OTL Extras logfile created on: 2011-12-10 16:49:48 - Run 4 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\qbar\Desktop Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 1,87 Gb Total Physical Memory | 1,53 Gb Available Physical Memory | 81,69% Memory free 3,73 Gb Paging File | 3,52 Gb Available in Paging File | 94,37% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37,26 Gb Total Space | 6,64 Gb Free Space | 17,82% Space Free | Partition Type: NTFS Drive E: | 74,53 Gb Total Space | 1,49 Gb Free Space | 2,00% Space Free | Partition Type: NTFS Computer Name: YOUR-E0367A1424 | User Name: qbar | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l [HKEY_USERS\S-1-5-21-3379761846-378779092-978630944-1007\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found .vbs [@ = VBSFile] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* http [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse] -- "E:\programy\Multimedia\XnView-win-full\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] "DisableMonitoring" = 1 [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime "{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player "{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}" = Atheros Wireless LAN MiniPCI card Driver "{099D12EC-0321-4CAC-A0CC-33D020156FCD}" = Toshiba Utility "{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel "{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA "{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist "{1BC4026B-1957-4514-9058-2B542557F143}" = Opera 9.63 "{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29 "{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK "{2B120B1D-1908-4FB3-8C9D-72128A74E80A}" = ZoneAlarm Security "{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3EB6332B-AF02-457C-A31C-835458C5B48B}" = TOSHIBA Manuals "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8 "{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility "{6CA2C4D7-4680-4164-95CA-BC79DBF93959}" = Scratch Live 2.0.0 (20049) "{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}" = Atheros Client Utility "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003 "{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer "{A1CFBEF8-D9F6-4B2A-BDBE-7D8C0B0FE03A}" = Toshiba Hotkey Utility "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A386CC19-1E79-4D4C-A54B-C8747871E4AD}" = ZoneAlarm Firewall "{AC76BA86-0000-7EC8-7489-000000000702}" = Adobe Acrobat 7.0.1 and Reader 7.0.1 Update "{AC76BA86-0000-7EC8-7489-000000000703}" = Adobe Acrobat 7.0.2 and Reader 7.0.2 Update "{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0 "{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{F77890F3-774A-4CBE-A2E3-7BB0DC71D1FA}" = Toshiba Touchpad Utility "Ableton Live_is1" = Ableton Live v7.0.1 "Addictive Drums" = Addictive Drums "Addictive Drums FreePak - 01 - Woofer Wonderland_is1" = Addictive Drums FreePak 01 - Woofer Wonderland "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "All ATI Software" = ATI - Software Uninstall Utility "ATI Display Driver" = ATI Display Driver "CCleaner" = CCleaner (remove only) "CNXT_AUDIO" = Conexant AC-Link Audio "CNXT_MODEM_PCI_VEN_1002&DEV_4378&SUBSYS_FF311179" = AC97 Data Fax SoftModem with SmartCP "dBpoweramp [Calculate Audio CRC] Codec" = dBpoweramp [Calculate Audio CRC] Codec "dBpoweramp FLAC Codec" = dBpoweramp FLAC Codec "dBpoweramp Monkeys Audio Codec" = dBpoweramp Monkeys Audio Codec "dBpoweramp Mp2 and BwfMp2 codec" = dBpoweramp Mp2 and BwfMp2 codec "dBpoweramp mp3 (Fraunhofer IIS) Codec" = dBpoweramp mp3 (Fraunhofer IIS) Codec "dBpoweramp Music Converter" = dBpoweramp Music Converter "dBpoweramp Ogg Vorbis Codec" = dBpoweramp Ogg Vorbis Codec "dBpoweramp WavPack Codec" = dBpoweramp WavPack Codec "DrTweakXP" = DoctorTweak XP v1.75 "ESET Online Scanner" = ESET Online Scanner v3 "ffdshow_is1" = ffdshow [rev 1993] [2008-06-09] "InstallShield_{099D12EC-0321-4CAC-A0CC-33D020156FCD}" = Toshiba Utility "InstallShield_{F77890F3-774A-4CBE-A2E3-7BB0DC71D1FA}" = Toshiba Touchpad Utility "LPD8Editor" = LPD8 Editor "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Native Instruments FM8" = Native Instruments FM8 "Nowe Gadu-Gadu" = Nowe Gadu-Gadu "PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool "SynTPDeinstKey" = Synaptics Pointing Device Driver "WIC" = Windows Imaging Component "Winamp" = Winamp "Windows Media Format Runtime" = Windows Media Format Runtime "Windows Media Player" = Windows Media Player 10 "WinRAR archiver" = WinRAR 4.00 (32-bitowy) "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 "ZoneAlarm Free" = ZoneAlarm Free "ZoneAlarm Toolbar" = ZoneAlarm Toolbar [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3379761846-378779092-978630944-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Ad-Remover" = Ad-Remover "Google Chrome" = Google Chrome "Mixxx (1.9.0)" = Mixxx 1.9.0 [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2011-06-19 09:07:53 | Computer Name = YOUR-E0367A1424 | Source = Application Hang | ID = 1002 Description = Hanging application iPlusManager.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2011-06-19 09:07:56 | Computer Name = YOUR-E0367A1424 | Source = Application Hang | ID = 1002 Description = Hanging application iPlusManager.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2011-06-19 09:08:00 | Computer Name = YOUR-E0367A1424 | Source = Application Hang | ID = 1002 Description = Hanging application iPlusManager.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2011-07-01 13:42:45 | Computer Name = YOUR-E0367A1424 | Source = MsiInstaller | ID = 11305 Description = Produkt: Nero 7 Demo -- Błąd 1305. Błąd odczytu z pliku: C:\Program Files\Nero\Nero 7\Nero MediaHome\msvcp71.dll. Błąd systemu 0. Zweryfikuj, czy plik istnieje i czy masz do niego dostęp. Error - 2011-07-01 13:44:39 | Computer Name = YOUR-E0367A1424 | Source = Application Hang | ID = 1002 Description = Hanging application explorer.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2011-07-01 13:45:02 | Computer Name = YOUR-E0367A1424 | Source = MsiInstaller | ID = 11305 Description = Produkt: Nero 7 Demo -- Błąd 1305. Błąd odczytu z pliku: C:\Program Files\Nero\Nero 7\Nero MediaHome\msvcp71.dll. Błąd systemu 0. Zweryfikuj, czy plik istnieje i czy masz do niego dostęp. Error - 2011-07-17 09:01:33 | Computer Name = YOUR-E0367A1424 | Source = Application Error | ID = 1005 Description = Windows cannot access the file C:\Documents and Settings\qbar\Local Settings\Application Data\Google\Chrome\Application\12.0.742.112\Installer\chrome.7z for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program chrome.7z because of this error. Program: chrome.7z File: C:\Documents and Settings\qbar\Local Settings\Application Data\Google\Chrome\Application\12.0.742.112\Installer\chrome.7z The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C000009C Disk type: 3 Error - 2011-07-17 09:01:37 | Computer Name = YOUR-E0367A1424 | Source = Application Error | ID = 1000 Description = Faulting application setup.exe, version 12.0.742.122, faulting module setup.exe, version 12.0.742.122, fault address 0x00012658. Error - 2011-07-24 10:33:15 | Computer Name = YOUR-E0367A1424 | Source = Application Hang | ID = 1002 Description = Hanging application CDGrab.exe, version 12.1.0.3, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2011-07-24 10:57:00 | Computer Name = YOUR-E0367A1424 | Source = Application Error | ID = 1000 Description = Faulting application foobar2000.exe, version 0.9.5.6, faulting module foobar2000.exe, version 0.9.5.6, fault address 0x0005a13d. [ System Events ] Error - 2011-12-08 18:48:42 | Computer Name = YOUR-E0367A1424 | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 2011-12-08 18:49:05 | Computer Name = YOUR-E0367A1424 | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort0, did not respond within the timeout period. Error - 2011-12-10 05:07:38 | Computer Name = YOUR-E0367A1424 | Source = BROWSER | ID = 8032 Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{4B578A2E-BED8-4498-B654-2CDF760BDED3}. The backup browser is stopping. Error - 2011-12-10 11:02:32 | Computer Name = YOUR-E0367A1424 | Source = Service Control Manager | ID = 7034 Description = The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s). Error - 2011-12-10 11:02:32 | Computer Name = YOUR-E0367A1424 | Source = Service Control Manager | ID = 7031 Description = The ZoneAlarm Toolbar IswSvc service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error - 2011-12-10 11:02:32 | Computer Name = YOUR-E0367A1424 | Source = Service Control Manager | ID = 7034 Description = The ConfigFree Service service terminated unexpectedly. It has done this 1 time(s). Error - 2011-12-10 11:02:32 | Computer Name = YOUR-E0367A1424 | Source = Service Control Manager | ID = 7034 Description = The Atheros Configuration Service service terminated unexpectedly. It has done this 1 time(s). Error - 2011-12-10 11:02:33 | Computer Name = YOUR-E0367A1424 | Source = Service Control Manager | ID = 7034 Description = The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). Error - 2011-12-10 11:08:57 | Computer Name = YOUR-E0367A1424 | Source = BROWSER | ID = 8032 Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{4B578A2E-BED8-4498-B654-2CDF760BDED3}. The backup browser is stopping. Error - 2011-12-10 11:41:32 | Computer Name = YOUR-E0367A1424 | Source = BROWSER | ID = 8032 Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{4B578A2E-BED8-4498-B654-2CDF760BDED3}. The backup browser is stopping. < End of report >