OTL Extras logfile created on: 2014-11-16 18:40:46 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Paulina\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17420) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1011,87 Mb Total Physical Memory | 166,42 Mb Available Physical Memory | 16,45% Memory free 1,99 Gb Paging File | 0,48 Gb Available in Paging File | 24,36% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 232,79 Gb Total Space | 211,23 Gb Free Space | 90,74% Space Free | Partition Type: NTFS Computer Name: PAULINA_ACER | User Name: Paulina | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3285843512-2645348934-3721872921-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- "%1" %* inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0754C605-DCEE-49C5-8EB0-4C66FED3E0DD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{166E7E41-F43C-47E0-87ED-B93F48BF1F8D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{16D3D703-DA39-4EC0-96C2-68C429B62C61}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{332CCDBE-F58A-49D6-9CE2-8DC04B784C86}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\google\chrome\application\chrome.exe | "{3D02A417-41BF-4E53-942F-B6B7B13D3519}" = lport=2869 | protocol=6 | dir=in | app=system | "{41BDC8CC-55A7-411D-B71A-425D4390FAA6}" = rport=10243 | protocol=6 | dir=out | app=system | "{4B5B3596-C5D1-4F7C-8EF0-1692D9602824}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{52F5CA97-3E6C-4BD6-B742-6151D7E4F6F6}" = rport=139 | protocol=6 | dir=out | app=system | "{70C920E8-CCC8-4E72-B4DB-3954F61492BF}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{780B4173-4E86-4DE7-B42F-E7615A872A10}" = rport=138 | protocol=17 | dir=out | app=system | "{7B5E1579-8C4A-4C6B-A69E-9A14255D3A3E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A1E0E343-090E-40DD-879A-90988B65DEDC}" = lport=445 | protocol=6 | dir=in | app=system | "{AAA6DB5B-85EF-49A7-A9C7-8AC536B01587}" = lport=137 | protocol=17 | dir=in | app=system | "{C1FF5255-8632-4C08-AD18-051F7BB392D4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C43C5425-258B-405E-A268-3CCBF38B2A23}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C7855EDA-B4DB-4A00-A1B6-FD9E2D018DCD}" = rport=137 | protocol=17 | dir=out | app=system | "{C7D7CCA8-BD94-4836-BAFF-BCE9F6797A0A}" = rport=445 | protocol=6 | dir=out | app=system | "{CD44E107-BDB8-4A88-A007-E56D742947D2}" = lport=138 | protocol=17 | dir=in | app=system | "{E02B2C19-0F1C-4E01-ABBB-2D8CCBEE5B20}" = lport=139 | protocol=6 | dir=in | app=system | "{E4DA74F8-1BD2-49E4-8CA3-10B2E717F4CF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EE17E903-1F4A-4AD7-A206-4D62C47A6E05}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{EE2A6BE6-65B5-43FE-9C2C-0AC231429500}" = lport=10243 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0E8D5404-3736-4AEC-AE48-F5671B164A41}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{1B2C9805-2BAF-4666-B40B-52B6B1E69B63}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2422C7EE-D169-41E7-920C-C34AE9DEE2E1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{278BD7C2-30E4-4AF8-B780-CED1EC4C3934}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4128799E-FA85-4730-B774-E3C3063F608C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{46EFA0AC-517B-4FE5-BBED-1655CE49A0B6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7516FFAE-22B1-44D7-BDBD-F0B33FDCA3D4}" = protocol=6 | dir=in | app=c:\users\paulina\appdata\roaming\dropbox\bin\dropbox.exe | "{7A2E097B-B277-4C14-A279-83B0C440BE75}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{815976CC-8301-4298-A188-E501DF5990DA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{91170A1E-63BE-4A27-B7F9-728F42BBDF13}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9C7867EA-9071-46E2-A315-8A90271BDC1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{A09AB9DC-8600-4FAE-AC8A-5F373AA91B50}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B2EBC000-AB20-4517-9902-BDEC4D229886}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D1E5D4EF-B603-4D0C-9BFF-DC29285D2D31}" = protocol=6 | dir=out | app=system | "{DCCDC91A-16B6-49C8-A6CF-C3FC2360BC96}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{E2099B48-9364-46EB-A6E6-F3E739E65050}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{EAD58ED8-21F5-4440-9932-42ED95324C8D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{F52B975F-29B2-4BB1-9C47-28A998B0DB84}" = protocol=17 | dir=in | app=c:\users\paulina\appdata\roaming\dropbox\bin\dropbox.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module "{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Avast" = Avast Free Antivirus "Broadcom 802.11 Network Adapter" = Broadcom 802.11 Network Adapter "ENTERPRISE" = Microsoft Office Enterprise 2007 "Google Chrome" = Google Chrome "SynTPDeinstKey" = Synaptics Pointing Device Driver [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3285843512-2645348934-3721872921-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-11-10 07:15:03 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-11 15:14:26 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-12 15:30:28 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-14 13:08:14 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-14 13:29:45 | Computer Name = paulina_acer | Source = PerfNet | ID = 2004 Description = Error - 2014-11-14 13:32:04 | Computer Name = paulina_acer | Source = PerfNet | ID = 2004 Description = Error - 2014-11-15 08:02:49 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-15 16:42:51 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-15 17:38:16 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = Error - 2014-11-16 12:59:04 | Computer Name = paulina_acer | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2014-11-15 16:40:29 | Computer Name = paulina_acer | Source = Service Control Manager | ID = 7031 Description = Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 2. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error - 2014-11-15 16:40:59 | Computer Name = paulina_acer | Source = Service Control Manager | ID = 7032 Description = Menedżer sterowania usługami próbował podjąć akcję korekcyjną (Uruchom usługę ponownie) po nieoczekiwanym zakończeniu usługi Windows Search, ale ta akcja nie powiodła się przy następującym błędzie: %%1056. Error - 2014-11-15 16:41:33 | Computer Name = paulina_acer | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10003 Description = Nastąpiło nieoczekiwane zatrzymanie modułu rozszerzalności sieci WLAN. Ścieżka modułu: C:\Windows\System32\bcmihvsrv.dll Error - 2014-11-15 16:41:45 | Computer Name = paulina_acer | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10003 Description = Nastąpiło nieoczekiwane zatrzymanie modułu rozszerzalności sieci WLAN. Ścieżka modułu: C:\Windows\System32\bcmihvsrv.dll Error - 2014-11-15 16:41:45 | Computer Name = paulina_acer | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10003 Description = Nastąpiło nieoczekiwane zatrzymanie modułu rozszerzalności sieci WLAN. Ścieżka modułu: C:\Windows\System32\bcmihvsrv.dll Error - 2014-11-15 16:41:48 | Computer Name = paulina_acer | Source = Service Control Manager | ID = 7038 Description = Usługa msiserver nie może zalogować się jako NT AUTHORITY\SYSTEM za pomocą obecnie skonfigurowanego hasła z powodu następującego błędu: %%50 Aby upewnić się, że usługa jest skonfigurowana prawidłowo, użyj przystawki Usługi w programie Microsoft Management Console (MMC). Error - 2014-11-15 16:41:48 | Computer Name = paulina_acer | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Instalator Windows z powodu następującego błędu: %%1069 Error - 2014-11-15 16:42:59 | Computer Name = paulina_acer | Source = Service Control Manager | ID = 7001 Description = Usługa Dostawca grupy domowej zależy od usługi Publikacja zasobów odnajdowania funkcji, której nie można uruchomić z powodu następującego błędu: %%1058 Error - 2014-11-15 17:39:29 | Computer Name = paulina_acer | Source = Service Control Manager | ID = 7001 Description = Usługa Dostawca grupy domowej zależy od usługi Publikacja zasobów odnajdowania funkcji, której nie można uruchomić z powodu następującego błędu: %%1058 Error - 2014-11-16 13:04:46 | Computer Name = paulina_acer | Source = Service Control Manager | ID = 7001 Description = Usługa Dostawca grupy domowej zależy od usługi Publikacja zasobów odnajdowania funkcji, której nie można uruchomić z powodu następującego błędu: %%1058 < End of report >