OTL Extras logfile created on: 2012-07-15 00:57:18 - Run 1 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\junior\Moje dokumenty\Pobieranie Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,43 Gb Available Physical Memory | 71,55% Memory free 3,85 Gb Paging File | 3,34 Gb Available in Paging File | 86,76% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 126,95 Gb Total Space | 120,52 Gb Free Space | 94,94% Space Free | Partition Type: NTFS Drive D: | 171,13 Gb Total Space | 46,99 Gb Free Space | 27,46% Space Free | Partition Type: NTFS Drive E: | 591,29 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: JUNIOR-8FD34819 | User Name: junior | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 60 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l .js [@ = JSFile] -- C:\Program Files\Panda Security\Panda Antivirus Pro 2012\PAVSCRIP.EXE (Panda Security, S.L.) .jse [@ = JSEFile] -- C:\Program Files\Panda Security\Panda Antivirus Pro 2012\PAVSCRIP.EXE (Panda Security, S.L.) .vbe [@ = VBEFile] -- C:\Program Files\Panda Security\Panda Antivirus Pro 2012\PAVSCRIP.EXE (Panda Security, S.L.) .vbs [@ = VBSFile] -- C:\Program Files\Panda Security\Panda Antivirus Pro 2012\PAVSCRIP.EXE (Panda Security, S.L.) .wsf [@ = WSFFile] -- C:\Program Files\Panda Security\Panda Antivirus Pro 2012\PAVSCRIP.EXE (Panda Security, S.L.) .wsh [@ = WSHFile] -- C:\Program Files\Panda Security\Panda Antivirus Pro 2012\PAVSCRIP.EXE (Panda Security, S.L.) [HKEY_USERS\S-1-5-21-1957994488-2111687655-725345543-1003\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l jsfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %* (Panda Security, S.L.) jsefile [open] -- C:\PROGRA~1\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %* (Panda Security, S.L.) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. vbefile [open] -- C:\PROGRA~1\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %* (Panda Security, S.L.) vbsfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %* (Panda Security, S.L.) wsffile [open] -- C:\PROGRA~1\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %* (Panda Security, S.L.) wshfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAA~1\PavScrip.exe "%1" %* (Panda Security, S.L.) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 1 "FirewallOverride" = 1 "UacDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "FirewallOverride" = 1 "UpdatesDisableNotify" = 1 "UacDisableNotify" = 1 [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "D:\Documents and Settings\junior\Moje dokumenty\Pobieranie\Opera_1160_int_Setup.exe" = D:\Documents and Settings\junior\Moje dokumenty\Pobieranie\Opera_1160_int_Setup.exe:*:Enabled:ipsec -- (Opera Software ASA) "C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software) "C:\WINDOWS\system32\nwiz.exe" = C:\WINDOWS\system32\nwiz.exe:*:Enabled:ipsec -- () "C:\ComboFix\CF13592.3XE" = C:\ComboFix\CF13592.3XE:*:Enabled:ipsec -- (Microsoft Corporation) "C:\Program Files\Vtune\TBPanel.exe" = C:\Program Files\Vtune\TBPanel.exe:*:Enabled:ipsec -- () "C:\WINDOWS\system32\userinit.exe" = c:\windows\system32\userinit.exe:*:Enabled:ipsec -- (Microsoft Corporation) "C:\WINDOWS\Explorer.EXE" = C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec -- (Microsoft Corporation) "C:\DOCUME~1\junior\USTAWI~1\Temp\vaim.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\vaim.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winurlbgn.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winurlbgn.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winrxnk.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winrxnk.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\sdscoh.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\sdscoh.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winusdj.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winusdj.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winywbige.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winywbige.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winfciin.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winfciin.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\xmsolh.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\xmsolh.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winnnnk.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winnnnk.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\erch.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\erch.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\nflxus.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\nflxus.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winrwxbbb.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winrwxbbb.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winmppjpe.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winmppjpe.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winswxgsx.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winswxgsx.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winsrejoq.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winsrejoq.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winjsmks.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winjsmks.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winncljf.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winncljf.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\umrtdw.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\umrtdw.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winaykl.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winaykl.exe:*:Enabled:ipsec "C:\Program Files\DAEMON Tools Lite\DTLite.exe" = C:\Program Files\DAEMON Tools Lite\DTLite.exe:*:Enabled:ipsec -- (DT Soft Ltd) "C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe" = C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe:*:Enabled:ipsec -- (Dll-FIles.Com) "C:\DOCUME~1\junior\USTAWI~1\Temp\winebft.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winebft.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winenrhgb.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winenrhgb.exe:*:Enabled:ipsec "C:\Program Files\Panda Security\Panda Antivirus Pro 2012\Inicio.exe" = C:\Program Files\Panda Security\Panda Antivirus Pro 2012\Inicio.exe:*:Enabled:ipsec -- (Panda Security, S.L.) "C:\DOCUME~1\junior\USTAWI~1\Temp\ulmpg.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\ulmpg.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winvummdr.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winvummdr.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\axqwjl.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\axqwjl.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\vunlok.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\vunlok.exe:*:Enabled:ipsec "C:\DOCUME~1\junior\USTAWI~1\Temp\winmqkuy.exe" = C:\DOCUME~1\junior\USTAWI~1\Temp\winmqkuy.exe:*:Enabled:ipsec -- () [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{A0C39D92-DEB9-434E-9F1A-2A4AEFB0EB86}" = Panda Antivirus Pro 2012 "{A7E07C2B-2220-4415-87E3-784D5814BC93}" = NVIDIA PhysX v8.09.04 "{B1D3568D-BC21-4C50-92A5-2396570DF1DE}_is1" = Panda Secure Vault 5 "{E55FB276-73C9-4776-AB53-BC028C0509ED}" = Panda Antivirus Pro 2012 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "6A1545AE87FC8D98ACA7539CE7AA69DF2A5C7E1C" = Pakiet sterowników systemu Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player Plugin "DAEMON Tools Lite" = DAEMON Tools Lite "Dll-Files.com Fixer_is1" = Dll-Files.com Fixer "Gadu-Gadu" = Gadu-Gadu 6.1 "Mozilla Firefox 13.0.1 (x86 pl)" = Mozilla Firefox 13.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIA Drivers" = NVIDIA Drivers "Opera 11.60.1185" = Opera 11.60 "V9Software" = V9 Homepage Uninstaller "Vtune_is1" = Vtune 6.7 "WinRAR archiver" = WinRAR 4.20 (32-bitowy) [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-14 05:46:19 | Computer Name = JUNIOR-8FD34819 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd iexplore.exe, wersja 7.0.6000.20696, moduł powodujący błąd mshtml.dll, wersja 7.0.6000.20710, adres błędu 0x0003c2b5. Error - 2012-07-14 06:13:47 | Computer Name = JUNIOR-8FD34819 | Source = SecurityCenter | ID = 1802 Description = Usługa Centrum zabezpieczeń systemu Windows nie może ustanowić kwerend zdarzeń z WMI, aby monitorować zaporę i program antywirusowy innej firmy. Error - 2012-07-14 07:00:37 | Computer Name = JUNIOR-8FD34819 | Source = Sentinel | ID = 251662241 Description = Unexpected failure during Anti-virus On-Access Scan Engine initialization. The AvRtlInitializeAnalyzer API failed unrecoverably (Error Status was f00006be). This may be because a needed image file is missing or corrupt. The Panda Anti-virus Service failed to initialize properly. Error - 2012-07-14 07:01:17 | Computer Name = JUNIOR-8FD34819 | Source = Sentinel | ID = 251662241 Description = Unexpected failure during Anti-virus On-Access Scan Engine initialization. The AvRtlInitializeAnalyzer API failed unrecoverably (Error Status was f00006be). This may be because a needed image file is missing or corrupt. The Panda Anti-virus Service failed to initialize properly. Error - 2012-07-14 15:52:10 | Computer Name = JUNIOR-8FD34819 | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd , wersja 0.0.0.0, moduł powodujący błąd unknown, wersja 0.0.0.0, adres błędu 0x00000000. [ System Events ] Error - 2012-07-14 10:17:08 | Computer Name = JUNIOR-8FD34819 | Source = Cdrom | ID = 262151 Description = W urządzeniu \Device\CdRom0 wystąpił zły blok. Error - 2012-07-14 10:17:10 | Computer Name = JUNIOR-8FD34819 | Source = Cdrom | ID = 262151 Description = W urządzeniu \Device\CdRom0 wystąpił zły blok. Error - 2012-07-14 10:17:11 | Computer Name = JUNIOR-8FD34819 | Source = Cdrom | ID = 262151 Description = W urządzeniu \Device\CdRom0 wystąpił zły blok. Error - 2012-07-14 10:17:12 | Computer Name = JUNIOR-8FD34819 | Source = Cdrom | ID = 262151 Description = W urządzeniu \Device\CdRom0 wystąpił zły blok. Error - 2012-07-14 15:16:19 | Computer Name = JUNIOR-8FD34819 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2012-07-14 15:37:27 | Computer Name = JUNIOR-8FD34819 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2012-07-14 15:50:40 | Computer Name = JUNIOR-8FD34819 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2012-07-14 15:58:32 | Computer Name = JUNIOR-8FD34819 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2012-07-14 16:06:08 | Computer Name = JUNIOR-8FD34819 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 Error - 2012-07-14 16:14:19 | Computer Name = JUNIOR-8FD34819 | Source = Service Control Manager | ID = 7023 Description = Usługa Przeglądarka komputera zakończyła działanie; wystąpił następujący błąd: %%1460 < End of report >