OTL Extras logfile created on: 2012-07-07 23:40:04 - Run 1 OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Samsung\Downloads Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,96 Gb Total Physical Memory | 1,51 Gb Available Physical Memory | 77,12% Memory free 3,92 Gb Paging File | 3,52 Gb Available in Paging File | 89,72% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 106,39 Gb Total Space | 87,87 Gb Free Space | 82,59% Space Free | Partition Type: NTFS Drive D: | 106,39 Gb Total Space | 106,05 Gb Free Space | 99,67% Space Free | Partition Type: NTFS Computer Name: SAMSUNGNOTEBOOK | User Name: Samsung | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{22856419-D990-441A-8C3C-E9AC3ED3D7A8}" = lport=2869 | protocol=6 | dir=in | app=system | "{2352941E-4EA9-4CE0-94BF-9EF472FC9549}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3286B3EC-A14B-45A4-BA8A-37263E877217}" = lport=138 | protocol=17 | dir=in | app=system | "{519712FC-1AF0-4FE0-A979-B86DC240A24B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{5AB36320-B185-44C0-865E-7ABCC2584E17}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5E4061E0-C342-4E43-A1A0-79FD26FE9201}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{69D9A0D3-BD2A-4540-AB3D-7DC4745F8CB1}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7E184772-6986-43C6-B27D-0D89F766CFBE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{875D5C89-1EA9-4EB4-A0C0-4F398A5F0C66}" = rport=138 | protocol=17 | dir=out | app=system | "{9157098C-DCAE-44EA-A267-FFEFAFD6F9CF}" = rport=137 | protocol=17 | dir=out | app=system | "{94835047-00DE-4B8F-8974-C6E2DE74BDB5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9A411F4F-7FA9-49BA-A0DD-3A87EBDA7B22}" = lport=445 | protocol=6 | dir=in | app=system | "{9BA1FECA-8E7C-4452-ACFC-E94196ACB818}" = rport=139 | protocol=6 | dir=out | app=system | "{9E643E6C-5119-4698-ABE9-9A94328523F6}" = rport=10243 | protocol=6 | dir=out | app=system | "{AF6C9D6A-CFCB-432A-9D31-E3A9390E9B9E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B584BEF8-A80C-4541-A199-A58A216A2378}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C467D912-F34F-4029-AD99-4D7448C8F72B}" = rport=445 | protocol=6 | dir=out | app=system | "{E2D5C70A-6B79-463F-8F58-9C8A126DA06B}" = lport=137 | protocol=17 | dir=in | app=system | "{E8D8F202-9970-42FD-B5F7-69655BD79DEB}" = lport=139 | protocol=6 | dir=in | app=system | "{F10D2575-D219-4BA8-8617-FF6FB8B3EFC9}" = lport=10243 | protocol=6 | dir=in | app=system | "{F2B3338D-83EF-4963-A6B0-3D73FE1FE202}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05C6FA96-8A48-45CE-A226-2F6F42949975}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{179DFA0C-5209-4F0A-924F-310C72FAC289}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{68A5D62B-FD57-4589-BDFC-6B775B473D32}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{68E911B9-EE8F-4167-82D0-26753A05E303}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{712CEE36-F1AD-47A4-870A-FC76D804BA69}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9C21A3D0-A3A8-4F4C-A93C-447C2E5F5064}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{9E6E21BB-AC24-46AC-ABBD-5930773AD6EE}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{A0822E83-3D8F-4FB2-8D10-A7CB442CDACE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B329469C-3D3C-4D7F-80DA-45EF08A2070B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CA74F06B-A628-4218-A4CA-3B62B62F5856}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CDEDE071-632A-40BD-9939-63A0DAEFDD02}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{D22BDA1F-F0E1-4ED9-90AA-80D9594D0589}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{D85CA7F6-6D63-4895-A11E-93BC4BB01664}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{EB388600-AABB-46FD-992A-5378706E9FAF}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{F3BB0791-C9A7-4842-B1D5-0388FC151D93}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{FD520144-08F8-43B0-A3F2-01760D2AF4E3}" = protocol=6 | dir=out | app=system | "TCP Query User{23C859DB-DC4C-4EEC-A93E-0A522B17A52A}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{675BB8FD-706D-4AEC-950C-6696395DCE6E}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java(TM) 6 Update 30 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1045-7B44-A95000000001}" = Adobe Reader 9.5.0 - Polish "{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 8.0.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Młody Doktor - Morskie Zwierzaki_is1" = Młody Doktor - Morskie Zwierzaki "Młody Doktor 3 - Lecznica dla Zwierząt_is1" = Młody Doktor 3 - Lecznica dla Zwierząt "NSS" = Norton Security Scan "WinRAR archiver" = WinRAR 4.01 (32-bitowy) [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-04 08:39:34 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-04 09:17:19 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-04 11:14:09 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-04 14:07:37 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-05 10:32:55 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-05 14:55:18 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-05 16:19:12 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-05 18:27:29 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-07 15:44:52 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = Error - 2012-07-07 15:56:49 | Computer Name = SamsungNotebook | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36874 Description = Odebrano żądanie połączenia SSL 3.0 ze zdalnej aplikacji klienckiej, lecz serwer nie obsługuje żadnego z mechanizmów szyfrowania obsługiwanych przez tę aplikację. Żądanie połączenia SSL nie powiodło się. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36888 Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego: 107. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36874 Description = Odebrano żądanie połączenia SSL 3.0 ze zdalnej aplikacji klienckiej, lecz serwer nie obsługuje żadnego z mechanizmów szyfrowania obsługiwanych przez tę aplikację. Żądanie połączenia SSL nie powiodło się. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36888 Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego: 107. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36874 Description = Odebrano żądanie połączenia SSL 3.0 ze zdalnej aplikacji klienckiej, lecz serwer nie obsługuje żadnego z mechanizmów szyfrowania obsługiwanych przez tę aplikację. Żądanie połączenia SSL nie powiodło się. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36888 Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego: 107. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36874 Description = Odebrano żądanie połączenia SSL 3.0 ze zdalnej aplikacji klienckiej, lecz serwer nie obsługuje żadnego z mechanizmów szyfrowania obsługiwanych przez tę aplikację. Żądanie połączenia SSL nie powiodło się. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36888 Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego: 107. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36874 Description = Odebrano żądanie połączenia SSL 3.0 ze zdalnej aplikacji klienckiej, lecz serwer nie obsługuje żadnego z mechanizmów szyfrowania obsługiwanych przez tę aplikację. Żądanie połączenia SSL nie powiodło się. Error - 2012-04-24 08:43:06 | Computer Name = SamsungNotebook | Source = Schannel | ID = 36888 Description = Został wygenerowany następujący alert krytyczny: 40. Stan błędu wewnętrznego: 107. < End of report >