OTL Extras logfile created on: 2013-05-23 18:04:12 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = H:\ Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 255,47 Mb Total Physical Memory | 55,58 Mb Available Physical Memory | 21,76% Memory free 1,20 Gb Paging File | 1,15 Gb Available in Paging File | 95,14% Paging File free Paging file location(s): D:\pagefile.sys 1000 1000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 6,35 Gb Total Space | 1,43 Gb Free Space | 22,52% Space Free | Partition Type: NTFS Drive D: | 1,00 Gb Total Space | 0,02 Gb Free Space | 1,70% Space Free | Partition Type: FAT Drive E: | 29,91 Gb Total Space | 2,77 Gb Free Space | 9,28% Space Free | Partition Type: NTFS Drive H: | 7,24 Gb Total Space | 7,24 Gb Free Space | 99,98% Space Free | Partition Type: FAT32 Computer Name: SREDNI | User Name: Administrator | Logged in as Administrator. Boot Mode: SafeMode | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "UacDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallDisableNotify" = 0 "FirewallOverride" = 0 "UacDisableNotify" = 0 "UpdatesDisableNotify" = 0 [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00000209-3866-11D4-9FBA-00E029111DA8}" = DLS2002 Tlink II Driver "{00000281-3866-11D4-9FBA-00E029111DA8}" = DLS2002 PC1832 v4.1EU Driver Pack "{00000358-3866-11D4-9FBA-00E029111DA8}" = DLS2002 PC1832 v4.2EU Driver Pack "{00000415-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium "{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}" = Scan "{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy "{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare "{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp "{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1 "{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) "{2D0AF258-C25B-4270-90C3-36A08B32C424}" = DLS 2002 International Products "{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload "{34A0B403-9953-40F3-B1C2-7E8662FA9077}" = DLS Update Service "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour "{38AD6EA4-BBC1-4A95-B792-9950D48E2171}" = Kerio Visual C++ 2005 redistributable permanent package "{3B6DE952-41FA-44BF-B133-8882E6EB04D4}" = DLS2002 Service Pack 2 "{3F257498-439E-11D4-9FBA-00E029111DA8}" = DLS 2002 "{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}" = Cisco Systems VPN Client 5.0.04.0300 "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English) "{5469D537-9B44-4c78-BF2D-5F9807564F74}" = HP PSC & OfficeJet 4.7 "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer "{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK "{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone "{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects "{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery "{64CB2553-C109-4132-AA51-1F421B515FD1}" = Microsoft .NET Framework 1.1 Polish Language Pack "{64FC0C98-B035-4530-B15D-3D30610B6DF1}" = HP Software Update "{655CB07D-C944-40BE-B93F-55957CAC7625}" = AiO_Scan "{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations "{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm "{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1 "{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1 "{85BCA736-A0F4-448E-9BC1-6EA08693E10B}" = HP Image Zone Express "{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder "{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A4E30E08-8BF2-4D91-986B-1852DDC70DCA}" = GS3055 Software "{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config "{B8B4D43C-EAA0-4EEC-B93E-D4D012316286}" = Free DWG Viewer 7.0 "{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg "{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player Plugin "Advertising" = Advertising "BDE Installation program" = BDE Installation program "DLS_IV_Installer_Version" = DLS IV (Installer Version) "EntraPass Special Edition" = EntraPass Special Edition "Express Assist 2000" = Express Assist 2000 "GAWEŁ URSUS_is1" = GAWEŁ URSUS 1.3 "GEOXCodec" = GeoVision MPEG4 "HP Photo & Imaging" = HP Image Zone 4.7 "ISP Programmer" = ISP Programmer 1.2.0.56 "JRE 1.3.1" = Java 2 Runtime Environment Standard Edition v1.3.1 "JSDK2.0" = Java Servlet Development Kit 2.0 "KLiteCodecPack_is1" = K-Lite Codec Pack 7.0.0 (Full) "Konfigurator_LX_is1" = Konfigurator LX v1.0.1110.10821 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft SQL Server 2005" = Microsoft SQL Server 2005 "MozBackup_is1" = MozBackup 1.4.5 "Mozilla Firefox (3.5)" = Mozilla Firefox (3.5) "Mozilla Thunderbird (1.5.0.14)" = Mozilla Thunderbird (1.5.0.14) "NetMeter_is1" = NetMeter 1.1.3 "NVIDIA Drivers" = NVIDIA Drivers "Odkurzacz 12.4_is1" = Odkurzacz 12.4 "Planescape - Torment" = Planescape - Torment "PonyProg v1.17h_is1" = PonyProg v1.17h "PonyProg2000_is1" = PonyProg2000 v2.07c "Rainbow Sentinel Driver" = Sentinel System Driver "SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set "Samsung ML-1660 Series" = Konserwacja programu Samsung ML-1660 Series "SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software "Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software "SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software "SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software "TŁUMACZENIE DLS2002_is1" = TŁUMACZENIE DLS2002 wersja styczeń 2005 "TŁUMACZENIE GS3055_is1" = TŁUMACZENIE GS3055 wersja 1.0 "VAG-COM AKP" = VAG-COM AKP 704.1 "WIC" = Windows Imaging Component "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-04-02 11:16:30 | Computer Name = SREDNI | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca wiaacmgr.exe, wersja 5.1.2600.2180, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2013-04-02 11:36:35 | Computer Name = SREDNI | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca wiaacmgr.exe, wersja 5.1.2600.2180, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2013-04-21 05:25:39 | Computer Name = SREDNI | Source = crypt32 | ID = 131077 Description = Nie można automatycznie pobrać aktualizacji głównego certyfikatu innej firmy z: , wystąpił błąd: Połączenie z serwerem zostało przerwane w nienormalny sposób Error - 2013-04-21 05:25:39 | Computer Name = SREDNI | Source = crypt32 | ID = 131077 Description = Nie można automatycznie pobrać aktualizacji głównego certyfikatu innej firmy z: , wystąpił błąd: To połączenie sieciowe nie istnieje. Error - 2013-04-21 06:23:38 | Computer Name = SREDNI | Source = crypt32 | ID = 131077 Description = Nie można automatycznie pobrać aktualizacji głównego certyfikatu innej firmy z: , wystąpił błąd: Połączenie z serwerem zostało przerwane w nienormalny sposób Error - 2013-04-21 06:23:39 | Computer Name = SREDNI | Source = crypt32 | ID = 131077 Description = Nie można automatycznie pobrać aktualizacji głównego certyfikatu innej firmy z: , wystąpił błąd: To połączenie sieciowe nie istnieje. Error - 2013-04-21 08:09:07 | Computer Name = SREDNI | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd viewdrive.exe, wersja 1.0.0.0, moduł powodujący błąd unknown, wersja 0.0.0.0, adres błędu 0x7feecbd7. Error - 2013-04-28 08:36:57 | Computer Name = SREDNI | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd cmd.exe, wersja 5.1.2600.2180, moduł powodujący błąd unknown, wersja 0.0.0.0, adres błędu 0x7feecbd7. Error - 2013-04-28 09:46:01 | Computer Name = SREDNI | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd explorer.exe, wersja 6.0.2900.3156, moduł powodujący błąd explorer.exe, wersja 6.0.2900.3156, adres błędu 0x00001b48. Error - 2013-04-28 13:46:41 | Computer Name = SREDNI | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd svchost.exe, wersja 5.1.2600.2180, moduł powodujący błąd wiaservc.dll, wersja 5.1.2600.3051, adres błędu 0x000223cd. [ System Events ] Error - 2013-05-23 10:41:01 | Computer Name = SREDNI | Source = Service Control Manager | ID = 7001 Description = Usługa Pomoc TCP/IP NetBIOS zależy od usługi AFD, której nie można uruchomić z powodu następującego błędu: %%31 Error - 2013-05-23 10:41:01 | Computer Name = SREDNI | Source = Service Control Manager | ID = 7001 Description = Usługa DSC Update Service zależy od usługi Sterownik protokołu TCP/IP, której nie można uruchomić z powodu następującego błędu: %%31 Error - 2013-05-23 10:41:01 | Computer Name = SREDNI | Source = Service Control Manager | ID = 7001 Description = Usługa Usługi IPSEC zależy od usługi Sterownik IPSEC, której nie można uruchomić z powodu następującego błędu: %%31 Error - 2013-05-23 10:41:01 | Computer Name = SREDNI | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: AFD Fips IPSec MRxSmb NetBIOS NetBT Processor RasAcd Rdbss Tcpip Error - 2013-05-23 10:43:39 | Computer Name = SREDNI | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd „%1084” podczas próby uruchomienia usługi netman z argumentami „” w celu uruchomienia serwera: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error - 2013-05-23 10:43:48 | Computer Name = SREDNI | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd „%1084” podczas próby uruchomienia usługi EventSystem z argumentami „” w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 2013-05-23 10:44:46 | Computer Name = SREDNI | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd „%1084” podczas próby uruchomienia usługi StiSvc z argumentami „” w celu uruchomienia serwera: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error - 2013-05-23 10:45:02 | Computer Name = SREDNI | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd „%1084” podczas próby uruchomienia usługi StiSvc z argumentami „” w celu uruchomienia serwera: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error - 2013-05-23 10:46:54 | Computer Name = SREDNI | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd „%1084” podczas próby uruchomienia usługi StiSvc z argumentami „” w celu uruchomienia serwera: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error - 2013-05-23 10:47:59 | Computer Name = SREDNI | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd „%1084” podczas próby uruchomienia usługi StiSvc z argumentami „” w celu uruchomienia serwera: {A1F4E726-8CF1-11D1-BF92-0060081ED811} < End of report >