OTL Extras logfile created on: 3/18/2010 11:59:55 AM - Run 1 OTL by OldTimer - Version 3.1.37.3 Folder = C:\test Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1,023.00 Mb Total Physical Memory | 526.00 Mb Available Physical Memory | 51.00% Memory free 3.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free Paging file location(s): C:\pagefile.sys 0 0D:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 179.89 Gb Total Space | 82.47 Gb Free Space | 45.85% Space Free | Partition Type: NTFS Drive D: | 6.40 Gb Total Space | 0.54 Gb Free Space | 8.47% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded Drive G: | 48.11 Gb Total Space | 38.79 Gb Free Space | 80.64% Space Free | Partition Type: NTFS Drive H: | 44.77 Gb Total Space | 29.60 Gb Free Space | 66.12% Space Free | Partition Type: NTFS Drive I: | 93.43 Gb Total Space | 24.75 Gb Free Space | 26.49% Space Free | Partition Type: NTFS Computer Name: MIKE-136F2019DC Current User Name: HP_Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 "44695:TCP" = 44695:TCP:*:Enabled:muletcp "64037:UDP" = 64037:UDP:*:Enabled:mulekad "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "80:TCP" = 80:TCP:*:Enabled:msn game "443:TCP" = 443:TCP:*:Enabled:msn signin [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe" = C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s -- () "C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation) "C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Disabled:BackWeb for Pavilion -- File not found "C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe" = C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Disabled:Nero ProductSetup -- (Nero AG) "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Program Files\MSN Gaming Zone\zone.exe" = C:\Program Files\MSN Gaming Zone\zone.exe:*:Enabled:zone.exe -- File not found "C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DUPA30.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DUPA30.EXE:*:Enabled:EPSON Driver Update -- (SEIKO EPSON CORPORATION) "C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1EA9F5CC-BD77-48FC-A9AF-E71646F2E55B}" = TurboCAD Deluxe 14 "{2FEA102C-F535-4513-009B-57B165013C18}" = Tiger Woods PGA TOUR 08 "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets "{49E76063-B342-4F69-9F82-719CE7A9999B}" = FranklinCovey Planning Software "{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition "{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2 "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University "{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage "{A3BC1DBD-64D6-4EBC-0091-24C811662D40}" = Madden NFL 08 "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2 "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{F2A056D9-54B2-4F2B-8DD8-A42A73D1E5E7}" = OneTouch Software "{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0 "{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife "7-Zip" = 7-Zip 4.65 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Advanced X Video Converter_is1" = Advanced X Video Converter "Agere Systems Soft Modem" = Agere Systems PCI Soft Modem "AoA DVD Copy_is1" = AoA DVD Copy "AoA DVD Ripper_is1" = AoA DVD Ripper "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "DVDFab 6_is1" = DVDFab 6.2.0.5 (11/11/2009) "eMule" = eMule "EPSON NX510 Series" = EPSON NX510 Series Printer Uninstall "EPSON Scanner" = EPSON Scan "ERUNT_is1" = ERUNT 1.1j "eTrust Suite Personal" = CA Internet Security Suite "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ImgBurn" = ImgBurn "InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition "IrfanView" = IrfanView (remove only) "Magic ISO Maker v5.4 (build 0247)" = Magic ISO Maker v5.4 (build 0247) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NVIDIA Drivers" = NVIDIA Drivers "RealPlayer 12.0" = RealPlayer "RegistryBooster 2_is1" = Uniblue RegistryBooster 2 "Smart Defrag_is1" = Smart Defrag "TurboCAD Furniture Maker-4.0.0" = TurboCAD Furniture Maker "uTorrent" = µTorrent "Video Editor" = Video Editor "Virtual Pool 3" = Virtual Pool 3 "Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 2.2 "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Xilisoft AVI to DVD Converter" = Xilisoft AVI to DVD Converter "Xilisoft DVD Creator" = Xilisoft DVD Creator "Xilisoft MPEG to DVD Converter" = Xilisoft MPEG to DVD Converter "Yahtzeev1" = Yahtzee [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2/20/2010 4:36:02 AM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2/20/2010 5:28:00 AM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application msiexec.exe, version 3.1.4001.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2/20/2010 5:28:03 AM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application msiexec.exe, version 3.1.4001.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2/27/2010 5:34:26 AM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application mypixdx.scr, version 5.1.2600.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 2/27/2010 5:34:27 AM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application mypixdx.scr, version 5.1.2600.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 3/5/2010 6:26:29 PM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application nero.exe, version 7.11.10.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 3/12/2010 7:49:55 PM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 3/12/2010 7:49:57 PM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 3/13/2010 1:56:10 PM | Computer Name = MIKE-136F2019DC | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 3/16/2010 9:19:01 AM | Computer Name = MIKE-136F2019DC | Source = Application Error | ID = 1000 Description = Faulting application beachhead16.exe, version 0.0.0.0, faulting module beachhead16.exe, version 0.0.0.0, fault address 0x00038594. [ System Events ] Error - 3/18/2010 8:47:02 AM | Computer Name = MIKE-136F2019DC | Source = Service Control Manager | ID = 7023 Description = The System Restore Service service terminated with the following error: %%5 Error - 3/18/2010 2:53:40 PM | Computer Name = MIKE-136F2019DC | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. Error - 3/18/2010 2:55:25 PM | Computer Name = MIKE-136F2019DC | Source = SRService | ID = 104 Description = The System Restore initialization process failed. Error - 3/18/2010 2:55:50 PM | Computer Name = MIKE-136F2019DC | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the NVIDIA Display Driver Service service to connect. Error - 3/18/2010 2:55:50 PM | Computer Name = MIKE-136F2019DC | Source = Service Control Manager | ID = 7000 Description = The NVIDIA Display Driver Service service failed to start due to the following error: %%1053 Error - 3/18/2010 2:55:50 PM | Computer Name = MIKE-136F2019DC | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the PPCtlPriv service to connect. Error - 3/18/2010 2:55:50 PM | Computer Name = MIKE-136F2019DC | Source = Service Control Manager | ID = 7000 Description = The PPCtlPriv service failed to start due to the following error: %%1053 Error - 3/18/2010 2:55:50 PM | Computer Name = MIKE-136F2019DC | Source = Service Control Manager | ID = 7023 Description = The System Restore Service service terminated with the following error: %%5 Error - 3/18/2010 6:03:40 PM | Computer Name = MIKE-136F2019DC | Source = SRService | ID = 104 Description = The System Restore initialization process failed. Error - 3/18/2010 6:03:40 PM | Computer Name = MIKE-136F2019DC | Source = Service Control Manager | ID = 7023 Description = The System Restore Service service terminated with the following error: %%5 < End of report >