OTL Extras logfile created on: 8/22/2009 11:42:07 AM - Run 1 OTL by OldTimer - Version 3.0.10.7 Folder = J:\Documents and Settings\Jean\My Documents\PC Fixes Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): J:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = J: | %SystemRoot% = J:\WINDOWS | %ProgramFiles% = J:\Program Files Drive C: | 37.26 Gb Total Space | 23.11 Gb Free Space | 62.01% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Drive J: | 465.75 Gb Total Space | 420.72 Gb Free Space | 90.33% Space Free | Partition Type: NTFS Computer Name: JUDY Current User Name: Jean Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html [@ = htmlfile] -- J:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- J:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "D:\NeroExpress\Installation\Setupx.exe" = D:\NeroExpress\Installation\Setupx.exe:*:Enabled:Nero ProductSetup -- File not found "J:\Program Files\Ventrilo\Ventrilo.exe" = J:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- () "J:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe" = J:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 -- (Firaxis Games) "J:\Program Files\AVG\AVG8\avgemc.exe" = J:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.) "J:\Program Files\AVG\AVG8\avgupd.exe" = J:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.) "J:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe" = J:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword -- (Firaxis Games) "J:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_Pitboss.exe" = J:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_Pitboss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss -- (Firaxis Games) "J:\Program Files\AVG\AVG8\avgnsx.exe" = J:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.) "J:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = J:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.) "J:\Program Files\LimeWire\LimeWire.exe" = J:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC) "J:\Program Files\NBC Direct\DirectPlayerCore.exe" = J:\Program Files\NBC Direct\DirectPlayerCore.exe:*:Enabled:NBC Direct -- (NBC Universal) "J:\Program Files\ICQ6.5\ICQ.exe" = J:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.) "J:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" = J:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet:Enabled:Pure Networks Platform Service -- (Cisco Systems, Inc.) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime "{0AF3FEAE-B651-4421-97EF-4808A588B4E5}" = LastChaos "{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up "{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in "{1898B8E5-43E2-4BCA-AD6A-B9FBE0C93F84}" = Heroes of Might and Magic V Collector Edition "{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 15 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5 "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client "{81E2D8D7-F104-4EB9-97A7-98996A611FF6}" = Sid Meier's Civilization 4 - Beyond the Sword "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8CAE7CB3-B7C0-41A2-B2E3-9BD16124A091}" = EasyInfo "{9BBB19C0-1FE1-4A4E-B25F-C9E1B0497EC5}" = Shaiya(US) "{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime "{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A84BD759-4C74-4F66-9038-D51E90D19F47}" = Sid Meier's Civilization 4 - Warlords "{A8589680-35C1-4732-ACCA-09B78921ECE3}" = Sid Meier's Civilization 4 "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2 "{B2163962-BFD2-4187-8B47-D9B24737DFD7}" = Kort's Spellcraft Calculator "{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX "{BA3FD02D-7BD0-4CD0-BFB4-B407D43D6A17}" = Cisco Network Magic "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer "{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CF8C077A-B467-4C43-8DB5-3A9B94FF9681}" = LightScribe System Software 1.12.29.2 "{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4 "{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse "{F46BF5EA-0B4E-4A41-8C4B-3B127346E30F}" = NBC Direct "{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform "8461-7759-5462-8226" = Vuze "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player "Advanced SystemCare 3_is1" = Advanced SystemCare 3 "AudioCS" = Creative Audio Control Panel "AVG8Uninstall" = AVG Free 8.5 "BobsUI_1.94_v4.03 (Complete)" = BobsUI_1.94_v4.03 (Complete) "Coupon Printer for Windows4.0" = Coupon Printer for Windows "DAOCCharplan" = DAOC-Charplan "Dark Age of Camelot - Darkness Rising_is1" = Dark Age of Camelot - Darkness Rising "Dark Age of Camelot - Labyrinth of the Minotaur_is1" = Dark Age of Camelot - Labyrinth of the Minotaur "Download Manager" = Download Manager 2.3.7 "ERUNT_is1" = ERUNT 1.1j "GearBunny_is1" = GearBunny 1.98 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "Impulse" = Impulse "InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in "LimeWire" = LimeWire 5.1.2 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MSNINST" = MSN "MyColors" = MyColors "Network MagicUninstall" = Network Magic "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NVIDIA Drivers" = NVIDIA Drivers "NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager "ObjectDock" = ObjectDock "OpenAL" = OpenAL "Picasa 3" = Picasa 3 "PopCap Browser Plugin" = PopCap Browser Plugin "Quick Zip_is1" = Quick Zip 4.60.019 "Smart Defrag_is1" = Smart Defrag 1.20 "Software Informer_is1" = Software Informer 1.0 BETA "Winamp" = Winamp "WindowBlinds" = WindowBlinds "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Messenger" = Yahoo! Messenger "ZoneAlarm" = ZoneAlarm "ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "idm_flash" = IDM Flash 4.4.0.468 "Move Media Player" = Move Media Player "Move Networks Player - IE" = Move Networks Media Player for Internet Explorer "NBC Direct" = NBC Direct "Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 5/18/2009 9:45:44 PM | Computer Name = JUDY | Source = Application Hang | ID = 1001 Description = Fault bucket 1245527889. Error - 5/18/2009 9:50:20 PM | Computer Name = JUDY | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 5/21/2009 9:14:20 AM | Computer Name = JUDY | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: A connection with the server could not be established Error - 5/28/2009 10:47:55 AM | Computer Name = JUDY | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: A connection with the server could not be established Error - 6/5/2009 1:21:58 AM | Computer Name = JUDY | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: A connection with the server could not be established Error - 6/5/2009 8:52:48 PM | Computer Name = JUDY | Source = Application Error | ID = 1000 Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x6600914c. Error - 6/5/2009 8:53:39 PM | Computer Name = JUDY | Source = Application Error | ID = 1001 Description = Fault bucket 596418048. Error - 6/12/2009 8:45:02 AM | Computer Name = JUDY | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: A connection with the server could not be established Error - 6/19/2009 11:40:53 AM | Computer Name = JUDY | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: A connection with the server could not be established Error - 6/26/2009 1:06:39 PM | Computer Name = JUDY | Source = crypt32 | ID = 131080 Description = Failed auto update retrieval of third-party root list sequence number from: with error: A connection with the server could not be established [ System Events ] Error - 8/20/2009 2:21:46 PM | Computer Name = JUDY | Source = Service Control Manager | ID = 7023 Description = The Application Management service terminated with the following error: %%126 Error - 8/20/2009 8:50:41 PM | Computer Name = JUDY | Source = Print | ID = 22 Description = Failed to ugrade printer settings for printer \\Dawana-njc7fszu\HP Photosmart C5200 series,LocalOnly driver J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\UNIDRVUI.DLL error 1722. Error - 8/22/2009 11:26:01 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7034 Description = The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). Error - 8/22/2009 11:26:01 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7031 Description = The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. Error - 8/22/2009 11:26:01 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7034 Description = The Creative Audio Service service terminated unexpectedly. It has done this 1 time(s). Error - 8/22/2009 11:26:01 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7034 Description = The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). Error - 8/22/2009 11:26:01 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7034 Description = The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s). Error - 8/22/2009 11:26:01 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7031 Description = The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error - 8/22/2009 11:26:02 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7034 Description = The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 1 time(s). Error - 8/22/2009 11:26:02 AM | Computer Name = JUDY | Source = Service Control Manager | ID = 7034 Description = The Pure Networks Platform Service service terminated unexpectedly. It has done this 1 time(s). < End of report >