OTL Extras logfile created on: 2013-01-11 18:25:08 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Euromat\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16982) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1013,50 Mb Total Physical Memory | 704,87 Mb Available Physical Memory | 69,55% Memory free 2,22 Gb Paging File | 2,02 Gb Available in Paging File | 90,91% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 39,06 Gb Total Space | 17,65 Gb Free Space | 45,19% Space Free | Partition Type: NTFS Drive D: | 36,00 Gb Total Space | 25,46 Gb Free Space | 70,73% Space Free | Partition Type: NTFS Drive E: | 2,11 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive F: | 35,26 Gb Total Space | 35,13 Gb Free Space | 99,62% Space Free | Partition Type: NTFS Computer Name: EUROMAT-PC | User Name: Euromat | Logged in as Administrator. Boot Mode: SafeMode | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_USERS\S-1-5-21-120728158-1668873095-2500419783-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- Reg Error: Key error. https [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- Reg Error: Key error. Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 1 "InternetSettingsDisableNotify" = 1 "AutoUpdateDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-120728158-1668873095-2500419783-1000] "EnableNotifications" = 1 "EnableNotificationsRef" = 1 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{4EF70B49-0D7A-4D82-A4B1-93F730150388}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe | "{E9E72755-2531-4A9D-A41A-ACE8EBAA96BD}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A686CC5E-EA51-43CC-9027-D014BBB7468A}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0020FEE2-7CDB-4250-B04B-81D68D3CA18B}" = "{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = TIPCI "{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for TOSHIBA "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Narzędzie do przekazywania usługi Windows Live "{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2668C32B-D3E3-4624-B9E6-8FD344AB7063}" = TMSDirect v.2 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba "{51958BA7-21E4-4A8B-9098-CD8375BD17B2}" = Asystent rejestracji usługi Windows Live "{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password "{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup "{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan "{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA7B0DE4-E3CA-443F-B1CF-418431664C63}" = Windows Live Movie Maker "{AC76BA86-7AD7-1045-7B44-A91000000001}" = Adobe Reader 9.1 - Polish "{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser "{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree "{C5096D00-8B9C-41DB-8472-9D721E982DF0}" = Podstawowe programy Windows Live "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba "{E39C185F-1240-4BA7-A03B-4FD99805D63E}" = Galeria fotografii usługi Windows Live "{E580DFEA-3F1D-4B56-9115-984217032FF5}" = Windows Live Sync "{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA "{FB83EAC4-E3F6-4666-B45B-44522F2344B6}" = Brother MFL-Pro Suite DCP-J125 "{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "avast" = avast! Free Antivirus "CCleaner" = CCleaner "Defraggler" = Defraggler "DMX5_is1" = DriverMax 5 "Google Chrome" = Google Chrome "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallShield_{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = Texas Instruments PCIxx21/x515/xx12 drivers. "InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for TOSHIBA "InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Hasło administratora "InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = Sprzęt instalacyjny TOSHIBA "InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility "InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "InstallWIX_{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "SynTPDeinstKey" = Synaptics Pointing Device Driver "TOSHIBA Software Modem" = TOSHIBA Software Modem "WinLiveSuite_Wave3" = Podstawowe programy Windows Live [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2011-08-20 01:59:10 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-20 01:59:19 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-20 05:47:26 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-20 05:47:35 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-21 11:56:48 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-21 11:57:04 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-21 12:37:33 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-21 12:41:32 | Computer Name = Euromat-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083 Description = Error - 2011-08-25 13:06:05 | Computer Name = Euromat-PC | Source = Automatic LiveUpdate Scheduler | ID = 101 Description = Error - 2011-08-29 02:55:35 | Computer Name = Euromat-PC | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd FotoSender.exe, wersja 1.0.0.1, sygnatura czasowa 0x4dc11cd8, moduł powodujący błąd MFC71U.DLL, wersja 7.10.3077.0, sygnatura czasowa 0x3e77fc29, kod wyjątku 0xc0000005, przesunięcie błędu 0x00049839, identyfikator procesu 0xd40, godzina rozpoczęcia aplikacji 0x01cc6617a7522d75. [ System Events ] Error - 2013-01-11 13:04:52 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:04:52 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:04:52 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:22:49 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:22:49 | Computer Name = Euromat-PC | Source = LSM | ID = 1048 Description = Error - 2013-01-11 13:22:53 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:23:00 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:23:03 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:23:03 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = Error - 2013-01-11 13:23:03 | Computer Name = Euromat-PC | Source = DCOM | ID = 10005 Description = < End of report >