OTL Extras logfile created on: 2010-12-06 21:47:34 - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = F:\ Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18975) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 72,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 104,75 Gb Total Space | 63,01 Gb Free Space | 60,15% Space Free | Partition Type: NTFS Drive E: | 44,29 Gb Total Space | 33,10 Gb Free Space | 74,72% Space Free | Partition Type: NTFS Drive F: | 7,45 Gb Total Space | 5,32 Gb Free Space | 71,37% Space Free | Partition Type: FAT32 Computer Name: VISTA | User Name: INSTALATOR | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 "" = [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{270FF344-86E5-4CF7-8BDE-3DD5A6022D67}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{72055970-FA57-4E24-B15C-8308E3B36029}" = protocol=6 | dir=in | app=c:\program files\tightvnc\vncviewer.exe | "{7723531D-6653-4752-B71D-99AA9ADA3548}" = protocol=17 | dir=in | app=c:\program files\tightvnc\vncviewer.exe | "{78BBF456-9455-475A-9DCB-1F15C0CF521A}" = protocol=6 | dir=in | app=c:\program files\tightvnc\tvnserver.exe | "{AA495010-C286-4D08-82DD-061838CFF8AA}" = protocol=17 | dir=in | app=c:\program files\tightvnc\tvnserver.exe | "TCP Query User{2BE2CE1D-1AE9-4A9C-94F7-98805AFF9A54}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{4EF5F661-1368-413D-9A61-2E88A8B171D4}C:\program files\voipdiscount.com\voipdiscount\voipdiscount.exe" = protocol=6 | dir=in | app=c:\program files\voipdiscount.com\voipdiscount\voipdiscount.exe | "UDP Query User{865A8AB2-AA97-4BF3-A60D-79CA24AB00B9}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{8A4DF279-ADDB-4062-BDFD-865795D1EA4B}C:\program files\voipdiscount.com\voipdiscount\voipdiscount.exe" = protocol=17 | dir=in | app=c:\program files\voipdiscount.com\voipdiscount\voipdiscount.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20C85B0A-412C-4E0E-8B1D-DDF88993FB57}" = Type2000 TWAIN Driver Ver.4 "{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17 "{43CF15E8-E3CF-4BCF-8AAC-19162268276A}_3.9.2.1_is1" = ScanSpyware 3.9.2.1 "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis "{4E837999-05BB-48FE-BC83-3B73FFDF40CA}" = OpenOffice.org 2.3 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_PROHYBRIDR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_PROHYBRIDR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_PROHYBRIDR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_PROHYBRIDR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_PROHYBRIDR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_PROHYBRIDR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_PROHYBRIDR_{E9EA2604-8AC9-47D2-8F4B-6BF60787A357}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_PROHYBRIDR_{D45F91DE-F0FC-4D5F-9A0C-FDE5B251AAC6}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00B1-0415-0000-0000000FF1CE}" = Dodatek Zapisywanie jako XPS firmy Microsoft dla programów pakietu Microsoft Office 2007 "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007 "{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010 "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A35883BD-9C83-4625-82F3-90F86728C662}" = FreeUndelete "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-A93000000001}" = Adobe Reader 9.3.1 - Polish "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update "{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime "{C138D676-4F0F-4FDE-8BE5-26CFD3566DCD}" = DeskTopBinder - SmartDeviceMonitor for Client "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint "{DD30D7C5-DD1A-46E7-9CA6-03CF6A398990}" = DeskTopBinder Lite "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "avast5" = avast! Pro Antivirus "CCleaner" = CCleaner "Gadu-Gadu 10" = Gadu-Gadu 10 "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010 "ipla" = ipla 2.1.1 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6)" = Mozilla Firefox (3.6) "PROHYBRIDR" = 2007 Microsoft Office system "TightVNC" = TightVNC 2.0.2 "Totalcmd" = Total Commander (Remove or Repair) "VoipDiscount_is1" = VoipDiscount "WheelMouse" = iWheelZoom 7.80 "WinRAR archiver" = Archiwizator WinRAR [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2010-12-05 16:04:13 | Computer Name = VISTA | Source = VSS | ID = 8194 Description = Error - 2010-12-05 16:37:48 | Computer Name = VISTA | Source = Wininit | ID = 1015 Description = Błąd krytycznego procesu systemowego C:\Windows\system32\lsm.exe z kodem stanu 1. Komputer musi być ponownie uruchomiony. Error - 2010-12-05 16:38:15 | Computer Name = VISTA | Source = EventSystem | ID = 4609 Description = Error - 2010-12-05 16:46:49 | Computer Name = VISTA | Source = Microsoft-Windows-CAPI2 | ID = 131584 Description = Error - 2010-12-05 16:50:29 | Computer Name = VISTA | Source = EventSystem | ID = 4609 Description = Error - 2010-12-05 16:56:49 | Computer Name = VISTA | Source = System Restore | ID = 8193 Description = Error - 2010-12-06 15:09:50 | Computer Name = VISTA | Source = EventSystem | ID = 4609 Description = Error - 2010-12-06 16:09:55 | Computer Name = VISTA | Source = EventSystem | ID = 4609 Description = Error - 2010-12-06 16:11:28 | Computer Name = VISTA | Source = EventSystem | ID = 4609 Description = Error - 2010-12-06 16:30:13 | Computer Name = VISTA | Source = EventSystem | ID = 4609 Description = [ Media Center Events ] Error - 2008-04-17 04:53:01 | Computer Name = VISTA | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: nie można pobrać pakietu MCESpotlight. Error - 2008-08-06 06:55:14 | Computer Name = VISTA | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: nie można pobrać pakietu MCESpotlight. [ OSession Events ] Error - 2010-04-20 03:52:28 | Computer Name = VISTA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 2204 seconds with 600 seconds of active time. This session ended with a crash. Error - 2010-04-27 03:39:18 | Computer Name = VISTA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 294 seconds with 240 seconds of active time. This session ended with a crash. Error - 2010-07-26 08:56:04 | Computer Name = VISTA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6535.5002, Microsoft Office Version: 12.0.6425.1000. This session lasted 671 seconds with 600 seconds of active time. This session ended with a crash. [ System Events ] Error - 2010-12-06 15:10:14 | Computer Name = VISTA | Source = Service Control Manager | ID = 7001 Description = Error - 2010-12-06 15:10:14 | Computer Name = VISTA | Source = Service Control Manager | ID = 7026 Description = Error - 2010-12-06 15:32:17 | Computer Name = VISTA | Source = Dhcp | ID = 1002 Description = Serwer DHCP 0.0.0.0 odmówił dzierżawy adresu IP 192.168.2.100 dla karty sieciowej o adresie 00304F3B4BFD. (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2010-12-06 16:04:45 | Computer Name = VISTA | Source = Service Control Manager | ID = 7030 Description = Error - 2010-12-06 16:10:20 | Computer Name = VISTA | Source = Service Control Manager | ID = 7030 Description = Error - 2010-12-06 16:30:05 | Computer Name = VISTA | Source = DCOM | ID = 10005 Description = Error - 2010-12-06 16:30:13 | Computer Name = VISTA | Source = DCOM | ID = 10005 Description = Error - 2010-12-06 16:30:16 | Computer Name = VISTA | Source = DCOM | ID = 10005 Description = Error - 2010-12-06 16:30:50 | Computer Name = VISTA | Source = Service Control Manager | ID = 7001 Description = Error - 2010-12-06 16:30:50 | Computer Name = VISTA | Source = Service Control Manager | ID = 7026 Description = < End of report >