OTL Extras logfile created on: 2012-07-07 22:33:07 - Run 1 OTL by OldTimer - Version 3.2.53.1 Folder = F:\ Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 503,48 Mb Total Physical Memory | 359,48 Mb Available Physical Memory | 71,40% Memory free 1,20 Gb Paging File | 1,12 Gb Available in Paging File | 92,82% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 25,69 Gb Total Space | 16,94 Gb Free Space | 65,95% Space Free | Partition Type: NTFS Drive D: | 48,83 Gb Total Space | 38,25 Gb Free Space | 78,34% Space Free | Partition Type: NTFS Drive F: | 3,77 Gb Total Space | 3,70 Gb Free Space | 98,16% Space Free | Partition Type: FAT32 Computer Name: KASIA89 | User Name: Administrator | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\.DEFAULT\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [HKEY_USERS\S-1-5-18\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [HKEY_USERS\S-1-5-21-1229272821-484763869-1177238915-500\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* batfile [print] -- Reg Error: Key error. cmdfile [open] -- "%1" %* cmdfile [print] -- Reg Error: Key error. comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* inffile [print] -- Reg Error: Key error. inifile [print] -- Reg Error: Key error. InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l InternetShortcut [print] -- Reg Error: Key error. piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. regfile [print] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [print] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with FastStone] -- "C:\Program Files\FastStone Image Viewer\FSViewer.exe" "%1" () Directory [cmd] -- cmd.exe /k cd "%L" (Microsoft Corporation) Directory [openNew] -- explorer %1 (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- Reg Error: Key error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- () "C:\Program Files\Gadu-Gadu 10\gg.exe" = C:\Program Files\Gadu-Gadu 10\gg.exe:*:Disabled:Gadu-Gadu 10 -- (GG Network S.A.) "C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe" = C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe:*:Enabled:SweetPacksUpdateManager -- (SweetIM Technologies Ltd.) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0}" = SweetIM for Messenger 3.6 "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan "{153898EE-EECA-471E-8E33-C8485EA84C07}" = QSS Installation Program "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg "{20CCA435-1465-4567-885C-4A0AFCD0EB05}" = F2100_Help "{24557DC0-0839-496f-82F9-C4EB72EFE4FA}" = HP Deskjet All-In-One Software 8.0 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{3354B408-2D6B-4F8A-9BB3-A9E0C567F891}" = QSS Installation Program "{4183178B-4D4E-48A7-9257-454BA90A760E}" = SweetPacks Toolbar for Internet Explorer 4.6 "{481EA8F8-CAC0-4137-9CF8-DD0297593E61}" = TP-LINK Wireless Client Utility "{53480330-E1D1-41CA-B8F8-7F78644F7F50}" = O&O Defrag Professional Edition "{5AF71003-1797-4D93-9F37-4F2125CBF539}" = Microsoft .NET Framework 2.0 Language Pack - PLK "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{64CB2553-C109-4132-AA51-1F421B515FD1}" = Microsoft .NET Framework 1.1 Polish Language Pack "{657F8B33-CBBB-45F4-9087-274F22C89400}" = DJ_AIO_ProductContext "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update "{90120000-0010-0415-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Polish) 12 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch "{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status "{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations "{9ECB4705-B9CB-405A-B6D4-33BDF707308E}" = DJ_AIO_Software "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter "{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm "{C716522C-3731-4667-8579-40B098294500}" = Toolbox "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{DC83F417-8068-4074-BA2F-C4F8AB872556}" = DJ_AIO_Software_min "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential "{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F6F90406-4726-4559-B6F7-3A96529CDD45}" = F2100 "{FB697452-8CA4-46B4-98B1-165C922A2EF3}" = Update Manager for SweetPacks 1.0 "{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Driver Magician_is1" = Driver Magician 3.28 "Driver Sweeper" = Driver Sweeper 0.9 (Remove Only) "DriveSpace" = Drive Space Indicator "Dyktando" = Dyktando "FastStone Image Viewer" = FastStone Image Viewer 3.5 "Gadu-Gadu 10" = Gadu-Gadu 10 "GMailFS" = GMail Drive Shell Extension "Google Chrome" = Google Chrome "HDMI" = Intel(R) Graphics Media Accelerator Driver "HFSLIPTotalSlipstream" = HFSLIP Total Slipstream (v2.0.0pre-alpha, build 80630a) "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "HP Imaging Device Functions" = HP Imaging Device Functions 8.0 "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0 "HPExtendedCapabilities" = HP Customer Participation Program 8.0 "MakeISO right click extensions" = MakeISO right click extensions "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0 "Microsoft .NET Framework 2.0 Language Pack - PLK" = Microsoft .NET Framework 2.0 — pakiet języka polskiego "Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19) "Mozilla Thunderbird (2.0.0.14)" = Mozilla Thunderbird (2.0.0.14) "Nero8Lite_is1" = Nero 8 Micro 8.3.2.1b "Notepad++" = Notepad++ "NSS" = Norton Security Scan "PowerISO" = PowerISO "Registry Mechanic_is1" = PC Tools Registry Mechanic 11.0 "ShellExtension" = FirmTools 2.0 build 313 "Unlocker" = Unlocker 1.8.7 "VisualTaskTips" = Visual Task Tips 2.3 "Winamp" = Winamp 5.54 addon by jeetu "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WinRAR archiver" = Archiwizator WinRAR "Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1229272821-484763869-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-03-02 15:31:51 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-03-02 15:39:29 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-03-08 08:25:59 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-03-08 08:28:53 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-03-19 15:40:32 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-03-21 15:40:36 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-03-26 13:39:54 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-04-01 10:48:52 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-04-05 07:54:26 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. Error - 2012-04-07 11:47:15 | Computer Name = KASIA89 | Source = Microsoft Office 12 | ID = 1000 Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028, faulting module hpz3r4v2.dll, version 61.63.247.0, stamp 45949947, debug? 0, fault address 0x00045a98. [ System Events ] Error - 2012-01-10 06:11:43 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.2 dla karty sieciowej o adresie 001A4D33470D został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2012-01-10 06:11:49 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.3 dla karty sieciowej o adresie 54E6FC959A43 został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2012-01-11 03:39:52 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.2 dla karty sieciowej o adresie 001A4D33470D został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2012-01-11 03:40:06 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.3 dla karty sieciowej o adresie 54E6FC959A43 został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2012-01-11 13:28:12 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.3 dla karty sieciowej o adresie 54E6FC959A43 został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2012-01-12 05:25:24 | Computer Name = KASIA89 | Source = Server | ID = 2505 Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{A6138019-6E2A-4322-B843-1923DBE504DC}, ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera. Error - 2012-01-12 05:25:56 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.3 dla karty sieciowej o adresie 54E6FC959A43 został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2012-01-13 03:43:40 | Computer Name = KASIA89 | Source = Server | ID = 2505 Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{A6138019-6E2A-4322-B843-1923DBE504DC}, ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera. Error - 2012-01-13 03:45:18 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.3 dla karty sieciowej o adresie 54E6FC959A43 został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). Error - 2012-01-13 06:34:59 | Computer Name = KASIA89 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.2 dla karty sieciowej o adresie 001A4D33470D został zabroniony przez serwer DHCP 192.168.1.254 (Serwer DHCP wysłał komunikat DHCPNACK). < End of report >