OTL Extras logfile created on: 7/14/2012 12:19:19 AM - Run 1 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Administrator\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1023.36 Mb Total Physical Memory | 669.84 Mb Available Physical Memory | 65.45% Memory free 2.41 Gb Paging File | 2.24 Gb Available in Paging File | 92.88% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29.29 Gb Total Space | 5.66 Gb Free Space | 19.31% Space Free | Partition Type: NTFS Drive D: | 119.75 Gb Total Space | 117.35 Gb Free Space | 97.99% Space Free | Partition Type: NTFS Computer Name: DOM-CFED9156FBC | User Name: Administrator | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1701765B-6D93-43C6-A835-DD423517581F}" = OpenOffice.org 3.2 "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{23D51AF4-E674-4F4C-A937-F98E458A37AB}_is1" = Testy B 2011b "{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10 "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM) "{57383270-6F61-4DC8-A9B8-C1745FC29F38}" = USB PC Camera (SN9C101) "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update "{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}" = Nero BurnLite 10 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}" = Nero BurnLite 10 "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3) "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype "{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3 "{D9ECBC61-0D76-4EDD-8D46-BB2BB0A02108}" = Localization Pack for Microsoft Windows XP Media Center Edition "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F40963EC-223E-4E65-8CF0-A60E9A227245}_is1" = Prawo Jazdy ABCDT - egzamin wewnętrzny "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Gadu-Gadu 10" = Gadu-Gadu 10 "Google Chrome" = Google Chrome "Guitar Pro 5_is1" = Guitar Pro 5.2 "ie8" = Windows Internet Explorer 8 "IrfanView" = IrfanView (remove only) "Kamerzysta" = Kamerzysta (deinstalacja) "KLiteCodecPack_is1" = K-Lite Codec Pack 5.1.0 (Full) "McAfee Security Scan" = McAfee Security Scan Plus "Mozilla Firefox 13.0.1 (x86 pl)" = Mozilla Firefox 13.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIA Drivers" = NVIDIA Drivers "Passage 3 Demo" = PASSAGE 3 Demo "PDF Editor 3" = PDF Editor 3 "Rmtablet" = SPYDEE USB Tablet Manager "Skrzyżowania_is1" = Skrzyżowania 1.0.0.17 "Taboret2" = Taboret2 - Czat komunikator "VDOTool_is1" = VDOTool 5.3 "VLC media player" = VLC media player 1.0.1 "Windows Media Format Runtime" = Windows Media Format Runtime "Windows XP Service Pack" = Windows XP Service Pack 3 "WinGimp-2.0_is1" = GIMP 2.6.11 "WinRAR archiver" = Archiwizator WinRAR "Znaki Drogowe_is1" = Znaki Drogowe [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 4/10/2012 6:07:50 PM | Computer Name = DOM-CFED9156FBC | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: Określony serwer nie może wykonać żądanej operacji. Error - 4/10/2012 6:07:50 PM | Computer Name = DOM-CFED9156FBC | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: Określony serwer nie może wykonać żądanej operacji. Error - 4/14/2012 2:58:45 PM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application i_view32.exe, version 4.2.5.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 5/6/2012 12:18:12 PM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 5/9/2012 5:37:26 PM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 5/14/2012 4:22:59 AM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 5/15/2012 3:38:33 AM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 6/3/2012 1:20:04 AM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 6/3/2012 1:20:06 AM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 7/3/2012 5:31:50 PM | Computer Name = DOM-CFED9156FBC | Source = Application Hang | ID = 1002 Description = Hanging application soffice.bin, version 3.2.9476.500, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 6/21/2012 8:20:40 AM | Computer Name = DOM-CFED9156FBC | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.104 for the Network Card with network address 0019DBA8B79D has been denied by the DHCP server 192.168.1.100 (The DHCP Server sent a DHCPNACK message). Error - 7/3/2012 6:31:35 PM | Computer Name = DOM-CFED9156FBC | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.102 for the Network Card with network address 0019DBA8B79D has been denied by the DHCP server 192.168.1.100 (The DHCP Server sent a DHCPNACK message). Error - 7/3/2012 6:32:17 PM | Computer Name = DOM-CFED9156FBC | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.101 for the Network Card with network address 0019DBA8B79D has been denied by the DHCP server 192.168.1.100 (The DHCP Server sent a DHCPNACK message). Error - 7/4/2012 4:30:34 AM | Computer Name = DOM-CFED9156FBC | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.101 for the Network Card with network address 0019DBA8B79D has been denied by the DHCP server 192.168.1.100 (The DHCP Server sent a DHCPNACK message). Error - 7/4/2012 11:17:25 AM | Computer Name = DOM-CFED9156FBC | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.102 for the Network Card with network address 0019DBA8B79D has been denied by the DHCP server 192.168.1.100 (The DHCP Server sent a DHCPNACK message). Error - 7/6/2012 1:57:48 PM | Computer Name = DOM-CFED9156FBC | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.102 for the Network Card with network address 0019DBA8B79D has been denied by the DHCP server 192.168.1.100 (The DHCP Server sent a DHCPNACK message). Error - 7/9/2012 5:55:07 AM | Computer Name = DOM-CFED9156FBC | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.102 for the Network Card with network address 0019DBA8B79D has been denied by the DHCP server 192.168.1.100 (The DHCP Server sent a DHCPNACK message). Error - 7/11/2012 10:42:50 AM | Computer Name = DOM-CFED9156FBC | Source = MRxSmb | ID = 8003 Description = The master browser has received a server announcement from the computer KOMPUTER that believes that it is the master browser for the domain on transport NetBT_Tcpip_{A30425FB-2765-47BD-. The master browser is stopping or an election is being forced. Error - 7/13/2012 6:09:00 PM | Computer Name = DOM-CFED9156FBC | Source = DCOM | ID = 10005 Description = DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 7/13/2012 6:10:21 PM | Computer Name = DOM-CFED9156FBC | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: Fips intelppm < End of report >