OTL Extras logfile created on: 08/02/2012 17:04:31 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Andrzej\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1.94 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 45.99% Memory free 4.11 Gb Paging File | 3.05 Gb Available in Paging File | 74.40% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 137.52 Gb Total Space | 99.76 Gb Free Space | 72.54% Space Free | Partition Type: NTFS Drive D: | 11.53 Gb Total Space | 1.36 Gb Free Space | 11.76% Space Free | Partition Type: NTFS Computer Name: ANDRZEJ-PC | User Name: Andrzej | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3618770030-2689959888-2769995599-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04F37E9B-95A9-4956-A065-2B307F20DA94}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{1CB07B66-D6E8-4585-9925-26940AC84BB0}" = protocol=17 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zseaf.tmp\symnrt.exe | "{36409F86-A6D2-45D2-9BE5-EFD1AC64413C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{40CAB336-B0A5-410A-A6E0-17B4FBD42F9F}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{421FA468-7C5C-4130-9E23-2DAA196F08A7}" = protocol=17 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zscf20.tmp\symnrt.exe | "{4912F982-69CF-4703-8944-2FF70C5FBEC8}" = protocol=6 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zsc3cc.tmp\symnrt.exe | "{67EED7DB-DD87-43A4-ADD4-7F4848BD017E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{73397346-CD6A-448D-8AB9-543A7F265071}" = protocol=6 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zs3f02.tmp\symnrt.exe | "{844F7DA1-4567-4C5D-8E18-535E0472DCAA}" = protocol=6 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zs5013.tmp\symnrt.exe | "{9231F702-C54D-4CE3-A026-EF17280EB55F}" = protocol=6 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zscf20.tmp\symnrt.exe | "{9A566C62-21A7-4580-89C7-FB27C90FE1E8}" = protocol=17 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zsc3cc.tmp\symnrt.exe | "{9F043B7E-D57E-4644-8285-6E096F44EB5A}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | "{BEE2A9F0-3323-474E-A75B-433435B538BC}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | "{DB6324DB-F5B7-45A7-B33A-E54ACC814C94}" = protocol=17 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zs2fe6.tmp\symnrt.exe | "{DC4DBB6F-6589-4840-AE63-E40485465F83}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{E790FEC8-A077-469F-A761-5E09353443A4}" = protocol=17 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zs3f02.tmp\symnrt.exe | "{EB6FA5DA-A5D4-47DC-A148-30617BAB2F91}" = protocol=17 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zs5013.tmp\symnrt.exe | "{EE03C472-8724-43C8-B952-0524FCA02506}" = protocol=6 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zseaf.tmp\symnrt.exe | "{F41ECE71-C64E-4922-8123-95BA4AE84324}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe | "{F7BBB7FD-60BF-4059-BFA5-2F8FD96A5ABA}" = protocol=6 | dir=in | app=c:\users\andrzej\appdata\local\temp\7zs2fe6.tmp\symnrt.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update "{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works "{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check "{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java(TM) 6 Update 30 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program "{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 D2 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.6 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check "{68471BF2-F1F7-4C89-BBBA-400B94996596}" = ESU for Microsoft Vista "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0 "{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor "{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{E6D3A461-8DDE-45C9-8C34-A33436FCC0B4}" = HP User Guides 0091 "{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "avast" = avast! Free Antivirus "CNXT_AUDIO_HDA" = Conexant HD Audio "CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Mozilla Firefox 10.0 (x86 pl)" = Mozilla Firefox 10.0 (x86 pl) "NVIDIA Drivers" = NVIDIA Drivers "Revo Uninstaller" = Revo Uninstaller 1.93 "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4 "SynTPDeinstKey" = Synaptics Pointing Device Driver "ViewpointMediaPlayer" = Viewpoint Media Player "WildTangent hp Master Uninstall" = My HP Games [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 08/02/2012 07:05:00 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 07:05:01 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 07:16:44 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 07:16:44 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 08:04:48 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 08:04:52 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 08:13:59 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 08:14:40 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 08:16:07 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 08/02/2012 08:26:28 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = [ System Events ] Error - 07/02/2012 20:52:16 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-Servicing | ID = 4385 Description = Error - 07/02/2012 20:52:16 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-Servicing | ID = 4385 Description = Error - 07/02/2012 20:52:16 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-Servicing | ID = 4375 Description = Error - 07/02/2012 20:52:16 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-Servicing | ID = 4375 Description = Error - 07/02/2012 20:52:16 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-Servicing | ID = 4375 Description = Error - 07/02/2012 20:52:16 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-Servicing | ID = 4375 Description = Error - 07/02/2012 20:57:23 | Computer Name = Andrzej-PC | Source = Microsoft-Windows-Kernel-WHEA | ID = 6 Description = Error - 07/02/2012 21:03:47 | Computer Name = Andrzej-PC | Source = DCOM | ID = 10010 Description = Error - 08/02/2012 03:02:59 | Computer Name = Andrzej-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 02:07:23 on 08/02/2012 was unexpected. Error - 08/02/2012 03:04:07 | Computer Name = Andrzej-PC | Source = Service Control Manager | ID = 7000 Description = < End of report >