OTL Extras logfile created on: 2014-01-12 13:47:37 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = E:\Pobrane 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16428) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,96 Gb Total Physical Memory | 6,24 Gb Available Physical Memory | 78,30% Memory free 15,93 Gb Paging File | 14,00 Gb Available in Paging File | 87,87% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 50,00 Gb Total Space | 10,64 Gb Free Space | 21,29% Space Free | Partition Type: NTFS Drive D: | 250,00 Gb Total Space | 162,49 Gb Free Space | 64,99% Space Free | Partition Type: NTFS Drive E: | 165,66 Gb Total Space | 96,16 Gb Free Space | 58,04% Space Free | Partition Type: NTFS Computer Name: BARTEK-PC | User Name: Bartek | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-963270176-3171651887-357313542-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- D:\Programy\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "D:\Programy\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "D:\Programy\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "D:\Programy\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [Bridge] -- D:\Programy\Adobe Photoshop\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "D:\Programy\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Winamp.Bookmark] -- "D:\Programy\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "D:\Programy\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "D:\Programy\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "D:\Programy\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "D:\Programy\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "D:\Programy\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [Bridge] -- D:\Programy\Adobe Photoshop\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "D:\Programy\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Winamp.Bookmark] -- "D:\Programy\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "D:\Programy\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "D:\Programy\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0819AE0E-D689-49E2-A185-2056D17AB57B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{08218948-2578-442A-B97A-A883895674D8}" = lport=139 | protocol=6 | dir=in | app=system | "{222327C2-4988-49BC-BD60-587327F3C042}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{24189152-8E06-4B8B-B08A-5210067D68E4}" = lport=10243 | protocol=6 | dir=in | app=system | "{31E948AF-14F2-418F-ACE7-E7AB8E16BC57}" = lport=56937 | protocol=6 | dir=in | name=pando media booster | "{37AC58C4-B962-43F0-BD11-D78A26F2EEC8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{3FD99A20-CE03-4EC9-9BAB-8BEA8631ADD2}" = rport=139 | protocol=6 | dir=out | app=system | "{429B52DD-11CA-4CCE-98F0-0B35A85E36F5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{4A6E8E2C-698C-4805-BCF4-5ABB5C577CCA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4F1F99E0-D91F-4265-AD91-1F15EE2232C4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{54C40DDB-CC19-4274-AF9A-546B59A7B910}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{64AA5D34-DC5D-47F1-B5FA-9F2C3A6212E4}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{683DE88A-BF9C-4CAA-BB5A-960FBA49D53F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{769B5443-8959-4AE9-8889-1F05C3C77D7A}" = rport=137 | protocol=17 | dir=out | app=system | "{7BD198C6-F36C-4FBF-877E-53B7C85273A1}" = rport=138 | protocol=17 | dir=out | app=system | "{8D2CFFBF-65D3-4081-AA44-5B7E4CC82951}" = lport=56937 | protocol=6 | dir=in | name=pando media booster | "{AA9EE9FF-0C64-431F-9A26-81B896CCA80E}" = lport=445 | protocol=6 | dir=in | app=system | "{BCC88261-F8CD-42CA-ACEA-C8CA08021C32}" = lport=137 | protocol=17 | dir=in | app=system | "{C7680302-430C-4ABE-BE90-CD815C8B52D5}" = lport=138 | protocol=17 | dir=in | app=system | "{E2BE2F12-8305-4A31-BB82-EE7B419EE37F}" = lport=2869 | protocol=6 | dir=in | app=system | "{E6006973-A05C-48C2-9AA7-F350DCCC0A91}" = rport=10243 | protocol=6 | dir=out | app=system | "{EBE1D6DF-9B40-4FD1-9BEC-1A7D11FA5400}" = lport=56937 | protocol=17 | dir=in | name=pando media booster | "{F1CA60E7-2569-4E2D-9605-D875799A92AC}" = lport=56937 | protocol=17 | dir=in | name=pando media booster | "{FD9D6D0B-4FE2-4D30-BA2C-CAF8164B11A0}" = rport=445 | protocol=6 | dir=out | app=system | "{FED38827-AC15-4109-91EE-68D6B3C400B2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02F8D2B3-BCD4-4FB9-8479-F13A38AD79F0}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{0C8708C7-E11E-410B-99C4-1C5AC99588A9}" = protocol=17 | dir=in | app=d:\programy\napiprojekt\napisy.exe | "{0F712E89-DF01-404D-9A03-90BBDB12C06A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{11B32889-F97C-485B-9E35-CD5DB6ADC104}" = protocol=17 | dir=in | app=d:\gry\origin\games\fifa 14\game\fifa14.exe | "{14A08E50-4FA0-49A1-B100-2BD07CCF0894}" = protocol=6 | dir=in | app=d:\gry\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{17F9DBC6-B265-4D77-8B89-725DD71103BB}" = protocol=6 | dir=in | app=d:\gry\steam\steamapps\common\sid meier's civilization v\launcher.exe | "{1DBD2A58-8C7C-4C99-ADE6-B95BF83ABFF0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{1F679217-2FE5-4F28-930D-DB1B41CB5A02}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{1F8EC21F-7B82-4488-80DF-696DE188B5E7}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{200A4F69-EFEB-490F-8C18-972C3BBF23DB}" = protocol=17 | dir=in | app=d:\programy\microsoft office\office14\groove.exe | "{2077C259-5999-4E74-875F-FEE1A0E9293E}" = protocol=6 | dir=in | app=d:\programy\napiprojekt\napisy.exe | "{22817997-70A3-4F1F-AAA5-02AF4CDBA5E5}" = protocol=6 | dir=in | app=d:\gry\steam\steam.exe | "{2862E822-F8A1-4288-B7BC-749CDADA45F5}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{313C5221-F7D4-49E6-B7A0-0BDA75B116EE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{39472229-A9E4-40C2-9CDE-CFB18110BECB}" = protocol=17 | dir=in | app=d:\programy\winamp\winamp.exe | "{3B6780DF-CF91-446E-86C5-03B4235777D2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{5111D6B2-CBBD-4F0D-8BF5-D0D4615D1AAB}" = protocol=6 | dir=in | app=d:\gry\steam\steamapps\common\portal 2\portal2.exe | "{57E1669A-3CA4-46BA-AE5B-C9553DEB960B}" = protocol=6 | dir=in | app=d:\gry\steam\steamapps\common\counter-strike global offensive\csgo.exe | "{57E3BA19-481C-4C3E-8DC5-4FD9628A1309}" = protocol=17 | dir=in | app=d:\programy\nero\nero blu-ray player\blu-rayplayer.exe | "{58F82382-8766-49FB-A8B0-7630E08AD4F4}" = protocol=6 | dir=in | app=d:\gry\origin\games\fifa 14\game\fifa14.exe | "{59AE6385-F3B6-40AF-B179-1F5853AFB482}" = protocol=17 | dir=in | app=d:\gry\steam\steam.exe | "{5EFBD948-46AD-4A6C-A82C-C53818F9BF1B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{65EC4F61-81BD-4CDB-AABD-73B19CFF2631}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{70AF2E41-A5D6-4E05-9A00-11216A07BE44}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{776E9FF5-9A7E-454E-9225-F4CD19A66F69}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{7911AB22-5B0A-4181-808D-E6FC754822EC}" = protocol=17 | dir=in | app=d:\gry\steam\steamapps\common\sid meier's civilization v\launcher.exe | "{7C64386E-B444-47F9-BDD8-AE74CEF75FC0}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{805EB75D-7DF8-4C7A-A0E4-23EC236B0182}" = protocol=17 | dir=in | app=d:\gry\steam\steamapps\common\portal 2\portal2.exe | "{810D5B3A-ED03-48C6-B59E-DD46F5E04DFB}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{861200F9-5B73-4087-A016-23C5B2590542}" = protocol=6 | dir=in | app=d:\programy\nero\nero blu-ray player\blu-rayplayer.exe | "{8770F6A5-ED78-44A3-9957-CC74F14B89BB}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{8888966F-47C6-4C71-B959-5ED0C0E53E39}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{92F55E40-49A6-433B-8020-FB70C8E8BBF1}" = protocol=17 | dir=in | app=d:\gry\origin\games\battlefield 4\bf4_x86.exe | "{9B4895ED-A7C1-4C52-B69A-ADB0775E315D}" = protocol=17 | dir=in | app=d:\gry\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{A76D19A4-C0D7-464F-8C4D-D6A5DEB20B77}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{B6500800-2276-4771-A042-C78A2FA8B0EF}" = protocol=6 | dir=in | app=d:\programy\microsoft office\office14\groove.exe | "{BA766616-66F3-4681-A451-31B48D1B0D46}" = protocol=6 | dir=out | app=system | "{BE7FAB3D-6112-4C4A-929B-9029BC64FFD2}" = protocol=17 | dir=in | app=d:\gry\steam\steamapps\common\natural selection 2\ns2.exe | "{BEA58D0B-A58A-44E7-B5A7-E93ECE1E60AA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C40BCC5F-9F37-4BC6-8907-A0D1434697C0}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{C5620E15-644F-4E2C-9D1F-8AF121AFB4E1}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{C5F89AE7-CFB9-4766-9772-B74F23E4A670}" = protocol=6 | dir=in | app=d:\gry\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{C774F623-CDB4-4967-B4D8-0028F9AA3B8D}" = protocol=17 | dir=in | app=d:\gry\steam\steamapps\common\counter-strike global offensive\csgo.exe | "{CB872AAA-A9C6-4FCA-BAC2-E3F7C42869DF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{D8BCBCBF-EE09-400B-A297-BA3FF397B029}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DA398837-020D-4759-99E8-BAF28FB83658}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DAAB1C8E-3B84-4EFA-9720-382AB3AB464C}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{DDB8BA72-2328-4411-9EA6-5F56B93B070A}" = protocol=17 | dir=in | app=d:\gry\origin\games\battlefield 4\bf4.exe | "{DDD85665-F28D-49E5-B18E-DDAD3FDF2DAF}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{DF13E29A-FB99-4AF5-864E-A9597A5E96E6}" = protocol=17 | dir=in | app=d:\gry\steam\steamapps\common\left 4 dead 2\left4dead2.exe | "{E414EFBC-2958-4681-89EB-082344D19F5A}" = protocol=6 | dir=in | app=d:\gry\origin\games\battlefield 4\bf4.exe | "{E4FBEDB8-3B4A-4C95-BF73-A557335FB89C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{EADB79D8-DD9A-488C-8CAF-5B073527DC23}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{EF50EB3D-13EA-404D-BC94-FE7B6EC4376D}" = protocol=6 | dir=in | app=d:\gry\origin\games\battlefield 4\bf4_x86.exe | "{F643FF03-B5B4-4CE1-8922-7C71E935341B}" = protocol=6 | dir=in | app=d:\programy\winamp\winamp.exe | "{F6E5B92B-02E7-45A1-9D48-AF63D32CAE11}" = protocol=6 | dir=in | app=d:\gry\steam\steamapps\common\natural selection 2\ns2.exe | "{F839261D-896D-422A-ACD6-40C63C3A31E5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FD2AE6D8-821B-40F0-BF1F-33075A66020D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "TCP Query User{050AADCE-9735-4319-93DA-C74E80A3FC3A}D:\programy\webserv\mysql\bin\webserv(mysqld).exe" = protocol=6 | dir=in | app=d:\programy\webserv\mysql\bin\webserv(mysqld).exe | "TCP Query User{14765B00-42BA-4150-9CB9-29E16FE4D4D6}D:\programy\sopcast\sopcast.exe" = protocol=6 | dir=in | app=d:\programy\sopcast\sopcast.exe | "TCP Query User{1DD8034F-E00D-4BE4-BD57-506272B12158}C:\program files (x86)\xfire2\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire2\xfire.exe | "TCP Query User{51F2A156-F71D-4711-AC84-9A871CA5B974}C:\windows\kmsemulator.exe" = protocol=6 | dir=in | app=c:\windows\kmsemulator.exe | "TCP Query User{5BB35AAD-D6CD-422A-B31A-06E4F3256723}D:\programy\webserv\apache2\bin\webserv(apache).exe" = protocol=6 | dir=in | app=d:\programy\webserv\apache2\bin\webserv(apache).exe | "UDP Query User{024BD6B1-32FE-4CD9-A7B2-34994C294F49}D:\programy\webserv\apache2\bin\webserv(apache).exe" = protocol=17 | dir=in | app=d:\programy\webserv\apache2\bin\webserv(apache).exe | "UDP Query User{13BCED57-DBA2-48D7-B414-A6B9988CBB60}C:\program files (x86)\xfire2\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire2\xfire.exe | "UDP Query User{37C6852E-E964-4439-AD62-5222CFA61B98}D:\programy\webserv\mysql\bin\webserv(mysqld).exe" = protocol=17 | dir=in | app=d:\programy\webserv\mysql\bin\webserv(mysqld).exe | "UDP Query User{8A2D1CA2-C6F4-4F9B-B96A-461B769ABDF7}D:\programy\sopcast\sopcast.exe" = protocol=17 | dir=in | app=d:\programy\sopcast\sopcast.exe | "UDP Query User{FAE5E988-8BA0-4A55-A43D-E6AD2543E021}C:\windows\kmsemulator.exe" = protocol=17 | dir=in | app=c:\windows\kmsemulator.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86417045FF}" = Java 7 Update 45 (64-bit) "{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 "{308051DA-0048-7A07-FE8B-9B6EC119A9E8}" = AMD Catalyst Install Manager "{45F1F774-38B4-3CC3-BAAF-051E6D19E48E}" = Microsoft .NET Framework 4.5.1 (PLK) "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{678A75C7-5953-B109-57EE-46C7BA4C29C1}" = AMD Drag and Drop Transcoding "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2010 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski) "{9ED333F8-3E6C-4A38-BAFA-728454121CDA}" = PDF-XChange Viewer "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{AEF57B06-B494-8180-AFC7-05EFB1DB2B64}" = ccc-utility64 "{BD1BCEF8-5CD6-D8ED-7D36-31C2172076EA}" = AMD Media Foundation Decoders "{C78F2980-5905-44E0-BE02-BDFC3DD6FBB9}" = ESET NOD32 Antivirus "{ED273D26-E354-1A5B-A0D0-CB5258D43BD2}" = AMD Wireless Display v3.0 "{FCC4426F-0296-D30D-729C-E76C8E7252C7}" = AMD Accelerated Video Transcoding "CCleaner" = CCleaner "CPUID HWMonitor_is1" = CPUID HWMonitor 1.24 "HP LaserJet Professional P1100-P1560-P1600 Series" = HP LaserJet Professional P1100-P1560-P1600 Series "Totalcmd64" = Total Commander 64-bit (Remove or Repair) "VLC media player" = VLC media player 2.1.2 "WinRAR archiver" = WinRAR 5.01 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{046B79EE-7ED3-37A4-621A-FE297EF484C2}" = CCC Help Greek "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{10CB5DDD-38E1-2EB2-F62C-C1948A99943E}" = AMD Catalyst Control Center "{1194740D-0DB8-A508-31BA-E722597B4516}" = Catalyst Control Center Graphics Previews Common "{179324FF-7B16-4BA8-9836-055CAAEE4F08}" = SDFormatter "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{1B6F5E51-575E-4693-BCA2-7543570D076D}" = Nero Kwik Themes Basic "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FB16E3B-3AFB-46CB-6E83-2F5A0CF4ED16}" = Catalyst Control Center Localization All "{2432E589-6256-4513-B0BF-EFA8E325D5F0}" = Nero SharedVideoCodecs "{29F67D84-3A70-456E-806A-52301B02070B}" = Nero Effects Basic "{2E3A81FB-7952-F8CB-9AD5-50544E2F4838}" = CCC Help Czech "{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 "{4172E797-CE12-AC47-05B7-0E48BDB33E75}" = CCC Help Russian "{43ADAE00-A4ED-4379-A76D-A1FF5D9D334A}_is1" = Xfire 2.0 "{4428AEE6-FA5E-2913-8D12-B410E85E11AA}" = CCC Help Spanish "{4FF1533E-FF2C-A04A-25DD-A8AEC6FA106B}" = CCC Help Chinese Standard "{5909A89E-C97F-407C-AE2B-47BDED86BF5D}" = Prerequisite installer "{5DE67937-45D5-45E4-923C-0B7F7EC929A7}" = League of Legends "{6071CB80-DABC-B10D-F244-7F410FB3B150}" = CCC Help Polish "{6343B6BA-F97F-B336-9ED8-FFD43776E84D}" = CCC Help Finnish "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7 "{8D3A11D0-D925-FA0F-43F3-242E49975CD2}" = CCC Help Danish "{8EF39A9F-6A57-9706-86A5-9312D9ED8016}" = CCC Help Portuguese "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{92352C97-C657-DB89-5F3A-E8C3789D9C89}" = CCC Help Chinese Traditional "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{95545E55-3309-1929-FF41-2908A9706742}" = CCC Help Turkish "{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9AAC4108-B87E-4B68-B5EB-5629819F6398}" = Nero Blu-ray Player "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9CA5F712-9CAA-B3CB-02D3-7134DFC8801E}" = CCC Help French "{A128A816-FD3F-990E-DD80-E1735BD718AE}" = CCC Help Italian "{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 "{A7A0BF2E-31CC-49E3-9913-52C503EB969D}" = Nero Audio Pack 1 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA7A2800-1E75-4240-855B-03AFF8E5171E}" = FIFA 14 "{ABADE36E-EC37-413B-8179-B432AD3FACE7}" = Battlefield 4™ "{ABC88553-8770-4B97-B43E-5A90647A5B63}" = Nero ControlCenter "{ACE49D50-19CD-44A6-B192-46F985283B26}" = Nero PiP Effects Basic "{AFC9ECA9-6A4E-1370-98F3-002B63B5AF8E}" = CCC Help Thai "{B166374C-105E-445E-8E5D-A86CA5742645}" = Nero Burning Core "{B791E0AB-87A9-41A4-8D98-D13C2E37D928}" = Nero Info "{B88F2045-CF9A-996C-1670-6F7D65F1D18A}" = CCC Help Norwegian "{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components "{BED96D0C-7743-3CE3-F7DF-A0A4475FBF2F}" = CCC Help Hungarian "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6 "{CB79256B-C0E0-40C6-8EB7-BDD796203581}" = Catalyst Control Center - Branding "{D281F8CD-B5F2-4F74-8A66-75FC08C0606B}" = Tt eSPORTS SAPHIRA "{D5115C78-2D22-4668-A5E2-6C87DED3ED1B}" = Nero Launcher "{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller "{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}" = Nero Disc Menus Basic "{E297492A-E114-CAE0-502E-5F36C386DD30}" = CCC Help Dutch "{E6533A85-ED92-F897-2B68-58AC3BD87F94}" = CCC Help English "{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 "{EBAC163A-588E-1E5A-3CE8-826E9A449244}" = CCC Help Korean "{ED65BD75-CEF3-C0C2-9E9C-FA567484FF60}" = CCC Help Japanese "{ED7943A4-2FF0-4096-BBEA-DE3CC206E3D4}" = Nero Express "{EEB34D84-92A1-7BE3-6DB7-ABD1C4912D6B}" = Catalyst Control Center InstallProxy "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F1289D68-1C48-930F-51CF-577BDB371252}" = CCC Help Swedish "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2B9C8D6-C69C-4BA7-95D2-66F1C68D15DA}" = Nero Burning ROM "{F384C1E1-3A16-4073-95C3-7271FE0ED4C2}" = Nero 2014 "{F3F340A5-64EC-AEEC-4BDF-DC537D390BF5}" = CCC Help German "{FC9D3C55-81BA-4F57-9750-17BC1C7A2CF3}" = Nero 2014 "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Ant Movie Catalog_is1" = Ant Movie Catalog "AudioCS" = Creative Audio Control Panel "Battlelog Web Plugins" = Battlelog Web Plugins "Console Launcher" = Creative Console Launcher "Creative Software AutoUpdate" = Creative Software AutoUpdate "Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition "DAEMON Tools Lite" = DAEMON Tools Lite "ESN Sonar-0.70.4" = ESN Sonar "Google Chrome" = Google Chrome "Image Grabber II" = Image Grabber II "InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller "IrfanView" = IrfanView (remove only) "League of Legends 3.0.1" = League of Legends "Mozilla Firefox 26.0 (x86 pl)" = Mozilla Firefox 26.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Mp3tag" = Mp3tag v2.58 "NapiProjekt_is1" = NapiProjekt (2.2.0.2399) "Notepad++" = Notepad++ "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "OpenAL" = OpenAL "Origin" = Origin "Picasa 3" = Picasa 3 "PunkBusterSvc" = PunkBuster Services "PuTTY_is1" = PuTTY version 0.63 "RealAlt_is1" = Real Alternative 2.0.2 "SopCast" = SopCast 3.8.3 "Steam" = Steam "Winamp" = Winamp "XfireCodec" = Xfire Codec (remove only) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-01-06 05:02:18 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-06 08:52:07 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-07 03:31:23 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-08 05:02:32 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-09 03:46:58 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-10 04:06:47 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-11 06:29:03 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-11 15:08:30 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-12 05:35:58 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-01-12 08:22:08 | Computer Name = Bartek-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2014-01-04 13:41:34 | Computer Name = Bartek-PC | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-01-04 15:16:23 | Computer Name = Bartek-PC | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-01-04 15:30:22 | Computer Name = Bartek-PC | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\DR1. Error - 2014-01-07 03:34:29 | Computer Name = Bartek-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Definition Update for Windows Defender - KB915597 (Definition 1.165.1308.0). Error - 2014-01-07 15:09:23 | Computer Name = Bartek-PC | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-01-09 05:39:22 | Computer Name = Bartek-PC | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-01-10 08:06:37 | Computer Name = Bartek-PC | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-01-10 15:51:52 | Computer Name = Bartek-PC | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error - 2014-01-11 15:06:49 | Computer Name = Bartek-PC | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 20:05:23 na ?2014-?01-?11 było nieoczekiwane. Error - 2014-01-12 05:59:14 | Computer Name = Bartek-PC | Source = volsnap | ID = 393252 Description = Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. < End of report >