OTL Extras logfile created on: 2012-08-29 09:11:50 - Run 1 OTL by OldTimer - Version 3.2.59.1 Folder = C:\Users\1201HA\Downloads Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 0,27 Gb Available Physical Memory | 13,54% Memory free 3,98 Gb Paging File | 1,91 Gb Available in Paging File | 47,97% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 232,79 Gb Total Space | 214,52 Gb Free Space | 92,16% Space Free | Partition Type: NTFS Drive E: | 562,92 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: 1201HA-GASTPOL | User Name: 1201HA | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01A5477D-AF66-43B5-987F-D7160E8B8B3D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{0D2E75E4-9388-4104-9095-AC55A44A4DC5}" = lport=445 | protocol=6 | dir=in | app=system | "{0FB5AF92-AC0B-4655-8FA6-17910392F1B7}" = rport=137 | protocol=17 | dir=out | app=system | "{198F8FE0-86A3-4BEA-A838-6EEAEE0F14B5}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe | "{27CC5DBF-650C-4C28-B7FA-632246CD6D77}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{49380A92-C394-403A-AE4C-032B9B99A7A3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6365E7E3-A12E-47C7-ADCB-A9F31530DBF7}" = lport=139 | protocol=6 | dir=in | app=system | "{6EFEC50F-43BC-4719-BCC5-80A3A3284B02}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7271AB63-F9F0-4A67-B954-57B0BFCAD6F9}" = lport=10243 | protocol=6 | dir=in | app=system | "{7FDEE094-F017-434F-A1C6-292528649452}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{8A243F41-ADF5-440F-ACFE-763BE6A59759}" = rport=138 | protocol=17 | dir=out | app=system | "{8DC9AAD0-7BD4-4AB5-8039-E4130C3CEC06}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{9378E3F1-9899-457D-BCEC-1D8A8DC2AB07}" = lport=138 | protocol=17 | dir=in | app=system | "{957C5848-D881-4143-BD0D-8D6F3AE50C97}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{95815240-4E78-4B1C-82A7-166A84970E77}" = lport=137 | protocol=17 | dir=in | app=system | "{BFE9D4C4-9A7E-4307-B9F2-E023C634FADA}" = rport=445 | protocol=6 | dir=out | app=system | "{C7376034-278B-48CB-9E40-88B6EBC89E4C}" = rport=10243 | protocol=6 | dir=out | app=system | "{C74552E2-F50D-47DB-945C-296B7C1A82E2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CB685CFB-D4B5-4212-995C-5FB914D9AD66}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CCE76D34-04B7-44D1-8B5C-4B43AC22FA54}" = lport=2869 | protocol=6 | dir=in | app=system | "{CCF7ADF0-F2A2-439F-AFBB-1017DD0D5A5E}" = rport=139 | protocol=6 | dir=out | app=system | "{FDA677C2-D205-4880-B084-A9AB63239C93}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04C7FE29-16F1-4271-AEA3-C46AB1AA7EDC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0CE6C22E-C851-44F3-A86D-6F93651E5C42}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{1B70316B-FA9A-4B23-A9CB-FB625698FE13}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{1F14FE45-9DB6-48EB-B58E-187EBD8DDDC9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{24858397-0ACB-43BE-9FBC-8D385B1BBB2F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{305C9A97-3775-4921-9746-9033B0488A04}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{4CAA3425-8487-4D53-9CC9-C18F9D72ED1F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{532C7D17-BC5B-4E24-B0C9-BF6CBBB96439}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{59D3BDC2-F4FD-43C2-92F6-05D14BAA9B59}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{5D6847B3-C457-4EF0-8539-52F76477DEE5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7CD0ED48-BA26-4317-A004-E815A8F2023E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{87232068-D940-4206-B0D1-376668F195F4}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{8A9B4076-53D9-43D6-B5E3-3ED5541081B5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{94D7A9F6-C240-4588-95CA-883296542DEA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{AD7B3BE7-D9AF-4A0E-9C55-18F0A45A9496}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D0FB8C95-F7DC-4004-9D29-9A6D48CEA7F9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe | "{D14B8662-2938-44C9-82D4-B783C71B1A1F}" = protocol=6 | dir=out | app=system | "{E6C6CA15-17C5-4BC2-B028-9960C9527AB2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E9C5EB70-280D-429B-A20D-B8DEAB86E17F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{ECB14383-C92E-4868-85E3-9A47BE6E3F8D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver "{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012 "{71C0E38E-09F2-4386-9977-404D4F6640CD}" = Hotkey Service "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" = "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}" = SRS Premium Sound Control Panel "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Browsers Protector" = Browsers Protector "DAEMON Tools Lite" = DAEMON Tools Lite "ENTERPRISE" = Microsoft Office Enterprise 2007 "fd0653a5" = Contextual Tool Extrafind "Gadu-Gadu 10" = Gadu-Gadu 10 "InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012 "LPCO" = Intel(R) Graphics Media Accelerator 500 "Mozilla Firefox 12.0 (x86 pl)" = Mozilla Firefox 12.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "StartSearch Toolbar" = StartSearch Toolbar 1.3 "SynTPDeinstKey" = Synaptics Pointing Device Driver [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-02-28 13:34:11 | Computer Name = 1201HA-GASTPOL | Source = VSS | ID = 8194 Description = Error - 2012-07-01 12:35:09 | Computer Name = 1201HA-GASTPOL | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 2012-07-01 12:36:43 | Computer Name = 1201HA-GASTPOL | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 2012-08-28 09:21:47 | Computer Name = 1201HA-GASTPOL | Source = Microsoft-Windows-CAPI2 | ID = 4101 Description = Nie można automatycznie pobrać aktualizacji głównego certyfikatu innych firm z: , wystąpił błąd: Operacja została zwrócona, ponieważ przekroczono limit czasu. . [ System Events ] Error - 2012-08-28 08:39:25 | Computer Name = 1201HA-GASTPOL | Source = sptd | ID = 262148 Description = Sterownik wykrył błąd wewnętrzny w swoich strukturach danych dla . Error - 2012-08-28 08:39:54 | Computer Name = 1201HA-GASTPOL | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: sptd Error - 2012-08-28 11:43:50 | Computer Name = 1201HA-GASTPOL | Source = sptd | ID = 262148 Description = Sterownik wykrył błąd wewnętrzny w swoich strukturach danych dla . Error - 2012-08-28 11:44:32 | Computer Name = 1201HA-GASTPOL | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 17:00:43 na ?2012-?08-?28 było nieoczekiwane. Error - 2012-08-28 11:44:44 | Computer Name = 1201HA-GASTPOL | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: sptd Error - 2012-08-28 13:37:20 | Computer Name = 1201HA-GASTPOL | Source = sptd | ID = 262148 Description = Sterownik wykrył błąd wewnętrzny w swoich strukturach danych dla . Error - 2012-08-28 13:37:50 | Computer Name = 1201HA-GASTPOL | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: sptd Error - 2012-08-29 02:07:47 | Computer Name = 1201HA-GASTPOL | Source = sptd | ID = 262148 Description = Sterownik wykrył błąd wewnętrzny w swoich strukturach danych dla . Error - 2012-08-29 02:08:04 | Computer Name = 1201HA-GASTPOL | Source = EventLog | ID = 6008 Description = Poprzednie zamknięcie systemu przy 23:09:39 na ?2012-?08-?28 było nieoczekiwane. Error - 2012-08-29 02:08:17 | Computer Name = 1201HA-GASTPOL | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: sptd < End of report >