Advertisement
Guest User

Untitled

a guest
Jul 21st, 2017
100
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.21 KB | None | 0 0
  1. OTL Extras logfile created on: 2/13/2011 4:23:20 AM - Run 1
  2. OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Al Talbot\Desktop
  3. Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
  4. Internet Explorer (Version = 7.0.5730.11)
  5. Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
  6.  
  7. 254.00 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 43.00% Memory free
  8. 624.00 Mb Paging File | 426.00 Mb Available in Paging File | 68.00% Paging File free
  9. Paging file location(s): C:\pagefile.sys 0 0 [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
  12. Drive C: | 18.63 Gb Total Space | 7.56 Gb Free Space | 40.59% Space Free | Partition Type: FAT32
  13.  
  14. Computer Name: DADSCOMPUTER | User Name: Al Talbot | Logged in as Administrator.
  15. Boot Mode: Normal | Scan Mode: Current user
  16. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
  17.  
  18. [color=#E56717]========== Extra Registry (SafeList) ==========[/color]
  19.  
  20.  
  21. [color=#E56717]========== File Associations ==========[/color]
  22.  
  23. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
  24. .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
  25. .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
  26.  
  27. [color=#E56717]========== Shell Spawning ==========[/color]
  28.  
  29. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
  30. batfile [open] -- "%1" %*
  31. cmdfile [open] -- "%1" %*
  32. comfile [open] -- "%1" %*
  33. cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
  34. exefile [open] -- "%1" %*
  35. InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
  36. piffile [open] -- "%1" %*
  37. regfile [merge] -- Reg Error: Key error.
  38. scrfile [config] -- "%1"
  39. scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
  40. scrfile [open] -- "%1" /S
  41. txtfile [edit] -- Reg Error: Key error.
  42. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
  43. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  44. Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
  45. Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
  46. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  47.  
  48. [color=#E56717]========== Security Center Settings ==========[/color]
  49.  
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
  51. "FirstRunDisabled" = 1
  52. "AntiVirusDisableNotify" = 1
  53. "FirewallDisableNotify" = 1
  54. "UpdatesDisableNotify" = 1
  55. "AntiVirusOverride" = 0
  56. "FirewallOverride" = 0
  57. "UacDisableNotify" = 0
  58.  
  59. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
  60. "DisableMonitoring" = 1
  61.  
  62. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
  63.  
  64. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
  65.  
  66. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
  67.  
  68. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
  69.  
  70. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
  71.  
  72. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
  73.  
  74. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
  75.  
  76. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
  77.  
  78. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
  79.  
  80. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
  81.  
  82. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
  83.  
  84. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
  85.  
  86. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
  87.  
  88. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
  89.  
  90. [color=#E56717]========== System Restore Settings ==========[/color]
  91.  
  92. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
  93. "DisableSR" = 0
  94.  
  95. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
  96. "Start" = 0
  97.  
  98. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
  99. "Start" = 2
  100.  
  101. [color=#E56717]========== Firewall Settings ==========[/color]
  102.  
  103. [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
  104.  
  105. [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
  106.  
  107. [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
  108.  
  109. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
  110.  
  111. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
  112. "EnableFirewall" = 0
  113. "DoNotAllowExceptions" = 0
  114.  
  115. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
  116. "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
  117. "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
  118. "139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
  119. "445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
  120. "137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
  121. "138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
  122. "1542:TCP" = 1542:TCP:*:Enabled:Realtek WPS TCP Prot
  123. "1542:UDP" = 1542:UDP:*:Enabled:Realtek WPS UDP Prot
  124. "53:UDP" = 53:UDP:*:Enabled:Realtek AP UDP Prot
  125.  
  126. [color=#E56717]========== Authorized Applications List ==========[/color]
  127.  
  128. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
  129. "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
  130.  
  131. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
  132. "C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
  133. "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
  134. "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
  135. "C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser
  136. "C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze
  137. "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
  138. "C:\Program Files\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe" = C:\Program Files\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan
  139.  
  140.  
  141. [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
  142.  
  143. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  144. "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
  145. "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
  146. "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
  147. "{21984000-3586-4292-87B5-7DCC7A0F04CF}" = Ashley Jones: The Heart Of Egypt
  148. "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 11
  149. "{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
  150. "{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5
  151. "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
  152. "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
  153. "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
  154. "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
  155. "{581CE7EA-A30D-0000-1211-088635773309}" = IOGEAR 802.11 b+g Utility
  156. "{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar
  157. "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
  158. "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
  159. "{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2
  160. "{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
  161. "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
  162. "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
  163. "{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
  164. "{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
  165. "{B26AEDA3-B044-4FC0-B243-871FDAA6D2B6}" = Hex Color Finder
  166. "{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
  167. "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
  168. "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
  169. "{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
  170. "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
  171. "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
  172. "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
  173. "Adobe AIR" = Adobe AIR
  174. "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
  175. "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
  176. "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
  177. "Amazing Adventures Free Trial_is1" = Amazing Adventures Free Trial
  178. "Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
  179. "ASIO4ALL" = ASIO4ALL
  180. "BFGC" = Big Fish Games Client
  181. "CCleaner" = CCleaner
  182. "Christmas Train Screensaver" = Christmas Train Screensaver
  183. "Cradle of Rome Free Trial_is1" = Cradle of Rome Free Trial
  184. "Endless Online" = Endless Online 0.28
  185. "Foxit Reader" = Foxit Reader
  186. "Hawaiian Explorer Pearl Harbour Free Trial_is1" = Hawaiian Explorer Pearl Harbour Free Trial
  187. "Hoyle Casino '98" = Hoyle Casino '98
  188. "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
  189. "ie7" = Windows Internet Explorer 7
  190. "InstallShield_{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
  191. "jewelquest" = Jewel Quest
  192. "Magic Match 1.19" = Magic Match 1.19
  193. "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
  194. "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
  195. "Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5
  196. "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
  197. "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
  198. "MostFun.com Games - Ashley Jones: The Heart Of Egypt" = MostFun.com Games - Ashley Jones: The Heart Of Egypt (remove only)
  199. "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
  200. "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
  201. "No-IP.com DUC" = No-IP.com DUC (remove only)
  202. "OpenAL" = OpenAL
  203. "Peggle Nights Deluxe 1.0" = Peggle Nights Deluxe 1.0
  204. "RealArcade" = RealArcade
  205. "Sierra Utilities" = Sierra Utilities
  206. "SystemRequirementsLab" = System Requirements Lab
  207. "The Weather Channel Desktop 6" = The Weather Channel Desktop 6
  208. "uTorrent" = µTorrent
  209. "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
  210. "White Winter Clock Screensaver" = White Winter Clock Screensaver
  211. "WIC" = Windows Imaging Component
  212. "Windows Media Format Runtime" = Windows Media Format 11 runtime
  213. "Windows Media Player" = Windows Media Player 11
  214. "WinRAR archiver" = WinRAR archiver
  215. "WMFDist11" = Windows Media Format 11 runtime
  216. "wmp11" = Windows Media Player 11
  217. "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
  218. "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
  219.  
  220. [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
  221.  
  222. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  223. "IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software
  224.  
  225. [color=#E56717]========== Last 10 Event Log Errors ==========[/color]
  226.  
  227. [ Application Events ]
  228. Error - 2/13/2011 3:49:32 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  229. Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
  230. and it will not be loaded. This is most likely caused by a faulty registration.
  231.  
  232. Error - 2/13/2011 3:49:32 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  233. Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
  234. and it will not be loaded. This is most likely caused by a faulty registration.
  235.  
  236. Error - 2/13/2011 4:05:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  237. Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
  238. and it will not be loaded. This is most likely caused by a faulty registration.
  239.  
  240. Error - 2/13/2011 4:05:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  241. Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
  242. and it will not be loaded. This is most likely caused by a faulty registration.
  243.  
  244. Error - 2/13/2011 4:05:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  245. Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
  246. and it will not be loaded. This is most likely caused by a faulty registration.
  247.  
  248. Error - 2/13/2011 4:05:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  249. Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
  250. and it will not be loaded. This is most likely caused by a faulty registration.
  251.  
  252. Error - 2/13/2011 5:31:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  253. Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
  254. and it will not be loaded. This is most likely caused by a faulty registration.
  255.  
  256. Error - 2/13/2011 5:31:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  257. Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
  258. and it will not be loaded. This is most likely caused by a faulty registration.
  259.  
  260. Error - 2/13/2011 5:31:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  261. Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
  262. and it will not be loaded. This is most likely caused by a faulty registration.
  263.  
  264. Error - 2/13/2011 5:31:07 AM | Computer Name = DADSCOMPUTER | Source = Userenv | ID = 1041
  265. Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
  266. and it will not be loaded. This is most likely caused by a faulty registration.
  267.  
  268. [ System Events ]
  269. Error - 2/8/2011 4:59:04 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  270. Description = The server's call to a system service failed unexpectedly.
  271.  
  272. Error - 2/8/2011 4:59:04 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  273. Description = The server's call to a system service failed unexpectedly.
  274.  
  275. Error - 2/8/2011 4:59:18 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  276. Description = The server's call to a system service failed unexpectedly.
  277.  
  278. Error - 2/8/2011 4:59:18 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  279. Description = The server's call to a system service failed unexpectedly.
  280.  
  281. Error - 2/8/2011 4:59:19 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  282. Description = The server's call to a system service failed unexpectedly.
  283.  
  284. Error - 2/8/2011 4:59:32 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  285. Description = The server's call to a system service failed unexpectedly.
  286.  
  287. Error - 2/8/2011 4:59:32 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  288. Description = The server's call to a system service failed unexpectedly.
  289.  
  290. Error - 2/8/2011 4:59:45 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  291. Description = The server's call to a system service failed unexpectedly.
  292.  
  293. Error - 2/8/2011 4:59:45 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  294. Description = The server's call to a system service failed unexpectedly.
  295.  
  296. Error - 2/8/2011 4:59:46 AM | Computer Name = DADSCOMPUTER | Source = Srv | ID = 2000
  297. Description = The server's call to a system service failed unexpectedly.
  298.  
  299.  
  300. < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement