OTL Extras logfile created on: 11/2/2010 9:54:19 AM - Run 1 OTL by OldTimer - Version 3.2.17.2 Folder = C:\Documents and Settings\PJL\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1,023.00 Mb Total Physical Memory | 656.00 Mb Available Physical Memory | 64.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free Paging file location(s): C:\pagefile.sys 1536 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 28.60 Gb Total Space | 18.32 Gb Free Space | 64.04% Space Free | Partition Type: NTFS Computer Name: NEMUE | User Name: PJL | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Browse with FastStone] -- "C:\Program Files\FastStone Image Viewer\FSViewer.exe" "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00CD55D6-EE5A-4570-9875-8A306628C032}" = Cisco Systems VPN Client 4.7.00.0533 "{1C943495-B69F-4D41-AE0E-23C57ECD90EE}" = Debugging Tools for Windows "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 21 "{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}" = Internet Worm Protection "{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}" = SymNet "{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10 "{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1 "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3C759736-8347-4031-BB9C-D75ADFE6B101}" = Norton Ghost 9.0 "{3EC91FDF-FE9A-43D5-96C4-8A9C24372500}" = Maxtor OneTouch "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0 "{6A7867BA-B7CA-4CC9-ACAB-85BA46865EE5}" = Norton Utilities "{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC "{807B1E67-FF69-4170-A835-E4B2C8A1D389}" = WRQ Reflection for UNIX and OpenVMS 10.0 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{900B1884-2D6F-4a70-A3C7-C3F4DA873FDB}" = NSW_DRM_COLLECTION "{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{9E23C48E-5483-4971-BA50-089F2FABCD66}" = Norton SystemWorks "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3 "{B9807C3D-B3DD-41B7-8321-53DDB3A3A888}" = Norton SystemWorks 2005 Premier "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C62F526B-76F7-477E-86EB-7A725E5B3C64}" = Positive Networks "{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2005 "{C713C8B5-F0E1-401D-AE9B-3AB0E180D626}" = WinDriversBackup "{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}" = Symantec Network Drivers Update "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D1725BDB-BA2B-4503-A8CB-F5C835D743FA}" = MSRedist "{D327AFC9-7BAA-473A-8319-6EB7A0D40138}" = Symantec Script Blocking Installer "{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD "{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}" = ccCommon "{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton AntiVirus Parent MSI "{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F64306A5-4C32-41bb-B153-53986527FAB4}" = Norton WMI Update "{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard "ActiveTouchMeetingClient" = WebEx "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player "CCleaner" = CCleaner "FastStone Image Viewer" = FastStone Image Viewer 4.2 "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{3EC91FDF-FE9A-43D5-96C4-8A9C24372500}" = Maxtor OneTouch "jv16 PowerTools 2010" = jv16 PowerTools 2010 "LiveReg" = LiveReg (Symantec Corporation) "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "MXOFX" = USB Storage Adapter FX (MXO) "NVIDIA Drivers" = NVIDIA Drivers "PROSet" = Intel(R) PRO Ethernet Adapter and Software "Remote Administrator v2.1" = Remote Administrator v2.1 "Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20 "SymSetup.{B9807C3D-B3DD-41B7-8321-53DDB3A3A888}" = Norton SystemWorks 2005 Premier (Symantec Corporation) "Tweak UI 2.10" = Tweak UI "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinZip" = WinZip "Wise Disk Cleaner_is1" = Wise Disk Cleaner 5.62 "Wise Registry Cleaner_is1" = Wise Registry Cleaner Free 5.33 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 1/26/2010 9:09:33 AM | Computer Name = NEMUE | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.18828, fault address 0x002c7033. Error - 9/19/2010 9:50:39 AM | Computer Name = NEMUE | Source = MsiInstaller | ID = 10005 Description = Product: Norton CleanSweep -- Norton Cleansweep installation must be run as a nested installation from Norton SystemWorks. Setup will exit. Error - 9/19/2010 9:51:47 AM | Computer Name = NEMUE | Source = MsiInstaller | ID = 10005 Description = Product: Norton CleanSweep -- Norton Cleansweep installation must be run as a nested installation from Norton SystemWorks. Setup will exit. Error - 9/23/2010 10:14:29 AM | Computer Name = NEMUE | Source = MsiInstaller | ID = 10005 Description = Product: Norton CleanSweep -- Norton Cleansweep installation must be run as a nested installation from Norton SystemWorks. Setup will exit. Error - 10/2/2010 10:28:54 AM | Computer Name = NEMUE | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Error - 10/5/2010 9:24:07 AM | Computer Name = NEMUE | Source = MSDTC | ID = 4163 Description = MS DTC log file not found. After ensuring that all Resource Managers coordinated by MS DTC have no indoubt transactions, please run msdtc -resetlog to create the log fil Error - 10/5/2010 9:24:07 AM | Computer Name = NEMUE | Source = MSDTC | ID = 4185 Description = MS DTC Transaction Manager start failed. LogInit returned error 0x Error - 10/5/2010 9:24:07 AM | Computer Name = NEMUE | Source = MSDTC | ID = 4112 Description = Could not start the MS DTC Transaction Manage Error - 10/5/2010 9:24:07 AM | Computer Name = NEMUE | Source = COM+ | ID = 135763 Description = The run-time environment was unable to initialize for transactions required to support transactional components. Make sure that MS-DTC is running. (DtcGetTransactionManagerEx(): hr = 0x8004d01 [ System Events ] Error - 10/19/2010 8:41:52 AM | Computer Name = NEMUE | Source = DCOM | ID = 10005 Description = DCOM got error "%1068" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} Error - 10/19/2010 8:41:52 AM | Computer Name = NEMUE | Source = Service Control Manager | ID = 7001 Description = The Universal Plug and Play Device Host service depends on the SSDP Discovery Service service which failed to start because of the following error: %%1058 Error - 10/19/2010 8:43:39 AM | Computer Name = NEMUE | Source = DCOM | ID = 10005 Description = DCOM got error "%1068" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} Error - 10/19/2010 8:43:39 AM | Computer Name = NEMUE | Source = Service Control Manager | ID = 7001 Description = The Universal Plug and Play Device Host service depends on the SSDP Discovery Service service which failed to start because of the following error: %%1058 Error - 10/22/2010 10:10:05 AM | Computer Name = NEMUE | Source = DCOM | ID = 10005 Description = DCOM got error "%1058" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error - 10/25/2010 1:52:09 PM | Computer Name = NEMUE | Source = DCOM | ID = 10005 Description = DCOM got error "%1053" attempting to start the service LiveUpdate with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435} Error - 10/25/2010 1:52:09 PM | Computer Name = NEMUE | Source = Service Control Manager | ID = 7009 Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect. Error - 10/26/2010 10:21:56 AM | Computer Name = NEMUE | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.50.10 for the Network Card with network address 0007E9B77093 has been denied by the DHCP server 192.168.50.1 (The DHCP Server sent a DHCPNACK message). Error - 10/27/2010 3:04:23 PM | Computer Name = NEMUE | Source = DCOM | ID = 10005 Description = DCOM got error "%1058" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error - 10/27/2010 3:18:30 PM | Computer Name = NEMUE | Source = DCOM | ID = 10005 Description = DCOM got error "%1058" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} < End of report >