OTL Extras logfile created on: 2014-12-10 23:15:10 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = E:\ 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16428) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,87 Gb Total Physical Memory | 2,60 Gb Available Physical Memory | 67,22% Memory free 7,73 Gb Paging File | 6,23 Gb Available in Paging File | 80,60% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 25,53 Gb Total Space | 0,14 Gb Free Space | 0,54% Space Free | Partition Type: NTFS Drive D: | 49,00 Gb Total Space | 2,37 Gb Free Space | 4,83% Space Free | Partition Type: NTFS Drive E: | 74,52 Gb Total Space | 23,73 Gb Free Space | 31,85% Space Free | Partition Type: NTFS Drive F: | 19,53 Gb Total Space | 0,03 Gb Free Space | 0,13% Space Free | Partition Type: NTFS Drive G: | 56,79 Gb Total Space | 5,54 Gb Free Space | 9,76% Space Free | Partition Type: NTFS Drive H: | 594,98 Mb Total Space | 590,26 Mb Free Space | 99,21% Space Free | Partition Type: FAT32 Computer Name: WITEK-KOMPUTER | User Name: Witek | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .hlp [@ = WinHelpCustomView.Scenario] -- C:\Windows\SysWow64\winhlp32.exe %1 .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .hlp [@ = WinHelpCustomView.Scenario] -- C:\Windows\SysWow64\winhlp32.exe %1 .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3474202831-752969469-3571592006-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\Winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\Winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\Winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\Winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0C632C52-92CD-4FF9-8C59-8E13277C1712}" = lport=2869 | protocol=6 | dir=in | app=system | "{207FBBD8-155A-484A-A5A4-374FD5453D09}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{268F1BEB-ABAA-417B-9A43-900728DE3613}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{37FA2BC8-D659-4089-A666-50096589CFC8}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{4F51EE80-01CA-432E-92D9-422593565F96}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{5459FE67-4593-4B23-B62A-6CF517F62D8B}" = lport=137 | protocol=17 | dir=in | app=system | "{54A1FDBD-8DAD-4014-A963-B71306C2D7E1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5842A7A8-7608-436A-B116-1E7E4B0934B8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5DD78E40-9445-453F-A397-23616FA12551}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{669963EA-A667-4E0C-A09F-864734EA288E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{66B63536-4969-48E7-A01E-8C49BF6BB536}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7984D705-AE1C-41B8-AC56-A734637CEA4D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{79AC59C1-A5BE-4F7C-A648-70F827FEC9C7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7DE527A7-A318-4C3C-B884-86EA85FF53F8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8C6A3D79-5C3F-4688-9F47-F13079FB25AF}" = rport=139 | protocol=6 | dir=out | app=system | "{8CA66905-32DA-4F81-A90B-D380E5944FE2}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{963C34AF-635B-4947-80DB-6E0B13267595}" = lport=138 | protocol=17 | dir=in | app=system | "{96CDBBD1-C26C-418C-A065-4DC29DC255F3}" = rport=138 | protocol=17 | dir=out | app=system | "{9D62814A-0CD1-4274-9B4A-61B374FD2184}" = lport=10243 | protocol=6 | dir=in | app=system | "{A4F2835C-83C3-402F-AD5C-38EA4E78F67C}" = lport=445 | protocol=6 | dir=in | app=system | "{ACB48BA0-5E07-422B-B917-E9FDD37E7849}" = rport=445 | protocol=6 | dir=out | app=system | "{B6A57C5D-6155-471A-935F-7842B9250FDE}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{B873413C-93D2-46D0-84D3-4635C8CE3EB9}" = rport=137 | protocol=17 | dir=out | app=system | "{BA8FFB1C-41D2-46B6-9589-8F899960D482}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C55018AB-EF9D-422A-B81B-BC0C701A540B}" = rport=10243 | protocol=6 | dir=out | app=system | "{C79504B5-D0DD-42CD-B154-6D04FAD99F14}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EC3EE467-FBD5-4144-8107-A143F1B75767}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{F2495468-3B70-4CBE-9D8D-84288B76370C}" = lport=139 | protocol=6 | dir=in | app=system | "{F3B2AFEF-07F7-4E93-8AF2-BF75F625AD2F}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05F13C7B-5ED2-420F-89FB-2D14584F1119}" = protocol=6 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\gu.exe | "{08FDF252-7BAD-4D13-BB9A-3F3598BD8219}" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | "{0B1647BB-D1B3-46DA-84B3-101FEEE6CE11}" = protocol=17 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\uplaybrowser.exe | "{108A3CFD-BBFC-43B5-A9B8-9D31C33EFDAB}" = protocol=17 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{16FD6577-BEC0-491F-AC0B-FBCB7608E3FF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{21432FCE-498D-4F67-99EC-F35B2F16C77C}" = protocol=6 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\prince of persia.exe | "{25237C05-6A4C-4557-A472-EE839642F888}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{2D94B7C4-DDB7-43ED-90BB-CF4DC575E834}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{318AE752-E51F-444C-88C6-01A6EF2171DD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{32A2C21F-93D9-4139-9CE8-FCE6CA70DEA1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{3A3CE241-6974-4BDC-BB7C-4500BF1A6DB4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{42713DE1-CC41-4F61-AE45-64997EBDA450}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{5416F4AA-3265-4CBD-A892-BFC7282B7077}" = protocol=6 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\gamesettings.exe | "{58D273CF-09D2-4C72-A951-7CE7295893F8}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{608E4F4A-12CE-4D47-8C59-C02839DD6542}" = protocol=6 | dir=in | app=d:\gry\apache air assault\yuplay\yuplay.exe | "{6748A495-DCAA-4F64-A1D7-AEDDFF662589}" = protocol=17 | dir=in | app=g:\gry\gry\far cry 3\bin\farcry3_d3d11.exe | "{6898E11B-F220-4D23-BC86-0D4F2E6A71C9}" = protocol=6 | dir=in | app=c:\program files (x86)\napiprojekt\napisy.exe | "{6C838D2C-F93A-4BA5-BC67-D1BA8A5B1523}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{6FEFBC6E-2A79-4EC5-8CF0-D356611BB20D}" = protocol=17 | dir=in | app=d:\gry\apache air assault\launcher.exe | "{70DAD815-40DD-4C84-8323-88D4B1C11F34}" = protocol=17 | dir=in | app=d:\gry\apache air assault\yuplay\yuplay.exe | "{71808377-8491-4018-919C-DD912A71695F}" = protocol=6 | dir=in | app=g:\gry\gry\far cry 3\bin\fc3updater.exe | "{85AC462C-A8C1-4680-BDCD-870545CC236B}" = protocol=17 | dir=in | app=g:\gry\gry\far cry 3\bin\farcry3.exe | "{88AA371D-2393-4A60-B1BB-95C2642E87E6}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{8BFB97CF-48EB-4699-93C2-AA794433E09B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{8FBF498F-0DD2-4A6E-A88D-5E81C820406F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{935F9E58-2276-437A-A0AB-33C9708CE1C2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{9998A7AA-5650-4BE6-AD2F-AEF7EB05F2BF}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{9E850037-8B1F-490E-8601-F960E4F7E204}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A2470996-34EA-4F92-9641-461A02EA3CD2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{A870ED1E-4B7E-4580-A3C9-406C189ACE32}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe | "{A94E592E-E387-4113-A228-833156737BEF}" = protocol=17 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\gamesettings.exe | "{AF3486CF-065F-4085-AF47-14ADBFBBE735}" = protocol=6 | dir=out | app=system | "{B04D359D-4489-4AD3-A68F-95712D82EC50}" = protocol=6 | dir=in | app=g:\gry\gry\far cry 3\bin\farcry3_d3d11.exe | "{B4051D69-AB6E-4395-95C2-02E5ADD306A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B5659C22-8177-4B81-830A-F10D5E87714A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{BC984A95-0C70-4E39-A817-ED261E9F4856}" = protocol=6 | dir=in | app=g:\gry\gry\far cry 3\bin\fc3editor.exe | "{BEBCCBC9-B216-4F2F-A210-4C65A92CA2F0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CBF3BB88-C2EC-4611-90DD-A97FEB42E689}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D194365E-393A-495D-8C09-D28D2B835B07}" = protocol=6 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\uplaybrowser.exe | "{D6308404-00E0-4AB6-B7E7-98AEC5E9B86C}" = protocol=6 | dir=in | app=g:\gry\gry\far cry 3\bin\farcry3.exe | "{D84F117B-0FC2-44E3-9860-746C18ACA6E6}" = protocol=17 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\prince of persia.exe | "{DBEE6B30-2BD8-495A-81C3-3EA58AF91CE8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DCD122FC-69E0-4F71-A083-713ECCDD903F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{E4382CF9-C643-41A7-9603-7E73834D9C37}" = protocol=17 | dir=in | app=g:\gry\gry\prince of persia zapomniane piaski\gu.exe | "{EA8F2B9E-2BEB-4D4E-B941-9CC52DD71FC7}" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | "{EC4BF964-995C-4179-A0A2-35188BF2FF5D}" = protocol=6 | dir=in | app=d:\gry\apache air assault\launcher.exe | "{EEF1E2AC-19C4-427D-A641-B73130C887E5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{F345BAEE-1CC7-4AFC-8953-C5011A7F0398}" = protocol=17 | dir=in | app=g:\gry\gry\far cry 3\bin\fc3editor.exe | "{F511443A-261F-4533-83C6-BF14F7FEE5ED}" = protocol=17 | dir=in | app=g:\gry\gry\far cry 3\bin\fc3updater.exe | "TCP Query User{3EBC0B1F-2217-4C01-9D63-F822CCA409B0}D:\gry\citycardriving\city car driving\bin\win32\starter.exe" = protocol=6 | dir=in | app=d:\gry\citycardriving\city car driving\bin\win32\starter.exe | "TCP Query User{4D73F72B-1EA6-4FE4-9036-488EDE71940D}D:\gry\apache air assault\apache.exe" = protocol=6 | dir=in | app=d:\gry\apache air assault\apache.exe | "TCP Query User{5763D6F1-4444-43D7-A913-77A9DB3920E1}D:\gry\apache air assault\apache.exe" = protocol=6 | dir=in | app=d:\gry\apache air assault\apache.exe | "TCP Query User{5F311142-ECE4-44A6-900A-6F7726D9CD82}C:\users\witek\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\witek\appdata\roaming\spotify\spotify.exe | "TCP Query User{60227571-4309-4BE8-850C-31CB041004FB}G:\gry\gry\far cry 3\bin\farcry3.exe" = protocol=6 | dir=in | app=g:\gry\gry\far cry 3\bin\farcry3.exe | "TCP Query User{6400CEC9-AD3D-44D6-9188-76E896C32BBA}C:\program files\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | "TCP Query User{A77751DD-36AA-4C6D-9ED2-B5636C6C2FAF}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe" = protocol=6 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdupdate.exe | "TCP Query User{C268307C-B0DB-47A3-99F5-681E3CCF6100}C:\users\witek\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\witek\appdata\roaming\spotify\spotify.exe | "TCP Query User{D16EBADD-F353-4696-BA2A-1F95CC08E1C5}D:\wamp\bin\apache\apache2.4.9\bin\httpd.exe" = protocol=6 | dir=in | app=d:\wamp\bin\apache\apache2.4.9\bin\httpd.exe | "TCP Query User{D49D4BA2-CF10-4B94-A766-F889EA5CDF98}E:\gry\assassins creed iv black flag\ac4bfmp.exe" = protocol=6 | dir=in | app=e:\gry\assassins creed iv black flag\ac4bfmp.exe | "TCP Query User{DFD0641B-7A88-4248-BD19-0B511D3D24F5}E:\wamp server\wamp\bin\apache\apache2.4.9\bin\httpd.exe" = protocol=6 | dir=in | app=e:\wamp server\wamp\bin\apache\apache2.4.9\bin\httpd.exe | "UDP Query User{46216D17-A069-4165-8A9F-4ABDB3F01545}G:\gry\gry\far cry 3\bin\farcry3.exe" = protocol=17 | dir=in | app=g:\gry\gry\far cry 3\bin\farcry3.exe | "UDP Query User{695D5B07-CFC0-4E96-B74C-4DB61B91C990}E:\gry\assassins creed iv black flag\ac4bfmp.exe" = protocol=17 | dir=in | app=e:\gry\assassins creed iv black flag\ac4bfmp.exe | "UDP Query User{7903BAA5-A38C-4511-BCB8-82CB842A2A91}D:\wamp\bin\apache\apache2.4.9\bin\httpd.exe" = protocol=17 | dir=in | app=d:\wamp\bin\apache\apache2.4.9\bin\httpd.exe | "UDP Query User{916A645D-9D36-417C-B7CF-515AAD0B6DA0}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe" = protocol=17 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdupdate.exe | "UDP Query User{A2B95328-6700-4486-AFD9-76BC23CE76D1}C:\program files\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | "UDP Query User{A9708F3F-71E0-491D-A3DA-36EBD1C6F4CC}D:\gry\apache air assault\apache.exe" = protocol=17 | dir=in | app=d:\gry\apache air assault\apache.exe | "UDP Query User{BB8180DC-C39B-47F5-9697-60D501E676F1}D:\gry\apache air assault\apache.exe" = protocol=17 | dir=in | app=d:\gry\apache air assault\apache.exe | "UDP Query User{C897902C-4B39-4EC7-8207-21BF66609E12}C:\users\witek\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\witek\appdata\roaming\spotify\spotify.exe | "UDP Query User{D615992C-0BDE-4A0F-835C-CDDE70AAAD5C}C:\users\witek\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\witek\appdata\roaming\spotify\spotify.exe | "UDP Query User{DDA09CF7-1739-48A9-A4BE-8A3C5C45EC40}D:\gry\citycardriving\city car driving\bin\win32\starter.exe" = protocol=17 | dir=in | app=d:\gry\citycardriving\city car driving\bin\win32\starter.exe | "UDP Query User{F2C1B253-53E5-406F-822C-A8E1C14742F1}E:\wamp server\wamp\bin\apache\apache2.4.9\bin\httpd.exe" = protocol=17 | dir=in | app=e:\wamp server\wamp\bin\apache\apache2.4.9\bin\httpd.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1444D2EE-C7AD-44A8-844F-2634B49353D1}" = Logitech Gaming Software 5.10 "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86417021FF}" = Java 7 Update 21 (64-bit) "{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 "{345F3F90-0505-4EDF-B7A9-5E3AC1AC6CE4}" = 64 Bit HP CIO Components Installer "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 334.89 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 334.89 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 334.89 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.13.1220 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 12.4.55 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 12.4.55 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.22 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "CCleaner" = CCleaner "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "WinRAR archiver" = WinRAR 5.00 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver "{26A24AE4-039D-4CA4-87B4-2F03217071FF}" = Java 7 Update 71 "{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.08) - Polish "{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy "{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR "{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}" = Far Cry 3 "{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 "{EAEAAF8C-8E86-4CAC-AC08-1A33EDCA34AC}" = Prince of Persia® Zapomniane Piaski "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F96D619D-99D6-4C9C-A393-0CD22DE1CA66}_is1" = Ezvid "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin "BitComet_x64" = BitComet 1.37 64-bit "ENTERPRISE" = Microsoft Office Enterprise 2007 "GOM Player" = GOM Player "Grid 2_is1" = Grid 2 / RePack by Baracuda "kED_is1" = kED 2.1.4.0 "KLiteCodecPack_is1" = K-Lite Codec Pack 10.1.5 Full "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 2.0.3.1025 "Mozilla Firefox 33.1 (x86 pl)" = Mozilla Firefox 33.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NapiProjekt_is1" = NapiProjekt (2.2.0.2399) "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "PunkBusterSvc" = PunkBuster Services "QmF0bWFuQXJraGFtT3JpZ2lucw==_is1" = Batman Arkham Origins "Uplay" = Uplay "WampServer 2_is1" = WampServer 2.5 "Winamp" = Winamp (remove only) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-12-07 16:43:46 | Computer Name = Witek-Komputer | Source = C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe | ID = 131073 Description = Error - 2014-12-07 17:45:21 | Computer Name = Witek-Komputer | Source = C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe | ID = 131073 Description = Error - 2014-12-08 17:33:51 | Computer Name = Witek-Komputer | Source = C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe | ID = 131073 Description = Error - 2014-12-09 15:02:45 | Computer Name = Witek-Komputer | Source = Schedule | ID = 0 Description = Error - 2014-12-09 16:36:01 | Computer Name = Witek-Komputer | Source = C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe | ID = 131073 Description = Error - 2014-12-09 16:36:40 | Computer Name = Witek-Komputer | Source = Schedule | ID = 0 Description = Error - 2014-12-09 16:39:39 | Computer Name = Witek-Komputer | Source = Schedule | ID = 0 Description = Error - 2014-12-10 17:32:50 | Computer Name = Witek-Komputer | Source = Schedule | ID = 0 Description = Error - 2014-12-10 17:39:20 | Computer Name = Witek-Komputer | Source = VSS | ID = 8194 Description = Error - 2014-12-10 17:40:41 | Computer Name = Witek-Komputer | Source = Schedule | ID = 0 Description = [ System Events ] Error - 2014-12-09 13:42:25 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-12-09 13:42:25 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-12-09 13:42:25 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-12-09 13:42:25 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-12-09 13:43:02 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2014-12-09 15:06:19 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7023 Description = Usługa Windows Update zakończyła działanie; wystąpił następujący błąd: %%-2147014874 Error - 2014-12-09 16:43:21 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7023 Description = Usługa Windows Update zakończyła działanie; wystąpił następujący błąd: %%-2147014874 Error - 2014-12-10 17:36:30 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7023 Description = Usługa Windows Update zakończyła działanie; wystąpił następujący błąd: %%-2147014874 Error - 2014-12-10 17:42:12 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: cdrom Error - 2014-12-10 17:44:19 | Computer Name = Witek-Komputer | Source = Service Control Manager | ID = 7023 Description = Usługa Windows Update zakończyła działanie; wystąpił następujący błąd: %%-2147014874 < End of report >