cheers
sharon
OTL Extras logfile created on: 12/6/2010 3:53:22 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 267.00 Mb Available Physical Memory | 26.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 447.83 Gb Free Space | 96.15% Space Free | Partition Type: NTFS
Drive D: | 148.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: DELL-A79E882B26 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows -- File not found
"C:\Program Files\Telstra\BigPond Wireless Broadband\SwiApiMux.exe" = C:\Program Files\Telstra\BigPond Wireless Broadband\SwiApiMux.exe:*:Enabled:SwiApiMux -- (Sierra Wireless, Inc.)
"C:\Program Files\Shareaza\Shareaza.exe" = C:\Program Files\Shareaza\Shareaza.exe:*:Enabled:Shareaza -- (Shareaza Development Team)
"C:\Program Files\MyShoppingGenie\mnumsg.exe" = C:\Program Files\MyShoppingGenie\mnumsg.exe:*:Enabled:MyShoppingGenie -- File not found
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)
"C:\WINDOWS\system32\nbirv4svr.exe" = C:\WINDOWS\system32\nbirv4svr.exe:*:Enabled:NeowizBugs IR4Music Control -- (Neowiz Bugs Corporation.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.6
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java 6 Update 16
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}" = iriver plus 4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CCD0C8-6D5E-4515-BDD7-2A22D5D91033}" = Nero 8 Essentials
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{B0255743-165B-4BD5-8DA8-37DFB9930014}" = Norton Ghost
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7F54262-AB66-44B3-88BF-9FC69941B643}" = Broadcom Gigabit Integrated Controller
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CDEDBC83-40F4-4C8B-9BA7-AA95F45246F9}" = BigPond Wireless Broadband
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"EPSON TX110 Series" = EPSON TX110 Series Printer Uninstall
"ie8" = Windows Internet Explorer 8
"InstallShield_{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}" = iriver plus 4
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"Playsushi" = PlaySushi
"VLC media player" = VLC media player 1.0.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World Gaming Center_is1" = World Gaming Center Version 2.1.2
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/18/2010 11:00:40 PM | Computer Name = DELL-A79E882B26 | Source = Norton Ghost | ID = 100
Description = Error EC8F17B7: Cannot create recovery points for job: My Computer
Backup. Error EC8F03FE: Cannot read the properties of the job. Error EC8F1F62:
Cannot find external device 'External Drive'. Details: The system cannot find the
path specified. Source: Norton Ghost
Error - 11/19/2010 4:02:31 AM | Computer Name = DELL-A79E882B26 | Source = Application Hang | ID = 1002
Description = Hanging application soffice.bin, version 3.1.9420.500, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 11/19/2010 6:00:30 PM | Computer Name = DELL-A79E882B26 | Source = Application Error | ID = 1000
Description = Faulting application Iera.exe, version 0.0.0.0, faulting module Iera.exe,
version 0.0.0.0, fault address 0x0000b4b7.
Error - 11/21/2010 7:50:25 PM | Computer Name = DELL-A79E882B26 | Source = Application Error | ID = 1000
Description = Faulting application client.exe, version 2.1.1.0, faulting module
unknown, version 0.0.0.0, fault address 0x0000dfe4.
Error - 11/21/2010 11:00:37 PM | Computer Name = DELL-A79E882B26 | Source = Norton Ghost | ID = 100
Description = Error EC8F17B7: Cannot create recovery points for job: My Computer
Backup. Error EC8F03FE: Cannot read the properties of the job. Error EC8F1F62:
Cannot find external device 'External Drive'. Details: The system cannot find the
path specified. Source: Norton Ghost
Error - 11/25/2010 11:00:31 PM | Computer Name = DELL-A79E882B26 | Source = Norton Ghost | ID = 100
Description = Error EC8F17B7: Cannot create recovery points for job: My Computer
Backup. Error EC8F03FE: Cannot read the properties of the job. Error EC8F1F62:
Cannot find external device 'External Drive'. Details: The system cannot find the
path specified. Source: Norton Ghost
Error - 11/28/2010 11:00:34 PM | Computer Name = DELL-A79E882B26 | Source = Norton Ghost | ID = 100
Description = Error EC8F17B7: Cannot create recovery points for job: My Computer
Backup. Error EC8F03FE: Cannot read the properties of the job. Error EC8F1F62:
Cannot find external device 'External Drive'. Details: The system cannot find the
path specified. Source: Norton Ghost
Error - 12/2/2010 11:00:33 PM | Computer Name = DELL-A79E882B26 | Source = Norton Ghost | ID = 100
Description = Error EC8F17B7: Cannot create recovery points for job: My Computer
Backup. Error EC8F03FE: Cannot read the properties of the job. Error EC8F1F62:
Cannot find external device 'External Drive'. Details: The system cannot find the
path specified. Source: Norton Ghost
Error - 12/5/2010 11:00:35 PM | Computer Name = DELL-A79E882B26 | Source = Norton Ghost | ID = 100
Description = Error EC8F17B7: Cannot create recovery points for job: My Computer
Backup. Error EC8F03FE: Cannot read the properties of the job. Error EC8F1F62:
Cannot find external device 'External Drive'. Details: The system cannot find the
path specified. Source: Norton Ghost
Error - 12/6/2010 7:30:59 PM | Computer Name = DELL-A79E882B26 | Source = Norton Ghost | ID = 100
Description = Error EC8F17B7: Cannot create recovery points for job: My Computer
Backup. Error EC8F03FE: Cannot read the properties of the job. Error EC8F1F62:
Cannot find external device 'External Drive'. Details: The system cannot find the
path specified. Source: Norton Ghost
[ System Events ]
Error - 11/24/2010 6:23:21 AM | Computer Name = DELL-A79E882B26 | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by -64797 seconds. The time service will not change the system time by more than
-54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com (ntp.m|0x1|124.187.118.90:123->207.46.232.182:123) is working
properly.
Error - 11/25/2010 10:07:00 PM | Computer Name = DELL-A79E882B26 | Source = Dhcp | ID = 1002
Description = The IP address lease 124.187.118.90 for the Network Card with network
address 00A0D5FFFFAE has been denied by the DHCP server 121.222.251.253 (The DHCP
Server sent a DHCPNACK message).
Error - 11/25/2010 10:07:20 PM | Computer Name = DELL-A79E882B26 | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by -64796 seconds. The time service will not change the system time by more than
-54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com (ntp.m|0x1|121.222.251.251:123->207.46.232.182:123) is
working properly.
Error - 11/30/2010 6:37:55 AM | Computer Name = DELL-A79E882B26 | Source = Dhcp | ID = 1002
Description = The IP address lease 121.222.251.251 for the Network Card with network
address 00A0D5FFFFAE has been denied by the DHCP server 124.185.14.253 (The DHCP
Server sent a DHCPNACK message).
Error - 11/30/2010 6:31:02 PM | Computer Name = DELL-A79E882B26 | Source = Dhcp | ID = 1002
Description = The IP address lease 124.185.14.94 for the Network Card with network
address 00A0D5FFFFAE has been denied by the DHCP server 121.222.158.253 (The DHCP
Server sent a DHCPNACK message).
Error - 11/30/2010 6:31:22 PM | Computer Name = DELL-A79E882B26 | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by -64792 seconds. The time service will not change the system time by more than
-54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com (ntp.m|0x1|121.222.158.74:123->207.46.232.182:123) is working
properly.
Error - 11/30/2010 9:19:34 PM | Computer Name = DELL-A79E882B26 | Source = DCOM | ID = 10010
Description = The server {0EEA2A0F-AD1F-4555-9827-0DD9335611A4} did not register
with DCOM within the required timeout.
Error - 12/1/2010 2:33:37 AM | Computer Name = DELL-A79E882B26 | Source = Dhcp | ID = 1002
Description = The IP address lease 58.165.79.31 for the Network Card with network
address 00A0D5FFFFAE has been denied by the DHCP server 124.186.219.253 (The DHCP
Server sent a DHCPNACK message).
Error - 12/6/2010 7:21:38 PM | Computer Name = DELL-A79E882B26 | Source = DCOM | ID = 10010
Description = The server {0EEA2A0F-AD1F-4555-9827-0DD9335611A4} did not register
with DCOM within the required timeout.
Error - 12/6/2010 7:24:03 PM | Computer Name = DELL-A79E882B26 | Source = Dhcp | ID = 1002
Description = The IP address lease 124.177.118.90 for the Network Card with network
address 00A0D5FFFFAE has been denied by the DHCP server 124.185.70.253 (The DHCP
Server sent a DHCPNACK message).
< End of report >