OTL Extras logfile created on: 2014-12-13 22:53:41 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Erhu\Desktop Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,96 Gb Total Physical Memory | 0,45 Gb Available Physical Memory | 23,01% Memory free 3,92 Gb Paging File | 2,04 Gb Available in Paging File | 52,11% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 195,21 Gb Total Space | 168,35 Gb Free Space | 86,24% Space Free | Partition Type: NTFS Drive D: | 270,45 Gb Total Space | 61,04 Gb Free Space | 22,57% Space Free | Partition Type: NTFS Computer Name: ERHU-PC | User Name: Erhu | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = OperaStable] -- C:\Program Files\Opera\Launcher.exe (Opera Software) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = OperaStable] -- C:\Program Files\Opera\Launcher.exe (Opera Software) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software) https [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{047FAE1D-FBE2-4526-AAEF-ED7450A643B6}" = protocol=6 | dir=in | app=c:\program files\napiprojekt\napisy.exe | "{28A39AEB-D525-499B-A922-3319130AE4F3}" = protocol=17 | dir=in | app=c:\users\erhu\appdata\roaming\utorrent\utorrent.exe | "{361A8027-58DF-4D84-B573-AF0DBBD5D873}" = protocol=17 | dir=in | app=c:\program files\napiprojekt\napisy.exe | "{37F6704C-1FC2-4AFB-9D33-D1C25A049BB1}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{4520A7E2-AD59-4EE9-8F7D-A28C46FFB232}" = protocol=6 | dir=in | app=c:\users\erhu\appdata\roaming\utorrent\utorrent.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{107F27B7-8EE4-4B3A-9CE5-497B120369DC}" = Microsoft Security Client "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.22 "{8ED5A2F1-338F-4608-8AF7-BCD1ADC1E1F7}_is1" = Free Alarm Clock 3.1.0 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{B5373BA3-BAD7-4EAC-A9D2-B66B41B82C57}" = OpenOffice 4.1.1 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Pepper" = Adobe Flash Player 15 Pepper "foobar2000" = foobar2000 v1.3.6 "KLiteCodecPack_is1" = K-Lite Codec Pack 10.8.5 Full "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware wersja "Microsoft Security Client" = Microsoft Security Essentials "NapiProjekt_is1" = NapiProjekt ( "Opera 26.0.1656.32" = Opera Stable 26.0.1656.32 "Scribe" = Express Scribe Transcription Software "WinRAR archiver" = WinRAR 5.20 (32-bit) [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Flux" = f.lux "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2014-11-30 12:42:55 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-11-30 12:49:59 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-11-30 20:03:40 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-12-02 08:55:52 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-12-02 10:50:47 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-12-03 18:57:44 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-12-09 19:54:55 | Computer Name = Erhu-PC | Source = MsiInstaller | ID = 11309 Description = Error - 2014-12-13 16:39:30 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = Error - 2014-12-13 17:10:08 | Computer Name = Erhu-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2014-12-02 08:54:28 | Computer Name = Erhu-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 13:52:59 on ?2014-?12-?02 was unexpected. Error - 2014-12-02 10:49:03 | Computer Name = Erhu-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 15:45:46 on ?2014-?12-?02 was unexpected. Error - 2014-12-03 18:56:00 | Computer Name = Erhu-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 21:04:44 on ?2014-?12-?02 was unexpected. Error - 2014-12-08 04:31:29 | Computer Name = Erhu-PC | Source = Microsoft Antimalware | ID = 2001 Description = %%860 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.189.1549.0 Update Source: %%859 Update Stage: %%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.11202.0 Error code: 0x80072ee2 Error description: The operation timed out Error - 2014-12-08 04:32:13 | Computer Name = Erhu-PC | Source = Microsoft Antimalware | ID = 2001 Description = %%860 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.189.1549.0 Update Source: %%851 Update Stage: %%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=1.1.11202.0&avdelta=1.189.1549.0&asdelta=1.189.1549.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.11202.0 Error code: 0x80072ee2 Error description: The operation timed out Error - 2014-12-08 04:32:13 | Computer Name = Erhu-PC | Source = Microsoft Antimalware | ID = 2001 Description = %%860 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.189.1549.0 Update Source: %%851 Update Stage: %%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=1.1.11202.0&avdelta=1.189.1549.0&asdelta=1.189.1549.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.11202.0 Error code: 0x80072ee2 Error description: The operation timed out Error - 2014-12-08 04:32:51 | Computer Name = Erhu-PC | Source = Microsoft Antimalware | ID = 2001 Description = %%860 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: Update Source: %%851 Update Stage: %%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=260974&clcid=0x409&NRI=true&arch=x86&eng=2.1.11005.0&sig= Signature Type: %%886 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 2.1.11005.0 Error code: 0x80072ee2 Error description: The operation timed out Error - 2014-12-13 15:42:09 | Computer Name = Erhu-PC | Source = Service Control Manager | ID = 7011 Description = A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service. Error - 2014-12-13 16:36:52 | Computer Name = Erhu-PC | Source = Service Control Manager | ID = 7031 Description = The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 2014-12-13 16:36:52 | Computer Name = Erhu-PC | Source = Service Control Manager | ID = 7031 Description = The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. < End of report >