OTL Extras logfile created on: 2013-09-06 04:04:14 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Właściciel.SICIAK-EF1F1335\Pulpit\dezyn Windows XP Home Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,31 Gb Available Physical Memory | 65,65% Memory free 3,85 Gb Paging File | 3,22 Gb Available in Paging File | 83,60% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 58,59 Gb Total Space | 6,29 Gb Free Space | 10,73% Space Free | Partition Type: NTFS Drive D: | 87,89 Gb Total Space | 87,65 Gb Free Space | 99,73% Space Free | Partition Type: NTFS Drive E: | 86,39 Gb Total Space | 83,40 Gb Free Space | 96,53% Space Free | Partition Type: NTFS Unable to calculate disk information. Drive J: | 3,72 Gb Total Space | 3,72 Gb Free Space | 99,99% Space Free | Partition Type: FAT32 Computer Name: SICIAK-EF1F1335 | User Name: Właściciel | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l [HKEY_USERS\S-1-5-21-448539723-838170752-839522115-1003\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- "C:\Documents and Settings\Właściciel.SICIAK-EF1F1335\Dane aplikacji\File Scout\filescout.exe" /open "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe -- (NVIDIA Corporation) "C:\Games\World_of_Tanks\WorldOfTanks.exe" = C:\Games\World_of_Tanks\WorldOfTanks.exe:*:Enabled:World of Tanks -- (Wargaming.net) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp "{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch "{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21 "{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg "{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan "{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing "{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.5 "{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport "{5783F2D7-0201-0415-0002-0060B0CE6BBA}" = AutoCAD 2004 "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{706BB40A-4102-4c89-8107-DC68C4EBD19B}" = HP Deskjet All-In-One Software 9.0 "{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01 "{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update "{90120000-0010-0415-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Polish) 12 "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery "{A3FD0CA9-884F-4525-97B8-0AE6179302E6}" = F2100 "{A9C365A3-06C0-43b4-A2DB-EDF0A6079AA9}" = DJ_AIO_Software "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0 "{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant "{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 306.81 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 306.81 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.28 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.12.0604 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B4B1F18B-5CED-4f8f-8A8F-1BD0503C222E}" = DJ_AIO_ProductContext "{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter "{CDC7BEC8-D631-4e36-81D7-FC3689209AA6}" = F2100_Help "{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component "{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm "{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox "{EB48851B-96A4-489f-9F95-29F3731E9764}" = F2100_doccd "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F56D6F46-1D62-4734-BF12-6457A1ED17BD}" = DJ_AIO_Software_min "{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27) "{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE "{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "ALLPlayer_is1" = ALLPlayer V5.X "Autodesk Express Viewer" = Autodesk Express Viewer "CdaC13Ba" = SafeCast Shared Components "DC-Bass Source" = DC-Bass Source 1.3.0 "DokanLibrary" = Dokan Library 0.6.0 "DownLite" = DownLite "ENTERPRISE" = Microsoft Office Enterprise 2007 "Google Chrome" = Google Chrome "HaaliMkx" = Haali Media Splitter "hosts" = hosts "HP Imaging Device Functions" = HP Imaging Device Functions 9.0 "HP Photosmart Essential" = HP Photosmart Essential 2.01 "HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0 "HPExtendedCapabilities" = HP Customer Participation Program 9.0 "KLiteCodecPack_is1" = K-Lite Codec Pack 9.6.5 (Standard) "LAME_is1" = LAME v3.99.3 (for Windows) "LazyCam 3.00.2" = LazyCam 3.00.2 "Mach3" = Mach3 "NVIDIA Drivers" = NVIDIA Drivers "OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter 1.0.0.5 "PunkBusterSvc" = PunkBuster Services "QType" = Quickly type(english) "Usbfix" = UsbFix By El Desaparecido "WinRAR archiver" = WinRAR 4.20 (32-bitowy) "WinZipper" = WinZipper "Xvid Video Codec 1.3.2" = Xvid Video Codec [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-448539723-838170752-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "2750411996.portal.qtrax.com" = Qtrax Player "DSite" = Update for Ultimate Codec [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-09-04 13:30:56 | Computer Name = SICIAK-EF1F1335 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd wins.exe, wersja 13.8.19.1, moduł powodujący błąd wins.exe, wersja 13.8.19.1, adres błędu 0x000216a4. Error - 2013-09-04 13:31:01 | Computer Name = SICIAK-EF1F1335 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd wins.exe, wersja 13.8.19.1, moduł powodujący błąd wins.exe, wersja 13.8.19.1, adres błędu 0x000216a4. Error - 2013-09-04 15:12:30 | Computer Name = SICIAK-EF1F1335 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca chrome.exe, wersja 29.0.1547.66, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2013-09-05 11:51:37 | Computer Name = SICIAK-EF1F1335 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd ati2avxx.exe, wersja 0.0.0.0, moduł powodujący błąd , wersja 0.0.0.0, adres błędu 0x00000000. Error - 2013-09-05 13:32:14 | Computer Name = SICIAK-EF1F1335 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.2180, moduł powodujący błąd , wersja 0.0.0.0, adres błędu 0x00000000. Error - 2013-09-05 17:32:36 | Computer Name = SICIAK-EF1F1335 | Source = LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Kod błędu to pierwszy wpis DWORD w sekcji danych (Data). Error - 2013-09-05 17:32:39 | Computer Name = SICIAK-EF1F1335 | Source = LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika dla języka o identyfikatorze 009. Stan Win32 zwrócony przez to wywołanie stanowi pierwszą wartość DWORD w sekcji danych (Data). Error - 2013-09-05 21:13:24 | Computer Name = SICIAK-EF1F1335 | Source = LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Kod błędu to pierwszy wpis DWORD w sekcji danych (Data). Error - 2013-09-05 21:13:27 | Computer Name = SICIAK-EF1F1335 | Source = LoadPerf | ID = 3006 Description = Nie można odczytać ciągów licznika dla języka o identyfikatorze 009. Stan Win32 zwrócony przez to wywołanie stanowi pierwszą wartość DWORD w sekcji danych (Data). Error - 2013-09-05 21:54:00 | Computer Name = SICIAK-EF1F1335 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd ati2avxx.exe, wersja 0.0.0.0, moduł powodujący błąd , wersja 0.0.0.0, adres błędu 0x00000000. [ System Events ] Error - 2013-09-05 13:50:06 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7034 Description = Usługa PnkBstrA niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2013-09-05 13:50:06 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7034 Description = Usługa DokanMounter niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2013-09-05 13:50:06 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7034 Description = Usługa Java Quick Starter niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2013-09-05 13:50:06 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7034 Description = Usługa NVIDIA Update Service Daemon niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2013-09-05 13:50:06 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7034 Description = Usługa Tor Win32 Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2013-09-05 13:56:34 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2013-09-05 17:32:19 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2013-09-05 21:06:42 | Computer Name = SICIAK-EF1F1335 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.10 dla karty sieciowej o adresie 001A4DFDA959 został zabroniony przez serwer DHCP 192.168.1.1 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2013-09-05 21:14:20 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2013-09-05 22:00:37 | Computer Name = SICIAK-EF1F1335 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 < End of report >