This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer - not sure if it has a bug or not

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Conspire, thanks for all your help so far. This is the last one I have….its an old desktop (6 years or so) that primarily my kids use, and which is really slow (especially when starting)…could be just because its old, but please give it a look over and see if there are any bugs lurking…below are the OTL Logs:

OTL.TXT

OTL logfile created on: 3/22/2011 12:36:38 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Steve\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 22.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 26.70 Gb Free Space | 35.83% Space Free | Partition Type: NTFS

Computer Name: SHAWDESKTOP1 | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Steve\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\eFax Messenger 4.3\J2GTray.exe (j2 Global Communications, Inc.)
PRC - C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe (j2 Global Communications, Inc.)
PRC - C:\Program Files\Netropa\OSD.exe (Netropa Corp.)
PRC - C:\WINDOWS\MMKeybd.exe (Netropa Corp.)
PRC - C:\Program Files\Netropa\Traymon.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Steve\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (CLTNetCnService) – File not found
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MpKsl467e83ff) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3C07F3DC-F000-4A1C-88C6-D175CF7B4056}\MpKsl467e83ff.sys (Microsoft Corporation)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (MxlW2k) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (GoProto) – C:\WINDOWS\SYSTEM32\DRIVERS\goprot51.sys (Gteko Ltd.)
DRV - (GPCIEnu1) – C:\WINDOWS\SYSTEM32\GPCIEnum.sys (Gteko Ltd.)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (SDDMI2) – C:\WINDOWS\SYSTEM32\DDMI2.sys (Gteko Ltd.)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (ICDUSB2) Sony IC Recorder (P) – C:\WINDOWS\SYSTEM32\DRIVERS\ICDUSB2.sys (Sony Corporation)
DRV - (tbcwdm) – C:\WINDOWS\SYSTEM32\DRIVERS\tbcwdm.sys (Voyetra Turtle Beach)
DRV - (tbcspud) – C:\WINDOWS\SYSTEM32\DRIVERS\tbcspud.sys (Voyetra Turtle Beach)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (rtl8139) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys (Realtek Semiconductor Corporation )
DRV - (hpt3xx) – C:\WINDOWS\System32\DRIVERS\hpt3xx.sys (HighPoint Technologies, Inc.)
DRV - (nv4) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4.SYS (NVIDIA Corporation)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2007/11/17 00:03:26 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe (Netropa Corp.)
O4 - HKLM..\Run: [eFax 4.3] C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe (j2 Global Communications, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe (j2 Global Communications, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll (Yahoo! Inc.)
O9 - Extra Button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (Yahoo! Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1180748275156 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} http://messenger.zone.msn.com/binary/Messe…nt.cab55762.cab (MessengerStatsClient Class)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/bingame/zpagames/zpa_txhe.cab55579.cab (ZPA_TexasHoldem Object)
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} http://www.linksysfix.com/netcheck/67/install/gtdownls.cab (LinkSys Content Update)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} http://messenger.zone.msn.com/binary/WoF.cab57176.cab (WheelofFortune Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.3.1.0.cab (SysInfo Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Steve\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Steve\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/08/31 11:50:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{38081e85-7960-11df-a1b9-00c0a884ae90}\Shell - "" = AutoRun
O33 - MountPoints2\{38081e85-7960-11df-a1b9-00c0a884ae90}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{38081e85-7960-11df-a1b9-00c0a884ae90}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\L3CODECX.ACM (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: VIDC.I263 - C:\WINDOWS\System32\i263_32.drv (Intel Corporation)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i263_32.drv (Intel Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Ligos Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\SYSTEM32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\SYSTEM32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\iyvu9_32.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/22 00:33:30 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Steve\Desktop\OTL.exe
[2011/03/21 22:05:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/03/21 22:01:39 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/03/21 21:30:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/03/21 21:29:49 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/03/21 21:29:48 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/21 21:29:48 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/21 21:29:48 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/21 21:26:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/03/21 21:22:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Steve\Local Settings\Application Data\Google
[2011/03/20 16:47:03 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/03/20 16:44:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2011/03/20 16:42:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/03/20 16:37:50 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/03/20 16:34:55 | 000,000,000 | —D | C] – C:\GameHouse Games
[2011/03/20 16:34:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GameHouse
[2011/03/20 16:34:07 | 000,000,000 | —D | C] – C:\Program Files\RealArcade
[2011/03/15 08:18:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2002/09/28 22:05:53 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\System32\IMPLODE.DLL
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/22 00:37:23 | 000,000,390 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2011/03/22 00:36:01 | 000,000,269 | —- | M] () – C:\WINDOWS\MSIOSD.INI
[2011/03/22 00:33:47 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Steve\Desktop\OTL.exe
[2011/03/21 23:47:01 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/21 22:16:40 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/03/21 22:06:39 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/03/21 22:05:13 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/03/21 21:59:19 | 000,441,456 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/03/21 21:59:19 | 000,071,408 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/03/21 21:56:13 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/21 21:55:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/03/21 21:55:25 | 535,904,256 | -HS- | M] () – C:\hiberfil.sys
[2011/03/21 21:42:17 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/02/28 19:12:15 | 000,000,318 | —- | M] () – C:\WINDOWS\MMKEYBD.INI
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/21 22:15:24 | 000,000,390 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2011/03/21 22:11:26 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/03/21 22:06:04 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/03/21 22:04:25 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/03/20 16:42:47 | 000,000,884 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/20 16:42:41 | 000,000,880 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/12/05 13:25:40 | 000,061,012 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2007/11/12 22:22:03 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2007/11/08 22:34:55 | 000,035,703 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LUInstall.LiveUpdate
[2007/11/04 17:24:53 | 000,000,396 | —- | C] () – C:\WINDOWS\dellstat.ini
[2007/08/16 15:05:09 | 000,001,212 | —- | C] () – C:\WINDOWS\checkip.dat
[2007/04/22 11:56:22 | 000,000,000 | —- | C] () – C:\WINDOWS\DVEdit.INI
[2007/01/27 15:29:10 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2006/12/28 11:05:47 | 000,001,774 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/12/25 13:29:44 | 000,005,509 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/09/21 14:09:55 | 025,184,485 | —- | C] () – C:\Program Files\NV11ESD.exe
[2004/09/21 10:15:05 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/05/30 10:10:06 | 000,000,313 | —- | C] () – C:\WINDOWS\EReg515.dat
[2004/05/30 10:07:57 | 000,001,003 | —- | C] () – C:\WINDOWS\disney.ini
[2004/04/25 13:14:56 | 000,000,199 | —- | C] () – C:\WINDOWS\DHOUSE.INI
[2004/02/10 16:08:00 | 000,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2004/02/02 14:59:43 | 000,000,733 | —- | C] () – C:\WINDOWS\eReg.dat
[2003/12/24 11:44:13 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2003/11/17 22:50:28 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/10/08 01:22:58 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/10/06 15:16:00 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\nvcod.dll
[2003/08/24 11:09:40 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2003/05/17 11:47:20 | 000,056,320 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2003/05/17 11:45:56 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/01 16:01:53 | 000,000,208 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2003/03/06 18:03:00 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2003/02/22 16:07:50 | 000,000,641 | —- | C] () – C:\WINDOWS\hegames.ini
[2002/12/25 12:41:18 | 000,000,011 | —- | C] () – C:\WINDOWS\ka.ini
[2002/11/13 16:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[2002/09/25 00:36:09 | 000,057,856 | —- | C] () – C:\Documents and Settings\Steve\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2002/09/24 23:29:22 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2002/09/14 16:10:19 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2002/08/29 12:50:43 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/08/29 12:41:03 | 000,000,803 | —- | C] () – C:\WINDOWS\lrun32.ini
[2002/08/29 12:38:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2002/08/29 12:36:59 | 001,642,496 | —- | C] () – C:\WINDOWS\System32\mplva6.dll
[2002/08/29 12:36:59 | 001,576,960 | —- | C] () – C:\WINDOWS\System32\mplvw7.dll
[2002/08/29 12:36:59 | 001,548,288 | —- | C] () – C:\WINDOWS\System32\mplvm6.dll
[2002/08/29 12:36:59 | 001,118,208 | —- | C] () – C:\WINDOWS\System32\mplvpx.dll
[2002/08/29 12:36:59 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\mplaw7.dll
[2002/08/29 12:36:59 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\mplaa6.dll
[2002/08/29 12:36:59 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\mplapx.dll
[2002/08/29 12:36:59 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\mplam6.dll
[2002/08/29 12:36:59 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2002/08/29 12:36:13 | 000,000,318 | —- | C] () – C:\WINDOWS\MMKEYBD.INI
[2002/08/29 12:36:13 | 000,000,269 | —- | C] () – C:\WINDOWS\MSIOSD.INI
[2002/08/29 12:36:12 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\msiosd32.dll
[2002/08/29 12:36:12 | 000,000,085 | —- | C] () – C:\WINDOWS\WININIT.INI
[2002/08/29 12:33:14 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/08/29 12:27:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2002/08/29 12:14:14 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/03/26 20:18:27 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/02/27 19:50:00 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2001/08/31 12:23:14 | 000,441,456 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2001/08/31 12:23:14 | 000,071,408 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2001/08/31 11:55:56 | 000,287,704 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2001/08/31 11:50:36 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2001/08/31 11:47:12 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2001/08/23 16:07:14 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2001/08/23 16:07:02 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2001/08/18 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2001/08/18 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2001/08/18 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2001/08/18 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2001/08/18 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2001/08/18 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2001/08/02 12:56:12 | 000,028,672 | —- | C] () – C:\WINDOWS\MMKeybd.dll
[2000/07/27 01:13:02 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\zlib.dll

========== LOP Check ==========

[2002/08/29 12:35:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/03/15 08:18:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/01/02 13:40:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output
[2008/01/02 13:39:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup
[2007/11/12 21:54:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2006/10/06 15:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Renaissance Learning
[2009/03/10 22:14:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/08/14 12:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/12/26 10:35:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivendi Universal Games
[2010/08/22 17:12:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/05 12:41:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/01/02 13:40:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve\Application Data\eFax Messenger
[2010/08/02 12:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve\Application Data\Sierra
[2011/03/21 22:16:40 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/03/22 00:37:23 | 000,000,390 | -H– | M] () – C:\WINDOWS\Tasks\MpIdleTask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2001/08/31 11:50:52 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2004/09/21 10:44:19 | 000,000,211 | —- | M] () – C:\Boot.bak
[2009/03/09 14:37:08 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2001/08/31 11:29:14 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/11/13 01:16:41 | 000,012,733 | —- | M] () – C:\Combo Fix2.txt
[2001/08/31 11:50:52 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2002/08/29 12:19:12 | 000,004,918 | RH– | M] () – C:\DELL.SDR
[2011/03/21 21:55:25 | 535,904,256 | -HS- | M] () – C:\hiberfil.sys
[2001/08/31 11:50:52 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2002/08/29 12:47:17 | 000,000,319 | -H– | M] () – C:\IPH.PH
[2009/03/10 10:58:41 | 000,007,954 | —- | M] () – C:\JavaRa.log
[2002/09/14 16:25:50 | 000,000,050 | RHS- | M] () – C:\lastfile.txt
[2001/08/31 11:50:52 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/09/22 11:22:29 | 000,092,672 | —- | M] () – C:\Northwestern Mutual Fax - Hatting1.doc
[2004/09/21 10:34:07 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/09/21 10:34:07 | 000,250,032 | RHS- | M] () – C:\NTLDR
[2011/03/21 21:55:23 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2009/03/10 17:29:16 | 000,002,695 | —- | M] () – C:\Rooter.txt
[2007/11/19 22:49:09 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2007/12/16 19:47:03 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2007/12/17 20:02:25 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2007/12/17 20:34:59 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2008/04/01 12:42:02 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2008/05/15 18:48:51 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2008/11/09 19:27:30 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/03/01 22:05:35 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/03/28 13:07:42 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/10/14 20:05:42 | 000,000,280 | -H– | M] () – C:\sqmdata09.sqm
[2007/10/30 18:17:12 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2007/10/30 19:10:48 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2007/11/04 16:37:39 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2007/11/04 17:12:03 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2007/11/04 17:29:49 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2007/11/05 21:05:18 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2007/11/12 20:31:06 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2007/11/12 21:59:37 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2007/11/18 14:26:11 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2007/11/19 22:48:52 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2007/11/19 22:49:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2007/12/16 19:47:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2007/12/17 20:02:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2007/12/17 20:34:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/04/01 12:42:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/05/15 18:48:50 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/11/09 19:27:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/03/01 22:05:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/03/28 13:07:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/10/14 20:05:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2007/10/30 18:17:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2007/10/30 19:10:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2007/11/04 16:37:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2007/11/04 17:12:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2007/11/04 17:29:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2007/11/05 21:05:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2007/11/12 20:31:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2007/11/12 21:59:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2007/11/18 14:26:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2007/11/19 22:48:52 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/08/13 11:39:06 | 000,006,188 | —- | M] () – C:\table1.txt
[2007/11/13 01:20:31 | 000,007,628 | —- | M] () – C:\uninstall_list.txt
[2007/08/16 15:07:42 | 000,000,000 | —- | M] () – C:\wizard.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2001/08/31 11:50:10 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/07/29 10:27:40 | 000,078,336 | —- | M] () – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2004/09/21 14:09:56 | 025,184,485 | —- | M] () – C:\Program Files\NV11ESD.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2001/08/31 11:38:54 | 000,090,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2001/08/31 11:38:54 | 000,606,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2001/08/31 11:38:54 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/09/21 10:43:32 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2002/08/29 12:45:41 | 000,000,246 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\INSTALL.LOG

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/09/21 10:52:47 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2003/10/13 14:58:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/06/17 09:49:54 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Steve\Desktop\ATF-Cleaner.exe
[2011/03/22 00:33:47 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Steve\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2002/04/23 16:42:50 | 000,003,718 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{187851b8-ffe2-4ed2-9a4e-c3fd26d7bb47}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-22 04:33:59

< End of report >


EXTRAS.TXT

OTL Extras logfile created on: 3/22/2011 12:36:39 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Steve\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 22.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 26.70 Gb Free Space | 35.83% Space Free | Partition Type: NTFS

Computer Name: SHAWDESKTOP1 | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\SYSTEM32\ftp.exe" = C:\WINDOWS\SYSTEM32\ftp.exe:*:Enabled:File Transfer Program – (Microsoft Corporation)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{10798AE3-DCBB-43C3-9C93-C23512427E25}" = The Sims Deluxe Edition
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 24
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}" = The Sims™ 2 Double Deluxe
"{33AE85D9-0386-41AD-BD99-FDF3ABC19DBB}" =
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Dell Modem-On-Hold
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{556A649F-72D2-4E41-A40C-794E0277AADB}" = System Requirements Lab CYRI
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = MyDVD
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" = Norton 360
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{706D5382-7381-4680-9DD0-161832578252}" = DellTouch
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7FC2AF73-10ED-404E-84A8-636B452404FD}" = Realtek RTL8139 Diagnostics Program
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{91E8A85F-2960-40ED-BA84-7F4567BB00C0}" = Dell | Support
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{94824ADD-8F26-43D2-84DB-22E11F377E5E}" = Microsoft English TTS Engine
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97D0C0A1-7E64-4B05-A2EE-61D2CE23F154}" = TTS Wrapper
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A73B468-AFF0-42C9-9D7A-3FD84A6CE4AE}" = MathFacts in a Flash Home
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D58580-EA01-11D3-9318-008048B86EFE}" = Santa Cruz
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{B3076A28-345A-4d89-90A3-B68866C0DFB8}" = eFax Messenger 4.3
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C82185E8-C27B-4EF4-2008-4444BC2C2B6D}" = Microsoft Streets & Trips 2008
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DF315348-721C-40B8-BAE2-58C6C7D935A2}" = Empire Earth II
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F596C356-BF35-4ED7-981C-CC791461A8F0}" = Empire Earth II: The Art of Supremacy
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"am-turtleodyssey2" = Turtle Odyssey 2
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Photo Printer 720" = Dell Photo Printer 720
"DivX 5.0.2 Bundle" = DivX 5.0.2 Bundle
"DivX Codec" = DivX Codec
"DivX Player" = DivX Player
"EasyLinkAdvisor" = Linksys EasyLink Advisor 1.5 (1045)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{9A73B468-AFF0-42C9-9D7A-3FD84A6CE4AE}" = MathFacts in a Flash Home
"InstallShield_{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"Microsoft Security Client" = Microsoft Security Essentials
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"NVIDIA Display Driver" = NVIDIA Display Driver
"OpenTTD" = OpenTTD 1.0.2
"RealPlayer 6.0" = RealPlayer
"Shockwave" = Shockwave
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster 4.1
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"WGA" = Windows Genuine Advantage Validation Tool
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"Yahoo! Login" = Yahoo! Login
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Messenger Explorer Bar" = Yahoo! Messenger Explorer Bar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ArcView GIS 3.3" = ArcView GIS 3.3
"ArcView StreetMap" = ArcView StreetMap

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/6/2011 1:58:31 PM | Computer Name = SHAWDESKTOP1 | Source = ESENT | ID = 473
Description = Catalog Database (876) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
was partially detached. Error -1032 encountered updating database headers.

Error - 2/13/2011 11:57:53 PM | Computer Name = SHAWDESKTOP1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/20/2011 3:48:47 PM | Computer Name = SHAWDESKTOP1 | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/21/2011 10:06:24 PM | Computer Name = SHAWDESKTOP1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8107.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 3/21/2011 10:06:31 PM | Computer Name = SHAWDESKTOP1 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 3/21/2011 10:17:54 PM | Computer Name = SHAWDESKTOP1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 3.0.8107.0, P3 timeout, P4 1.1.6502.0, P5 fixed, P6 1 _ 512, P7 10 _ not boot,
P8 NIL, P9 NIL, P10 NIL.

Error - 3/21/2011 11:04:24 PM | Computer Name = SHAWDESKTOP1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0, P2 moaccapability, P3 3.0.8107.0, P4
0, P5 0, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 3/21/2011 11:34:14 PM | Computer Name = SHAWDESKTOP1 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 3/22/2011 12:33:55 AM | Computer Name = SHAWDESKTOP1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional – Error 1706. Setup cannot
find the required files. Check your connection to the network, or CD-ROM drive.
For other potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 3/22/2011 12:33:57 AM | Computer Name = SHAWDESKTOP1 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional - Update '{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}'
could not be installed. Error code 1603. Windows Installer can create logs to help
troubleshoot issues with installing software packages. Use the following link for
instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

[ System Events ]
Error - 1/2/2011 1:10:56 AM | Computer Name = SHAWDESKTOP1 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.103
with the system having network hardware address 90:4C:E5:40:9D:92. Network operations
on this system may be disrupted as a result.

Error - 1/2/2011 7:02:50 AM | Computer Name = SHAWDESKTOP1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.103 for the Network Card with network
address 00C0A884AE90 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 2/21/2011 7:41:55 PM | Computer Name = SHAWDESKTOP1 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time-a.nist.gov,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 2/21/2011 7:41:55 PM | Computer Name = SHAWDESKTOP1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 3/11/2011 8:26:40 PM | Computer Name = SHAWDESKTOP1 | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 3/21/2011 10:18:08 PM | Computer Name = SHAWDESKTOP1 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.97.840.0 Update Source: %%851 Update Stage:
%%854 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6502.0 Error code: 0x80070008 Error description: Not
enough storage is available to process this command.

Error - 3/21/2011 10:18:08 PM | Computer Name = SHAWDESKTOP1 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.97.840.0 Update Source: %%851 Update Stage:
%%854 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6502.0 Error code: 0x80070008 Error description: Not
enough storage is available to process this command.

Error - 3/21/2011 10:18:08 PM | Computer Name = SHAWDESKTOP1 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.97.840.0 Update Source: %%851 Update Stage:
%%854 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6502.0 Error code: 0x80070008 Error description: Not
enough storage is available to process this command.

Error - 3/21/2011 10:18:08 PM | Computer Name = SHAWDESKTOP1 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.97.840.0 Update Source: %%851 Update Stage:
%%854 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6502.0 Error code: 0x80070008 Error description: Not
enough storage is available to process this command.

Error - 3/22/2011 12:34:03 AM | Computer Name = SHAWDESKTOP1 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8024002d: Office XP Service Pack 3.


< End of report >
Hi ShawBuck,

This time, same procedure. :)

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Per your request, below are the GMER and Checkup Logs:

GMER LOG:

GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-22 16:00:21
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 MAXTOR_6L080J4 rev.A93.0500
Running: pce2uouu.exe; Driver: C:\DOCUME~1\Steve\LOCALS~1\Temp\pwloypoc.sys


—- System - GMER 1.0.15 —-

SSDT IPVNMon.sys (IPVNMon/Visual Networks) ZwDeviceIoControlFile [0xF83F2803]

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xF822A340, 0x121A5F, 0xF8000020]
.text C:\WINDOWS\System32\nv4_disp.dll section is writeable [0xBF012380, 0x25BA81, 0xF8000020]

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device Udfs.SYS (UDF File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-


CHECKUP LOG:

Results of screen317's Security Check version 0.99.9
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Norton 360
Microsoft Security Essentials
```````````````````````````````
Anti-malware/Other Utilities Check:

Out of date Spybot installed!
Spybot - Search & Destroy 1.4
SpywareBlaster 4.1
Windows Defender
SpywareBlaster 4.1 Out of Date!
Java™ 6 Update 24
Adobe Flash Player 9 (Out of date Flash Player installed!)
Adobe Flash Player
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
Microsoft Security Client Antimalware MsMpEng.exe
``````````End of Log````````````
First off, good news for you. There is no malware found on board. However…. A few things to note, let's start from the top. Please update your XP to SP3 at soonest possible. You might want to consider to look for a second hand 512MB of memory because from the way it looks now, it seems barely enough. Do you know how to look for a suitable RAM? 511.00 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 22.00% Memory free Take note on your HDD space, be careful to not occupy the space for as low as 15%. If you do, you could hamper the performance a lot. 26.70 Gb Free Space | 35.83% Space Free You seem to have two AV installed. Get rid of MSE if your Norton 360 hasn't expired. It is not advisable to have two AV's installed and I suppose you might not know that MSE is also part of AV program. Norton 360 Microsoft Security Essentials
Thank goodness for no Malware! I tried to update to SP3, but it asked for the original XP disks and I have no clue where they are…I have moved twice since I've owned the computer and was looking for them a year or so ago and couldn't find it. Is there a way to work around this?? Regarding the RAM, is it something that I would be able to install, or would I need to take it to a computer repair shop? I'm fairly handy, so I'm not afraid to try…but if it's quite complicated, I'd rather leave it to someone so I don't screw it up. Also, how much more would you recommend….Is 512MB the minimum you would get, or should I add more? Is there a certain type of RAM that my pc would take since it's kind of old? Regarding HDD space, maybe I'll try to move some files off of that pc to my external drive which is currently connected to my laptop… I noticed that one of the logs said that Norton 360 is still on the machine…I was surprised since I know that I removed it long ago (1 year or so), and after checking, it does'nt show up on the add/delete program directory in the control panel. I don't think that it's running, since I don't get any pop-ups or anything like that…but I'm not sure.
You could borrow someone's XP SP2 CD to try because most of them are the same except for the keys. If you still have the license key intact and can borrow the XP CD from somebody, then it should be no problem.

It's fairly straight forward for the RAM install, just that the reason I recommend 512MB is because your PC is a bit too old so I don't think it's worth upgrading anything more than 1GB. You open the case, inside the motherboard you can see something like this. Generally, there are latches or retainer clips for this. Simply push those out and pull the ram, then you can see specifically what RAM you'll need or just bring the RAM to your nearest local computer shop. But make sure you ground yourself first before touching any components to avoid static.

http://www.build-your-own-computer-tips.com/install-ram.html


For Norton, click on the following link and select whichever deemed as appropriate.
http://us.norton.com/support/kb/web_view.j…EN&ln=en_US
Conspire, sorry for the delay in responding….I was out of town for the past few days and have been unable to look for the XP SP2 CD. I have XP on my laptop, but don't remember having a specific SP2 CD…but I'll look in the next day or two to see if I have it. I'll also look into the additional RAM soon. I'll update you in the next day or so…thanks again…
Sorry again…I'm in a really busy period at work and won't be able to get to the RAM or SP3 for a few weeks. Is there anything else I need to do, or is this basically it? And because I don't want to leave you hanging, I will donate for the help you already provided me….thank you so much. I don't want to offend, so please be honest…is $75 a fair donation level? Thanks again…
Not to worry, there is no need to rush to get those things if you're too busy. And I really appreciate for the fact that you still keeping me informed. Actually yeah basically that's what you can do to speed things up in your computer. As for the donation, I'm ready to accept any amount you willing to pay. :) Thanks for informing me and I will continue open this thread until we get this resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI