OTL Extras logfile created on: 2014-05-05 20:53:01 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Oli\Downloads Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17041) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,96 Gb Total Physical Memory | 1,75 Gb Available Physical Memory | 58,96% Memory free 5,92 Gb Paging File | 4,65 Gb Available in Paging File | 78,57% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 292,97 Gb Total Space | 189,14 Gb Free Space | 64,56% Space Free | Partition Type: NTFS Drive D: | 172,78 Gb Total Space | 155,38 Gb Free Space | 89,93% Space Free | Partition Type: NTFS Computer Name: OLI-PC | User Name: Oli | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1130741811-4048778706-3566420752-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{043DF432-F2D2-4D04-9300-DF5D0E17A0B6}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{111B54B6-4B42-4DD3-BBB2-967B24FA5434}" = lport=138 | protocol=17 | dir=in | app=system | "{1A1D585E-FFB0-490C-AAA0-4BE1F5FEF7F4}" = rport=10243 | protocol=6 | dir=out | app=system | "{1CABD3AC-77E0-4051-A4FB-BAD2E236F3BC}" = lport=445 | protocol=6 | dir=in | app=system | "{1D8B276E-8A5A-496F-8FD9-47A4B94ABCF2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2134BAAE-C3D9-4DD7-B790-11382D9435C9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{29C929FA-2FBD-4902-9825-E4B58A44506C}" = rport=138 | protocol=17 | dir=out | app=system | "{4F7ABFA5-BDE4-4B51-8981-041718003055}" = lport=10243 | protocol=6 | dir=in | app=system | "{5A31C18D-E5FC-453B-93E6-DD9D7B0613B7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{77127126-DA07-48FC-991E-6FDB204AE428}" = lport=139 | protocol=6 | dir=in | app=system | "{87ADEFE1-E288-46C3-947F-863CDF3D328E}" = lport=137 | protocol=17 | dir=in | app=system | "{8CFBFF68-5137-4BE5-9F3D-A002E970D069}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{8ED95599-4962-45F0-9B54-E1715D7E3C73}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9941600F-644B-4192-8D62-96CA818B33C8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9A84B11A-9E17-4475-8E5A-42E8FFB586D9}" = rport=139 | protocol=6 | dir=out | app=system | "{9E938351-C19F-4EC2-B19D-F5A2B58A8386}" = lport=2869 | protocol=6 | dir=in | app=system | "{A71E6C2C-DA69-4C05-A4CC-84CD6AE54509}" = rport=445 | protocol=6 | dir=out | app=system | "{C61CA34F-7264-49F0-B8D6-5DA4A9215010}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E27F4C23-26CC-4CEC-8409-EDA52FDF4FBC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{EF4F2F84-A693-458E-A44B-78F7286C9FE1}" = rport=137 | protocol=17 | dir=out | app=system | "{EFE23F38-8977-46DF-A852-674B206E34FC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07C232FB-FE25-404F-BFEB-26BC64AC84B3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{08018760-3F61-404F-99D9-6A1DA5C62D1E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{232DCE86-3B36-49CA-974E-F311AD6A8A0D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{23BA636F-9E5C-485B-8949-0B2A4B4F8D3A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{24D937D8-AB0F-405C-8F1C-C06603B66223}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{28162298-CCE2-420B-A860-CC8EFF0DA186}" = protocol=17 | dir=in | app=c:\users\oli\desktop\utorrent.exe | "{29E7DF5B-0DC7-45DA-98F9-6B2C1A885F5A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{30EA34BC-C818-4124-8A1C-0FEF8207E2AF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{325B1913-A90D-4DB1-A787-F3432CFB35D1}" = protocol=6 | dir=out | app=system | "{43432E77-3DD9-4143-BAEA-34B2EA5B0E19}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{4BFA2979-15CB-4303-AFBF-F25689FE5C03}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version9\teamviewer.exe | "{576864CE-5078-48BD-81E1-87906EE0C1DF}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version9\teamviewer_service.exe | "{59E12947-1B8E-4F5C-B768-FD77DE82A0A7}" = protocol=6 | dir=in | app=c:\users\oli\appdata\roaming\utorrent\utorrent.exe | "{633D1232-6FF9-4905-8808-99056CEC0C67}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version9\teamviewer.exe | "{6B40961B-C594-4C50-BFAB-7CB47092B254}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A745415B-23BA-4311-A2F8-037F0BF77F32}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{A952441A-0AF6-4E1A-A6BF-6DD9628CEA2D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{C285E687-C02C-485B-A281-C3B80D63A6BC}" = protocol=6 | dir=in | app=c:\users\oli\desktop\utorrent.exe | "{C87C9E3D-6595-4424-B2AD-E228B7CE99B0}" = protocol=17 | dir=in | app=c:\users\oli\appdata\roaming\utorrent\utorrent.exe | "{DC275335-EDFB-4F5B-A742-D2A5343C6ABF}" = protocol=6 | dir=in | app=c:\users\oli\appdata\roaming\dropbox\bin\dropbox.exe | "{E0E15424-0DDE-471C-97D7-64D759A5652F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E5387132-0995-4A84-A416-EC60FED389D7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{EF2C0380-A776-49B1-A472-199945B10305}" = protocol=17 | dir=in | app=c:\users\oli\appdata\roaming\dropbox\bin\dropbox.exe | "{F4638E5F-E62D-4D44-88A6-1A71AE551D67}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version9\teamviewer_service.exe | "{F79FAED8-E481-467E-87A0-EEC38B2ED223}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F9DDE283-97FD-4C70-846D-F2A1456050CF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{14ABC40D-B37F-44DD-B32D-1AEEEACEFA47}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "TCP Query User{47284D56-523D-4854-9939-48D180B63C19}C:\users\oli\appdata\roaming\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\users\oli\appdata\roaming\utorrent\utorrent.exe | "TCP Query User{E516EC95-E34C-4169-9725-2BECE3FE9241}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "UDP Query User{1EA41C36-3A22-40BE-A8FA-290DCE270304}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "UDP Query User{28DB8071-0939-4B2D-A47F-BA7972791FE1}C:\users\oli\appdata\roaming\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\users\oli\appdata\roaming\utorrent\utorrent.exe | "UDP Query User{9D7C34E5-FF50-46DE-A3FA-ADE6171F56B6}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1" = World of Tanks "{1EAC1D02-C6AC-4FA6-9A44-96258C37C812NA}_is1" = World of Tanks "{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = MPC-HC 1.7.4 "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program "{31BFEC6C-1F27-45B5-839C-BCBAE327993A}" = OpenOffice.org 3.0 "{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1 "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski) "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{C83B8B35-C2C4-3302-9A6E-C2AF1A59E8D6}" = Microsoft .NET Framework 4.5.1 (PLK) "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "7-Zip" = 7-Zip 9.22beta "Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin "Avast" = avast! Free Antivirus "CCleaner" = CCleaner "Google Chrome" = Google Chrome "HDMI" = Intel(R) Graphics Media Accelerator Driver "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version "Mozilla Firefox 28.0 (x86 pl)" = Mozilla Firefox 28.0 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "TeamViewer 9" = TeamViewer 9 "Totalcmd" = Total Commander (Remove or Repair) "TVWiz" = Intel(R) TV Wizard "VLC media player" = VLC media player 2.1.3 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1130741811-4048778706-3566420752-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "UnityWebPlayer" = Unity Web Player "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-05-05 08:03:16 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 10:08:54 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 10:08:54 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 10:54:44 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 10:54:44 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 12:10:03 | Computer Name = Oli-PC | Source = Application Error | ID = 1000 Description = Faulting application name: firefox.exe, version:, time stamp: 0x53240e37 Faulting module name: xul.dll, version:, time stamp: 0x53240e04 Exception code: 0xc0000005 Fault offset: 0x00184729 Faulting process id: 0xb44 Faulting application start time: 0x01cf687c3fd9d344 Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files\Mozilla Firefox\xul.dll Report Id: b6ef2a6c-d46f-11e3-9d24-001f1601018e Error - 2014-05-05 12:12:46 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 12:12:46 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 14:37:30 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. Error - 2014-05-05 14:37:30 | Computer Name = Oli-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006 Description = Unable to read the performance counter strings defined for the 015 language ID. The first DWORD in the Data section contains the Win32 error code. [ System Events ] Error - 2014-04-28 15:34:39 | Computer Name = Oli-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR1. Error - 2014-04-28 15:34:40 | Computer Name = Oli-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR1. Error - 2014-04-28 15:34:40 | Computer Name = Oli-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR1. Error - 2014-04-28 15:34:41 | Computer Name = Oli-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR1. Error - 2014-05-04 06:25:38 | Computer Name = Oli-PC | Source = Microsoft-Windows-Application-Experience | ID = 205 Description = The Program Compatibility Assistant service failed to perform the phase two initialization. Error - 2014-05-04 06:27:57 | Computer Name = Oli-PC | Source = Microsoft-Windows-Time-Service | ID = 34 Description = The time service has detected that the system time needs to be changed by 172808 seconds. The time service will not change the system time by more than 54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|> is working properly. Error - 2014-05-04 12:17:55 | Computer Name = Oli-PC | Source = Microsoft-Windows-Time-Service | ID = 34 Description = The time service has detected that the system time needs to be changed by 172808 seconds. The time service will not change the system time by more than 54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|> is working properly. Error - 2014-05-04 13:49:43 | Computer Name = Oli-PC | Source = Microsoft-Windows-Time-Service | ID = 34 Description = The time service has detected that the system time needs to be changed by 172808 seconds. The time service will not change the system time by more than 54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|> is working properly. Error - 2014-05-05 07:34:36 | Computer Name = Oli-PC | Source = Microsoft-Windows-Time-Service | ID = 34 Description = The time service has detected that the system time needs to be changed by 172806 seconds. The time service will not change the system time by more than 54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|> is working properly. Error - 2014-05-05 07:56:41 | Computer Name = Oli-PC | Source = DCOM | ID = 10010 Description = < End of report >