OTL Extras logfile created on: 2012-12-09 16:49:12 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HashMan\Downloads Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,64 Gb Available Physical Memory | 54,57% Memory free 5,99 Gb Paging File | 4,46 Gb Available in Paging File | 74,48% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 148,89 Gb Total Space | 129,62 Gb Free Space | 87,06% Space Free | Partition Type: NTFS Drive D: | 147,73 Gb Total Space | 24,47 Gb Free Space | 16,57% Space Free | Partition Type: NTFS Computer Name: HASHMAN-PC | User Name: HashMan | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-4141006419-3361506613-2479011934-1001\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0165A46A-C2F7-49DB-A45E-2546094E8C84}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{02C55DCF-0DAF-485E-9040-F48BCF933837}" = lport=2869 | protocol=6 | dir=in | app=system | "{136C63A2-17C1-47AB-B7FA-07931A9ECBF3}" = rport=10243 | protocol=6 | dir=out | app=system | "{28DFE81B-9228-4290-ABBA-22C8E62670F4}" = lport=138 | protocol=17 | dir=in | app=system | "{2D1738FC-3FA5-4038-A062-567F1887B2BB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3DB10330-735F-4AD8-B95F-C981CB85B00E}" = rport=445 | protocol=6 | dir=out | app=system | "{57609DB4-AF26-4977-B3AA-1F4C43F5D80C}" = lport=445 | protocol=6 | dir=in | app=system | "{856E6781-62F5-4298-8AAB-84A67287B963}" = lport=137 | protocol=17 | dir=in | app=system | "{8BDF3EC0-27FC-4D07-9E1B-2B765607252D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{8EDAEE18-E398-4E2D-9559-F69C54B98A51}" = rport=139 | protocol=6 | dir=out | app=system | "{93EFFD69-F180-47B1-B0D2-53CE6D4285BC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{AD43BF15-AE62-41A2-924B-2322902317B5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{AD49349F-411E-4D11-936E-47329334C9BF}" = lport=139 | protocol=6 | dir=in | app=system | "{BBA7651A-7648-4C03-9BBF-8527E0686119}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BD92596B-6F53-4D8A-8CB5-0914FD4CA90C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{C432571F-C8C9-4AA9-B1EA-C3E86DF1A157}" = lport=10243 | protocol=6 | dir=in | app=system | "{E0263E35-F3F1-43A1-AF44-3CB0D11FD449}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E6751391-5DC9-4BE0-A2FD-1772BF82778A}" = rport=138 | protocol=17 | dir=out | app=system | "{F7779E5D-12AC-4094-B9ED-30B53A57058D}" = rport=137 | protocol=17 | dir=out | app=system | "{FE0F61D3-7572-4F4D-AC49-68E0F654DFA1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FE47FFF1-16F9-4126-95A4-955A105CE0BA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0CDC1E38-6634-4CC6-9B94-AB1F1E70A41A}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{11285C7A-721B-47D7-99A7-0F8B33E7603E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{14E87593-647E-49AB-9E88-965684B6EC11}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1802086F-65B4-4DCA-A48E-73C71EBC13D9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{23C49E2D-41DB-4798-B6A3-EAEC52A13434}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{264F3B20-B3E4-4128-9C37-87BA5AF07B93}" = dir=in | app=c:\program files\itunes\itunes.exe | "{2E8865D4-AE75-4A75-ACF6-2808B9B0ADDD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{374FDE55-AE96-4936-B42A-3C57301F7AAD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{4BD5800F-D3A4-4FF8-8671-F6D73F9290AB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{5AFFB101-0383-4272-B574-9A43CBBE8974}" = protocol=6 | dir=out | app=system | "{76D80702-7FC1-46F3-B5A0-A870E23E59A7}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{8CD2B06D-EEB6-4917-9E4D-5A949AA73BA8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{96BF353B-B6D3-430A-8FA4-3C468221AF10}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{9D52D9A7-12E6-4B2F-AD18-6BB70BDC8C53}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{A6B7ADB4-95E9-4C2A-983F-6A7BF79CDCA9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{AE6B09BA-9708-4F23-BC20-02F359BC6619}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B851C989-B778-4F56-845D-E8373FF48A53}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{BE43B947-2D9E-4E5D-88EA-A0E3418D1CDA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{DD1FA528-9B7B-44E8-8A14-AA38DB7378A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{DD45828F-2546-469C-B31D-2856199F5069}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{ECF8CF31-0B21-421E-9288-6EEA7586F055}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{EE5A9820-BB5B-4D2E-9066-A180A1D9E3DB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{F86572D0-684A-4746-A518-B93D5E62FBD0}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "TCP Query User{97C4712B-63B2-434E-BBA4-34DAB8F2992A}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | "UDP Query User{A0715FB4-F18E-4847-B9CC-66DB5DF9C8BB}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0163E195-D5EF-BF70-CBEE-73AA7CBBBEEE}" = CCC Help Thai "{03883959-80DA-6151-CEAE-46A058CF774F}" = CCC Help Danish "{096D1CCF-0F1E-08FB-094F-C40A633D5AEB}" = ccc-core-static "{13D0EB07-FCA0-C005-A6C5-B1A4B7E5BB48}" = Catalyst Control Center Core Implementation "{1B6C0E95-182C-48E0-9C4B-4F916308249C}" = iTunes "{1D4A3E7D-A580-5BB7-DED3-48508A53D2B2}" = CCC Help Chinese Standard "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{22354A21-BE84-0D40-191D-6E530B715CCF}" = CCC Help Polish "{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9 "{2F36BA32-7986-9E40-B3F6-908B214EC898}" = CCC Help Japanese "{2F4A39B2-5A2D-3E9F-E8EA-6F891A097ACF}" = CCC Help English "{3DBE8669-1F7D-E1C9-2BC8-CC4BAE0A5136}" = CCC Help Turkish "{3FF5FF03-DB97-2ACE-BAE7-61D6D4A39F9B}" = Catalyst Control Center Graphics Full Existing "{459699C3-9430-4381-964B-4248D87B49F9}" = Apple Mobile Device Support "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CEE0E9F-2116-BE92-CD54-8D1834935B54}" = Catalyst Control Center Localization All "{5DD59391-FED6-576D-B6BD-71111EF96522}" = CCC Help Russian "{601E6234-EC57-0948-6E33-7F2339EC5AA1}" = ATI Catalyst Install Manager "{6168260A-6D56-50BB-193C-BF6F471394AA}" = CCC Help Greek "{6A150790-FC79-D323-92D4-E773E3A03789}" = CCC Help Portuguese "{6CB88B54-4C1C-E6AB-49C6-476DE56327BC}" = CCC Help Spanish "{6DE880FE-F0C9-BC57-B7C5-2ABEAE1E501E}" = CCC Help German "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{79660B73-3DD0-9C3D-3F29-0E266F3AE5EA}" = CCC Help Norwegian "{81E5E076-F2C1-AE09-A360-0CAC2967FD5F}" = CCC Help Swedish "{986CAA52-3249-B34F-DC64-07347926CF57}" = CCC Help Korean "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{B5B8BA5D-55CA-9351-984B-048FEF97A544}" = Catalyst Control Center Graphics Previews Vista "{B6DECBD2-EC09-17C3-35AE-8C72B08062C9}" = CCC Help Czech "{BF3AB290-563B-2F6F-9AF0-189B5CCF2C01}" = Catalyst Control Center Graphics Light "{C644BA4B-07D6-A67E-9EB4-157F6DEB68BE}" = CCC Help Chinese Traditional "{CC6ECC37-F908-4575-D549-3E0F1084B2B3}" = ccc-utility "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Obsługa programów Apple "{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba "{D0831990-FF97-1F08-668D-4743CC32EFBC}" = CCC Help Finnish "{D9835CE0-E294-83FE-AF9F-BC113A0D2EA9}" = CCC Help Hungarian "{E25FA4E1-678F-414F-9777-1E3FDBBDA4D1}" = Catalyst Control Center InstallProxy "{E3D63B95-4B21-414A-A2C7-D6D6A6AC6D79}" = Catalyst Control Center - Branding "{E8B28EF5-2A73-03A7-4F02-2DFF1D182940}" = Catalyst Control Center Graphics Full New "{E94F833D-6435-40A2-112C-4BC18100B91D}" = CCC Help Italian "{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0 "{EEA02668-D5D9-AEFF-6FFB-1EB5BC765A52}" = CCC Help French "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FCD674E3-F281-46D6-7717-6EAFDD16D8FC}" = CCC Help Dutch "{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "AIMP3" = AIMP3 "avast" = avast! Free Antivirus "CCleaner" = CCleaner "D27D7E9318CFA89EDDE8D448B507A8EB725F5A52" = Pakiet sterowników systemu Windows - TOSHIBA (FwLnk) System (11/19/2006 1.0.0.3) "FreeFixer0.70" = FreeFixer "Google Chrome" = Google Chrome "InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "KLiteCodecPack_is1" = K-Lite Codec Pack 9.5.5 (Full) "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.65.1.1000 "Totalcmd" = Total Commander (Remove or Repair) "uTorrent" = µTorrent [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-4141006419-3361506613-2479011934-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "GG" = GG [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-12-08 22:38:46 | Computer Name = HashMan-PC | Source = VSS | ID = 8194 Description = Error - 2012-12-09 01:01:31 | Computer Name = HashMan-PC | Source = Office Software Protection Platform Service | ID = 1017 Description = Error - 2012-12-09 01:01:41 | Computer Name = HashMan-PC | Source = Office Software Protection Platform Service | ID = 1017 Description = [ System Events ] Error - 2012-12-08 22:37:03 | Computer Name = HashMan-PC | Source = atikmdag | ID = 43029 Description = Display is not active Error - 2012-12-08 22:41:38 | Computer Name = HashMan-PC | Source = atikmdag | ID = 52236 Description = CPLIB :: General - Invalid Parameter Error - 2012-12-08 22:41:38 | Computer Name = HashMan-PC | Source = atikmdag | ID = 43029 Description = Display is not active Error - 2012-12-08 23:30:07 | Computer Name = HashMan-PC | Source = DCOM | ID = 10010 Description = Error - 2012-12-09 00:16:33 | Computer Name = HashMan-PC | Source = atikmdag | ID = 52236 Description = CPLIB :: General - Invalid Parameter Error - 2012-12-09 00:16:33 | Computer Name = HashMan-PC | Source = atikmdag | ID = 43029 Description = Display is not active Error - 2012-12-09 00:18:00 | Computer Name = HashMan-PC | Source = Service Control Manager | ID = 7023 Description = Usługa Instalator modułów systemu Windows zakończyła działanie; wystąpił następujący błąd: %%16405 Error - 2012-12-09 00:20:28 | Computer Name = HashMan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować następującej aktualizacji, ponieważ wystąpił błąd 0x80242016: Aktualizacja zabezpieczeń programu Internet Explorer 8 w systemie Windows 7 (KB2544521). Error - 2012-12-09 10:02:30 | Computer Name = HashMan-PC | Source = atikmdag | ID = 43029 Description = Display is not active Error - 2012-12-09 10:34:59 | Computer Name = HashMan-PC | Source = atikmdag | ID = 43029 Description = Display is not active < End of report >