query User{57913FB6-F75F-43F6-8824-61E68BA5FB8E}D:\program files\funcom\age of conan\conanpatcher.exe" = protocol=6 | dir=in | app=d:\program files\funcom\age of conan\conanpatcher.exe | "TCP Query User{61F54644-F384-487F-9659-B0BA93089354}C:\program files\blacksite area 51\binaries\blacksite.exe" = protocol=6 | dir=in | app=c:\program files\blacksite area 51\binaries\blacksite.exe | "TCP Query User{6882130A-058D-4F59-8162-9436326BBFEF}D:\program files\funcom2\age of conan\conanpatcher.exe" = protocol=6 | dir=in | app=d:\program files\funcom2\age of conan\conanpatcher.exe | "TCP Query User{699B4901-2E6E-4427-9009-1AED5F667830}C:\program files\kohan ii kings of war\k2.exe" = protocol=6 | dir=in | app=c:\program files\kohan ii kings of war\k2.exe | "TCP Query User{76013756-A324-4A4C-B6FD-A0F69AC34773}E:\rom\yuleech-runes_of_magic_3_0_0_2130_playpl.exe" = protocol=6 | dir=in | app=e:\rom\yuleech-runes_of_magic_3_0_0_2130_playpl.exe | "TCP Query User{76D92D60-ED06-41F8-A9FF-B7549EC0CF04}C:\program files\jowood\gothic ii\system\gothic.exe" = protocol=6 | dir=in | app=c:\program files\jowood\gothic ii\system\gothic.exe | "TCP Query User{9E2EEC29-3DFB-4B55-89A6-4DA8D8B3C9F1}C:\program files\haemimont games\rising kingdoms\rk.exe" = protocol=6 | dir=in | app=c:\program files\haemimont games\rising kingdoms\rk.exe | "TCP Query User{A9A7C4FE-3A9E-4FEB-AACD-C66ACD9EBAD1}C:\users\piotr\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\piotr\appdata\local\akamai\netsession_win.exe | "TCP Query User{B6E792F6-A1F8-4C46-AC20-73853249A954}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{BC897931-23D7-40C8-8D05-D39C0D482EAD}C:\program files\lucasarts\star wars jedi knight jedi academy\gamedata\jamp.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars jedi knight jedi academy\gamedata\jamp.exe | "TCP Query User{C0089540-2481-474C-BD83-61420B10567D}C:\users\piotr\appdata\local\temp\rar$ex32.130\assassin's creed ii - crack\5. server.exe\server.exe" = protocol=6 | dir=in | app=c:\users\piotr\appdata\local\temp\rar$ex32.130\assassin's creed ii - crack\5. server.exe\server.exe | "TCP Query User{C0B1D905-FA97-4B86-8CC6-0BDAAB8E311B}C:\program files\ares\ares.exe" = protocol=6 | dir=in | app=c:\program files\ares\ares.exe | "TCP Query User{F02BC749-AAEC-4100-80E7-F26E2F149AFC}C:\users\piotr\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\piotr\appdata\local\akamai\netsession_win.exe | "TCP Query User{F0946DD8-CACE-405A-B721-60CB260A343F}C:\program files\city interactive\dark sector\ds.exe" = protocol=6 | dir=in | app=c:\program files\city interactive\dark sector\ds.exe | "TCP Query User{F6643E60-322E-4FF5-B35A-B94C5E83F8C7}C:\users\piotr\appdata\local\temp\rar$ex28.572\assassin's creed ii - crack\5. server.exe\server.exe" = protocol=6 | dir=in | app=c:\users\piotr\appdata\local\temp\rar$ex28.572\assassin's creed ii - crack\5. server.exe\server.exe | "TCP Query User{FF8C4500-2780-4024-89F0-362BF10B8DD9}C:\program files\blackstar interactive\oil tycoon\ot.exe" = protocol=6 | dir=in | app=c:\program files\blackstar interactive\oil tycoon\ot.exe | "UDP Query User{16ABFF02-A084-4995-A361-0AB9EC2ACFFD}D:\program files\wiedźmin 2\bin\witcher2.exe" = protocol=17 | dir=in | app=d:\program files\wiedźmin 2\bin\witcher2.exe | "UDP Query User{228AA37C-A011-4CEA-8328-E8A06429AAD7}C:\program files\kohan ii kings of war\k2.exe" = protocol=17 | dir=in | app=c:\program files\kohan ii kings of war\k2.exe | "UDP Query User{268F21ED-F34C-4699-9567-9E051EC01B1F}C:\users\piotr\desktop\yuleech-runes_of_magic_3_0_8_2349_slim_eu.exe" = protocol=17 | dir=in | app=c:\users\piotr\desktop\yuleech-runes_of_magic_3_0_8_2349_slim_eu.exe | "UDP Query User{2CC5DD26-1874-49D3-BEE5-0580577AC3A1}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "UDP Query User{3C9B0571-CF81-4EA5-BEF1-B9C70348FBF8}C:\program files\jowood\gothic ii\system\gothic.exe" = protocol=17 | dir=in | app=c:\program files\jowood\gothic ii\system\gothic.exe | "UDP Query User{3D904880-0538-4E93-8B02-E346BF17A709}C:\program files\haemimont games\rising kingdoms\rk.exe" = protocol=17 | dir=in | app=c:\program files\haemimont games\rising kingdoms\rk.exe | "UDP Query User{54C8570B-EC72-4EAB-827E-FB200C008D8C}D:\program files\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe" = protocol=17 | dir=in | app=d:\program files\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe | "UDP Query User{6F6EDE52-0AEB-4DCA-ACB6-3F699BF39207}C:\users\piotr\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\piotr\appdata\local\akamai\netsession_win.exe | "UDP Query User{74CF2F46-0123-4BE8-AE15-41798C75CE1F}C:\program files\ares\ares.exe" = protocol=17 | dir=in | app=c:\program files\ares\ares.exe | "UDP Query User{7E3007E3-A219-4296-B62A-C99A18FA2EF1}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "UDP Query User{947C99E0-7580-4302-A851-E8D1B2FACF28}C:\program files\blackstar interactive\oil tycoon\ot.exe" = protocol=17 | dir=in | app=c:\program files\blackstar interactive\oil tycoon\ot.exe | "UDP Query User{9ECD15B7-743D-4733-B2F6-66129E6272EE}C:\program files\lucasarts\star wars jedi knight jedi academy\gamedata\jamp.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars jedi knight jedi academy\gamedata\jamp.exe | "UDP Query User{A7BFFEAE-A944-478E-9C67-AD23FE28C5F8}C:\users\piotr\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\piotr\appdata\local\akamai\netsession_win.exe | "UDP Query User{A998236D-5D5C-436A-B656-802C555BB352}C:\program files\city interactive\dark sector\ds.exe" = protocol=17 | dir=in | app=c:\program files\city interactive\dark sector\ds.exe | "UDP Query User{BC897E02-0498-457E-8D05-A63EB8EFF69A}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{BE22E924-DE7F-4220-A567-61C1E603BDAB}E:\rom\yuleech-runes_of_magic_3_0_0_2130.exe" = protocol=17 | dir=in | app=e:\rom\yuleech-runes_of_magic_3_0_0_2130.exe | "UDP Query User{C3E25417-B632-4A17-A490-F1F1347326DC}E:\rom\yuleech-runes_of_magic_3_0_0_2130_playpl.exe" = protocol=17 | dir=in | app=e:\rom\yuleech-runes_of_magic_3_0_0_2130_playpl.exe | "UDP Query User{C654DBA3-E0DD-4F38-A4D5-98FBD1AB7AAB}D:\program files\funcom\age of conan\conanpatcher.exe" = protocol=17 | dir=in | app=d:\program files\funcom\age of conan\conanpatcher.exe | "UDP Query User{C6717354-228E-481C-9D2F-D57D3FA99D0A}D:\program files\funcom2\age of conan\conanpatcher.exe" = protocol=17 | dir=in | app=d:\program files\funcom2\age of conan\conanpatcher.exe | "UDP Query User{E4518EE7-CCB3-46C6-AE3C-04054E4A9249}C:\program files\blacksite area 51\binaries\blacksite.exe" = protocol=17 | dir=in | app=c:\program files\blacksite area 51\binaries\blacksite.exe | "UDP Query User{E56A8B72-EA62-459A-BD92-DEE52E2EE1FB}C:\users\piotr\appdata\local\temp\rar$ex32.130\assassin's creed ii - crack\5. server.exe\server.exe" = protocol=17 | dir=in | app=c:\users\piotr\appdata\local\temp\rar$ex32.130\assassin's creed ii - crack\5. server.exe\server.exe | "UDP Query User{FC40247B-EF59-438D-94C7-E9C5302EBA3F}C:\users\piotr\appdata\local\temp\rar$ex28.572\assassin's creed ii - crack\5. server.exe\server.exe" = protocol=17 | dir=in | app=c:\users\piotr\appdata\local\temp\rar$ex28.572\assassin's creed ii - crack\5. server.exe\server.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00000415-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium "{040FF9BD-17BE-427B-85DD-67694FB8F786}" = Badoo Desktop "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{10685EE0-47B0-11D6-851F-00C0CA129740}" = Panzer Elite "{173D51C6-869C-4C67-8694-11912F044570}" = Windows Live Writer "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1B79A292-DDF2-4AE8-BD77-6547F68F6888}" = Gothic Multiplayer "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2158685C-E2B3-4026-B0A1-0FFE31837AFD}" = PlayLinc "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{259A8A5E-2886-4BED-9EF1-D5485282CCC3}" = Overlord "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26 "{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable "{311F799A-FCE9-4D9E-B5D2-CBB8859B40BB}" = Microsoft XNA Framework Redistributable 1.0 Refresh "{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX "{3CE06D54-72B1-44B2-AB60-E4277EC80EF4}" = Microsoft XML Parser "{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{51834149-2F93-4EC7-AA13-46FC93CD028C}" = Panda Antivirus Pro 2009 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{6039C740-40B3-456C-8DDC-D63D29F634C8}" = Poczta systemu Windows Live "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2 "{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007 "{9192066C-2E36-4A94-ABF3-463314819323}" = Windows Live Messenger "{929C29A0-E9C3-11D5-BA55-00C0CA129740}" = Europa Universalis 2 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A05BE20E-6510-44BC-95ED-6E6D730407D3}" = Vplayer "{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-A70500000002}" = Adobe Reader 7.0.5 - Polish "{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Asystent rejestracji usługi Windows Live "{B0BC0B99-C81A-4AAD-9713-14A82011364C}" = Windows Live Toolbar "{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War "{C3CF41F1-0373-4DD7-BE99-F33B00E51045}" = Nero 7 Essentials "{CD0159C9-17FB-11D6-A76A-00B0D079AF64}" = Java 2 Runtime Environment, SE v1.4.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D659C084-24CE-477A-BC76-6BE150355C26}" = Windows Live installer "{DE4BF4BE-3CDC-43B5-BBDA-DDDA73103111}" = Corel PaintShop Photo Pro X3 "{DE8B9311-ADE7-4EDE-B121-326CAA3D225D}" = PSPPContent "{DE99075E-7D25-4B96-B32E-BFE6FBFAA644}" = IPM_PSP_CL "{DEAEB5DB-04FA-489D-94EF-8600898B93EE}" = ICA "{DEDE6612-0CC9-408C-8C9A-15C5527B4934}" = Rise of the Argonauts "{DEF1928A-FC01-48E7-A7E6-4651D42EF6A1}" = PSPPRO_DCRAW "{DEF8C145-CC4F-4DAA-AD5C-E707C07AEE50}" = IPM_PSP_COM "{E01662A1-BF0F-4DA8-A2FC-4E7F685884B8}" = Rome - Total War "{E32CD782-32A6-4E72-96F3-9911CE93FA6B}" = Galeria fotografii usługi Windows Live "{E52D32D7-0005-11D7-928D-000ACD006A23}" = TES Construction Set "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager "{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}" = Wiedźmin 2 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F112F66E-25CA-42DD-983C-6118EB38F606}" = Microsoft Games for Windows - LIVE "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Age of Conan_is1" = Age of Conan - Hyborian Adventures "Akamai" = Akamai NetSession Interface Service "ALLPlayer V1.X" = ALLPlayer V1.X "AP Tuner 3.06" = AP Tuner 3.06 "AP Tuner 3.08" = AP Tuner 3.08 "Applian FLV Player2.0.24" = Applian FLV Player "Chromatia Tuner_is1" = Chromatia Tuner v3.0 "Gothic Multiplayer" = Gothic Multiplayer "InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune "InstallShield_{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla "InstallShield_{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager "Java Web Start" = Java Web Start "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox 7.0.1 (x86 pl)" = Mozilla Firefox 7.0.1 (x86 pl) "NVIDIA Drivers" = NVIDIA Drivers "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "OpenAL" = OpenAL "PIT 2009 z Gazetą Wyborczą_is1" = PIT 2009 z Gazetą Wyborczą ver. 6.0.1.0 "PLAY ONLINE" = PLAY ONLINE "PROHYBRIDR" = 2007 Microsoft Office system "PunkBusterSvc" = PunkBuster Services "Steam App 48700" = Mount & Blade: Warband "Steam App 72850" = The Elder Scrolls V: Skyrim "Two Worlds" = Two Worlds "Two Worlds II" = Two Worlds II "Windows Live Toolbar" = Windows Live Toolbar "WinRAR archiver" = Archiwizator WinRAR "WMV9_VCM" = Microsoft Windows Media Video 9 VCM "Xfire" = Xfire (remove only) "XviD_is1" = XviD MPEG-4 Video Codec [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-08 03:00:18 | Computer Name = Piotr-PC | Source = EventSystem | ID = 4609 Description = Error - 2012-07-08 03:03:47 | Computer Name = Piotr-PC | Source = Software Licensing Service | ID = 1001 Description = Uruchomienie usługi licencjonowania oprogramowania nie powiodło się. hr=0x80070002, [2, 4] Error - 2012-07-08 03:12:14 | Computer Name = Piotr-PC | Source = Software Licensing Service | ID = 1001 Description = Uruchomienie usługi licencjonowania oprogramowania nie powiodło się. hr=0x80070002, [2, 4] Error - 2012-07-08 03:21:18 | Computer Name = Piotr-PC | Source = EventSystem | ID = 4609 Description = Error - 2012-07-08 03:24:21 | Computer Name = Piotr-PC | Source = Software Licensing Service | ID = 1001 Description = Uruchomienie usługi licencjonowania oprogramowania nie powiodło się. hr=0x80070002, [2, 4] Error - 2012-07-08 03:25:04 | Computer Name = Piotr-PC | Source = RasClient | ID = 20227 Description = Error - 2012-07-08 03:37:26 | Computer Name = Piotr-PC | Source = EventSystem | ID = 4609 Description = Error - 2012-07-08 03:42:56 | Computer Name = Piotr-PC | Source = Software Licensing Service | ID = 1001 Description = Uruchomienie usługi licencjonowania oprogramowania nie powiodło się. hr=0x80070002, [2, 4] Error - 2012-07-15 11:15:51 | Computer Name = Piotr-PC | Source = Software Licensing Service | ID = 1001 Description = Uruchomienie usługi licencjonowania oprogramowania nie powiodło się. hr=0x80070002, [2, 4] Error - 2012-07-15 11:32:42 | Computer Name = Piotr-PC | Source = Software Licensing Service | ID = 1001 Description = Uruchomienie usługi licencjonowania oprogramowania nie powiodło się. hr=0x80070002, [2, 4] [ Media Center Events ] Error - 2010-03-19 02:53:50 | Computer Name = Piotr-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide Error - 2010-11-06 05:49:38 | Computer Name = Piotr-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide Error - 2010-11-06 05:49:57 | Computer Name = Piotr-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide Error - 2010-11-06 05:50:09 | Computer Name = Piotr-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide Error - 2012-05-30 05:07:10 | Computer Name = Piotr-PC | Source = Media Center Guide | ID = 0 Description = Informacje o zdarzeniu: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Proces: DefaultDomain Nazwa obiektu: Media Center Guide [ System Events ] Error - 2010-09-08 14:53:10 | Computer Name = Piotr-PC | Source = HTTP | ID = 15016 Description = Error - 2010-09-08 15:49:20 | Computer Name = Piotr-PC | Source = Service Control Manager | ID = 7016 Description = Error - 2010-09-09 12:01:51 | Computer Name = Piotr-PC | Source = HTTP | ID = 15016 Description = Error - 2010-09-09 13:46:17 | Computer Name = Piotr-PC | Source = Service Control Manager | ID = 7016 Description = Error - 2010-09-10 02:22:59 | Computer Name = Piotr-PC | Source = HTTP | ID = 15016 Description = Error - 2010-09-10 02:57:28 | Computer Name = Piotr-PC | Source = Service Control Manager | ID = 7016 Description = Error - 2010-09-10 02:58:41 | Computer Name = Piotr-PC | Source = HTTP | ID = 15016 Description = Error - 2010-09-10 04:19:30 | Computer Name = Piotr-PC | Source = Service Control Manager | ID = 7016 Description = Error - 2010-09-10 14:04:07 | Computer Name = Piotr-PC | Source = HTTP | ID = 15016 Description = Error - 2010-09-11 09:37:24 | Computer Name = Piotr-PC | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 21:51:02 na 2010-09-10 było nieoczekiwane. < End of report >