OTL Extras logfile created on: 2011-03-18 14:44:51 - Run 2 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Krystyna\Desktop\Bob\Sterowniki & Programy\Skanery Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 7.0.6002.18005) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 65,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 84,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 288,09 Gb Total Space | 158,14 Gb Free Space | 54,89% Space Free | Partition Type: NTFS Drive D: | 9,00 Gb Total Space | 1,93 Gb Free Space | 21,43% Space Free | Partition Type: NTFS Drive F: | 1021,00 Mb Total Space | 1018,74 Mb Free Space | 99,78% Space Free | Partition Type: FAT32 Computer Name: KRYSTYNA-PC | User Name: Krystyna | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\S-1-5-21-1234806826-2403135869-279979013-1004\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AntiVirusOverride" = 1 "AntiVirusDisableNotify" = 1 "FirewallOverride" = 1 "FirewallDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1234806826-2403135869-279979013-1004] "EnableNotifications" = 0 "EnableNotificationsRef" = 3 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 1 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\windows\system32\igfxdkp32.exe" = C:\windows\system32\igfxdkp32.exe:*:Enabled:VLAN [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{003B375D-608E-48A0-B9E2-2607903315D1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{02082CB1-A643-43E5-B678-FBD896351E70}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{0216E459-13FE-42F4-A370-4CFE904FD2FB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{074390EF-09DC-4F20-A8F5-84547ECECB39}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{476EE289-B149-4489-8E55-449D598A5055}" = lport=2869 | protocol=6 | dir=in | app=system | "{49FF3245-F5B9-4460-A6B0-3E1E986542C1}" = rport=10243 | protocol=6 | dir=out | app=system | "{4F30AFD3-7CEB-41D8-9A13-DE1FE4813A4D}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{5ECCC17B-6EBB-4755-930A-FFB385B331C6}" = rport=445 | protocol=6 | dir=out | app=system | "{63109F59-7B3F-492C-B754-5353B8F586E7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{70795F64-29F2-4011-B790-50282537E2DB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7AECAF13-DEE3-49E0-BEB6-17D43AC5BF5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{916DC5A2-6D13-4844-993A-67D4046B0F24}" = lport=139 | protocol=6 | dir=in | app=system | "{9404D69B-6ED0-46F6-B3EF-E484466FB44C}" = lport=2869 | protocol=6 | dir=in | app=system | "{971BC495-F5A8-41B1-815C-3041816EE8F8}" = lport=138 | protocol=17 | dir=in | app=system | "{98261ACE-F1AC-4B6B-B67F-A3BE5158A3E4}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{9BA4B386-A910-4D0C-9CFD-B1E59B8B96CC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9C91412E-8633-403C-8306-28D64B4E428B}" = rport=139 | protocol=6 | dir=out | app=system | "{AD838837-269F-4BBF-87D2-9E3333CDFCFB}" = lport=137 | protocol=17 | dir=in | app=system | "{B14021DD-D443-4007-BC13-67AD8790E54C}" = rport=137 | protocol=17 | dir=out | app=system | "{B73470B8-1D47-4B47-BF91-95F6E4BBAA0A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CFF68C51-A84A-4CBC-959A-67D7BB16A418}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D79FAA30-4FAE-49BC-A5CC-C87F20586AD2}" = lport=445 | protocol=6 | dir=in | app=system | "{DDA2FF12-85C4-4E6B-BE26-2D1F99E117D3}" = rport=138 | protocol=17 | dir=out | app=system | "{DE250E5A-EFA3-458B-BC3D-FC62E00C7785}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{E4DB5752-D6A2-4DCD-8A59-088CB6F05979}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{ECE8586C-94FD-473E-A73A-F6E7F0F618B9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{F515D0ED-3DC7-484B-9C97-473FA8A0B172}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{FB43A6C1-962D-4167-8753-CC819E0B27A4}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{FDCAE68C-8C0B-4798-BC6F-7B9855857B07}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FF4A439F-2FC5-43E1-8821-2FC1C328CAFA}" = lport=10243 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03F73AAA-2454-4846-ACCA-F273F33CE15B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{0DCA808B-4F25-43E2-A45E-C48BB772A251}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{2508D20B-FC6B-4B7E-848B-7C84AAEC6FE2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{27A6070E-2CA1-478B-854A-16DA473E2909}" = dir=in | app=c:\program files\msn messenger\livecall.exe | "{2B83E502-04A2-4488-8AE1-C55F1A4490DF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3054C7A4-5DBA-4EAD-8359-2F979B07A4C9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3578FCFD-2B08-4AD5-8E8D-B1342FD584C8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{505B43EB-067A-427E-8CE0-5738E8550FFD}" = protocol=17 | dir=in | app=c:\program files\mcafee\managed virusscan\agent\myagtsvc.exe | "{50FD83A2-AA06-4269-99B6-07ED6FC0F199}" = protocol=6 | dir=in | app=c:\program files\mcafee\managed virusscan\agent\myagtsvc.exe | "{514185B2-2FE8-4D4A-A7BD-36F33667E736}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{6067B8CC-6D9C-4D08-A978-2C0CAA895B40}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6AB4F18E-D1FA-42D1-8A1B-0E1745ED6D54}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{700EF9EE-621D-4C46-99CD-7739112BA4A1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{780C1C3B-7978-4AED-B448-2FE6C82AC9FD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{823FBBFC-5B84-4309-9FD1-79FA9882350E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{829B41AF-7FB9-40C0-B49D-5E523266A9FC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8F974552-602D-4B13-98F4-87AC99FDE958}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe | "{96073F4A-081D-438A-B0AC-B8FAE50622D6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{9AA24DFC-6E01-410E-9825-237C081A81C8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{AFD8169D-810C-4EAB-83FA-9B0FB1A2B95D}" = protocol=17 | dir=in | app=c:\users\krystyna\appdata\roaming\dropbox\bin\dropbox.exe | "{BC93048C-64D1-40F0-A11C-61CC18B59D7E}" = protocol=6 | dir=in | app=c:\users\krystyna\appdata\roaming\dropbox\bin\dropbox.exe | "{C1D78776-617F-4B81-96B8-05C666280F80}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{CC903B45-5E58-4776-B427-C60F5071412A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{D3B4A561-F3F9-49F4-844F-B87EBEB117AA}" = protocol=6 | dir=out | app=system | "{EE4ADC29-DC91-4CE1-83D6-4F376D5CABD9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{F3DAEFF3-65FD-4C54-AC0F-B2CDB2489C9F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F79DA120-F1A9-4230-B557-85D2F86EA3C1}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{FA806DC6-625F-4779-BCF9-C6FD5BF54A03}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "TCP Query User{202830BA-AD60-4DD6-B386-2BEBF0EAC4D2}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{30E59278-3F38-430C-8A39-BFFD24F964C9}C:\program files\metin2_pl\pandoramt2.exe" = protocol=6 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "TCP Query User{38DE92F7-A5AD-45FB-BBBA-FEB9221C0B38}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{3A556E32-D871-4D19-913A-5149C694E506}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "TCP Query User{3CF20FD1-E9E4-498C-9202-009C0ADEBFAA}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{3F2B2638-E199-40BC-AEA7-9AE82D829AF7}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=6 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "TCP Query User{50127F44-5D1F-4486-9876-A631B65D94FC}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "TCP Query User{54BE1B22-C1E1-44A0-BDD7-50B365667F29}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "TCP Query User{5F9995FF-F2C0-4CCB-95E0-C1A32D2D8AFB}C:\program files\cavalos\cavalos.exe" = protocol=6 | dir=in | app=c:\program files\cavalos\cavalos.exe | "TCP Query User{865920BA-7BD5-4766-9271-01111BA4661F}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "TCP Query User{990AB7D6-9D13-47D9-A105-C929B58F1E8C}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | "TCP Query User{A2BE5F47-560A-42E8-84D4-AAE805961ABC}C:\program files\metin2_pl\metin2.bin" = protocol=6 | dir=in | app=c:\program files\metin2_pl\metin2.bin | "TCP Query User{A3D365BE-68E0-4AA8-A0A6-D7487C5E75D2}C:\program files\nowe gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "TCP Query User{A9731401-AD78-4BC1-917C-D8E67B20B593}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=6 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "TCP Query User{D9A6F8E9-BAA7-4052-AC51-B404097D0103}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=6 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | "TCP Query User{F5388CA7-F35A-402A-9AE2-EAC8B352D321}C:\program files\metin2_pl elitemt2\elitemt2.exe" = protocol=6 | dir=in | app=c:\program files\metin2_pl elitemt2\elitemt2.exe | "TCP Query User{F79E4C50-1020-48AE-A60F-7F47D32F1737}C:\program files\metin2_pl\pandoramt2.exe" = protocol=6 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "UDP Query User{1033F9F2-8153-4592-AF5A-D5013A9ACB89}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "UDP Query User{1420CEEC-B1E9-49E4-BF60-4656E5AB9D2C}C:\program files\metin2_pl\pandoramt2.exe" = protocol=17 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "UDP Query User{41087A50-D9D4-4E17-A487-37DF1D4AE2C7}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{42BB121F-1074-4D68-9616-F67DBF96DF46}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=17 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "UDP Query User{52CFAC34-3B6B-4D3F-8434-74A2BEA46BAE}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{5CB0A0FF-7489-47DE-A72B-77DDDECFCD39}C:\program files\nowe gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\nowe gadu-gadu\gg.exe | "UDP Query User{8AECF8D5-7362-4F06-9648-7602403EAD13}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=17 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "UDP Query User{99024D85-0A33-4E70-A121-79BD025E8B78}C:\program files\wapster\wapster aqq\aqq.exe" = protocol=17 | dir=in | app=c:\program files\wapster\wapster aqq\aqq.exe | "UDP Query User{9953823A-0780-4E1C-A614-D928F9F4756E}C:\users\krystyna\desktop\pandoramt2\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2\pandoramt2.exe | "UDP Query User{A5AC7D65-C762-45B8-8E35-F86AF255D19E}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | "UDP Query User{C363B555-1A95-4DC4-B8C9-2A8A0FCDE589}C:\program files\metin2_pl elitemt2\elitemt2.exe" = protocol=17 | dir=in | app=c:\program files\metin2_pl elitemt2\elitemt2.exe | "UDP Query User{CD244F23-52C1-4B26-B54E-1029B29CA8C0}C:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin" = protocol=17 | dir=in | app=c:\users\krystyna\appdata\local\virtualstore\program files\subagames\metin2\metin2.bin | "UDP Query User{D256E151-BB0E-4B16-A98F-BA361F4B7516}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{E5DB6D25-0640-4E0D-9C6A-EE8222B3627F}C:\program files\cavalos\cavalos.exe" = protocol=17 | dir=in | app=c:\program files\cavalos\cavalos.exe | "UDP Query User{E6B49B31-8E0C-439A-8A63-1B65B57B8A8C}C:\program files\metin2_pl\metin2.bin" = protocol=17 | dir=in | app=c:\program files\metin2_pl\metin2.bin | "UDP Query User{ECCE0872-3B48-4EA5-9935-B72F8C6C0F51}C:\program files\metin2_pl\pandoramt2.exe" = protocol=17 | dir=in | app=c:\program files\metin2_pl\pandoramt2.exe | "UDP Query User{F913577A-F1C9-4B1B-96C9-B7832B2DED61}C:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe" = protocol=17 | dir=in | app=c:\users\krystyna\desktop\pandoramt2_client\pandoramt2.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1 "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6200 "{06CB77AB-CDE1-EF6B-175D-85FA59C7F0EE}" = Catalyst Control Center Core Implementation "{07D78C7B-2AA8-5C02-4238-EE3F39279221}" = Catalyst Control Center Localization Thai "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{0AF9C2B7-2E98-8D77-3892-F8512305C6CE}" = CCC Help Turkish "{0F98662A-EA83-414F-8766-3FCE46A32641}" = Credential Manager for HP ProtectTools "{154E4F71-DFC0-4B31-8D99-F97615031B02}" = HP Webcam Application "{164280AB-98C2-FD02-EC0B-5DFBB98E89C1}" = Catalyst Control Center Localization Chinese Standard "{173317B8-D99E-F58E-CAAE-924D8F26C435}" = CCC Help Czech "{1779522E-BFC6-738C-E97E-39405E196FA6}" = Catalyst Control Center Localization Spanish "{1871FE54-36AA-478F-B374-A46BA54474CC}" = ESET NOD32 Antivirus "{1DB44CB7-D68E-9F09-D656-0FBC7D4D9C00}" = Catalyst Control Center Localization Norwegian "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FD3DF19-EF58-2A29-222B-A4B6E237D3DD}" = Catalyst Control Center Graphics Previews Vista "{207A8D54-51C9-48B6-80E6-CBA5403B3ED4}" = Vista Default Settings "{2086797F-A4BA-4CD3-8104-09B8D39DA5D8}" = HP JavaCard for HP ProtectTools "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library "{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 24 "{2EC294E6-2E8C-23A7-C174-4E59532B0E06}" = Catalyst Control Center Localization Korean "{30BF4E6C-D866-46F7-A4F6-81A45E97706E}" = Catalyst Control Center - Branding "{311BF3BF-6AAB-7859-1E5A-EB46644A6011}" = CCC Help French "{32063923-8066-18D5-BF07-2B692547AEF5}" = CCC Help Korean "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{323C15C3-6DE1-05E6-B202-6F1D90BB1B06}" = Catalyst Control Center Localization Turkish "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 E1 "{3848DCD1-E356-ACB9-93AF-FB93485E1598}" = CCC Help Thai "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = HP Webcam "{3A76F96A-637B-9A0E-F65B-AE595A49DEDA}" = ccc-core-static "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3FCFB6B6-B5DE-C5B8-825F-5998C220C24E}" = Catalyst Control Center Localization Russian "{420BBA1D-B275-4891-838C-EA88FE87A632}" = HP Customer Experience Enhancements "{45BA0F82-FC61-828B-A188-49A24B7B39F4}" = Catalyst Control Center Localization Swedish "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4ADB08ED-A385-21BA-3511-00EB170C9CCA}" = Catalyst Control Center Localization Greek "{4C203E35-B5C7-4E35-9834-619668C0FFEE}" = HP 3D DriveGuard "{500CAC18-1509-AC6C-3E91-A437F9457D5E}" = CCC Help Japanese "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features "{5B5494F7-FD30-AFAB-ACD5-345F26B6AAF4}" = Catalyst Control Center Graphics Full Existing "{5BF2EC0B-2A01-DDEA-5645-E700BCE9CDA6}" = CCC Help Spanish "{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check "{5EF644FA-3703-3253-7372-AE46FD862588}" = ccc-utility "{63BABF5E-B142-02F9-85E1-F0A1DBEC6D5D}" = Catalyst Control Center Localization Chinese Traditional "{647ED1EC-1D53-9886-B5A1-234CE9D7BE3F}" = Catalyst Control Center Localization Danish "{64F561F5-17B7-0721-8D08-78777BB91382}" = CCC Help Italian "{65E63D8F-F763-940E-38FA-1A6B2C30ADB2}" = Catalyst Control Center Graphics Light "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library "{69333A04-5134-40A5-A055-9166A7AA1EC8}" = "{6B4591DF-C531-255E-BDE6-25226A5AE115}" = Skins "{6C4592F5-A803-1740-A708-84F3578DC083}" = Catalyst Control Center Localization German "{6DF8EB4D-F5E5-369C-38B2-4F7CD0F02AC3}" = Catalyst Control Center Localization Italian "{70CEFEBA-F757-4DBE-8A21-027C326137CE}" = HP Software Setup 5.00.A.7 "{75D7BB3A-9AB7-4ad1-AD5E-0059B90C624B}" = HP ProtectTools Security Manager Suite "{789C97CE-9E17-4126-BDF4-11FF458BF705}" = File Sanitizer For HP ProtectTools "{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8BB128BE-2670-485D-A221-B00715BCEBCF}" = HP Easy Setup - Frontend "{8BEA3254-8719-4815-9312-69AF21B8D779}" = CCC Help Chinese Traditional "{8BF85A3B-C2EE-2A32-DF54-B565062FBEC9}" = Catalyst Control Center Localization Japanese "{8DD39028-8B90-88D8-781A-AB82A9AE6662}" = CCC Help English "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD "{91B26C13-34A4-36FA-E1F0-22664915EED1}" = Catalyst Control Center Localization Dutch "{926F4D5F-C8FC-4FB7-8E09-BCB8A997D1C7}" = HP ProtectTools Security Manager "{968933D6-A9FC-891C-6292-F7E68DB2C7EA}" = CCC Help Finnish "{96DB55D1-E21F-126C-1ADD-35EAAC852C7C}" = Catalyst Control Center Localization Finnish "{988B865E-CC06-7B3D-FBC0-52093DB75C9A}" = CCC Help Dutch "{997F39AA-6CDC-2E23-F9C3-D59AACABAB8F}" = Catalyst Control Center Localization French "{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant "{9DBD8BEE-B3EC-4D82-A81C-0F6250176DCC}" = Drive Encryption for HP ProtectTools "{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A1410161-F615-4B91-A019-FA33833EF00D}" = BIOS Configuration for HP ProtectTools "{AC194855-F7AC-4D04-B4C9-07BA46FCB697}" = ActivClient 6.1 x86 "{AC76BA86-7AD7-1045-7B44-AA0000000001}" = Adobe Reader X (10.0.1) - Polish "{B0704448-6681-607E-D97F-A148C2E2F763}" = CCC Help Danish "{B79DB290-9F72-4B20-9776-848D7832705B}" = HP User Guides 0108 "{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX "{BABEDC2E-5718-1D6D-9E76-93C7EC76BBC4}" = CCC Help Greek "{BC1DC565-8B34-4B29-9DB2-BF281C2FB56E}" = ESU for Microsoft Vista SP1 "{BD5DE09E-3C1C-1DCE-E98D-7B7BBDBE15AD}" = CCC Help Portuguese "{BFCBCC48-9027-17B7-BD08-5214898494CC}" = CCC Help German "{C3036710-8564-ECEA-0E19-1B7880111167}" = CCC Help Swedish "{C7D03B2F-5B3A-A6D8-1C6C-AFCA02DDD3EC}" = Catalyst Control Center Localization Czech "{C8A33E2B-5DDB-BF2E-24A9-95DFA1CDF56D}" = Catalyst Control Center Localization Polish "{CA144572-CEAD-5A14-A338-D28B35D9C7FF}" = Catalyst Control Center Localization Hungarian "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE3020D2-1742-19F4-EFB4-4D76097C81D0}" = Catalyst Control Center Localization Portuguese "{CF755AAE-7801-359C-E9D3-FE8572F8C760}" = Catalyst Control Center Graphics Full New "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 "{DC04644B-C7B3-AF77-610C-7F0AF59AC44D}" = ATI Catalyst Install Manager "{DE80F89F-6132-42A9-1A47-542F6C60E1A2}" = CCC Help Russian "{E333CA5F-00ED-4EEF-90E5-6A33A8FE969F}" = HP Help and Support "{E979B690-80A7-8E8B-1281-C68DBEDDB491}" = CCC Help Norwegian "{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "{F173C2B3-296F-458C-98FF-1676A42EBA02}" = HP Wallpaper "{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager "{F23DFEB2-A5D1-3B97-FBF3-30DC859411C0}" = CCC Help Hungarian "{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner "{FBE38124-B7F0-3EEE-98C5-D8C3AE353FF5}" = CCC Help Chinese Standard "{FD9FAE60-2BF1-C877-9843-AABA9DA06A2B}" = CCC Help Polish "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Advanced SystemCare 3_is1" = Advanced SystemCare 3 "Agere Systems Soft Modem" = Agere Systems HDA Modem "ALLPlayer V2.2" = ALLPlayer V2.2 "AQQ" = WapSter AQQ "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "ENTERPRISE" = Microsoft Office Enterprise 2007 "IrfanView" = IrfanView (remove only) "JDownloader" = JDownloader "KLiteCodecPack_is1" = K-Lite Codec Pack 5.0.5 (Full) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3) "NapiProjekt_is1" = NapiProjekt 1.0.6.9 "Nero8Lite_is1" = Nero 8 Lite 8.3.6.0 "RealAlt_is1" = Real Alternative 1.9.0 "Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "Smart Defrag 2_is1" = Smart Defrag 2 "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = Archiwizator WinRAR [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1234806826-2403135869-279979013-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2011-03-17 17:10:45 | Computer Name = Krystyna-PC | Source = WinMgmt | ID = 10 Description = Error - 2011-03-17 17:17:12 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-17 17:17:12 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-17 17:17:12 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3011 Description = Error - 2011-03-18 06:28:32 | Computer Name = Krystyna-PC | Source = WinMgmt | ID = 10 Description = Error - 2011-03-18 06:33:15 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-18 06:33:15 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3012 Description = Error - 2011-03-18 06:33:15 | Computer Name = Krystyna-PC | Source = LoadPerf | ID = 3011 Description = Error - 2011-03-18 09:37:47 | Computer Name = Krystyna-PC | Source = Application Hang | ID = 1002 Description = Program OTL.exe w wersji 3.2.22.3 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania raportami i rozwiązaniami problemów. Identyfikator procesu: fdc Godzina rozpoczęcia: 01cbe57133a29118 Godzina zakończenia: 0 Error - 2011-03-18 09:42:06 | Computer Name = Krystyna-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2011-03-18 06:28:18 | Computer Name = Krystyna-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = Error - 2011-03-18 06:28:33 | Computer Name = Krystyna-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2011-03-18 06:28:33 | Computer Name = Krystyna-PC | Source = Service Control Manager | ID = 7001 Description = Error - 2011-03-18 09:39:40 | Computer Name = Krystyna-PC | Source = Service Control Manager | ID = 7034 Description = Error - 2011-03-18 09:41:11 | Computer Name = Krystyna-PC | Source = volmgr | ID = 262190 Description = Inicjowanie zrzutu awaryjnego nie powiodło się! Error - 2011-03-18 09:41:26 | Computer Name = Krystyna-PC | Source = volmgr | ID = 262190 Description = Inicjowanie zrzutu awaryjnego nie powiodło się! Error - 2011-03-18 09:41:47 | Computer Name = Krystyna-PC | Source = Print | ID = 64 Description = Próba instalacji drukarki Microsoft XPS Document Writer 6.0.6002.18005 w obrazie systemu operacyjnego w trybie offline nie powiodła się z powodu następującego błędu systemu Win32: 1797 (0x705). Może to występować, jeśli sterownik drukarki wymaga wprowadzenia danych przez użytkownika lub wyświetla interfejs użytkownika podczas instalacji. Error - 2011-03-18 09:42:06 | Computer Name = Krystyna-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2011-03-18 09:42:06 | Computer Name = Krystyna-PC | Source = Service Control Manager | ID = 7001 Description = Error - 2011-03-18 09:42:19 | Computer Name = Krystyna-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001 Description = < End of report >