OTL Extras logfile created on: 2012-09-26 18:52:21 - Run 2 OTL by OldTimer - Version 3.2.68.0 Folder = C:\Users\Sylwia i Mateusz\Desktop 64bit-Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 2,60 Gb Available Physical Memory | 64,93% Memory free 8,17 Gb Paging File | 6,75 Gb Available in Paging File | 82,66% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 112,63 Gb Total Space | 26,88 Gb Free Space | 23,87% Space Free | Partition Type: NTFS Drive D: | 185,46 Gb Total Space | 176,35 Gb Free Space | 95,09% Space Free | Partition Type: NTFS Computer Name: SYLWIAIMATEU-PC | User Name: Sylwia i Mateusz | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\S-1-5-21-302822950-2560111836-3072577246-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML.R65E4HYXABJXM5M22YTHN467XA] -- "C:\Users\Sylwia i Mateusz\AppData\Local\Google\Chrome\Application\chrome.exe.exe" -- "%1" [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" () InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l InternetShortcut [print] -- rundll32.exe C:\Windows\system32\mshtml.dll,PrintHTML "%1" () piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = E1 0B B4 13 DC 5B C8 01 [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "oobe_av" = 1 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{E6F06B7D-943D-4ACF-9775-2912E606C596}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05D2AD94-BA7F-4620-9149-8418B2B78511}" = protocol=6 | dir=in | app=c:\program files (x86)\firebird\firebird_2_0\bin\isql.exe | "{06583046-165D-4FE0-A724-E7DFFDB7EA43}" = protocol=6 | dir=in | app=c:\users\sylwia i mateusz\appdata\local\temp\~os9878.tmp\rlvknlg.exe | "{0A39A819-C84F-49ED-A9A9-BEC5B02DC5B1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{27CF7789-783D-4A9F-BE34-69C3B9CBD668}" = protocol=17 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe | "{37BBFB15-A781-4FCC-873F-626EBE34BCEF}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe | "{3D5B4BF9-109B-41C2-9710-F16BA4F4C996}" = protocol=17 | dir=in | app=c:\program files (x86)\adobe\acrobat 6.0\reader\plug_ins\printme\consoleapp.exe | "{598104EF-C316-49A9-BB66-113E8F237649}" = protocol=6 | dir=in | app=c:\users\sylwia i mateusz\appdata\local\temp\~osfbcc.tmp\rlvknlg.exe | "{62BFD8F2-CFEA-4B36-97C1-D42E6521F01A}" = protocol=6 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe | "{68E423D5-558A-4820-98E0-091911D46739}" = protocol=6 | dir=in | app=c:\users\sylwia i mateusz\appdata\local\temp\~ose4f2.tmp\rlvknlg.exe | "{6959D374-27F2-40AB-8312-66E053C66ED5}" = protocol=17 | dir=in | app=c:\program files (x86)\firebird\firebird_2_0\bin\isql.exe | "{6F377CD1-4E75-4019-B6E4-13D33B18828C}" = protocol=6 | dir=in | app=c:\program files (x86)\firebird\firebird_2_0\unins000.exe | "{7D22B6CA-815D-45C2-B7AD-4BD080CB5591}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe | "{9299A0DE-0A61-4FBC-BA67-38692FF85164}" = protocol=6 | dir=in | app=c:\users\sylwia i mateusz\appdata\local\temp\~os312e.tmp\rlvknlg.exe | "{A6A0D17D-A740-4E70-9B19-B202DA487F19}" = protocol=17 | dir=in | app=c:\program files (x86)\firebird\firebird_2_0\unins000.exe | "{ACA4763F-9108-42F0-B7B0-B5DF3F90535A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{AE154CE7-B426-4826-9E7E-9472B20F0DC7}" = protocol=6 | dir=in | app=c:\users\sylwia i mateusz\appdata\local\temp\~os8e3a.tmp\rlvknlg.exe | "{B154F175-B9A3-4B0F-A7B8-B82539F13E9C}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{B84C89EF-6909-4B7E-A3DB-D3125A189ED2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{BC4EAD0C-9D57-4D7A-B3D0-13C8A99DBF4D}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{D02E6EF9-9817-488A-9885-453729DB55F4}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{D7B29B32-E3DB-4CD2-9E15-27A1037C1DA8}" = protocol=6 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe | "{F1C97B01-3D99-44A9-92DC-F6CB491C4D2F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{F831226C-FA6C-41B2-8E84-C6E1A82D520E}" = protocol=17 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe | "{FC45886F-9796-4119-9362-3B7766E3790F}" = protocol=6 | dir=in | app=c:\program files (x86)\adobe\acrobat 6.0\reader\plug_ins\printme\consoleapp.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0C682623-8F66-46A8-B9B3-93FE1E66A001}" = iTunes "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2 "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64 "{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}" = PaperPort Image Printer 64-bit "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "NVIDIA Drivers" = NVIDIA Drivers "WinRAR archiver" = Archiwizator WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0141D498-16DA-4221-A529-1D7A64BE8B05}" = OpenOffice.org 3.3 "{0A795E81-7E99-4574-923D-8A0AF1F11CA1}" = ScanSoft PaperPort 11 "{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java(TM) 6 Update 35 "{2D10FC46-1D96-44C4-8855-85F21B9B011E}" = Ovi Desktop Sync Engine "{3A08B59E-A9F0-4F4D-B7E5-6875D7F13327}" = Brother MFL-Pro Suite MFC-250C "{3BD98AAF-61B5-46E0-A6C8-593C242C7C48}" = TP-LINK Wireless Client Utility "{41CC8FAF-B177-4AB0-8572-D37534D8941B}" = IC_Katalog Framework "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{AB3F9176-E74A-4F28-9A09-4F22349B145E}" = livebox tp "{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1 "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86 "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{d08d9f98-1c78-4704-87e6-368b0023d831}" = RelevantKnowledge "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{EFA6E481-DB55-475D-8B89-EA9A9F903F52}" = Visual Prolog Examples "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F90D6825-8F1F-4E3A-9E42-A9C8A9DD1045}" = Nero 7 Essentials "{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package "{FF10D622-7BFE-48C6-8DF6-40D8CB1D3C1B}" = Тачки 2 "8461-7759-5462-8226" = Vuze "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "ALLPlayer_is1" = ALLPlayer V4.X "Audacity_is1" = Audacity 1.2.6 "BearShare" = BearShare "ENTERPRISE" = Microsoft Office Enterprise 2007 "EXPERTool_is1" = EXPERTool 7.0 "FBDBServer_2_0_is1" = Firebird 2.0.5.13206 (win32) "Gadu-Gadu 10" = Gadu-Gadu 10 "IC_Katalog" = IC_Katalog "IrfanView" = IrfanView (remove only) "Mozilla Thunderbird (7.0.1)" = Mozilla Thunderbird (7.0.1) "Mp3 Knife_is1" = Mp3 Knife 3.2 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-302822950-2560111836-3072577246-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-09-19 12:13:08 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-20 13:42:30 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-21 01:28:49 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-22 04:56:10 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-22 08:43:11 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-23 05:05:55 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-23 13:30:19 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-24 15:02:36 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-25 11:30:24 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-09-26 12:42:32 | Computer Name = SylwiaiMateu-PC | Source = WinMgmt | ID = 10 Description = [ OSession Events ] Error - 2011-06-24 15:22:36 | Computer Name = SylwiaiMateu-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 114 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 2012-09-23 05:04:24 | Computer Name = SylwiaiMateu-PC | Source = HTTP | ID = 15016 Description = Error - 2012-09-23 05:05:55 | Computer Name = SylwiaiMateu-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2012-09-23 13:29:12 | Computer Name = SylwiaiMateu-PC | Source = HTTP | ID = 15016 Description = Error - 2012-09-23 13:30:20 | Computer Name = SylwiaiMateu-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2012-09-24 15:01:12 | Computer Name = SylwiaiMateu-PC | Source = HTTP | ID = 15016 Description = Error - 2012-09-24 15:02:36 | Computer Name = SylwiaiMateu-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2012-09-25 11:28:53 | Computer Name = SylwiaiMateu-PC | Source = HTTP | ID = 15016 Description = Error - 2012-09-25 11:30:24 | Computer Name = SylwiaiMateu-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2012-09-26 12:41:05 | Computer Name = SylwiaiMateu-PC | Source = HTTP | ID = 15016 Description = Error - 2012-09-26 12:42:32 | Computer Name = SylwiaiMateu-PC | Source = Service Control Manager | ID = 7000 Description = < End of report >