OTL Extras logfile created on: 2013-11-25 14:51:25 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\magdalena\Desktop Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 954,45 Mb Total Physical Memory | 181,87 Mb Available Physical Memory | 19,06% Memory free 2,12 Gb Paging File | 1,16 Gb Available in Paging File | 54,71% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 138,97 Gb Total Space | 35,40 Gb Free Space | 25,47% Space Free | Partition Type: NTFS Drive D: | 10,08 Gb Total Space | 1,74 Gb Free Space | 17,28% Space Free | Partition Type: NTFS Computer Name: MAGDALENA-PC | User Name: magdalena | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = Opera.HTML] -- Reg Error: Key error. File not found .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- Reg Error: Key error. Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0D70E02A-F1B1-497D-8F9E-F93AD8C03843}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{1DA1AE3B-4FB1-4DDD-9BC9-AC528AA2B6C8}" = lport=445 | protocol=6 | dir=in | app=system | "{24F79913-E854-4FF0-9A8E-708DE9CB70EC}" = lport=138 | protocol=17 | dir=in | app=system | "{392B78A9-107F-4B65-9489-F755DFFCA701}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{58CC5BB6-AC14-47C6-9D38-EA5C6EA0ACCE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5A2D46DE-2767-476D-B945-4AC6C645B708}" = rport=138 | protocol=17 | dir=out | app=system | "{6C87B451-ABDF-411B-8F6A-4B8F1DB3F385}" = rport=137 | protocol=17 | dir=out | app=system | "{7C0B6C06-8231-4299-B3EA-D30CCD6C1863}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A1004C5B-C008-4216-8C3C-AE0350CD23B4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A51E7B39-A68A-4E8E-8437-E82A6BF78439}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{A72E2359-03BF-4C12-AC92-A009A22060E4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B1A27E6B-3C03-43D7-AAB6-6F0018573AF3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{C0EA36A7-D595-481F-A1EA-8A12489A6800}" = lport=137 | protocol=17 | dir=in | app=system | "{CBD9BB5F-FEA2-4DB1-956C-8FDCF8D86AB5}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{E7764382-33D2-4D8B-B7A9-C3AE4E1C5659}" = rport=139 | protocol=6 | dir=out | app=system | "{EF621199-3684-494E-9ADF-17011B80380B}" = rport=445 | protocol=6 | dir=out | app=system | "{F10DDA28-4D8F-446F-B83C-E12A559406E3}" = lport=139 | protocol=6 | dir=in | app=system | "{F3B1A54A-8895-4BE4-8616-4D83691DC033}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{2A5633A3-F5D9-46D6-9FDD-94C41C437039}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | "{2E7ADC58-EED1-42C6-BF15-F8DC7D2BC711}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{4B8BB6D7-7603-413D-8EAE-0ABD1406022A}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | "{511E43E6-8443-49FF-8B3E-342B2062701B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{861D21BB-270D-479A-9B63-873B735CDDD4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{ACEFF7C4-2C4F-445E-A24E-76DD912890B9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{BE04A283-BE64-4138-8CE1-FAFA3E1EFEBA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "TCP Query User{4E56185C-28A6-4400-958E-B90992114A15}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{81ECE2F7-4CE9-4822-9D94-69EC7F61F8DA}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "UDP Query User{4C3AC7C8-EAFA-43FF-9904-43A80F02017E}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "UDP Query User{DCA495D7-4910-48C7-A906-C9B3431F9CCF}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1 "{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library "{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 45 "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2 "{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{79361740-EAE3-11E2-9911-B8AC6F98CCE3}" = Google Earth Plug-in "{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module "{846DDADA-0239-4B67-A6B1-33658863793B}" = HPTCSSetup "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-0415-0000-0000000FF1CE}" = Pakiet zgodności dla systemu Office 2007 "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9E35B051-C7EE-47CB-BA43-9A7FFD4E61DE}" = OpenOffice.org 3.1 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9 "{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}" = HP User Guides 0118 "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE "avast" = avast! Free Antivirus "CCleaner" = CCleaner "CNXT_AUDIO_HDA" = Conexant HD Audio "CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "DivX Setup.divx.com" = DivX Setup "ffdshow_is1" = ffdshow v1.2.4422 [2012-04-09] "Google Chrome" = Google Chrome "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "KLiteCodecPack_is1" = K-Lite Codec Pack 3.6.5 Full "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.75.0.1300 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Mozilla Firefox 25.0.1 (x86 pl)" = Mozilla Firefox 25.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Picasa 3" = Picasa 3 "PLAY ONLINE" = PLAY ONLINE "SynTPDeinstKey" = Synaptics Pointing Device Driver [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "3491853630.portal.qtrax.com" = Qtrax Player [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-11-04 17:03:24 | Computer Name = magdalena-PC | Source = Application Error | ID = 1000 Description = Faulting application PLAY ONLINE.exe, version 1.0.0.1, time stamp 0x4a1a2814, faulting module MSVCR71.dll, version 7.10.3052.4, time stamp 0x3e561eac, exception code 0xc0000005, fault offset 0x00030b56, process id 0xe48, application start time 0x01cdbac9264d08e0. Error - 2012-11-05 04:58:11 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-06 06:34:48 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-07 06:34:46 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-11 11:49:55 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-14 11:02:16 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-16 05:59:23 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-16 14:47:58 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-16 19:25:45 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error - 2012-11-18 05:26:48 | Computer Name = magdalena-PC | Source = WinMgmt | ID = 10 Description = Error encountered while reading event logs. < End of report >