OTL Extras logfile created on: 2012-03-27 20:46:56 - Run 3 OTL by OldTimer - Version 3.2.26.4 Folder = C:\Documents and Settings\XP\Pulpit\adw i OTL\OTL Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 1,18 Gb Available Physical Memory | 59,46% Memory free 3,84 Gb Paging File | 3,10 Gb Available in Paging File | 80,84% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,83 Gb Total Space | 2,71 Gb Free Space | 5,55% Space Free | Partition Type: NTFS Drive D: | 184,05 Gb Total Space | 66,86 Gb Free Space | 36,33% Space Free | Partition Type: NTFS Computer Name: XP-01498C0B63E4 | User Name: XP | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found [HKEY_USERS\S-1-5-21-1202660629-861567501-1417001333-1003\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows -- (Ares Development Group) "C:\Program Files\Gadu-Gadu 10\gg.exe" = C:\Program Files\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 -- (GG Network S.A.) "D:\Program Files\Techland\Chrome\ChromeNet.exe" = D:\Program Files\Techland\Chrome\ChromeNet.exe:*:Enabled:Chrome -- (Techland) "C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation) "D:\Program Files\Midway Home Entertainment\Rise and Fall\RiseAndFall.exe" = D:\Program Files\Midway Home Entertainment\Rise and Fall\RiseAndFall.exe:*:Enabled:Rise And Fall -- (Midway Home Entertainment) "C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.) "D:\Program Files\npsasvr.exe" = D:\Program Files\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server "D:\Program Files\npsvsvr.exe" = D:\Program Files\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server "D:\Program Files\BFP4f.exe" = D:\Program Files\BFP4f.exe:*:Enabled:BFP4f "D:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = D:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace "D:\Program Files\L4D\Left 4 Dead\left4dead.exe" = D:\Program Files\L4D\Left 4 Dead\left4dead.exe:*:Enabled:left4dead -- () [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}" = Star Wars Jedi Knight Jedi Academy "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java(TM) 6 Update 29 "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{5281E5CC-70B1-4B1B-8731-B8533C9E5EEE}" = Chrome "{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands "{5C19E2DC-4CCF-3114-B40A-6E565987025F}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{5E1375CB-6792-4464-8715-CC3EC83D48FA}" = VirtualDJ Home FREE "{6FB6D550-DDC4-4996-9CDF-91C34F0A4C4A}" = Gothic II Złota Edycja "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0 "{758A4269-70E5-4B11-B419-F692882408A9}" = Gothic "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{85DAE0C8-B3BB-11D8-88E4-0004769F25D1}" = Spellforce "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-A70000000000}" = Adobe Reader 7.0 - Polish "{ADE91A13-434D-4229-00BC-182BAD607303}" = Need for Speed™ Most Wanted "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War "{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters "{D078226E-83F2-45FD-9CDE-5DA66E5ADB51}" = Rise and Fall "{D078226E-83F2-45FD-9CDE-5DA66E5ADB51}_is1" = Rise and Fall "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}" = Broadcom Gigabit Integrated Controller "{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas "{D56B0E27-4A3E-46C9-B5C1-D93D580C099C}" = NVIDIA PhysX v8.10.29 "{E2494AD8-314D-44F8-B39C-4358A60DC184}" = LogMeIn Hamachi "{E52D32A0-0005-11D7-928D-000ACD006A23}" = The Elder Scrolls III - Morrowind Złota Edycja "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "18 Wheels of Steel: Haulin'" = 18 Wheels of Steel: Haulin' "2DA959FE3D6F0F5BC313481E72071D510DD786FB" = Windows Driver Package - Intel (w29n51) net (12/19/2007 9.0.4.39) "6A1545AE87FC8D98ACA7539CE7AA69DF2A5C7E1C" = Pakiet sterowników systemu Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) "7-Zip" = 7-Zip 9.20 "Acala 3GP Movies Free_is1" = Acala 3GP Movies Free 4.2.4 "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Advanced SystemCare 5_is1" = Advanced SystemCare 5 "Ares" = Ares 2.1.7 "ASIO4ALL" = ASIO4ALL "Audacity_is1" = Audacity 1.2.6 "avast" = avast! Free Antivirus "blueconnect" = blueconnect "CABAL Online: Saint's Requiem Client_is1" = CABAL Online - Saint's Requiem Client "CCleaner" = CCleaner "DAEMON Tools Lite" = DAEMON Tools Lite "DarkWave Studio" = DarkWave Studio 3.8.7 "Dzielenie i łączenie plików_is1" = Dzielenie i łączenie plików v1.2.2 "EA92D36B2621B412A14375F1D39FCB7FBC2C84D4" = Windows Driver Package - Intel (NETw5x32) net (11/17/2008 12.2.0.11) "FL Studio 10" = FL Studio 10 "Fraps" = Fraps (remove only) "Free Easy Burner_is1" = Free Easy Burner V 5.1 "Gadu-Gadu 10" = Gadu-Gadu 10 "HDMI" = Intel(R) Graphics Media Accelerator Driver "ie8" = Windows Internet Explorer 8 "IL Download Manager" = IL Download Manager "InstallShield_{5281E5CC-70B1-4B1B-8731-B8533C9E5EEE}" = Chrome "InstallShield_{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters "InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "LogMeIn Hamachi" = LogMeIn Hamachi "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Minecraft 1.2.0_02" = Minecraft 1.2.0_02 "PhotoScape" = PhotoScape "Sniper Elite_is1" = Sniper Elite "Spolszczenie do Medieval 2: Total War" = Spolszczenie do Medieval 2: Total War "THIV_is1" = The Hell in Vietnam "uTorrent" = µTorrent "Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 "WinGimp-2.0_is1" = GIMP 2.6.11 "WinRAR archiver" = WinRAR 4.01 (32-bit) "yvnkwpdgga" = Advanced Performance Platform Revenuestreaming. [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1202660629-861567501-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "Third Age - Total War 1.0 Part1" = Third Age - Total War 1.0 Part1 "Third Age - Total War 1.0 Part2" = Third Age - Total War 1.0 Part2 "UnityWebPlayer" = Unity Web Player [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-03-20 09:19:32 | Computer Name = XP-01498C0B63E4 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 2157 Error - 2012-03-20 09:19:32 | Computer Name = XP-01498C0B63E4 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 2157 Error - 2012-03-25 05:40:25 | Computer Name = XP-01498C0B63E4 | Source = LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces Performance dostawcę licznika rozszerzeń. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych (Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-03-25 05:40:25 | Computer Name = XP-01498C0B63E4 | Source = LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces Performance dostawcę licznika rozszerzeń. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych (Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-03-25 05:40:25 | Computer Name = XP-01498C0B63E4 | Source = LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Kod błędu to pierwszy wpis DWORD w sekcji danych (Data). Error - 2012-03-27 07:08:58 | Computer Name = XP-01498C0B63E4 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd iexplore.exe, wersja 8.0.6001.18702, moduł powodujący błąd ntdll.dll, wersja 5.1.2600.6055, adres błędu 0x0000100b. Error - 2012-03-27 07:09:11 | Computer Name = XP-01498C0B63E4 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd iexplore.exe, wersja 8.0.6001.18702, moduł powodujący błąd ntdll.dll, wersja 5.1.2600.6055, adres błędu 0x0000100b. Error - 2012-03-27 12:08:55 | Computer Name = XP-01498C0B63E4 | Source = LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces Performance dostawcę licznika rozszerzeń. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych (Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-03-27 12:08:55 | Computer Name = XP-01498C0B63E4 | Source = LoadPerf | ID = 3012 Description = Ciągi wydajności w wartości rejestru wydajności są uszkodzone, kiedy proces Performance dostawcę licznika rozszerzeń. Wartość BaseIndex z rejestru wydajności to pierwszy wpis DWORD w sekcji danych (Data, wartość LastCounter to drugi wpis DWORD, a wartość LastHelp to trzeci wpis DWORD w sekcji Data. Error - 2012-03-27 12:08:55 | Computer Name = XP-01498C0B63E4 | Source = LoadPerf | ID = 3011 Description = Nie można usunąć z pamięci ciągów licznika wydajności dla usługi WmiApRpl (WmiApRpl). Kod błędu to pierwszy wpis DWORD w sekcji danych (Data). [ System Events ] Error - 2012-03-27 06:36:39 | Computer Name = XP-01498C0B63E4 | Source = ACPI | ID = 262187 Description = Operacja wstrzymania systemu nie powiodła się Error - 2012-03-27 12:08:50 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa Advanced SystemCare Service 5 niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2012-03-27 12:08:51 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa Usługa Bonjour niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2012-03-27 12:08:51 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7031 Description = Usługa Apple Mobile Device niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 60000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error - 2012-03-27 12:08:51 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa DCService.exe niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2012-03-27 12:08:51 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa FsUsbExService niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2012-03-27 12:08:51 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa Java Quick Starter niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2012-03-27 12:08:51 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa PnkBstrA niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2012-03-27 12:08:51 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa LogMeIn Hamachi Tunneling Engine niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2012-03-27 12:08:54 | Computer Name = XP-01498C0B63E4 | Source = Service Control Manager | ID = 7034 Description = Usługa Usługa Google Update (gupdate) niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. < End of report >