OTL Extras logfile created on: 2012-08-09 16:36:10 - Run 1 OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\User\Desktop\Nowy folder Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,51 Gb Available Physical Memory | 75,53% Memory free 4,00 Gb Paging File | 3,52 Gb Available in Paging File | 88,13% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 37,57 Gb Total Space | 15,04 Gb Free Space | 40,05% Space Free | Partition Type: NTFS Drive D: | 195,31 Gb Total Space | 195,22 Gb Free Space | 99,95% Space Free | Partition Type: NTFS Drive K: | 953,19 Mb Total Space | 415,72 Mb Free Space | 43,61% Space Free | Partition Type: FAT Computer Name: USER-KOMPUTER | User Name: User | Logged in as Administrator. Boot Mode: SafeMode | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3894080676-3054358842-2607150260-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{154B1595-6F33-4104-B420-D5F381B4FDE4}" = lport=10243 | protocol=6 | dir=in | app=system | "{16340A8D-7646-46E9-AAB8-0EEC885F4FF3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1FE8152B-1032-4F41-9E70-0CAE0BE1E9AA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{21F5F5F9-E7DA-4D15-B32F-76D6B7038934}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2B0D11DC-BB57-4533-9D7C-5E2AE782257B}" = rport=445 | protocol=6 | dir=out | app=system | "{2BE987F1-6ED0-45F1-B1A1-6425EC6ED6EC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2E8CDB21-76F2-41B1-A1B9-B30FADAF3F38}" = lport=2869 | protocol=6 | dir=in | app=system | "{3D4FE7F2-7037-49AC-88A3-B7A855595046}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{623ECE27-3C96-4F91-A4F7-02138BAFFF61}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{72014F4F-825C-4038-81FD-962D5F03C4AA}" = rport=138 | protocol=17 | dir=out | app=system | "{78221E23-738F-412B-832F-31493A20A7F7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7AC213D1-28D4-4572-BD5F-B495DE328789}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{88FFFED5-8A33-44B1-B9D8-B1986C270ED1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8D6B936C-3297-459B-80E6-7D66892BA593}" = rport=137 | protocol=17 | dir=out | app=system | "{91B5C4F3-E86E-4DB0-B225-ACEB1E24AC16}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{A41897D9-21B4-4F74-8194-186ACC0850DF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B29822E0-933A-4550-BA3B-C42EEB86D0DD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{B759622B-C378-47CE-B30F-465B47BC2014}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C1336891-6FE0-4BFF-AC46-2D47922A30F1}" = rport=139 | protocol=6 | dir=out | app=system | "{C2FE533E-53F9-4D83-A301-8AA54D681AAB}" = rport=10243 | protocol=6 | dir=out | app=system | "{D169CC64-2ABF-4B36-AD2F-5FB674FFAA19}" = lport=139 | protocol=6 | dir=in | app=system | "{D675B7F9-8A4A-4ED7-8B97-86F8920168AE}" = lport=138 | protocol=17 | dir=in | app=system | "{DE75A7BB-3E3B-44CB-8ECF-E6FB5AE12F78}" = lport=445 | protocol=6 | dir=in | app=system | "{EEA15D7B-7A7E-4D3C-B629-21724D4CE80C}" = lport=137 | protocol=17 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{12424A12-0AFD-4C77-9AE6-A4AD40EBFFF1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{27AEBA9A-1DB4-4843-BFDB-5B872E93A22A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{3C451E1C-736D-4431-A5D8-7E56A8DDC952}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4876C77A-E12A-417A-A40D-1FC37220AB33}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{50918CF5-824C-4877-A481-4EF2E1A85A7F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{535F87AD-2071-44FF-92F6-7EF50B051879}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{74B8369B-5680-4BCD-94A1-A0507CEACCBF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7F3EB03E-AE25-4BB5-974A-3E54BCFCEE4B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7F76C275-F8E7-4B97-9421-2F298655C980}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{98FC4EEB-2C98-4DCB-9BB1-0925CC23E468}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A6FA7140-7F94-4219-9148-ABD1625FDD2C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A86C74C1-01AC-40C0-A86D-596CBF069DCB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{A948C31A-EAAA-415B-B449-48F64D3D5149}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{B12690EA-7B83-4C66-A637-C421BA3EC02D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{B1DA4C1E-5692-420E-AC46-CF6A4F1F374D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C0F26C58-3D95-448B-98E5-644FCAC11563}" = protocol=6 | dir=out | app=system | "{C3C35B78-9945-4E8F-AB1A-EFB2B3F34F6E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{C4E92EAB-D3E4-4294-BEA0-16374A5FBCDC}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{D039DAA7-F846-41F2-B9C7-FCA66E35D2F1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{E3AA93B6-602E-4A7D-9749-4741E0F50826}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "TCP Query User{7AB963B9-0BBA-4FF0-90A7-423004FE9504}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{C849B21D-F782-4AC7-8771-1600E0198008}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "TCP Query User{E794E274-7E26-438A-BE2A-BDC5E1BD4E8D}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "TCP Query User{F26CA9A6-710A-456C-9959-8280C14EE083}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{096009A3-2881-4703-AEEA-C5E67ABAEFCE}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | "UDP Query User{58692B8E-1460-4622-BB2D-42DEEC6F872D}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{75990488-BDAB-4B7E-9516-90560753AD01}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{ED78674D-7BF8-49E8-A3EA-F7D631A21903}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{644CEC11-C3D3-4F8D-A935-74F1EEF38209}" = ESET NOD32 Antivirus "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{AC76BA86-7AD7-1045-7B44-A90000000001}" = Adobe Reader 9 - Polish "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3 "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "ALLPlayer_is1" = ALLPlayer V4.X "COMODO GeekBuddy" = COMODO GeekBuddy "EADM" = EA Download Manager "ENTERPRISE" = Microsoft Office Enterprise 2007 "Gadu-Gadu 10" = Gadu-Gadu 10 "KLiteCodecPack_is1" = K-Lite Codec Pack 4.6.2 (Full) "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.62.0.1300 "Mozilla Firefox 14.0.1 (x86 pl)" = Mozilla Firefox 14.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Nero7Lite_is1" = Nero 7 Lite 7.7.5.1 "RealAlt_is1" = Real Alternative 2.0.2 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-08-08 17:59:45 | Computer Name = User-Komputer | Source = Software Protection Platform Service | ID = 8198 Description = Wystąpił błąd aktywacji licencji (slui.exe), kod błędu: 0x800401F9 Error - 2012-08-08 17:59:45 | Computer Name = User-Komputer | Source = Winlogon | ID = 4103 Description = Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x00000000. Error - 2012-08-09 02:54:33 | Computer Name = User-Komputer | Source = Software Protection Platform Service | ID = 8198 Description = Wystąpił błąd aktywacji licencji (slui.exe), kod błędu: 0x800401F9 Error - 2012-08-09 02:54:33 | Computer Name = User-Komputer | Source = Winlogon | ID = 4103 Description = Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x00000000. Error - 2012-08-09 10:12:07 | Computer Name = User-Komputer | Source = Software Protection Platform Service | ID = 8198 Description = Wystąpił błąd aktywacji licencji (slui.exe), kod błędu: 0x800401F9 Error - 2012-08-09 10:12:07 | Computer Name = User-Komputer | Source = Winlogon | ID = 4103 Description = Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x00000000. Error - 2012-08-09 10:14:04 | Computer Name = User-Komputer | Source = Software Protection Platform Service | ID = 8198 Description = Wystąpił błąd aktywacji licencji (slui.exe), kod błędu: 0x800401F9 Error - 2012-08-09 10:14:04 | Computer Name = User-Komputer | Source = Winlogon | ID = 4103 Description = Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x00000000. Error - 2012-08-09 10:18:02 | Computer Name = User-Komputer | Source = Software Protection Platform Service | ID = 8198 Description = Wystąpił błąd aktywacji licencji (slui.exe), kod błędu: 0x800401F9 Error - 2012-08-09 10:18:02 | Computer Name = User-Komputer | Source = Winlogon | ID = 4103 Description = Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x00000000. [ System Events ] Error - 2012-08-09 10:35:35 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-09 10:35:36 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-09 10:35:36 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-09 10:35:36 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-09 10:35:36 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-09 10:35:36 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-09 10:35:36 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 Error - 2012-08-09 10:35:40 | Computer Name = User-Komputer | Source = DCOM | ID = 10005 Description = Error - 2012-08-09 10:35:40 | Computer Name = User-Komputer | Source = DCOM | ID = 10005 Description = Error - 2012-08-09 10:35:40 | Computer Name = User-Komputer | Source = Service Control Manager | ID = 7001 Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji w sieci, której nie można uruchomić z powodu następującego błędu: %%1068 < End of report >