OTL Extras logfile created on: 2014-06-25 15:47:15 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Patrycja\Desktop\OTL Professional (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,87 Gb Total Physical Memory | 1,22 Gb Available Physical Memory | 65,02% Memory free 3,75 Gb Paging File | 3,04 Gb Available in Paging File | 81,04% Paging File free Paging file location(s): c:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 48,73 Gb Total Space | 10,48 Gb Free Space | 21,50% Space Free | Partition Type: NTFS Drive D: | 79,16 Gb Total Space | 68,45 Gb Free Space | 86,46% Space Free | Partition Type: NTFS Drive E: | 104,89 Gb Total Space | 54,88 Gb Free Space | 52,32% Space Free | Partition Type: NTFS Computer Name: MACIEK-KOMPUTER | User Name: Patrycja | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-229973720-4146371379-1289688960-1003\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1E3C9A02-20A5-4303-B75A-E88A5A863B92}" = lport=10243 | protocol=6 | dir=in | app=system | "{2321ADC3-BB83-4549-887D-97174B0BA8FF}" = rport=139 | protocol=6 | dir=out | app=system | "{3413A40C-75CB-4721-8E86-BE5FBC9BA678}" = lport=137 | protocol=17 | dir=in | app=system | "{3F38D53C-0C0C-4FE1-95AA-99E5698DABA0}" = lport=445 | protocol=6 | dir=in | app=system | "{51386FD7-28D0-4A53-9594-B17A0A33468E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{583BE330-67DC-40B9-B3CD-70AD00B01C5A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{5A2B183F-FD93-40A2-A83F-47E5DC5B1B44}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{666BC877-2D73-4936-9FC9-7CEEA3A17155}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{794C6656-309D-4ACA-909B-3D1AB96B7011}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7958AA6C-95C3-40F7-B9BD-9ADFD53381A2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7F1FDACE-6949-45A1-ADB5-5AD97FA5914C}" = rport=137 | protocol=17 | dir=out | app=system | "{81D8D91A-21B3-42FC-B802-1B227BE83718}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A872F1C9-6B33-48FB-BE2B-51C19BFADF45}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B8018B81-F2FC-401E-8436-B43FA02A81E9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BDD90336-B07F-4AA7-AE44-1F53BF5247B1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C5781B38-70AE-409D-95BF-EDB92A630DCD}" = lport=2869 | protocol=6 | dir=in | app=system | "{C9DE4BC2-22B4-4E11-B897-9444147235AA}" = lport=139 | protocol=6 | dir=in | app=system | "{CBDE7844-5265-4EF4-915B-C920BC97DCCA}" = rport=445 | protocol=6 | dir=out | app=system | "{D7FED889-366C-4B68-975A-0CDD918AC115}" = lport=138 | protocol=17 | dir=in | app=system | "{DD7C37F0-E841-4F71-A579-2F985E1463A3}" = rport=138 | protocol=17 | dir=out | app=system | "{E19A12CE-C535-4421-AD85-C9F6BC271CBA}" = rport=10243 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{2834BC7E-23A4-4DA2-A51B-F591819C44FA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{2C3EB473-F852-409B-885A-B3AACAC0EA00}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{33BA41A6-A145-4182-9ED6-A4866042313D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{3497958B-640D-484D-A60D-F4A84226EB2F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{5838746C-9D56-4621-B01A-7A2EA5881DA8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{65E84061-45A4-4E91-8F06-2ABA72F94108}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7FBAA62D-D663-47A2-ACB4-43222DB9F4AB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{88C9A8DF-48BE-4722-92BE-9D0BACA45D22}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{8F41B263-CAF9-421E-B6F1-1FF00A8132B9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{9E78A1D2-CFBB-417F-B785-7E5312909F18}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A077EE47-B74E-47B8-BE51-06E8645F10B7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{AF10B367-6D22-4226-A7BB-9FDD1A643D58}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{AF27A947-C28D-47FD-8798-5CF269DE3439}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{CC09A074-413D-4A6B-9A93-0ADBB33BB5EF}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{CEE61E3B-C01C-4E49-A0FA-F22579E0365B}" = protocol=6 | dir=out | app=system | "{D1BEAD13-0742-40A9-B7BC-7AA9E70AFBC9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D2067C31-E9D8-4213-8DDC-E1BB993E1BC0}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{DB197A75-B597-4E49-A7ED-0D5CBA4BD707}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E94CB1F9-81DB-4E52-90E2-92D20CB362E8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{4B67E9AB-2139-418F-B3B8-A2B65D0CC876}C:\program files\unified remote\remoteserver.exe" = protocol=6 | dir=in | app=c:\program files\unified remote\remoteserver.exe | "TCP Query User{51C84D1A-FC5E-40A8-9A1D-8859FB000D45}C:\program files\unified remote\remoteserver.exe" = protocol=6 | dir=in | app=c:\program files\unified remote\remoteserver.exe | "TCP Query User{766AA191-3B68-4094-AEB7-C7D6F43BA0A0}C:\users\patrycja\appdata\roaming\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\users\patrycja\appdata\roaming\bittorrent\bittorrent.exe | "UDP Query User{1D462FD5-A0AF-49C9-BA5E-35B2B6F271EE}C:\users\patrycja\appdata\roaming\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\users\patrycja\appdata\roaming\bittorrent\bittorrent.exe | "UDP Query User{BA63F782-55A1-48FD-8DB9-372A29273053}C:\program files\unified remote\remoteserver.exe" = protocol=17 | dir=in | app=c:\program files\unified remote\remoteserver.exe | "UDP Query User{C1E779D6-6E65-4204-8F83-7B56E5B3DBDF}C:\program files\unified remote\remoteserver.exe" = protocol=17 | dir=in | app=c:\program files\unified remote\remoteserver.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{319D91C6-3D44-436C-9F79-36C0D22372DC}" = TP-LINK Wireless Configuration Utility "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{38A1E3ED-D913-41D2-9953-A93D5ACE3ADF}" = TP-LINK 150Mbps Wireless N USB Adapter Driver "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3DE92282-CB49-434F-81BF-94E5B380E889}" = The Sims™ 3 Cztery pory roku "{5C19E2DC-4CCF-3114-B40A-6E565987025F}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16 "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.07) - Polish "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3 "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{F9CFFF94-4077-417B-87B0-C5B75F5D7707}" = Unified Remote "Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin "Canon My Image Garden" = Canon My Image Garden "Canon My Image Garden Design Files" = Canon My Image Garden Design Files "CanonMyPrinter" = Canon My Printer "CCleaner" = CCleaner "CPUID CPU-Z_is1" = CPUID CPU-Z 1.69.2 "Defraggler" = Defraggler "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Mozilla Firefox 30.0 (x86 pl)" = Mozilla Firefox 30.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "Picasa 3" = Picasa 3 "UltraISO_is1" = UltraISO Premium V9.53 "VLC media player" = VLC media player 2.1.3 "webget" = webget "WinRAR archiver" = WinRAR 5.01 (32-bitowy) "Wise Registry Cleaner_is1" = Wise Registry Cleaner 8.12 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-229973720-4146371379-1289688960-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "BitTorrent" = BitTorrent "Google+ Auto Backup" = Google+ Auto Backup [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-06-20 10:12:20 | Computer Name = Maciek-Komputer | Source = ESENT | ID = 455 Description = Windows (2704) Windows: Wystąpił błąd -1811 podczas otwierania pliku dziennika C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0000D.log. Error - 2014-06-20 10:12:21 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 9000 Description = Error - 2014-06-20 10:12:21 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 7040 Description = Error - 2014-06-20 10:12:21 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 7042 Description = Error - 2014-06-20 10:12:21 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 9002 Description = Error - 2014-06-20 10:12:21 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 3029 Description = Error - 2014-06-20 10:12:21 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 3029 Description = Error - 2014-06-20 10:12:21 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 3028 Description = Error - 2014-06-20 10:12:22 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 3058 Description = Error - 2014-06-20 10:12:22 | Computer Name = Maciek-Komputer | Source = Windows Search Service | ID = 7010 Description = [ System Events ] Error - 2014-06-23 14:59:44 | Computer Name = Maciek-Komputer | Source = Server | ID = 2505 Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{43EA2D9D-0E1C-4AEC-BAED-2F5B9581A08B}, ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera. Error - 2014-06-23 14:59:44 | Computer Name = Maciek-Komputer | Source = NetBT | ID = 4321 Description = Nie można zarejestrować nazwy „MACIEK-KOMPUTER:20” w interfejsie o adresie IP 192.168.1.103. Komputer o adresie IP 192.168.1.101 nie zezwolił na przejęcie tej nazwy przez ten komputer. Error - 2014-06-23 15:17:18 | Computer Name = Maciek-Komputer | Source = Server | ID = 2505 Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{43EA2D9D-0E1C-4AEC-BAED-2F5B9581A08B}, ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera. Error - 2014-06-23 15:17:18 | Computer Name = Maciek-Komputer | Source = NetBT | ID = 4321 Description = Nie można zarejestrować nazwy „MACIEK-KOMPUTER:0” w interfejsie o adresie IP 192.168.1.103. Komputer o adresie IP 192.168.1.101 nie zezwolił na przejęcie tej nazwy przez ten komputer. Error - 2014-06-23 15:17:18 | Computer Name = Maciek-Komputer | Source = NetBT | ID = 4321 Description = Nie można zarejestrować nazwy „MACIEK-KOMPUTER:20” w interfejsie o adresie IP 192.168.1.103. Komputer o adresie IP 192.168.1.101 nie zezwolił na przejęcie tej nazwy przez ten komputer. Error - 2014-06-24 15:55:13 | Computer Name = Maciek-Komputer | Source = NetBT | ID = 4321 Description = Nie można zarejestrować nazwy „MACIEK-KOMPUTER:0” w interfejsie o adresie IP 192.168.1.102. Komputer o adresie IP 192.168.1.101 nie zezwolił na przejęcie tej nazwy przez ten komputer. Error - 2014-06-24 15:55:24 | Computer Name = Maciek-Komputer | Source = Server | ID = 2505 Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{43EA2D9D-0E1C-4AEC-BAED-2F5B9581A08B}, ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera. Error - 2014-06-24 15:55:24 | Computer Name = Maciek-Komputer | Source = NetBT | ID = 4321 Description = Nie można zarejestrować nazwy „MACIEK-KOMPUTER:20” w interfejsie o adresie IP 192.168.1.102. Komputer o adresie IP 192.168.1.101 nie zezwolił na przejęcie tej nazwy przez ten komputer. Error - 2014-06-25 09:45:27 | Computer Name = Maciek-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 15:43:25 na ?2014-?06-?25 było nieoczekiwane. Error - 2014-06-25 09:45:32 | Computer Name = Maciek-Komputer | Source = BugCheck | ID = 1001 Description = < End of report >