OTL Extras logfile created on: 2012-12-21 12:02:57 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\user\Downloads Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,25 Gb Total Physical Memory | 1,86 Gb Available Physical Memory | 57,29% Memory free 6,49 Gb Paging File | 4,96 Gb Available in Paging File | 76,34% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 97,57 Gb Total Space | 53,08 Gb Free Space | 54,40% Space Free | Partition Type: NTFS Drive D: | 97,66 Gb Total Space | 66,06 Gb Free Space | 67,64% Space Free | Partition Type: NTFS Drive E: | 270,44 Gb Total Space | 62,47 Gb Free Space | 23,10% Space Free | Partition Type: NTFS Drive F: | 386,71 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: USER-KOMPUTER | User Name: user | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2871383845-20140808-1513811140-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- "%1" %* inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Livebox\Connectivity\ConnectivityManager.exe" = C:\Program Files\Livebox\Connectivity\ConnectivityManager.exe:*:enabled:CSS -- (France Telecom SA) [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1D2969E8-77C9-4756-AD0A-7247CEF61113}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{224AF6A5-C61E-452F-A837-7AD61BB1F4AF}" = lport=2869 | protocol=6 | dir=in | app=system | "{24557B88-FE7A-48D8-9120-F8EA3CB4D858}" = lport=139 | protocol=6 | dir=in | app=system | "{2B453CF8-D74C-4531-A03D-2FA0BBCD8723}" = lport=137 | protocol=17 | dir=in | app=system | "{2C735BDB-A621-40E4-B1BB-7EE39B594890}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2CF3AB9C-F144-409A-A41E-D33A3AC78277}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{313E4149-6014-4C3C-A7B2-476B4415323E}" = rport=445 | protocol=6 | dir=out | app=system | "{32134ECC-3ECF-48DD-A3C9-2B2AB186D5EA}" = lport=445 | protocol=6 | dir=in | app=system | "{424F1423-0BBF-41D0-BAA9-7BBF0075C8AA}" = rport=137 | protocol=17 | dir=out | app=system | "{44FCE0E5-15DE-4111-A463-F3E169DEAA26}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4615B45A-7898-45CD-A305-DA39CC72C595}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4866F45E-F54B-498C-B607-ABBDA8B482A0}" = rport=139 | protocol=6 | dir=out | app=system | "{4E0E09AF-B8F5-46CF-9970-99922E2131F8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5469DCC7-8486-4F18-ABD5-341706F43A0D}" = rport=10243 | protocol=6 | dir=out | app=system | "{58D854A4-0E78-4B70-B7B8-B6C5F0319D75}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5FA5F5BC-A458-49FB-9788-A3F58BA77AEE}" = rport=138 | protocol=17 | dir=out | app=system | "{6FC95518-59A7-45A9-8CB6-D00C9D42F554}" = lport=10243 | protocol=6 | dir=in | app=system | "{73071C6D-3C3C-43D8-9E55-2DCE427DCBD1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{83F4627E-62D7-4D71-B4B8-DD7A0188F141}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8B7D109D-AA08-463F-B614-5A46B9C5ECB7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{8C810BB5-2D63-4D4F-AC32-ABE6202E46F4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{8F3C7684-9516-4D0D-8003-2A487B73C34D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{98CBCFAE-4ACA-4D45-9075-5E15276344B6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{9E59C91E-8CF7-4EFE-9FD2-E64C4540DA5F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A2F0F7FE-A238-447B-BDC3-8ACC3A5BDB88}" = lport=138 | protocol=17 | dir=in | app=system | "{B60F976C-BD80-4204-883D-EA1DEE8A352D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{C167C0AD-508A-4803-AF75-11377B37DA63}" = rport=137 | protocol=17 | dir=out | app=system | "{C25D8D76-BA21-4983-AF4F-DB4D05392C07}" = lport=445 | protocol=6 | dir=in | app=system | "{C6CC9267-28F4-4B0A-99B5-7739B75E5FB7}" = rport=138 | protocol=17 | dir=out | app=system | "{CBAD735E-15BE-4F9C-AB3F-14DAF5EC02DF}" = rport=445 | protocol=6 | dir=out | app=system | "{DA787D15-9DAB-46C4-95FF-95AC64AD483E}" = rport=139 | protocol=6 | dir=out | app=system | "{DCF9EB1E-BCD0-4F1E-8773-1C03B1D8A166}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{DD925023-56F1-407E-BA8B-666461CAC97B}" = lport=139 | protocol=6 | dir=in | app=system | "{DE63D6A9-C1FC-420F-A29F-D9870449BF9A}" = lport=138 | protocol=17 | dir=in | app=system | "{F6A513F4-E0A4-4DFB-9C66-2217FDAB4317}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F6D98EC6-968A-467D-80FC-7255D87514CB}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{F7D4069A-217E-4F63-BFC0-7F10937067C3}" = lport=137 | protocol=17 | dir=in | app=system | "{F9FF7259-02B6-4CC9-BA40-B3E8A9216153}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{003F9932-46B9-4BBC-8714-D8DD531340BE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{0520FA8D-D474-46F2-8B4D-2335332FC68A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{05475750-9EC1-4BDE-94C1-445499F1CED4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe | "{12E7532D-E204-4388-972B-FAE9F6D5C1F7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{12EFE80C-53DB-4534-B81D-CBE797D9DD58}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe | "{1719EB12-989B-4C04-A178-ACA5A1DA8AB6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{19CEE510-4918-4C7A-A5AC-8905177D21B4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{22456BC2-263C-4B31-AA8B-B6E7C0408BBB}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe | "{2871ABFB-36CC-4947-8A5C-1E93D06CCB35}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{2B856E3C-A650-450A-8A8E-90E982ABF8F1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe | "{32939127-28EF-44D8-8DFA-76D5C925DF92}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{34EA10DB-F640-4288-8F2C-1219AFC2AD3F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | "{35C96163-B714-4A9C-83CB-0BAFEDD16C9B}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe | "{3A1DACE4-C5D5-4631-BA7A-B3DA86FE2C8D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3A4010FE-4B88-4E2F-BA77-8ABFFDF4A0E6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{41FFEC6C-C7B1-4648-AD8F-700AE32C14A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{43DE4927-F0AC-4F0E-89E3-E8705B0C4C27}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{475DFEF3-6A7E-4885-B375-F00575CE1F54}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{4A6A2E48-5BFE-4F49-B6F9-24CB3E008093}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{521D321F-F9BE-44AF-B5D6-2CEB71DCE328}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe | "{57AB30D3-478C-4DA6-A2C0-1098F056C5F5}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe | "{6005F977-9E48-470B-9A36-AA40B224D534}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe | "{6219C6AE-2510-4132-8098-D4A5354CA982}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{63C76534-C216-4510-B285-5036D85B8875}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{68438BCA-7D2E-4FF6-96DF-470214A76E05}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe | "{6AE1132F-F4E9-46C8-9FB3-BDEC13F0F8AB}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe | "{7CBFCE94-E0D1-4334-AA7C-52701633DFDC}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe | "{7E860B2B-61FF-456D-8AB4-7B82FF83073B}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe | "{83C70028-3510-4FFE-B1CA-E53B74EAD492}" = protocol=6 | dir=in | app=e:\gry\diablo iii\diablo iii.exe | "{87FA090A-7253-462D-9C38-3CBEE44AB1C8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{8A10990F-D689-43D7-8A25-AD0661B72B94}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe | "{8AA47E02-085A-44BC-B4BE-248B8F2B086A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe | "{8EC88A9C-36FE-470E-B2A7-E72023E152FB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9183AADD-4EB8-4238-86B7-2DB2B57E5D9A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe | "{98ACAAB5-6385-4899-996F-4EC65CB8AE0F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe | "{990950ED-0586-4A8F-8550-8850EBD75DF4}" = protocol=17 | dir=in | app=e:\gry\diablo iii\diablo iii.exe | "{A073FFB4-9D0E-4033-B24C-548E31E7786C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe | "{A702FC5B-B0B6-4D26-B262-2B91DF178D94}" = protocol=6 | dir=out | app=system | "{A81F0AB5-20E9-4893-9AD1-80364CA6D3E1}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe | "{A92164A8-EC32-4FD7-B6B9-64B65B475C2B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe | "{AC56B95F-A6ED-4231-9185-563E99935B76}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{AE87137A-7E2C-49F3-9A25-365558B52171}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{B221D949-9B63-465B-9162-CCEAD778CC89}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe | "{B60B7DE9-1365-4864-9975-CC6EACB95908}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\war in the north\witn.exe | "{BCDF4E41-CE2D-414C-9281-B04FC5CFBC54}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{BD0BB6C8-F556-49A7-9C08-B1BD22D2C5CE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C85C6210-3C55-460A-9EBD-682A77322AAE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{C950DCEB-8652-4B54-AE1D-B7CFDBC09DCA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{CA4D76EE-804E-458E-9A48-1B32B1C8BCE3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{D6515E0C-1E39-41AD-9518-1D71582BCFAB}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe | "{D7577D76-5F7B-4A93-9BA2-EB55319C0D99}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\war in the north\witn.exe | "{DA5E7247-9806-4177-816E-32FD38337FF9}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe | "{E497E6FE-5EB6-4D61-9D33-F06FBD8083C2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E7F65DC7-6E51-458E-A0AD-91EA607E64AD}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe | "{F08E5E33-0682-45C7-8F45-92FE00832489}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe | "{F61F6E5F-0337-428C-B6FE-FC85CB9E159B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqnrs08.exe | "{F622FFD9-73CC-42DF-828D-263F50BD4C1E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{FB743246-A3A1-4122-9D52-B04ECC569A7D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe | "{FC9CD618-BBBD-4F6F-BF25-B1AC52C5208E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe | "TCP Query User{1F4A86C1-0F07-4702-81A5-300A634F73DD}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{79290B53-4286-4113-955A-CE71C95A532E}E:\gry\wiedźmin 2\bin\witcher2.exe" = protocol=6 | dir=in | app=e:\gry\wiedźmin 2\bin\witcher2.exe | "TCP Query User{A34CB5C6-47D6-45E1-BD6F-952880E0D77A}E:\gry\electronic arts\shift 2 unleashed\shift2u.exe" = protocol=6 | dir=in | app=e:\gry\electronic arts\shift 2 unleashed\shift2u.exe | "TCP Query User{BE6AD00F-F570-4112-91B8-180693E710C2}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{E15E0C48-1E14-43C1-9208-F425D9176907}E:\gry\wiedźmin 2\bin\witcher2.exe" = protocol=6 | dir=in | app=e:\gry\wiedźmin 2\bin\witcher2.exe | "TCP Query User{F0EC4671-0F61-4BF6-8FD1-9BEF414826F3}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | "UDP Query User{0B8D4429-539A-407A-BC18-A004A9E89366}E:\gry\wiedźmin 2\bin\witcher2.exe" = protocol=17 | dir=in | app=e:\gry\wiedźmin 2\bin\witcher2.exe | "UDP Query User{16075527-5845-482E-A47B-DFF822B94EF2}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | "UDP Query User{256CD54C-BA2A-4473-B596-2833E179A69B}E:\gry\electronic arts\shift 2 unleashed\shift2u.exe" = protocol=17 | dir=in | app=e:\gry\electronic arts\shift 2 unleashed\shift2u.exe | "UDP Query User{5FF741E8-37F3-4922-BAAE-83F28DF99E51}E:\gry\wiedźmin 2\bin\witcher2.exe" = protocol=17 | dir=in | app=e:\gry\wiedźmin 2\bin\witcher2.exe | "UDP Query User{7804491F-A181-473A-AA37-10F9CAA19F26}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{AEBCBF12-C9B0-495B-8942-DEA90E7E2912}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan "{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{1A858611-0B61-11D6-AA2E-0008C760B784}" = Kubusiowe Przedszkole - Maluchy "{1AE3E621-E0C0-4aa1-B10B-B3E353A8D110}" = c3100_Help "{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp "{26A24AE4-039D-4CA4-87B4-2F83216037FF}" = Java(TM) 6 Update 37 "{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9 "{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2F173C40-563E-11D4-89C5-0010ADDAAC33}" = EA.com Matchup "{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX "{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{354038F6-0A35-4C55-A80B-F86C4C1A6D38}" = C3100 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport "{4F64A46D-67F7-4497-AEA2-313D4305A5F6}" = Torchlight "{5B6D2707-8C04-47B5-B8E6-8D170ED6F998}_is1" = 6klasa wersja 1.0 "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1 "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8FE4D086-63BD-44EB-882C-C7EA5A1EF016}" = Gamer HUD Lite "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer "{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1" = Panda Cloud Cleaner "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9AB97F52-512B-43EF-AAEC-4825C17B32ED}" = EA.com Update "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI - Polish "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Sterownik kontrolera 3D Vision 306.23 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.12.0604 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential "{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan "{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting "{E3D180D1-AA01-48CA-88A6-812DA5207C27}" = Świadectwa Optivum "{E8C37E27-5205-4C8A-BECB-B00533045AAE}" = SHIFT 2 UNLEASHED™ "{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}" = Wiedźmin 2 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Obsługa programów Apple "{F9000000-0001-0000-0000-074957833700}" = ABBYY FineReader 9.0 Professional Edition "{FDF3A1E0-186A-11D5-0089-C400C04FAE70}" = NHL 2002 "{ORAHSS}.UninstallSuite" = Livebox "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adibu - Odkrywam tajemnice przyrody_is1" = Adibu - Odkrywam tajemnice przyrody "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "Amiga SWOS_is1" = Amiga SWOS v1.02 "AQQ" = WapSter AQQ "ArduoPdfMerger_is1" = ArduoPdfMerger alpha "Barbie(TM) - Salon Piękności" = Barbie(TM) - Salon Piękności "CCleaner" = CCleaner "Championship Manager 01-02" = Championship Manager 01-02 "Diablo III" = Diablo III "ENTERPRISE" = Microsoft Office Enterprise 2007 "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Photosmart Essential" = HP Photosmart Essential 3.5 "HP Smart Web Printing" = HP Smart Web Printing 4.51 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "HPOCR" = OCR Software by I.R.I.S. 13.0 "IrfanView" = IrfanView (remove only) "KLiteCodecPack_is1" = K-Lite Codec Pack 7.1.0 (Full) "Mały Adibu - W fabryce cukierków_is1" = Mały Adibu - W fabryce cukierków "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Mozilla Firefox 17.0.1 (x86 pl)" = Mozilla Firefox 17.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NapiProjekt_is1" = NapiProjekt 1.0.6.9 "Nero8Lite_is1" = Nero 8 Lite 8.3.6.0 "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "RealAlt_is1" = Real Alternative 2.0.2 "Shop for HP Supplies" = Shop for HP Supplies "Steam App 32800" = The Lord of the Rings: War in the North "SWOS-Total Pack 1.10-pre4" = SWOS-Total Pack 1.10-pre4 "Totalcmd" = Total Commander (Remove or Repair) "Twoje Lekcje" = Twoje Lekcje "UEFA EURO 2012_is1" = UEFA EURO 2012 "Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions "WinRAR archiver" = Archiwizator WinRAR "ZMBV" = Zip Motion Block Video codec (Remove Only) [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2871383845-20140808-1513811140-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater "Mozilla Firefox 16.0.1 (x86 pl)" = Mozilla Firefox 16.0.1 (x86 pl) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = ESENT | ID = 455 Description = Windows (3316) Windows: Wystąpił błąd -1811 podczas otwierania pliku dziennika C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00020.log. Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 9000 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 7040 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 7042 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 9002 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 3029 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 3029 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 3028 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 3058 Description = Error - 2012-12-21 06:57:17 | Computer Name = user-Komputer | Source = Windows Search Service | ID = 7010 Description = [ OSession Events ] Error - 2011-06-10 14:41:38 | Computer Name = user-Komputer | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 44 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 2012-12-21 06:21:46 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą France Telecom Routing Table Service. Error - 2012-12-21 06:21:47 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: prodrv06 prohlp02 prosync1 sfhlp01 Error - 2012-12-21 06:56:29 | Computer Name = user-Komputer | Source = Application Popup | ID = 875 Description = Sterownik sfhlp01.sys został zablokowany dla ładowania. Error - 2012-12-21 06:56:29 | Computer Name = user-Komputer | Source = Application Popup | ID = 875 Description = Sterownik prosync1.sys został zablokowany dla ładowania. Error - 2012-12-21 06:56:29 | Computer Name = user-Komputer | Source = Application Popup | ID = 875 Description = Sterownik prohlp02.sys został zablokowany dla ładowania. Error - 2012-12-21 06:56:32 | Computer Name = user-Komputer | Source = Application Popup | ID = 875 Description = Sterownik prodrv06.sys został zablokowany dla ładowania. Error - 2012-12-21 06:57:15 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7009 Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą France Telecom Routing Table Service. Error - 2012-12-21 06:57:15 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: prodrv06 prohlp02 prosync1 sfhlp01 Error - 2012-12-21 06:57:18 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7024 Description = Usługa Windows Search zakończyła działanie; wystąpił specyficzny dla niej błąd %%-1073473535. Error - 2012-12-21 06:57:18 | Computer Name = user-Komputer | Source = Service Control Manager | ID = 7031 Description = Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. < End of report >