OTL Extras logfile created on: 2013-09-23 08:56:47 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\NADIA\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,02 Gb Available Physical Memory | 51,13% Memory free 4,23 Gb Paging File | 3,09 Gb Available in Paging File | 73,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 140,52 Gb Total Space | 56,95 Gb Free Space | 40,53% Space Free | Partition Type: NTFS Drive D: | 8,53 Gb Total Space | 2,73 Gb Free Space | 31,97% Space Free | Partition Type: NTFS Computer Name: NADIA-PC | User Name: NADIA | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-696015614-601039676-1639490482-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07D30962-F917-470F-A357-84ECAC95F6F4}" = lport=2869 | protocol=6 | dir=in | app=system | "{871164D1-4E27-4CA1-A7B0-6D88BB13340A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{357CB133-1211-472A-9149-AD859C35EBD6}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{4FDB491E-3479-4E26-AE26-0BDC193276AC}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | "{884C9326-65BA-47F6-9546-C711C0A6458C}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | "{ECC8D68E-4CD7-4082-9CB8-E8B1FB1634D8}" = dir=in | app=c:\program files\msn messenger\livecall.exe | "{EDCB29F5-5704-45FF-BE8A-33691F440A6E}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{FCB2F939-A8AA-429F-BABD-6BC5A8290F58}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe | "TCP Query User{0F335D21-F851-41D7-942B-E8839FED2B64}C:\emule\emule.exe" = protocol=6 | dir=in | app=c:\emule\emule.exe | "UDP Query User{37EDEC55-0018-434E-B662-F0F493BD7CE9}C:\emule\emule.exe" = protocol=17 | dir=in | app=c:\emule\emule.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime "{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library "{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{223818EB-2BB5-4AAD-9F38-BA9668A4E3F3}" = Windows Live Messenger "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check "{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 40 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program "{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support "{306B39C9-3AB1-4161-8567-9C7E50B41AE3}" = Microsoft Works "{30BB4D60-81DB-11D5-BB77-00400536ABAC}" = OLYMPUS CAMEDIA Master 4.2 "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1 "{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode "{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6 "{46E1B1F2-A279-4356-9B17-029F9CC72EAE}" = Brother MFL-Pro Suite "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = SAGEM F@st 800-840 "{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087 "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{5EF68077-1766-426C-AB97-F148A0E0E7EC}_is1" = Testy A "{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart "{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights "{79361740-EAE3-11E2-9911-B8AC6F98CCE3}" = Google Earth Plug-in "{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4 "{7F362F06-A9A3-440F-8B19-6A01A72723C4}" = AuthenTec Fingerprint Sensor Minimum Install "{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-0415-0000-0000000FF1CE}" = Pakiet zgodności dla systemu Office 2007 "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{95120000-00AF-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (Polish) "{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap "{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk "{A0F40029-79E7-40B1-8841-C79199C9D0A2}" = ESU for Microsoft Vista "{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor "{A83FB5BD-3A15-48C4-824C-5FFEF8F87C16}" = Barbie(TM) jako Księżniczka i żebraczka "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update "{AC76BA86-7AD7-1045-7B44-A81200000003}" = Adobe Reader 8 - Polish "{AFC33362-1D75-40F5-A1EB-2D4D9D0D65B2}_is1" = L-instruktor 2.0.1.28 "{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles "{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit "{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements "{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax "{C7AF7F33-9092-997E-2D29-DE8095863FE3}" = DigitalPersona Personal 3.0.0 "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM "{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime "{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit "{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer "{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget "{FA8BFB25-BF48-4F8B-8859-B30810745190}" = LightScribe System Software "{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60 "avast" = avast! Free Antivirus "CCleaner" = CCleaner "CNXT_AUDIO_HDA" = Conexant HD Audio "CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP "DEMO OSK-Auto-Trener-Wykłady_is1" = DEMO OSK-Auto-Trener-Wykłady "eMule" = eMule "Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149) "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.75.0.1300 "Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Mozilla Firefox 22.0 (x86 pl)" = Mozilla Firefox 22.0 (x86 pl) "Mozilla Thunderbird 10.0.2 (x86 pl)" = Mozilla Thunderbird 10.0.2 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Nero7Lite_is1" = Nero 7 Lite 7.11.10.0 "NVIDIA Drivers" = NVIDIA Drivers "RealAlt_is1" = Real Alternative 1.60 "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4 "SynTPDeinstKey" = Synaptics Pointing Device Driver "Wi-Fi Modem" = Wi-Fi Modem "WinRAR archiver" = Archiwizator WinRAR [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-696015614-601039676-1639490482-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2013-09-20 09:56:31 | Computer Name = NADIA-PC | Source = VSS | ID = 8193 Description = Error - 2013-09-20 09:56:31 | Computer Name = NADIA-PC | Source = System Restore | ID = 8193 Description = Error - 2013-09-20 09:56:39 | Computer Name = NADIA-PC | Source = VSS | ID = 39 Description = Error - 2013-09-20 09:56:39 | Computer Name = NADIA-PC | Source = VSS | ID = 8193 Description = Error - 2013-09-20 09:56:39 | Computer Name = NADIA-PC | Source = System Restore | ID = 8193 Description = Error - 2013-09-20 10:02:13 | Computer Name = NADIA-PC | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd QPSched.exe, wersja 5.0.0.3327, sygnatura czasowa 0x46fbc733, moduł powodujący błąd QPSched.exe, wersja 5.0.0.3327, sygnatura czasowa 0x46fbc733, kod wyjątku 0xc0000005, przesunięcie błędu 0x000075bd, identyfikator procesu 0xea8, godzina rozpoczęcia aplikacji 0x01ceb608a2c56e15. Error - 2013-09-22 04:37:19 | Computer Name = NADIA-PC | Source = VSS | ID = 39 Description = Error - 2013-09-22 04:37:19 | Computer Name = NADIA-PC | Source = VSS | ID = 8193 Description = Error - 2013-09-22 23:06:44 | Computer Name = NADIA-PC | Source = VSS | ID = 39 Description = Error - 2013-09-22 23:06:50 | Computer Name = NADIA-PC | Source = VSS | ID = 8193 Description = [ DigitalPersona Pro Events ] Error - 2012-04-12 07:15:07 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-12 13:19:49 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-13 07:41:13 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-13 09:22:24 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-13 11:24:03 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-14 05:35:51 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-14 09:00:50 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-15 13:50:52 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-15 14:29:33 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2012-04-16 00:59:37 | Computer Name = NADIA-PC | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. [ System Events ] Error - 2013-09-20 09:49:32 | Computer Name = NADIA-PC | Source = DCOM | ID = 10005 Description = Error - 2013-09-20 09:52:25 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2013-09-20 09:52:25 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2013-09-20 09:52:25 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7009 Description = Error - 2013-09-20 09:52:25 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2013-09-21 04:04:24 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7034 Description = Error - 2013-09-22 23:06:44 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7034 Description = Error - 2013-09-22 23:06:58 | Computer Name = NADIA-PC | Source = DCOM | ID = 10010 Description = Error - 2013-09-23 02:38:11 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7000 Description = Error - 2013-09-23 02:38:11 | Computer Name = NADIA-PC | Source = Service Control Manager | ID = 7000 Description = < End of report >