OTL Extras logfile created on: 2012-08-01 17:45:57 - Run 2 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Olga\Downloads Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 1,24 Gb Available Physical Memory | 62,08% Memory free 3,98 Gb Paging File | 3,19 Gb Available in Paging File | 80,18% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 39,07 Gb Total Space | 6,21 Gb Free Space | 15,90% Space Free | Partition Type: NTFS Drive D: | 109,98 Gb Total Space | 7,99 Gb Free Space | 7,26% Space Free | Partition Type: NTFS Computer Name: OLGA-KOMPUTER | User Name: Olga | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2241325764-2108550729-2011939928-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{11AAA208-B526-413D-84EC-CD89ACDEBAB3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{142C09E1-436A-4DF1-82A1-357A8472A67D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{183805AF-926B-499E-A571-E5EAA6BB9A95}" = rport=10243 | protocol=6 | dir=out | app=system | "{478C8C13-845F-4A56-9BBB-C37558FFC515}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5EBD5D67-39C0-4AC0-8C92-691A27D86768}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6D60FAA2-9D4E-4E68-A6A2-779B8FE8A1D8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{711FD7A3-1D3E-4333-A354-3A6F382D971B}" = lport=137 | protocol=17 | dir=in | app=system | "{9E209B55-70EE-4C8D-B7D4-89859A7FB591}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A0B541AD-97D7-4616-AD6B-39797F709119}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{A44A9442-FFEB-42B1-A40F-48A64133BEEF}" = lport=139 | protocol=6 | dir=in | app=system | "{A53116F1-99A6-44FA-92CD-A584C379B245}" = lport=10243 | protocol=6 | dir=in | app=system | "{ABA117B3-B96D-4122-AD21-1B5140726978}" = lport=445 | protocol=6 | dir=in | app=system | "{BF8F87E9-5706-479B-8902-70930D1A6C64}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C0A14193-162D-4D02-869A-0E8CFAE760E7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C5F4E187-F010-4DAE-BF1E-92A16BBFB21F}" = rport=139 | protocol=6 | dir=out | app=system | "{C7065D5B-C5A7-43D1-9C68-B14AA532AF41}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C8DE73AF-3FA6-47A5-89AC-159854B14B78}" = rport=137 | protocol=17 | dir=out | app=system | "{D91AAD3C-268C-4F79-AED7-256634FD218C}" = lport=138 | protocol=17 | dir=in | app=system | "{E6E2BEA3-8F7C-40E4-BE6A-690CD267598F}" = rport=138 | protocol=17 | dir=out | app=system | "{EAB08746-38DF-4445-B00B-1DBAB7775097}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{F3A71B5B-2721-4F13-ACC4-F38A4BEAB134}" = lport=2869 | protocol=6 | dir=in | app=system | "{FD28E645-0E44-4B3C-9CA2-D23AB8B631EC}" = rport=445 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1004FB97-FDA1-4E35-BDA4-69799B50F14A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{4175B35A-6BC8-4BB6-B135-F4EA486E8779}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{437F4A48-D23C-4048-9EFB-8B65D720985B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{468DD33C-1E49-4326-9FB5-779718D0D3F6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{5ADF4183-B734-4F6F-A11D-203AF599A252}" = protocol=6 | dir=out | app=system | "{5C844275-B1AD-4A69-923C-31BD35005231}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{644C90B0-7A47-4951-BB47-B898729DDBE0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{6C169EAF-B9F9-4C21-99CA-DEEB683C96B1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{741E26FA-822E-4BA0-A928-193874345FC9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{907B0683-9E58-4D67-85C4-AD96E44A4E0B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{91290738-CB2A-4421-9DB0-D96B737B0AF7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{994AA0D0-6163-4D6A-9522-EA297D24337E}" = dir=in | app=c:\users\olga\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{A40C7E40-265A-4C85-9A4F-591853B3D580}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{A55156D2-765A-4103-85B3-74CCCC276756}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{AEB182CE-15AC-4ECB-932E-8A27778E12F4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{C2783810-2139-4C67-9E49-D6915904292F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{C54D3EEF-0C26-479A-B129-1B10288395A0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D4DC1968-05F7-49ED-A708-27C7293EF3A4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D8F9C4E9-DF85-4491-9F22-DD1FD16A420C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E62A0394-C41E-4D05-BB07-728097916AFC}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{ED19DB4C-E208-4AF5-810C-FF3B4A28052D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{328B1011-42CE-4D10-A4DF-78CC7A883657}" = Claw "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159 "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{AC76BA86-7AD7-1045-7B44-A95000000001}" = Adobe Reader 9.5.0 - Polish "{D1399216-81B2-457C-A0F7-73B9A2EF6902}" = PDFill PDF Editor with FREE Writer and FREE Tools "{DA683EB9-E863-42B1-8F73-70B549E69D7D}" = ESET Smart Security "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "1DF1F719-D43A-46E8-950F-65A8D96C678A.MBT_is1" = Motorola Bluetooth "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "ALLPlayer_is1" = ALLPlayer V5.X "CCleaner" = CCleaner "DAEMON Tools Lite" = DAEMON Tools Lite "DAEMON Tools Toolbar" = DAEMON Tools Toolbar "Driver Genius Professional Edition_is1" = Driver Genius Professional Edition "HDMI" = Intel(R) Graphics Media Accelerator Driver "IObit Unlocker_is1" = IObit Unlocker "KLiteCodecPack_is1" = K-Lite Codec Pack 8.2.0 (Full) "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151) "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "PLAY ONLINE" = PLAY ONLINE "SMSERIAL" = Motorola SM56 Data Fax Modem "SopCast" = SopCast 3.5.0 "TNod" = TNod User & Password Finder "TVWiz" = Intel(R) TV Wizard "WinRAR archiver" = WinRAR 4.01 (32-bitowy) [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2241325764-2108550729-2011939928-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-07-31 13:47:36 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-07-31 13:55:28 | Computer Name = Olga-Komputer | Source = System Restore | ID = 8193 Description = Error - 2012-07-31 13:58:10 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-07-31 14:03:54 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-07-31 14:10:37 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-07-31 17:31:16 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-07-31 18:32:51 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-08-01 10:32:41 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-08-01 11:08:35 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = Error - 2012-08-01 11:12:56 | Computer Name = Olga-Komputer | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2012-07-04 11:56:22 | Computer Name = Olga-Komputer | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk1\DR1. Error - 2012-07-05 04:36:26 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 10:34:26 na ?2012-?07-?05 było nieoczekiwane. Error - 2012-07-05 04:37:26 | Computer Name = Olga-Komputer | Source = WMPNetworkSvc | ID = 866300 Description = Error - 2012-07-05 15:20:43 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 14:06:33 na ?2012-?07-?05 było nieoczekiwane. Error - 2012-07-06 03:12:13 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 02:23:17 na ?2012-?07-?06 było nieoczekiwane. Error - 2012-07-08 10:46:39 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 12:24:05 na ?2012-?07-?06 było nieoczekiwane. Error - 2012-07-09 10:46:35 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 16:44:11 na ?2012-?07-?09 było nieoczekiwane. Error - 2012-07-09 11:09:34 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 17:06:27 na ?2012-?07-?09 było nieoczekiwane. Error - 2012-07-09 14:26:54 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 20:23:57 na ?2012-?07-?09 było nieoczekiwane. Error - 2012-07-10 15:43:36 | Computer Name = Olga-Komputer | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 18:06:19 na ?2012-?07-?10 było nieoczekiwane. < End of report >