OTL Extras logfile created on: 2011-11-07 18:10:36 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\PC\Moje dokumenty\Downloads Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,24 Gb Total Physical Memory | 0,47 Gb Available Physical Memory | 37,98% Memory free 2,96 Gb Paging File | 2,29 Gb Available in Paging File | 77,19% Paging File free Paging file location(s): C:\pagefile.sys 1908 3816 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 19,53 Gb Total Space | 5,77 Gb Free Space | 29,55% Space Free | Partition Type: NTFS Drive D: | 17,73 Gb Total Space | 1,29 Gb Free Space | 7,26% Space Free | Partition Type: NTFS Drive F: | 939,16 Mb Total Space | 239,62 Mb Free Space | 25,51% Space Free | Partition Type: FAT32 Computer Name: PC-CFA2F2374BC2 | User Name: PC | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* [HKEY_USERS\S-1-5-21-1229272821-764733703-1177238915-1003\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- C:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDSee Pro 2.5.Browse] -- "C:\Program Files\ACD Systems\ACDSee Pro\2.5\ACDSeeQVPro25.exe" "%1" (ACD Systems) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\AVG\AVG8\avgam.exe" = C:\Program Files\AVG\AVG8\avgam.exe:*:Enabled:avgam.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\Nowe Gadu-Gadu\gg.exe" = C:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu -- (GG Network S.A.) "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Program Files\Easy Downloads\easydownloads.exe" = C:\Program Files\Easy Downloads\easydownloads.exe:*:Enabled:EasyDownloads -- (http://izloader.com/) "C:\Program Files\Easy Downloads\easydl.exe" = C:\Program Files\Easy Downloads\easydl.exe:*:Enabled:EasyDownloadsDL -- () [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{10110FE9-1EE8-4A3D-ADFD-1294F86BE5FC}" = Logitech QuickCam "{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0 "{2D95950E-6D76-43E7-94A5-D9DBA2FD29E4}" = ACDSee Pro 2.5 "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 J1 "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision "{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 C1 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0010-0415-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Polish) 12 "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00B2-0415-0000-0000000FF1CE}" = Dodatek Zapisywanie jako PDF lub XPS firmy Microsoft dla programów pakietu Microsoft Office 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{AC76BA86-7AD7-1045-7B44-A90000000001}" = Adobe Reader 9 - Polish "{AEE7FA17-11D2-3243-509B-29B594FC1045}" = Nero 7 Demo "{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component "{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator "{F246C2FF-7323-411E-9CE5-674D819FC80F}" = SecureW2 Enterprise Client 3.5.0 MSI Installer "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Agere Systems Soft Modem" = Agere Systems AC'97 Modem "AVG8Uninstall" = AVG 8.5 "BabylonToolbar" = Babylon toolbar on IE "CCleaner" = CCleaner "ENTERPRISE" = Microsoft Office Enterprise 2007 "HDMI" = Intel(R) Graphics Media Accelerator Driver "KLiteCodecPack_is1" = K-Lite Codec Pack 6.8.0 (Full) "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 1836) "Nowe Gadu-Gadu" = Nowe Gadu-Gadu "Picasa 3" = Picasa 3 "QcDrv" = Camera Driver "SubEdit-Player_is1" = SubEdit-Player "uTorrent" = µTorrent "vShare" = vShare Plugin "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "Winamp" = Winamp (remove only) "WinRAR archiver" = WinRAR archiver [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1229272821-764733703-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "EasyDownloads" = EasyDownloads - fastest downloads in two clicks! "Google Chrome" = Google Chrome [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2011-06-08 19:34:14 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 | ID = 2001 Description = Rejected Safe Mode action : Microsoft Office PowerPoint. Error - 2011-06-08 19:34:15 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application powerpnt.exe, version 12.0.4518.1014, stamp 45428035, faulting module oart.dll, version 12.0.4518.1014, stamp 454283f8, debug? 0, fault address 0x00020701. Error - 2011-06-08 19:35:25 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module oart.dll, version 12.0.4518.1014, stamp 454283f8, debug? 0, fault address 0x00020708. Error - 2011-06-08 19:35:57 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module oart.dll, version 12.0.4518.1014, stamp 454283f8, debug? 0, fault address 0x00020708. Error - 2011-06-12 15:50:44 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 | ID = 2001 Description = Rejected Safe Mode action : Microsoft Office PowerPoint. Error - 2011-06-17 20:30:52 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module mso.dll, version 12.0.4518.1014, stamp 4542867b, debug? 0, fault address 0x008f4f36. Error - 2011-06-17 20:31:53 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 | ID = 5000 Description = EventType offdiag12, P1 2b7fcac0-bf78-4e01-bb5c-6a72eb417cc223fad6b5-638f-4cc7-8666-04cbcb49a426, P2 NIL, P3 NIL, P4 NIL, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL. Error - 2011-07-13 12:09:04 | Computer Name = PC-CFA2F2374BC2 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd iexplore.exe, wersja 8.0.6001.18702, moduł powodujący błąd mshtml.dll, wersja 8.0.6001.23181, adres błędu 0x00067878. Error - 2011-08-10 14:28:12 | Computer Name = PC-CFA2F2374BC2 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca IEXPLORE.EXE, wersja 8.0.6001.18702, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2011-08-10 14:28:36 | Computer Name = PC-CFA2F2374BC2 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca IEXPLORE.EXE, wersja 8.0.6001.18702, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. [ OSession Events ] Error - 2011-06-08 17:02:33 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 420 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-08 17:02:49 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-08 19:31:16 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 14799 seconds with 10500 seconds of active time. This session ended with a crash. Error - 2011-06-08 19:31:43 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 8929 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-08 19:33:46 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 140 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-08 19:33:52 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-08 19:34:14 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 148 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-08 19:35:20 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 49 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-08 19:35:55 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20 seconds with 0 seconds of active time. This session ended with a crash. Error - 2011-06-17 20:30:44 | Computer Name = PC-CFA2F2374BC2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 18500 seconds with 11700 seconds of active time. This session ended with a crash. [ System Events ] Error - 2011-10-23 07:17:54 | Computer Name = PC-CFA2F2374BC2 | Source = Dhcp | ID = 1000 Description = Komputer utracił połączenie dla swojego adresu IP 130.89.172.73 na karcie sieciowej o adresie sieciowym 0014C2E5F7FF. Error - 2011-10-23 11:41:58 | Computer Name = PC-CFA2F2374BC2 | Source = Dhcp | ID = 1000 Description = Komputer utracił połączenie dla swojego adresu IP 130.89.172.73 na karcie sieciowej o adresie sieciowym 0014C2E5F7FF. Error - 2011-10-24 17:54:56 | Computer Name = PC-CFA2F2374BC2 | Source = Dhcp | ID = 1000 Description = Komputer utracił połączenie dla swojego adresu IP 130.89.172.73 na karcie sieciowej o adresie sieciowym 0014C2E5F7FF. Error - 2011-10-27 14:14:38 | Computer Name = PC-CFA2F2374BC2 | Source = Dhcp | ID = 1000 Description = Komputer utracił połączenie dla swojego adresu IP 130.89.171.98 na karcie sieciowej o adresie sieciowym 0014C2E5F7FF. Error - 2011-10-31 11:54:03 | Computer Name = PC-CFA2F2374BC2 | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\D. Error - 2011-10-31 11:54:04 | Computer Name = PC-CFA2F2374BC2 | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\D. Error - 2011-10-31 11:54:05 | Computer Name = PC-CFA2F2374BC2 | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\D. Error - 2011-11-02 12:35:40 | Computer Name = PC-CFA2F2374BC2 | Source = Dhcp | ID = 1000 Description = Komputer utracił połączenie dla swojego adresu IP 130.89.173.30 na karcie sieciowej o adresie sieciowym 0014C2E5F7FF. Error - 2011-11-04 11:25:20 | Computer Name = PC-CFA2F2374BC2 | Source = Dhcp | ID = 1000 Description = Komputer utracił połączenie dla swojego adresu IP 130.89.170.16 na karcie sieciowej o adresie sieciowym 0014C2E5F7FF. Error - 2011-11-04 16:46:46 | Computer Name = PC-CFA2F2374BC2 | Source = Dhcp | ID = 1000 Description = Komputer utracił połączenie dla swojego adresu IP 130.89.170.16 na karcie sieciowej o adresie sieciowym 0014C2E5F7FF. < End of report >